Privacy notice
What this website collects, what happens to it, and how to get rid of it. Short, because the site does very little.
Version 1.0, 18 September 2026
This notice covers the website at applocksmith.com.
It does not cover the data I see inside your systems when you hire me. That is governed by your engagement terms and any NDA we sign, and the short version is that it stays between us, it's kept only as long as the work needs, and it's never used for anything else.
Who is responsible
Nate Parker, a sole proprietor in Pennsylvania, United States, trading as App Locksmith. I'm the only person who sees anything collected here. Contact: [email protected].
What this site does not do
It's worth stating plainly, because almost every site says the opposite:
- No cookies. None at all.
- No advertising, no advertising networks, no retargeting, no pixels.
- No third-party scripts. The font is served from this site rather than a font service, so no other company sees that you visited.
- Nothing is ever sold, rented or shared for anyone else's marketing.
- No profiling, and no automated decisions made about you.
What is stored on your device
One thing. If you arrive from a tagged link, the campaign tags, the site you came from and the page you landed on are kept in your browser's session storage under the name al_src. It is deleted when you close the tab, it is never sent anywhere unless you send the form, and it exists so that a message tells me which post or message brought you here.
It is not a cookie and it can't follow you to any other website.
What the booking form collects
Only what you put in it, plus the context of where it was sent from:
- Your email address, and whatever you write in the message.
- A phone number, only if you choose to give one. The field is optional and the form works without it. I use it to call you about your enquiry and nothing else: no texts, no marketing, and it is never given to anyone.
- Which page you sent it from and which service that page offers.
- Those same campaign tags, if you arrived by a tagged link.
- The time you sent it, and the country your request came from, as reported by Cloudflare.
- Nothing else. Not your name unless you write it, and not your IP address.
When you send it, the message is delivered to a private chat channel that only I can read, and may also be kept in Cloudflare's key-value storage so that nothing is lost if the channel fails.
Server logs and analytics
The site runs on Cloudflare Pages. Cloudflare processes every request and keeps its own short-term logs, including IP addresses, to deliver the site and protect it from attack. That's Cloudflare acting as my processor, and it's covered by their terms.
If page analytics are switched on, they are Cloudflare Web Analytics, which sets no cookies, does not fingerprint visitors and reports only aggregate counts. I use it to see which pages people read, not who read them.
Why I hold any of it
To reply to you. To work out whether I can help. To know which of the things I write and post actually lead to conversations, so I can stop doing the ones that don't.
That's the entire list. There is no other use and no other recipient.
How long it's kept
Enquiries that don't turn into work: up to 24 months, then deleted.
Enquiries that do: kept with the client records for as long as the work and my tax and business records require, normally seven years.
Session storage: until you close the tab.
Getting it changed or deleted
Email [email protected] and ask. I'll tell you what I hold, correct it, or delete it, normally within a few days and at most within thirty.
I do this for anyone who asks, wherever you live, rather than only for people whose local law compels it. It's one person and a chat channel; it isn't hard.
If you're in California
App Locksmith is far below every threshold that makes the CCPA and CPRA apply. I follow the parts that matter anyway: I don't sell or share personal information, I've never done so, and I'll honour access and deletion requests as described above.
If you're in the UK or the EU
The site is run from the United States and anything you send is processed there.
Where the UK GDPR or EU GDPR applies to an enquiry you send me, I rely on legitimate interests: you asked me to get in touch about a service, and replying to you is the obvious use. You can object at any time by emailing me, and I'll delete what I hold.
You have the right to ask what I hold, to have it corrected or deleted, and to complain to your data protection authority.
Children
This site sells security work to businesses. It isn't aimed at children and I don't knowingly collect anything from anyone under 16.
Keeping it safe
The site is HTTPS only. It ships a strict content security policy that blocks anything not served from this domain, so a third-party script can't be injected into a page and read what you type. The form posts to this site and nowhere else.
That's a small amount of protection for a small amount of data, which is the point: the best way to keep your data safe is not to collect it.
Changes
If this notice changes, the version and date at the top change with it. Material changes get a note on the home page for a month.
Questions: [email protected].