Digital Vibes Design (“Digital Vibes”, “we”, “us”) is a web design and local marketing studio based in Salinas, California, operated by Roberto Cerda. This policy covers our website at digitalvibes.design, our online store at shop.digitalvibes.design, our on-site AI chat and voice assistant, and the forms and audits we run on those sites.
Reading this page, browsing the site, chatting with the assistant or buying a service means this policy applies to you. If you disagree with it, please don’t use the site or the store.
1. Information you give us
- Contact and lead details. Name, business name, email address, phone number, city and whatever you type into a message field, when you use a contact form, request an audit, take the Local SEO Scorecard, unlock a Google Business Profile report, or start an intake.
- Project intake information. Answers about your business, services, hours, service area, competitors, existing accounts, and any documents or images you upload so we can build or manage something for you.
- Conversations. Messages you send to the AI assistant, and, if you start voice mode, the audio you speak and its transcript. Conversation turns are stored so the assistant has context and so a human can follow up on a real lead.
- Order details. What you bought, the plan you chose, billing email, and billing address as required for tax. Card numbers never touch our servers. See section 4.
2. Information collected automatically
- Usage data. Pages viewed, referring page, approximate location derived from IP address, device, browser and language, timestamps, and which buttons or CTAs were clicked.
- A visitor identifier. A random ID stored in your browser that lets us tie a conversation to the pages that preceded it, and to remember your language preference. It is not tied to your name unless you give us your name.
- Cookies and similar storage. Set by us for the items above and by the analytics and advertising tools in section 4. Section 5 covers your choices.
- Server logs. Standard request logs kept by our hosting provider for security and debugging, including IP address.
3. Why we use it
- To answer your question, prepare a quote, run the audit you asked for, and follow up on it.
- To deliver, support and improve the services you bought.
- To take payment, renew a subscription, issue a receipt and handle refunds.
- To measure which pages and campaigns actually produce customers, and to show ads to people who visited the site.
- To keep the site working and secure: rate limiting, abuse prevention, debugging.
- To meet legal, tax and accounting obligations.
We do not use your information to make automated decisions that produce legal effects about you.
4. Who processes it on our behalf
We are a small studio and we use established vendors rather than building everything ourselves. Each one receives only what it needs to do its job, and is contractually a service provider, not an independent owner of your data.
| Provider | What it handles |
|---|---|
| Vercel | Website hosting, server logs, page performance and traffic analytics |
| Supabase | The database that stores leads, conversations, audits and intake answers |
| Shopify | The online store at shop.digitalvibes.design, including checkout and order records |
| Stripe | Card payments and subscription billing |
| Google (Analytics 4, Tag Manager, Ads) | Traffic measurement and ad measurement |
| Meta (Facebook Pixel) | Ad measurement and audiences for Facebook and Instagram |
| OpenAI | The language and voice models behind the on-site assistant |
| Mem0 | Conversation memory, so the assistant remembers context between visits |
| Langfuse | Logging of assistant conversations so we can debug and improve them |
| GoHighLevel | Our CRM: leads, notes, appointments and follow-up messages |
| Upstash | Rate limiting and caching |
Card numbers, CVV codes and full payment credentials are handled by Stripe and Shopify and are never stored on our systems. We see the last four digits, the card brand and the result.
We may also disclose information when the law requires it, to enforce our terms, to protect someone’s safety, or to a buyer if the business is ever sold. If that last one ever happens, this policy travels with the data.
We do not sell your personal information for money. Our use of Google and Meta advertising tags may count as “sharing” for cross-context behavioral advertising under California law. See the CCPA Notice for what that means and how to opt out.
5. Your choices
- Cookies. Your browser can block or delete cookies. Blocking them may break the chat and the store cart.
- Google Analytics. Install the Google Analytics opt-out add-on.
- Meta ads. Adjust your Facebook ad preferences.
- Marketing email and SMS. Every marketing email has an unsubscribe link; reply STOP to any text.
- The assistant. Don’t type or say anything into chat you wouldn’t want stored: health details, government IDs, card numbers, or passwords. Ask for a call instead and we’ll take it verbally.
- Do Not Track. Browsers send this signal inconsistently and there is no agreed standard, so we do not respond to it. We do honor the requests described in the CCPA Notice.
6. How long we keep it
- Leads, conversations and audits: up to 3 years from your last interaction with us, then deleted or anonymized.
- Client project files and intake answers: for the life of the engagement plus 3 years.
- Orders, invoices and tax records: 7 years, because tax law requires it.
- Server and analytics logs: per the provider’s retention, typically 14 months or less.
You can ask us to delete sooner. See section 8.
7. Security
The site is served over TLS. The database uses row-level security so one visitor’s records aren’t reachable from another’s session. Admin surfaces are token-gated. Secrets live in environment variables, not in the codebase.
No system is perfectly secure, and we won’t pretend otherwise. If a breach ever affects your personal information, we will notify you as California law requires.
8. Your rights and how to use them
Depending on where you live, you may have the right to know what we hold, get a copy, correct it, delete it, opt out of sale or sharing, and not be discriminated against for asking. California residents: the CCPA Notice is the detailed version, with the categories and the request process.
To make a request, email hey@digitalvibes.design with “Privacy request” in the subject, or call (831) 214-4827. We answer within 45 days and will tell you if we need the one extension the law allows. We may need to verify who you are before we act, usually by confirming details we already have on file.
9. Children
The site and the store are for businesses and are not directed to children. We do not knowingly collect personal information from anyone under 16. If you believe a child gave us information, email us and we’ll delete it.
10. Where your information is processed
We operate in the United States and our providers process data in the United States. If you use the site from outside the US, you are sending your information to the US, where privacy law differs from your home country’s.
11. Changes
When this policy changes we update the “Last updated” date at the top. Material changes get a notice on the site. The current version always lives at digitalvibes.design/privacy-policy.
12. Contact
Digital Vibes Design Salinas, California, United States Email: hey@digitalvibes.design Phone: (831) 214-4827
A postal address for formal notices is available on request.