We are a small, founder-led company and we collect remarkably little about you. This policy sets out exactly what we do collect, why, who sees it, how long we keep it, and the rights you have over it — written to be read, not to be skimmed past.
There are no contact forms on this website and we do not run a mailing list, so we do not collect your details unless you choose to call, email or use our live chat. We do not sell your personal information and never have. We do not show behavioural advertising on this site. The main things we collect are server logs, analytics data, and whatever you tell us when you get in touch about work.
Scriplit LLC is a limited liability company registered with the Wyoming Secretary of State (Company ID 2024-001536050), with its registered office at 30 N Gould St Ste R, Sheridan, WY 82801, United States. We operate the website at scriplit.com and provide digital and business filing services.
For the purposes of the EU General Data Protection Regulation (Regulation (EU) 2016/679) and the UK GDPR, Scriplit LLC is the controller of the personal data described in this policy. For the purposes of the California Consumer Privacy Act as amended by the CPRA, we are a business.
You can reach our privacy contact at contact@scriplit.com or by telephone on (901) 401-0039. Because of our size we have not appointed a statutory Data Protection Officer, which is permitted under Article 37 GDPR as our processing is neither large-scale nor systematic monitoring. Privacy enquiries go directly to our founder.
This policy covers personal information we handle when you visit scriplit.com, contact us by any channel, engage us for services, or are a representative of a client or supplier.
It does not cover: websites we build for clients, which are governed by that client's own privacy policy; third-party websites we link to; or personal data we process purely on a client's behalf as a processor, where the client is the controller and their own policy and our written processing agreement govern instead.
Below are the categories of personal information we have collected in the preceding 12 months, expressed using the category labels required by California law so that the same table serves both US and European disclosure requirements.
| Category | Examples of what this means for us | Collected? |
|---|---|---|
| Identifiers | Name, email address, telephone number, postal address, IP address, and identifiers held in cookies | Yes |
| Customer records | Billing name and address, records of services purchased, correspondence with us | Yes |
| Commercial information | Services you enquired about or purchased, quotes issued, project history | Yes |
| Internet or network activity | Pages viewed, time on page, referring URL, browser and operating system, interactions with our live chat | Yes |
| Geolocation data | Approximate city or country inferred from your IP address. We do not collect precise GPS location | Approximate only |
| Professional or employment information | Company name, job title, business sector — where you tell us | Yes |
| Government identifiers (LLC and tax clients only) | Passport or national ID details, EIN, ITIN, and the information required on IRS and state filings | Only where you engage us for company formation or tax filing |
| Payment information | Handled entirely by our payment processors. We receive confirmation and the last four digits only — we never see or store your full card number | Limited |
| Biometric information | — | No |
| Sensitive personal information | Racial or ethnic origin, religion, health, sex life, political opinions, union membership, genetic data | No — we do not seek or want this |
| Inferences and profiling | Behavioural profiles built to predict characteristics or preferences | No |
If you engage us to form a US LLC or file US tax returns, we necessarily handle government identifiers such as passport details, EIN and ITIN. Under Article 9 GDPR these are not "special category" data, but California treats some government identifiers as sensitive personal information. We collect them only where a government form requires them, use them for no purpose other than completing that filing, and you may direct us to limit their use as described in section 14.
We do not buy personal data from data brokers, and we do not scrape contact lists.
Article 13(1)(c) GDPR requires us to tell you the purpose of each use and the legal basis we rely on. This table does that.
| What we do | Why | Legal basis (GDPR / UK GDPR) |
|---|---|---|
| Respond to your enquiry | To answer your question and prepare a quote | Steps taken at your request prior to entering a contract — Art. 6(1)(b) |
| Deliver the services you bought | To perform our side of the agreement | Performance of a contract — Art. 6(1)(b) |
| Submit government filings | To register your company or file your returns | Performance of a contract — Art. 6(1)(b); and legal obligation — Art. 6(1)(c) |
| Take and record payment | To get paid and keep accurate accounts | Contract — Art. 6(1)(b); legal obligation for tax records — Art. 6(1)(c) |
| Keep our website secure and working | To prevent abuse, detect faults and maintain availability | Legitimate interests — Art. 6(1)(f): running a secure service |
| Analytics and site improvement | To understand which pages are useful | Your consent — Art. 6(1)(a), where required. Withdrawable at any time |
| Live chat | To let you talk to us instantly | Your consent — Art. 6(1)(a). The chat widget does not load until you allow it |
| Keep records of a project | To evidence what was agreed and delivered, and defend claims | Legitimate interests — Art. 6(1)(f): establishing and defending legal claims |
| Comply with law | Tax, accounting, anti-money-laundering and sanctions obligations | Legal obligation — Art. 6(1)(c) |
Where we rely on legitimate interests, we have carried out a balancing assessment and concluded that our interest does not override your rights. You may object to any such processing at any time under Article 21 GDPR, and we will stop unless we can demonstrate compelling grounds that override your interests.
Where we rely on consent, you may withdraw it at any time under Article 7(3) GDPR. Withdrawing consent is as easy as giving it, and does not affect the lawfulness of anything we did beforehand.
Scriplit has never sold personal information, and does not share it for cross-context behavioural advertising, as those terms are defined in the California Consumer Privacy Act and equivalent state laws. We have not done so in the preceding 12 months and we have no plans to. We also do not sell or share the personal information of anyone we know to be under 16.
Because we do not sell or share, there is nothing for you to opt out of. We still honour Global Privacy Control signals and still provide the opt-out mechanism described in section 14, so that you never have to take our word for it.
We disclose personal information for business purposes only, to the recipients listed in section 7, each of whom is contractually barred from using it for their own purposes.
Article 13(2)(a) GDPR requires us to tell you our retention periods, not merely that we have some.
| What | How long | Why that long |
|---|---|---|
| Enquiries that never became projects | 12 months | So we have context if you come back to us |
| Client project files and correspondence | 6 years after the engagement ends | Matches the longest general limitation period for contract claims |
| Invoices and accounting records | 7 years | US federal and state tax record-keeping requirements |
| Company formation and tax filing records | 7 years after the last filing | IRS record-keeping expectations and potential audit window |
| Live chat transcripts | 12 months | Support quality and dispute resolution |
| Server access logs | 90 days | Security monitoring and fault diagnosis |
| Analytics data | 14 months maximum | Enough for year-on-year comparison, no longer |
| Cookie consent records | 12 months | To evidence that consent was validly obtained |
When a retention period ends we delete the data or irreversibly anonymise it. If you ask us to erase your data sooner we will do so, except where we are legally required to keep it — and if that happens we will tell you precisely which obligation prevents deletion.
Scriplit is based in the United States, so if you are outside the US your personal data will be transferred to and processed there. The United States does not have an adequacy decision covering all transfers, so we rely on the safeguards required by Chapter V GDPR:
You may request a copy of the safeguards we have in place by emailing contact@scriplit.com. We will provide them, redacted only for commercial terms.
We apply technical and organisational measures appropriate to the risk, as required by Article 32 GDPR. In concrete terms: the whole site is served over HTTPS with HSTS; access to client files is restricted to those who need it and protected by multi-factor authentication; payment card data never touches our servers because it goes directly to PCI-DSS compliant processors; we keep software patched; and we review who has access on a regular basis.
We will not claim our systems are unbreakable, because no honest company can. Transmission over the internet carries inherent risk. What we can commit to is that we take security seriously, we limit what we collect so there is less to lose, and if something does go wrong we will tell you promptly as set out in section 17.
Everyone who contacts us gets the following, regardless of where you live. We apply the strongest standard to all users rather than sorting people by jurisdiction.
Find out what we hold about you and get a copy of it.
Have inaccurate or incomplete information put right.
Have your data erased, where no legal obligation requires us to keep it.
Receive your data in a structured, machine-readable format.
Object to processing based on our legitimate interests.
Have processing paused while a dispute about accuracy is resolved.
Change your mind at any time, as easily as you consented.
Exercise any right without being charged more or given a worse service.
If you are in the European Economic Area, the United Kingdom or Switzerland, the rights in section 12 correspond to Articles 15 to 22 GDPR and you additionally have:
We respond to requests within one month as required by Article 12(3) GDPR, extendable by two further months for genuinely complex requests, in which case we will tell you within the first month and explain why.
We do not currently have an establishment in the EU or UK and have assessed that we are not required to designate a representative under Article 27 GDPR, because our processing of EU residents' data is occasional, does not involve large-scale processing of special categories, and is unlikely to result in a risk to rights and freedoms. If that changes we will appoint a representative and name them here.
Under the California Consumer Privacy Act, Cal. Civ. Code § 1798.100 et seq., as amended by the CPRA, California residents have the right to know, delete, correct, opt out of sale or sharing, limit the use of sensitive personal information, and not be discriminated against for exercising any of these.
The categories we collect, our purposes, and the recipients we disclose to are set out in sections 3, 5 and 7 respectively, which together satisfy the notice-at-collection requirement. As stated in section 8, we do not sell or share personal information, so the "Do Not Sell or Share My Personal Information" right has nothing to act upon — but the mechanism is available at contact@scriplit.com and through the Global Privacy Control signal, which we honour automatically.
Limiting sensitive personal information. We use the government identifiers described in section 3 solely to perform the filing you engaged us for, which is a permitted purpose under § 1798.121(a) that does not trigger the right to limit. You may still ask us to restrict their use, and we will comply to the extent it does not make the filing impossible.
Authorised agents. You may use an authorised agent to make a request. We will ask for written proof of authorisation signed by you, and may ask you to verify your own identity directly.
Financial incentives. We do not operate any financial incentive or loyalty programme involving personal information.
Shine the Light. Under Cal. Civ. Code § 1798.83, California residents may request details of personal information shared with third parties for their direct marketing purposes. We do not share personal information for that purpose.
Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland and other states with comprehensive privacy laws in force have substantially similar rights: to confirm processing and access data, correct it, delete it, obtain a portable copy, and opt out of targeted advertising, sale, and certain profiling.
We recognise universal opt-out mechanisms including Global Privacy Control, as required by Colorado, Connecticut, Texas, Montana, Oregon and others.
Right to appeal. If we refuse your request, you may appeal by replying to our decision with the word "Appeal". We will review and respond in writing within 45 days, explaining our reasoning. If we deny the appeal we will give you a link to lodge a complaint with your state Attorney General. This appeal right is required by Virginia, Colorado, Connecticut, Texas and several other states, and we extend it to every US resident.
Nevada. Nevada residents may direct us not to sell covered information under NRS 603A. We do not sell it, but requests may be sent to contact@scriplit.com.
Email contact@scriplit.com with "Privacy Request" in the subject line, or call (901) 401-0039. Tell us what you want and enough detail for us to find your records.
Our website and services are aimed at businesses and are not directed at children. We do not knowingly collect personal information from anyone under 16.
Under the US Children's Online Privacy Protection Act (COPPA), 15 U.S.C. §§ 6501–6506, verifiable parental consent is required before collecting personal information from a child under 13. Under Article 8 GDPR, information society services offered directly to a child require parental consent below an age set by each member state between 13 and 16. We apply the higher threshold of 16 everywhere rather than tracking the varying national ages.
If you believe a child has provided us with personal information, contact us and we will delete it promptly. If we discover it ourselves, we will delete it without waiting to be asked.
If a personal data breach occurs we will act quickly and tell you honestly.
We will not delay notification to protect our reputation.
We do not carry out automated decision-making that produces legal effects concerning you or similarly significantly affects you, within the meaning of Article 22 GDPR. We do not profile you for advertising and we do not use automated systems to accept or reject clients — a human being makes every decision about your work.
We use AI tools internally to assist with drafting and development. Where any client personal data is involved, it is handled under agreements that prohibit the provider from training models on it. We will never make a decision about you that has a significant effect without a human reviewing it.
Our site links to other websites, including social media profiles, payment providers and government resources. Once you follow a link, that site's own privacy policy governs. We have no control over them and are not responsible for their practices, so it is worth reading their policies before giving them anything.
Where we build a website for a client, that finished site is operated by the client under their own privacy policy. Scriplit is not the controller for data collected through a client's site once it has been handed over.
We may update this policy to reflect changes in what we do or in the law. The "Last updated" date at the top always shows the current version.
For material changes — a new purpose, a new category of recipient, or a change in legal basis — we will give prominent notice on the site and, where we hold your contact details and the change affects you, email you at least 14 days before it takes effect. Where a change requires your consent under applicable law, we will ask for it rather than assume it.
For any privacy question, request or complaint:
Scriplit LLC — Privacy EnquiriesWe aim to answer every privacy enquiry within one business day and to resolve complaints ourselves. If we cannot, you always have the right to go to your data protection authority or state Attorney General, and we will never discourage you from doing so.
Choose which categories you are comfortable with. You can change this at any time from the “Cookie settings” link in the footer. Every cookie we set is listed individually in our Cookie Policy.
Required for the site to function and to remember your cookie choices. No consent is needed for these under Article 5(3) of the ePrivacy Directive.
Powers our live chat widget (tawk.to). Decline this and the site works normally, you just will not see live chat — phone, email and WhatsApp still work.
Aggregate statistics about which pages are useful and where the site is confusing. Never used to identify you or build a profile.
We do not run advertising or cross-site tracking cookies on this website, so there is nothing here to switch on.