← Red Rooster Labs

Privacy Policy

Last updated: 20 July 2026

In short: we collect the information you send us through our contact form, and we use it to reply to you. We do not use advertising or analytics cookies, we do not track you across sites, and we do not sell your personal data.

1. Who is responsible for your data

Red Rooster Labs LLC, a Delaware limited liability company ("Red Rooster Labs", "we", "us"), registered at 8 The Green, Suite B, Dover, DE 19901, United States, is the controller of the personal data described in this policy.

We operate certain products under trade names or "doing business as" (DBA) designations. Unless a product publishes its own privacy policy, this policy applies to it.

Privacy contact: hello@redroosterlabs.com

2. What we collect

Information you give us

When you submit our contact form, we collect:

  • your name;
  • your work email address;
  • your company name, if you provide it;
  • the type of engagement you select; and
  • the content of your message.

If you become a client, we also process the contact and billing information needed to perform and invoice the engagement.

Information collected automatically

When you submit the contact form we record your IP address and browser user-agent string alongside the submission. We use these only to detect and prevent automated abuse of the form.

Our hosting provider processes standard server request data (including IP address) to deliver the site and protect it from attack.

Cookies

This site does not use cookies for analytics, advertising, or tracking. We do not operate cross-site tracking and we do not respond to Do Not Track signals because we do not track you in the first place.

3. Why we use it, and our legal basis

For individuals in the European Economic Area and the United Kingdom, the General Data Protection Regulation (GDPR) requires us to state a legal basis:

  • Responding to your enquiry — legal basis: steps taken at your request prior to entering a contract (Art. 6(1)(b) GDPR).
  • Delivering services and invoicing — legal basis: performance of a contract (Art. 6(1)(b) GDPR).
  • Preventing abuse and securing the site — legal basis: our legitimate interest in protecting our infrastructure (Art. 6(1)(f) GDPR).
  • Meeting tax and accounting obligations — legal basis: compliance with a legal obligation (Art. 6(1)(c) GDPR).

We do not use your contact-form data to send marketing communications unless you separately ask us to.

4. Who we share it with

We do not sell or rent personal data. We share it only with service providers who process it on our behalf under contract:

  • Google Cloud Platform — website hosting and storage of contact form submissions.
  • Google Workspace — delivery of the notification email generated by your submission, and our business email, where your message is received and read.
  • Payment processors and merchants of record — for clients only, to process payments. We do not receive or store your full card details.

We may also disclose personal data where required by law, to enforce our agreements, or in connection with a merger, acquisition, or sale of assets, in which case we will notify affected individuals where required.

5. International transfers

We are established in the United States and our service providers are primarily located there. If you are in the European Economic Area, the United Kingdom, Switzerland, or Latin America, your personal data will be transferred outside your country.

Where required, these transfers rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or an applicable adequacy decision or certification held by the receiving provider. You may request information about the safeguards applied by writing to us.

6. How long we keep it

  • Contact-form submissions that do not lead to an engagement: up to 24 months from the last contact, then deleted.
  • Client records: for the duration of the relationship and afterwards for the period required by tax, accounting, and limitation-period rules, typically seven (7) years.
  • Abuse-prevention data (IP, user agent): up to 12 months.

7. Your rights

Depending on where you live, you may have some or all of the following rights: access to your data, correction, deletion, restriction of processing, objection to processing, portability, and the right to withdraw consent where processing is based on consent.

European Economic Area and United Kingdom (GDPR / UK GDPR)

You may exercise the rights above and lodge a complaint with your national supervisory authority, or with the UK Information Commissioner's Office, if you believe we have handled your data unlawfully.

California (CCPA / CPRA)

You have the right to know what personal information we collect, to request its deletion or correction, and to be free from discrimination for exercising these rights. We do not sell or share personal information as those terms are defined by the CCPA, and we do not process sensitive personal information for the purpose of inferring characteristics.

Colombia (Ley 1581 de 2012)

You may exercise your rights of access, update, rectification, and deletion ("derechos de acceso, actualización, rectificación y supresión"), revoke your authorisation, and file a complaint with the Superintendencia de Industria y Comercio.

Mexico (LFPDPPP)

You may exercise your ARCO rights (access, rectification, cancellation, and opposition), limit the use or disclosure of your data, and revoke your consent, by writing to the privacy contact below.

How to exercise your rights

Write to hello@redroosterlabs.com. We will respond within the period required by applicable law — within one month under the GDPR, and within 45 days under the CCPA — and we may need to verify your identity before acting. Exercising these rights is free of charge.

8. Security

We apply technical and organisational measures appropriate to the risk, including encryption in transit (HTTPS), access controls with least-privilege permissions, secrets held in a managed secret store rather than in code, and infrastructure hosted on Google Cloud Platform. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

9. Children

The Services are intended for businesses and professionals. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact us and we will delete it.

10. Automated decision-making

We do not carry out automated decision-making that produces legal or similarly significant effects concerning you, as described in Art. 22 GDPR.

11. Changes to this policy

We may update this policy. We will update the "Last updated" date above and, for material changes affecting how we use your data, provide notice where we have your contact details.

12. Contact

Red Rooster Labs LLC
8 The Green, Suite B, Dover, DE 19901, United States
hello@redroosterlabs.com