Privacy Policy
Pave Technologies LLC
Last Updated: October 1, 2026
1. Introduction and Scope
Pave Technologies LLC (“Pave,” “we,” “us,” or “our”) respects your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard personal information when you visit or interact with our websites and related online services (collectively, the “Services”), including:
- https://pavetechnologies.net/ (primary marketing site)
- https://medspa.pavetechnologies.net/ (Lead Capture Fix niche offer)
- https://book.pavetechnologies.net/ (scheduling via Easy!Appointments)
- https://blog.pavetechnologies.net/ (blog powered by Ghost)
- Related Pave-branded subdomains used for niche offers from time to time
This Policy applies to personal information we collect as a business / controller in connection with our own marketing, sales, and operations websites (B2B MSP / IT / cybersecurity services and related cash-sprint offers such as Lead Capture Fix, managed email stack-on, and cyber assessment funnels).
Client-built lead-capture sites. When we design, host, or operate lead-capture or similar websites for our clients, we typically act as a service provider / processor on behalf of the client (the controller). In those engagements, the client’s privacy notice and instructions govern how that client’s data is handled. This Policy describes Pave’s own website and controller practices; it does not replace a client’s privacy policy for sites we build for them.
By using the Services, you acknowledge the practices described in this Policy. If you do not agree, please do not use the Services or submit personal information through our forms.
Jurisdiction note. This Policy is drafted for a United States audience with a default governing-law assumption of the State of Arizona (Maricopa County venue for disputes, consistent with our commercial contracts). Our principal business region is Metro Phoenix, Arizona. Pave Technologies LLC is formed under the laws of the State of Arizona. As of the Last Updated date, Arizona does not have a comprehensive consumer privacy statute equivalent to the California Consumer Privacy Act (CCPA/CPRA). We nonetheless provide access, correction, deletion, and related rights on a voluntary basis, and we include U.S.-friendly “Do Not Sell or Share” language that also serves California and other state visitors.
2. Information We Collect
2.1 Information You Provide Directly
Website contact form (typically submitted via POST /api/contact on our marketing sites):
| Field | Typical requirement |
|---|---|
| Full name | Required |
| Work email | Required |
| Company / district | Required |
| Organization type (e.g., enterprise / K-12) | As presented on the form |
| Need type / service interest | Required |
| Phone | Optional |
| Message | Optional |
| How you heard about us | Optional |
| Consent checkbox (“OK to contact me about Pave services”) | Required where presented |
Booking / scheduling (Easy!Appointments on book.pavetechnologies.net):
- Name, email, and phone number for a short (e.g., 15-minute) phone introductory call
- Scheduling-related details necessary to confirm the appointment
Email correspondence: If you email us (including at hello@pavetechnologies.net, andi@pavetechnologies.net, or luke@pavetechnologies.net), we receive the content of your messages and any information you choose to include.
What we do not collect on main marketing-site forms:
- Passwords
- Payment card numbers or bank account details
- Social Security numbers / Tax Identification Numbers (SSN/TIN)
- K-12 student personally identifiable information (student PII)
- Health or medical information / protected health information (PHI)
- Arbitrary file uploads
We do not claim to process PHI under a Business Associate arrangement for our marketing sites, and our marketing forms are not designed for HIPAA-regulated data.
2.2 Information Collected Automatically
When you visit the Services, our infrastructure and security layers may automatically collect limited technical data, such as:
- IP address, approximate location derived from IP, browser type and version, device/OS information
- Pages or URLs visited, referring/exit pages, timestamps, and request metadata
- Security and bot-mitigation signals (e.g., Cloudflare Turnstile or similar, where enabled)
Analytics and advertising pixels: As of the Last Updated date, we do not currently use Google Analytics, Meta (Facebook) Pixel, or similar third-party advertising/analytics pixels on the Services. If we add analytics or advertising technologies later, we will update this Policy and, where required, obtain appropriate consent or provide opt-out mechanisms.
Essential / functional technologies: We use essential cookies and similar technologies for security, CDN delivery, load balancing, and basic site functionality (see Section 6).
2.3 Information from Service Providers
We may receive information about you from the processors listed in Section 5 when they process form submissions, booking webhooks, email, or calendar invites on our behalf (for example, Twenty CRM creating Company / Person / Opportunity / Note records from a lead).
2.4 Payment Information
Our primary marketing sites do not currently operate a live payment-card checkout. We do not collect payment card data through the marketing site contact forms. If a payment processor (e.g., Stripe) is added later for paid offers, [TO CONFIRM — Stripe / payment processor status], card data would be handled by that processor under its own terms, and this Policy would be updated.
3. How We Use Your Information
We use personal information for the following business purposes:
- Respond to inquiries and provide sales/ops follow-up about Pave services (MSP / IT / cybersecurity, Lead Capture Fix, managed email, cyber assessments, and related offers), consistent with your consent checkbox where presented.
- Schedule and conduct introductory calls via Easy!Appointments and related calendar/Meet invites.
- Operate and improve CRM pipeline — routing leads into Twenty CRM (Company, Person, Opportunity, Note) for sales and account management.
- Communicate operationally — email replies, booking confirmations, and service-related messages via Zoho Mail and, if configured, transactional email (e.g., Resend) when CRM environment variables are unavailable.
- Secure and operate the Services — Cloudflare Pages/Workers, Turnstile (planned/partial), hosting/CDN, abuse prevention, and troubleshooting.
- Publish and operate content — blog content via Ghost; site fonts via Google Fonts CDN.
- Comply with law and enforce our terms; defend legal claims; respond to lawful requests.
- Business transfers — evaluate or complete a merger, acquisition, financing, or sale of assets (see Section 5).
We do not use personal information collected via the marketing Services to sell it to third parties for monetary consideration, and we do not “share” personal information for cross-context behavioral advertising as those terms are commonly used under California law, unless and until we update this Policy and provide required notices/opt-outs (current stance: no sale / no share for ads).
4. Legal Basis / When We Process (United States–Focused)
For U.S. visitors, we process personal information as permitted by applicable U.S. federal and state law, including where:
- You have provided information and requested contact (contractual steps / legitimate business communications);
- You have consented (e.g., “OK to contact me about Pave services”);
- Processing is necessary for our legitimate business interests that are not overridden by your rights (security, CRM operations, improving B2B marketing sites), consistent with applicable law; or
- Processing is necessary to comply with a legal obligation.
Optional note for EU/EEA/UK visitors: Our Services are directed primarily at U.S. businesses. If you contact us from the EU/EEA/UK, we may process your inquiry data as necessary to take steps at your request prior to entering a contract, based on consent, or based on our legitimate interests in responding to B2B inquiries. Where GDPR or UK GDPR applies, you may have additional rights (see Section 8). Contact hello@pavetechnologies.net for privacy requests.
5. Information Sharing and Disclosure
We do not sell personal information. We do not share personal information for cross-context behavioral advertising, unless we later change practices and update this Policy with required notices and opt-outs.
We disclose personal information only as described below:
5.1 Service Providers / Processors
We use vetted service providers who process data on our instructions for hosting, security, CRM, email, scheduling, and related operations. As of the Last Updated date, these include (as applicable):
| Provider | Role |
|---|---|
| Cloudflare (Pages / Workers; Turnstile planned/partial) | Hosting, CDN, security, bot mitigation |
| Twenty CRM | Lead / CRM records (Company, Person, Opportunity, Note); form and booking webhook intake |
| Zoho Mail | Business email |
| Ghost | Blog hosting/publishing (blog.pavetechnologies.net) |
| Easy!Appointments | Online booking for introductory calls |
| Google Calendar / Google Meet | Calendar invites and meeting links for booked calls |
| Google Fonts CDN | Web font delivery |
| Resend (optional) | Transactional email fallback if Twenty CRM environment configuration is missing |
| Coolify / Forge-style or similar self-hosted deploy tooling | Application deployment and operations [TO CONFIRM — exact production deploy stack details] |
These providers are authorized to use personal information only to perform services for us (or as required by law), not for their own unrelated marketing.
5.2 Legal and Safety
We may disclose information if we believe in good faith that disclosure is necessary to comply with law, regulation, legal process, or governmental request; to protect the rights, property, or safety of Pave, our clients, or others; or to investigate fraud or security issues.
5.3 Business Transfers
In connection with a merger, acquisition, reorganization, bankruptcy, or sale of assets, personal information may be transferred as part of that transaction, subject to customary confidentiality and this Policy’s principles (or a successor notice).
5.4 With Your Direction
We may share information when you ask us to or consent to a specific disclosure.
5.5 Client Controller Arrangements
For client lead-capture sites we build or operate as a service provider, we process data under the client’s instructions; those disclosures are governed by the client’s notices and our agreement with the client, not solely by this Policy.
6. Cookies and Similar Technologies
We and our infrastructure providers may use cookies, local storage, pixels, and similar technologies as follows:
| Category | Purpose | Current status |
|---|---|---|
| Essential / security | CDN, load balancing, session integrity, bot protection (e.g., Cloudflare; Turnstile where enabled) | In use as needed for the Services to function securely |
| Functional | Remember preferences or support booking/form flows | Limited; as required by the tool |
| Analytics | Measure traffic and usage | Not currently confirmed in production — we do not presently run GA, Meta Pixel, or similar; if added, this Policy will be updated |
| Advertising | Cross-context behavioral ads | Not used as of Last Updated |
You can control cookies through your browser settings. Blocking essential cookies may impair site security or functionality. Because we do not currently run third-party ad/analytics pixels, there is no separate analytics opt-out widget on the marketing site as of this draft; if that changes, we will provide appropriate controls.
Google Fonts: Pages may request fonts from Google’s CDN, which can involve a connection to Google’s servers and associated technical data (e.g., IP address). See Google’s privacy documentation for details.
7. Data Retention
We retain personal information only as long as reasonably necessary for the purposes described in this Policy, including:
- Sales/inquiry leads in Twenty CRM and email: for the duration of the sales relationship and a reasonable period thereafter for follow-up, dispute resolution, and recordkeeping (typically aligned with our business and tax retention needs) [TO CONFIRM — exact retention schedule / months].
- Booking records: for scheduling history and related communications for a reasonable period after the appointment.
- Security and server logs: for shorter operational periods unless needed for security investigation or legal holds.
- Blog / account data (Ghost): according to Ghost’s configuration and our content operations.
When retention is no longer necessary, we will delete or de-identify information, except where longer retention is required by law or needed for legitimate legal claims.
8. Your Rights
Depending on where you live and applicable law, you may have the right to:
- Access — request confirmation of whether we process your personal information and obtain a copy.
- Correction — request that we correct inaccurate personal information.
- Deletion — request that we delete personal information, subject to legal exceptions (e.g., completing a transaction, security, legal compliance, internal uses reasonably aligned with your expectations).
- Opt out of sale / sharing — we do not sell personal information and do not share it for cross-context behavioral advertising. If that changes, you will be able to opt out as required by law. You may still email us at hello@pavetechnologies.net with the subject line “Do Not Sell or Share My Personal Information” to state your preference.
- Limit use of sensitive personal information — our marketing forms are not designed to collect sensitive categories (SSN, precise health data, etc.). If you believe we hold sensitive data about you, contact us.
- Appeal — if we deny a privacy request, you may appeal by replying to our decision email or writing to hello@pavetechnologies.net with the subject “Privacy Request Appeal.” We will respond within a reasonable period consistent with applicable law.
- Withdraw consent — where processing is based on consent (including marketing contact consent), you may withdraw consent going forward without affecting prior lawful processing.
- Non-discrimination — we will not discriminate against you for exercising privacy rights available under applicable law.
How to submit a request: Email hello@pavetechnologies.net with a clear description of your request and enough information for us to verify your identity (e.g., the email address you used on a form or booking). We do not publish a company phone number for privacy requests; please use email.
Authorized agents (e.g., California): You may designate an authorized agent where law permits; we may require proof of authorization and identity verification.
Voluntary rights (Arizona and other states without a comprehensive consumer privacy act): Even where not legally required, we endeavor to honor reasonable access, correction, and deletion requests for marketing-site leads, subject to verification and legal exceptions.
EU/EEA/UK (if applicable): You may also have rights to restriction, portability, and objection, and the right to lodge a complaint with a supervisory authority.
9. Security Measures
We implement reasonable administrative, technical, and organizational measures designed to protect personal information, including reliance on reputable infrastructure (e.g., Cloudflare security features), access controls for CRM and mail systems, and least-privilege practices among team members.
No method of transmission or storage is 100% secure. We cannot guarantee absolute security. You are responsible for maintaining the confidentiality of any credentials if we later provide portal access (not applicable to current public marketing forms).
If we become aware of a security incident affecting your personal information in a manner that legally requires notice, we will notify you and/or regulators as required by applicable law.
10. Children’s Privacy
The Services are B2B offerings directed at businesses, professionals, and organizational decision-makers. They are not directed at children under 13, and we do not knowingly collect personal information from children under 13.
Our marketing and booking forms are not designed to collect K-12 student PII. Organization-type fields that mention “K-12” refer to institutional / district contacts (adults), not student data.
If you believe a child has provided us personal information, contact hello@pavetechnologies.net and we will take appropriate steps to delete it.
Parked or future products (e.g., Compass K-12 or similar) are not live storefronts as of this Policy. If we launch services that change our data practices regarding education or student-related data, we will update this Policy before or concurrent with those changes.
11. International / United States Transfers
We are based in the United States (Metro Phoenix, Arizona region). If you access the Services from outside the United States, you understand that your information may be transferred to, stored, and processed in the United States and other countries where we or our processors operate (including Cloudflare’s global network). U.S. law may differ from the law of your country of residence. Where required, we will use appropriate transfer mechanisms for restricted transfers.
12. Changes to This Policy
We may update this Privacy Policy from time to time. The “Last Updated” date at the top indicates the latest revision. Material changes will be posted on this page; where required by law, we may provide additional notice or obtain consent. Continued use of the Services after an update constitutes acknowledgment of the revised Policy, except where applicable law requires a different standard.
13. Contact Information
Controller: Pave Technologies LLC
Privacy inquiries (preferred): hello@pavetechnologies.net
Other team mailboxes (not preferred for formal privacy requests): andi@pavetechnologies.net; luke@pavetechnologies.net
Region: Metro Phoenix, Arizona, United States
Street / mailing / registered agent address: [TO CONFIRM]
Public company phone for privacy requests: None published — please use email.
Website: https://pavetechnologies.net/
This Policy URL: https://pavetechnologies.net/privacy
For privacy requests, use subject lines such as “Privacy Access Request,” “Privacy Deletion Request,” or “Do Not Sell or Share My Personal Information.”
14. Disclaimer
---
DISCLAIMER: This document was generated by Legal Docs Pro for informational
purposes only. It is not a substitute for professional legal advice. Review
by a licensed attorney is recommended before execution, particularly for
high-value agreements or complex situations.
Generated: October 1, 2026 | Jurisdiction: State of Arizona, United States
Draft only — not legal counsel. Remaining [TO CONFIRM] items: street/mailing address, Stripe/payment processor (if any), exact CRM retention months, exact production deploy stack detail. Entity formation state confirmed: Arizona.