Skip to content

24k / Privacy

Privacy policy

Last updated September 30, 2026

This page explains what 24k Design Studio collects through this website, why, and how we handle it. It's written in plain English on purpose — if anything is unclear, email hello@24kdesignstudio.co.

Who we are

24k Design Studio (“24k”, “we”, “us”) is a US-based design and development agency. This policy covers 24kdesignstudio.co and the services linked from it — the consultation form, the client portal, and invoice pages. It doesn't cover any third-party site you reach by following a link from ours.

What we collect and why

Consultation requests. When you fill out the consultation form, we collect your name, email, company (optional), the services you're interested in, and your message, so we can reply. The form also has a hidden field (a “honeypot”) that catches automated spam submissions; it stays empty for real visitors and we don't use it for anything else.

Client portal. If you're a 24k client, you sign in with a one-time 6-digit code sent to your email — no password to manage. We link your signed-in account to your client record so you can see your projects and invoices. Any change request you submit (title, details, priority) is stored against your project.

Payments. When you pay an invoice, Stripe collects your card details directly and processes the charge. Card numbers never reach our servers. We keep a record of the payment itself — amount, date, invoice number and a Stripe payment reference — for our accounting.

We don't run analytics, advertising cookies or third-party tracking scripts on this site, so we don't collect browsing behavior beyond the standard server logs described under “Service providers” below.

How we use it

We use the information above to:

  • reply to consultation requests and quote work,
  • deliver and manage client projects,
  • send invoices, payment receipts and change-request updates by email,
  • keep the client portal secure and working, and
  • meet our own legal and accounting obligations, such as keeping invoice records for tax purposes.

We don't sell your information, share it for advertising, or use it to train AI models.

Service providers

We use a small number of providers to run this site and our business. Each only sees what it needs to do its job, and processes data under its own privacy policy:

Cookies

This site sets one cookie: the Supabase authentication session cookie, created when you sign in to the client portal. It's strictly necessary to keep you signed in and isn't used for advertising or cross-site tracking. We don't set analytics or marketing cookies, and no third-party scripts run on this site.

Do Not Track

Some browsers send a “Do Not Track” (DNT) signal. California law (CalOPPA) requires us to say how we respond to it: we don't currently change this site's behavior based on a DNT signal, because the site doesn't track visitors across other websites in the first place — there's no cross-site tracking for DNT to turn off.

How long we keep data

Consultation inquiries. We keep these while they're relevant to following up, and delete them on request.

Client, project and invoice records. We keep these for the life of the client relationship. Invoices and payment records are kept longer, in line with common US tax and accounting recordkeeping practice — typically up to 7 years — per IRS recordkeeping guidance.

You can ask us to delete information that isn't legally required to be kept — see “Your rights and choices” below.

Security

We use reasonable, industry-standard safeguards: HTTPS everywhere, database access rules (row-level security) that limit each client to their own data, an admin area restricted to 24k's owner, and payment processing handled entirely by Stripe, which is PCI-compliant. No method of storage or transmission is 100% secure, but we work to protect your information.

Your rights and choices

Wherever you are, you can ask us to:

  • show you what information we hold about you,
  • correct anything that's wrong, or
  • delete your information, where we're not required to keep it (for example, tax records).

Email hello@24kdesignstudio.co or use the consultation form, and we'll respond within a reasonable time.

California residents. The California Consumer Privacy Act (CCPA/CPRA) gives California residents specific rights, but it only applies to businesses that cross certain size thresholds (broadly: over $26.625 million in annual revenue, personal information from 100,000 or more California consumers/households a year, or most of their revenue from selling personal data). 24k doesn't meet any of these thresholds, and we don't sell or share personal information. If you're a California resident, you're still welcome to use the access, correction and deletion rights above — we'll honor reasonable requests the same way.

Children

This site isn't directed at children, and we don't knowingly collect personal information from anyone under 13 (in line with COPPA, the Children's Online Privacy Protection Act). If you believe a child has given us information, email us and we'll delete it.

International visitors

24k and its service providers operate in the United States. If you visit this site from outside the US, your information will be transferred to and processed in the US, where privacy laws may differ from those where you live.

Changes

We may update this policy as our site or services change. We'll update the “Last updated” date at the top when we do. Check back occasionally if you want to stay current.

Contact

Questions, requests, or anything unclear? Email hello@24kdesignstudio.co or use our consultation form. Our public marketing pages don't list an email address; it appears here, and in the client portal and on invoice pages for existing clients.

This is a plain-English privacy policy written for a small US agency. It's not legal advice; for anything high-stakes, have a lawyer review it against your specific situation.