24k / Privacy
Privacy policy
Last updated September 30, 2026
This page explains what 24k Design Studio collects through this website, why, and how we handle it. It's written in plain English on purpose — if anything is unclear, email hello@24kdesignstudio.co.
Who we are
24k Design Studio (“24k”, “we”, “us”) is a US-based design and development agency. This policy covers 24kdesignstudio.co and the services linked from it — the consultation form, the client portal, and invoice pages. It doesn't cover any third-party site you reach by following a link from ours.
What we collect and why
Consultation requests. When you fill out the consultation form, we collect your name, email, company (optional), the services you're interested in, and your message, so we can reply. The form also has a hidden field (a “honeypot”) that catches automated spam submissions; it stays empty for real visitors and we don't use it for anything else.
Client portal. If you're a 24k client, you sign in with a one-time 6-digit code sent to your email — no password to manage. We link your signed-in account to your client record so you can see your projects and invoices. Any change request you submit (title, details, priority) is stored against your project.
Payments. When you pay an invoice, Stripe collects your card details directly and processes the charge. Card numbers never reach our servers. We keep a record of the payment itself — amount, date, invoice number and a Stripe payment reference — for our accounting.
We don't run analytics, advertising cookies or third-party tracking scripts on this site, so we don't collect browsing behavior beyond the standard server logs described under “Service providers” below.
How we use it
We use the information above to:
- reply to consultation requests and quote work,
- deliver and manage client projects,
- send invoices, payment receipts and change-request updates by email,
- keep the client portal secure and working, and
- meet our own legal and accounting obligations, such as keeping invoice records for tax purposes.
We don't sell your information, share it for advertising, or use it to train AI models.
Service providers
We use a small number of providers to run this site and our business. Each only sees what it needs to do its job, and processes data under its own privacy policy:
- Stripe — processes payments on invoices. stripe.com/privacy
- Supabase — hosts our database and powers client-portal sign-in. supabase.com/privacy
- Resend — sends the emails this site generates (consultation replies, invoices, receipts, change-request updates). resend.com/legal/privacy-policy
- Vercel — hosts this site and keeps standard server logs (e.g. IP address, request time) for security and reliability. vercel.com/legal/privacy-policy
Do Not Track
Some browsers send a “Do Not Track” (DNT) signal. California law (CalOPPA) requires us to say how we respond to it: we don't currently change this site's behavior based on a DNT signal, because the site doesn't track visitors across other websites in the first place — there's no cross-site tracking for DNT to turn off.
How long we keep data
Consultation inquiries. We keep these while they're relevant to following up, and delete them on request.
Client, project and invoice records. We keep these for the life of the client relationship. Invoices and payment records are kept longer, in line with common US tax and accounting recordkeeping practice — typically up to 7 years — per IRS recordkeeping guidance.
You can ask us to delete information that isn't legally required to be kept — see “Your rights and choices” below.
Security
We use reasonable, industry-standard safeguards: HTTPS everywhere, database access rules (row-level security) that limit each client to their own data, an admin area restricted to 24k's owner, and payment processing handled entirely by Stripe, which is PCI-compliant. No method of storage or transmission is 100% secure, but we work to protect your information.
Your rights and choices
Wherever you are, you can ask us to:
- show you what information we hold about you,
- correct anything that's wrong, or
- delete your information, where we're not required to keep it (for example, tax records).
Email hello@24kdesignstudio.co or use the consultation form, and we'll respond within a reasonable time.
California residents. The California Consumer Privacy Act (CCPA/CPRA) gives California residents specific rights, but it only applies to businesses that cross certain size thresholds (broadly: over $26.625 million in annual revenue, personal information from 100,000 or more California consumers/households a year, or most of their revenue from selling personal data). 24k doesn't meet any of these thresholds, and we don't sell or share personal information. If you're a California resident, you're still welcome to use the access, correction and deletion rights above — we'll honor reasonable requests the same way.
Children
This site isn't directed at children, and we don't knowingly collect personal information from anyone under 13 (in line with COPPA, the Children's Online Privacy Protection Act). If you believe a child has given us information, email us and we'll delete it.
International visitors
24k and its service providers operate in the United States. If you visit this site from outside the US, your information will be transferred to and processed in the US, where privacy laws may differ from those where you live.
Changes
We may update this policy as our site or services change. We'll update the “Last updated” date at the top when we do. Check back occasionally if you want to stay current.
Contact
Questions, requests, or anything unclear? Email hello@24kdesignstudio.co or use our consultation form. Our public marketing pages don't list an email address; it appears here, and in the client portal and on invoice pages for existing clients.
This is a plain-English privacy policy written for a small US agency. It's not legal advice; for anything high-stakes, have a lawyer review it against your specific situation.