Who we are. This site, fndry39.com, is operated by Ryan Murrell, a sole proprietor in Alberta, Canada, carrying on business under the registered trade name FNDRY39 WEB DESIGN (Alberta trade name registration TN27072784) (“FNDRY39”, “we”, “us”). Our mailing address is PO Box 117, Sunnybrook, Alberta T0C 2M0. For any privacy question, contact us at privacy@fndry39.com.
This policy explains what we collect on this website and why. We collect the minimum needed and never sell your personal information. We design to the stricter of Quebec’s Law 25 and the GDPR.
1. What we collect
This is a marketing site for our studio. The only personal information we collect is what you choose to send us:
- Your name, email address, and message — and your business name if you add it — when you submit the contact form.
- Payment and billing information, if you buy something. Your name, billing address, email, what you bought, the amount, your payment schedule, and whether each payment succeeded — plus your company name and GST/HST registration number if you give us those for your invoices.
If we host or look after your site, we also hold what we need to do that job: the accounts and DNS access you give us, and your site’s own data as it passes through the infrastructure we run it on. We use that only to keep your site working. Where your site collects personal information from your visitors, that information is yours and we handle it on your instructions, not for our own purposes.
If we invoice you, two small things worth knowing. First, your private invoice page records the time it is first opened — that single timestamp tells us you received it, and we use nothing more invasive (no tracking pixels in our emails, ever). Second, we send transactional billing emails: your invoice link, a copy when an invoice is updated, one courtesy reminder before a payment’s due date, and a note when a scheduled payment is taken. Those are part of running your invoice, not marketing, and we don’t send marketing.
If you accept a quote, we keep a record of the acceptance. The name you type, the date and time, the version of our Terms of Engagement you accepted under, and the amounts you accepted — plus the IP address and browser the acceptance came from. That last pair is there for one reason: an accepted quote is a contract, and if it is ever questioned, a typed name on its own is thin evidence. We use it for nothing else — not analytics, not location, not advertising — and we keep it with the invoice records for the six years Canadian tax law requires. If a quote is later re-priced, your acceptance of the earlier version stays on the record rather than being deleted, and the new version is not binding on you until you accept it too.
We never see or store your full card number, security code, or bank login. Those go straight from you to Stripe and never touch our systems. What we can see is the card brand, the last four digits, the expiry date, the name on the card, and whether a payment went through — plus, if one fails, the reason the bank gave. There are no accounts and no sign-in on this site, and payment happens on Stripe’s own pages, not ours.
We use Google Analytics to count visits, but only if you accept cookies — nothing analytics-related loads before that. See our Cookie Policy.
FNDRY39 Programs (our free tools — the converters, compressors, resizers, trimmers, GIF tools, metadata remover, and the rest). Files you put into any of these tools are processed entirely on your own device, in your browser. They are never uploaded to us or to anyone else — we have no server that could receive them, we cannot see them, and there is nothing for us to store or delete. The working copies live in your browser’s memory and are gone when you close the page. If you accept analytics cookies, we count anonymous tool usage (for example, “a PNG was converted to WebP” and coarse size ranges) — never file names and never file contents. The tool-suggestion box on the Programs page opens your own email app; nothing you type there is sent to us until you choose to send that email.
Sending a report to an AI assistant. A few of the tools that check a web address — the SEO, speed, accessibility, broken-link, security-headers and privacy checkers — offer to hand their finished report to an AI assistant, so you can ask it how to fix what was found. You choose which one: Claude, ChatGPT, the Gemini app or Grok. Nothing happens until you press the button, nothing is picked for you, and no choice is remembered. When you do press it, the report goes to that company — not to us. For Claude and ChatGPT it travels in the link and reaches their servers the moment their site opens; for the Gemini app and Grok it only goes to your clipboard, and travels no further until you paste it. The panel says which, for the one you picked, before you press anything, and shows you the exact text first. After that their privacy policy applies and ours doesn’t: we can’t see the conversation, we don’t know you had one, and we can’t take the report back. The report is the same text you can already read on screen and download, and it describes a public web address rather than anything from your device. Anything that looked like a session cookie or an access token is blanked out before it goes — but read it first anyway, especially if you checked a staging site or a page you were logged into.
Advertising on the Programs tools. The free tools are paid for by ads, served by Google AdSense on programs.fndry39.com only — never on this marketing site. The ads run whether or not you accept cookies, because they are what pays for the tools. What you choose is whether Google may personalize them: say no and Google picks an ad from the page you are reading rather than from anything it knows about you. Either way Google receives the ordinary technical details of the visit (your IP address, browser information, and the page you are on) and may use cookies to select and measure ads, as described in our Cookie Policy. Nothing about the files you put into the tools — not names, not types, not sizes, not contents — is ever shared with Google or any ad network, and neither is anything from a tool’s report: the ads and the tools simply don’t talk to each other. The AI button described above is a separate thing entirely, it goes nowhere near an ad network, and it only ever moves when you press it. How Google uses data from sites that show its ads is described at policies.google.com/technologies/partner-sites, and you can control ad personalization at adssettings.google.com.
2. Why we use it (purpose & legal basis)
We use what you send through the contact form for one purpose: to reply to you and discuss the work you’re asking about. Our legal basis is your consent, given when you submit the form. You can withdraw it at any time (see “Your rights”). We won’t add you to a marketing list off the back of an enquiry.
If you buy from us, the basis is different. We use your billing information to take payment, send receipts and invoices, run the schedule you chose, and keep the records the Canada Revenue Agency requires us to keep. That isn’t based on consent — we need it to deliver the contract you signed and to meet legal obligations — so it isn’t something you can withdraw while the work is live. We also use limited payment information to check for fraud, because we have a genuine business interest in not being defrauded. (For anyone in the EU or UK: that is contract, legal obligation, and legitimate interests respectively — not consent.)
3. Sharing
We share your information only with the service providers that help us run this site:
- Hostinger — our email provider. What you send through the contact form is delivered to a Hostinger mailbox. We do not store it in a database.
- Stripe — our payment processor. If you pay us, you give your card or bank details directly to Stripe, not to us. Stripe takes the payment, checks it for fraud, securely stores your payment method so any scheduled instalments can run, and sends receipts. Stripe is a US company operating in Canada through Stripe Payments Canada Ltd., and it processes payment data in the United States. Their privacy policy is at stripe.com/privacy.
- Vercel — our hosting provider. It serves this site, and it serves client sites we host under a hosting or care plan.
- Google Analytics — visit statistics, only after you accept cookies.
- Google AdSense — advertising on the Programs tools (programs.fndry39.com) only. The ads run for every visitor; your cookie choice decides whether they are personalized. Google acts as an independent controller for the ad data it collects; see the advertising section above and our Cookie Policy for the cookies involved and your opt-outs. Google processes this data on servers around the world, including in the United States.
- Google reCAPTCHA — spam protection on the contact form. When you send us a message, Google checks the submission is from a person and not a bot. To do that it receives your IP address and information about how you interacted with the page. This runs on the contact page only, it is not analytics, and we get back nothing but a pass or fail — no score, no profile, nothing we could identify you from. Their privacy policy is at policies.google.com/privacy.
- AI assistants — Anthropic (Claude), OpenAI (ChatGPT), Google (the Gemini app), SpaceXAI (Grok) — only when you press the AI button on one of the report tools, and only the report that was on your screen at the time. We never send them anything on our own, we hold no account with any of them on your behalf, and there is no background call to any of them anywhere in these tools. Each acts as its own controller for whatever you send, under its own policy: anthropic.com/legal/privacy, openai.com/policies/privacy-policy, policies.google.com/privacy and x.ai/legal/privacy-policy. Some may use what you send to improve their models depending on your settings with them — that is theirs to explain, and worth checking if the report describes a site you would rather not discuss with a model.
We do not sell or rent your personal information to anyone.
4. Storage & retention
We hold no database of enquiries. What you send through the contact form is emailed to us and lives only in our mailbox, which is hosted by Hostinger and encrypted in transit. Hostinger is an international provider, so your message may be stored on servers outside Canada. We keep enquiries while the conversation is live and for up to 24 months after our last exchange — or until you ask us to delete yours, whichever comes first.
Billing and payment records are different: Canadian tax law requires us to keep them for six years from the end of the tax year they relate to, so we cannot delete those on request while that period is running. We keep our own copy of that ledger — who was invoiced, for what, and what was paid — rather than relying on Stripe to still hold it in six years’ time.
5. Your rights
You can ask us to access, correct, delete, or export your information, or to withdraw your consent, by emailing privacy@fndry39.com. You may also complain to a regulator: in Canada, the Office of the Privacy Commissioner of Canada; in Quebec, the Commission d’accès à l’information (CAI).
6. Security
We follow modern security practices: encryption in transit, and least-privilege access to every system we use. We deliberately run no database of our own — your messages travel by email, and payment records live with Stripe, who encrypt them at rest. No system is perfectly secure, but we work to protect your information and to notify you if a breach ever affects you.
7. Quebec (Law 25)
Our designated privacy officer is Ryan Murrell, founder of FNDRY39 — as a sole proprietorship, that is the person with the highest authority here — reachable at privacy@fndry39.com. We ask before switching on analytics or personalized advertising, the boxes start unticked, and refusing is one click and takes effect immediately. Advertising itself is not optional on the free tools — it is what pays for them — but a visitor who refuses is shown plain, contextual ads rather than ones chosen from a profile.
8. International users (GDPR / UK)
If you are in the EU or UK, you have the right to access, rectify, erase, restrict, and port your data, and to object to processing. Our lawful basis depends on why we hold the information, as set out in section 2: consent for enquiries, performance of a contract and legal obligation for billing records, and legitimate interests for fraud checks. To exercise any right, contact privacy@fndry39.com.
9. Children
This site is for businesses and adults. It is not directed to anyone under 18, we do not knowingly collect information from children, and if we learn that we have, we delete it.
10. Changes
We may update this policy as FNDRY39 grows. We’ll change the “Last updated” date above and, for material changes, tell anyone with a live enquiry.