Skip to content
SDDIGITAL
Legal Privacy Cookies Terms Accessibility
619.777.1313 Back to site

Legal · Document 01

Privacy Policy

This policy explains what personal information SD Digital collects when you visit sd.digital or contact us, why we collect it, who we share it with, how long we keep it, and the rights you have over it — wherever you live.

Effective August 11, 2026 Last updated August 11, 2026 Version 1.0 Applies to sd.digital

The short version

  • We collect the name, email address, and message you type into our contact form — nothing more.
  • This website sets no cookies, runs no analytics, and loads no third-party trackers. Every font, script, and image is served from our own domain.
  • We have never sold or shared personal information, and we do not use it for targeted advertising or profiling.
  • You can ask us to show you, correct, or delete what we hold — free of charge — by emailing privacy@sd.digital or calling (619) 777-1313.

Contents

  1. Who we are
  2. Scope of this policy
  3. Notice at collection
  4. What we collect
  5. Where it comes from
  6. Why we use it & legal bases
  7. Sensitive information
  8. Cookies & tracking
  9. Who we disclose to
  10. No sale, no sharing
  11. How long we keep it
  12. How we protect it
  13. International transfers
  14. California rights
  15. Other US state rights
  16. UK & EEA rights
  17. Other regions
  18. How to exercise rights
  19. Children's privacy
  20. Automated decisions
  21. Third-party links
  22. Changes to this policy
  23. Contact us

01Who we are

SD Digital is a software studio headquartered in San Diego, California, with an outpost in Metro Detroit, Michigan. We build applications, websites, web apps, APIs, connected devices, and IoT systems for clients across the United States.

For the purposes of the UK GDPR and the EU GDPR, SD Digital is the controller of the personal information described in this policy. Under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (together, the “CCPA”), we are a business.

Controller / business
SD Digital, operating at sd.digital
Based in
San Diego, California, United States
Privacy contact
privacy@sd.digital
Telephone
(619) 777-1313 — call or text

We operate online. If you need to reach us in writing on paper, ask by email or phone and we will give you a postal address for that correspondence.

We are a small business. There is no separate privacy department: your request goes straight to the people who run the studio.

02Scope of this policy

This policy covers personal information we handle when you:

  • browse sd.digital or any page on it;
  • submit our contact form;
  • call, text, or email us about our services.

This policy does not cover:

  • Client project data. When we are engaged to build or maintain software, we typically act as a service provider (CCPA) or processor (UK/EU GDPR) for personal data inside our clients' systems. That processing is governed by the written services agreement and data processing addendum with the client, not by this policy. If you are an end user of a system we built for someone else, please contact that organisation — they are the controller.
  • Third-party websites we link to. See section 21.
  • Job applicants and personnel, who receive a separate notice at the point of application.

03Notice at collection

This section is the notice at collection required by the CCPA (Cal. Civ. Code § 1798.100(a)) and the equivalent transparency duties in other US state privacy laws. It summarises, at or before the point of collection, everything we collect and why.

Summary — categories collected, purpose, retention, and disclosure
Category Purpose Retention Sold or shared?
Identifiers — name, email address To read and reply to your enquiry 24 months from last contact No — never
Commercial information — the contents of your message To understand and scope the work you are asking about 24 months from last contact No — never
Internet or network activity — IP address, user agent, request logs To serve the page, keep the site secure, and prevent abuse Held by our host for a short period; see section 11 No — never
Audio / electronic information — call and text metadata if you phone us To return your call or message As retained by the carrier and our phone records No — never

We do not collect sensitive personal information

We do not collect or process any category of sensitive personal information as defined by Cal. Civ. Code § 1798.140(ae), nor any special category data under Article 9 of the UK/EU GDPR. See section 7.

04What we collect

4.1 Information you give us

Our contact form asks for exactly three things, all of which are required for us to answer you:

  • Name — so we know who we are writing back to.
  • Email address — so we can reply.
  • Project description — the free-text message you write.

The form contains one hidden field, a “honeypot”, which is invisible to you and left empty by real people. Automated spam bots fill it in, which is how we discard them. It collects no information about you.

Please do not include sensitive details in the message box — health information, government identifiers, payment card numbers, passwords, or credentials. If a project requires that kind of information, we will set up an appropriate secure channel first.

If you call or text (619) 777-1313 or email us directly, we receive whatever you choose to tell us, plus your phone number or email address.

4.2 Information collected automatically

This website is a set of static files. It runs no analytics software, sets no cookies, and makes no requests to advertising networks, social networks, content delivery networks, or font services. There is no tracking pixel, no session recording, and no fingerprinting.

However, like every web server on the internet, the server that delivers these pages records basic technical information about each request. Those server logs are generated and held by our hosting provider, GitHub, Inc., not by us, and typically include:

  • your IP address;
  • the date and time of the request;
  • the page or file requested;
  • your browser's user-agent string and preferred language;
  • the referring page, if your browser sends one.

We do not have routine access to these logs, we do not combine them with anything else, and we do not use them to build a profile of you. GitHub uses them to operate the service, keep it available, and defend against attacks.

4.3 CCPA statutory categories

The table below maps what we collect onto the categories listed at Cal. Civ. Code § 1798.140(v), which several other state laws also track.

Statutory categories — collected in the last 12 months
Statutory category Collected? Detail
A. IdentifiersYesName, email address, IP address
B. Customer records (Civ. Code § 1798.80(e))YesName and email address, where they appear together in an enquiry
C. Protected classificationsNoWe never ask
D. Commercial informationYesThe services you enquire about, in your own words
E. Biometric informationNo—
F. Internet or network activityYesHost server logs only; no browsing history across other sites
G. Geolocation dataNoWe do not use the geolocation API. A coarse country or city may be inferable from an IP address in host logs
H. Sensory data (audio, visual)NoWe do not record calls
I. Professional or employment informationYesOnly if you volunteer it — for example your company or job title in a message
J. Education information (FERPA)No—
K. Inferences drawn to build a profileNoWe draw no profiles
L. Sensitive personal informationNoSee section 7

05Where the information comes from

We collect personal information from two sources only:

  1. Directly from you, when you fill in the contact form, call, text, or email us.
  2. Automatically from your device, in the ordinary technical course of your browser requesting a page, as described in section 4.2.

We do not buy contact lists, scrape personal information, enrich records with third-party data brokers, or acquire personal information from social networks or advertising platforms.

06Why we use it, and our legal bases

We use personal information only for the purposes listed below. If you are in the UK or the EEA, the UK/EU GDPR requires us to have a lawful basis for each purpose; those are given in the right-hand column.

Purposes and lawful bases
Purpose Information used Lawful basis (UK/EU GDPR)
Reading and answering your enquiry Name, email, message Article 6(1)(b) — steps at your request prior to entering a contract; or Article 6(1)(f) — our legitimate interest in responding to people who contact us
Preparing a proposal, quote, or statement of work Name, email, message Article 6(1)(b) — pre-contractual steps
Keeping a record of our correspondence Name, email, message Article 6(1)(f) — legitimate interest in maintaining an accurate business record and defending legal claims
Serving the website and keeping it secure IP address, request logs Article 6(1)(f) — legitimate interest in delivering and protecting our own site
Filtering spam submissions Honeypot field, submission metadata Article 6(1)(f) — legitimate interest in not drowning in bot traffic
Complying with law, and establishing or defending legal claims Whatever is strictly relevant Article 6(1)(c) — legal obligation; Article 6(1)(f) — legitimate interest in legal claims

Where we rely on legitimate interests, we have considered whether those interests are overridden by your interests and fundamental rights, and concluded they are not, because the processing is limited, expected, low-risk, and something you can object to at any time (see section 16).

6.1 Compatible use

We will not use your personal information for a materially different, unrelated, or incompatible purpose without telling you first and, where the law requires it, obtaining your consent.

6.2 Marketing

We do not run an email marketing list, and we do not add people who contact us to one. If that ever changes, we will only send marketing emails where we have your consent or another lawful basis, every message will carry a working unsubscribe link, and we will honour opt-outs promptly — as required by the CAN-SPAM Act in the US and PECR in the UK. We will never sell your email address to anyone.

07Sensitive personal information

We do not collect, use, disclose, or infer sensitive personal information. That means we do not handle:

  • Social Security, driver's licence, state identification, or passport numbers;
  • account log-in credentials, financial account numbers, or payment card details;
  • precise geolocation;
  • racial or ethnic origin, religious or philosophical beliefs, or union membership;
  • the contents of your mail, email, or text messages other than those you send to us;
  • genetic or biometric data;
  • health information;
  • information about sex life or sexual orientation;
  • immigration or citizenship status;
  • criminal offence data.

Because we collect none of it, the CCPA right to limit the use and disclosure of sensitive personal information does not arise here — but if you believe you have sent us something in this list by accident, tell us at privacy@sd.digital and we will delete it.

08Cookies, analytics, and tracking technologies

This website sets no cookies. It stores nothing in localStorage or sessionStorage, uses no web beacons or pixels, and loads no third-party scripts. Because we place no non-essential storage on your device, there is no consent banner to click through — under the UK Privacy and Electronic Communications Regulations (PECR) and the EU ePrivacy Directive, consent is required for non-essential storage, and there is none here.

Our full Cookie Notice sets this out in detail.

8.1 Do Not Track

Some browsers transmit a “Do Not Track” (DNT) signal. There is no industry-accepted standard for how a site should respond to it. Because we do not track visitors across sites or over time in the first place, our behaviour is identical whether or not DNT is set. This paragraph is our disclosure under the California Online Privacy Protection Act, Cal. Bus. & Prof. Code § 22575(b)(5).

8.2 Global Privacy Control and opt-out preference signals

We treat a Global Privacy Control (GPC) or comparable opt-out preference signal as a valid request to opt out of the sale or sharing of personal information, in line with the CCPA regulations and the equivalent requirements in Colorado, Connecticut, Texas, Montana, Oregon, Delaware, New Jersey, and other states. In practice the signal changes nothing, because we never sell or share personal information for anyone — see section 10.

8.3 Third-party content

We deliberately self-host every asset — fonts, scripts, icons, and images — so that loading this site does not disclose your IP address to any company other than our host. There are no embedded videos, maps, chat widgets, or social buttons.

09Who we disclose personal information to

We disclose personal information only for the business purposes described in section 6, and only to the categories of recipient below. Every vendor we use is engaged as a service provider or processor, contractually restricted to processing personal information on our instructions and for no purpose of their own.

Recipients
Recipient Role What they receive Location
GitHub, Inc. (a Microsoft company) Website hosting — GitHub Pages Server request logs, including IP addresses United States
FormSubmit Form-to-email delivery for the contact form The name, email address, and message you submit, plus the submitting IP address United States
Google LLC Email hosting for the mailbox that receives enquiries The contents of your enquiry, as an email United States
Telecoms carriers Voice and SMS delivery Your phone number and message, if you call or text us United States
Professional advisers Accountants, insurers, and lawyers, as needed Only what is strictly relevant, and rarely United States
Authorities and courts Legal compliance Only what a valid, binding legal request requires As applicable

9.1 Business transfers

If SD Digital is involved in a merger, acquisition, financing, reorganisation, or sale of assets, personal information may be transferred as part of that transaction. We will require the recipient to honour this policy, and we will notify you — by email, or by a prominent notice on this site — before your information becomes subject to a materially different privacy policy.

9.2 Legal disclosures

We may disclose personal information where we reasonably believe it is necessary to comply with a law, regulation, subpoena, warrant, or court order; to enforce our Terms of Service; to detect or prevent fraud, security incidents, or illegal activity; or to protect the rights, property, or safety of SD Digital, our clients, or the public. Where we are legally permitted to do so, we will tell you first.

10We do not sell or share personal information

Plainly stated

SD Digital has never sold personal information, and has never shared personal information for cross-context behavioural advertising, as those terms are defined in the CCPA. We have not done so in the preceding twelve months, and we have no plans to.

The same applies under every other US state privacy law: we do not sell personal data, we do not process it for targeted advertising, and we do not engage in profiling in furtherance of decisions that produce legal or similarly significant effects.

We have never sold or shared the personal information of anyone we know to be under 16 years of age.

Because we do not sell or share, there is no “Do Not Sell or Share My Personal Information” link on this site — none is required. You may still send us an opt-out request, and we will confirm our practices in writing.

11How long we keep it

We keep personal information only as long as we need it for the purpose we collected it for, then delete it or irreversibly anonymise it.

Retention schedule
Record Retention period Why
Enquiry that does not become a project 24 months from your last message to us So we have context if you come back, and a record of what was discussed
Enquiry that becomes a project Duration of the engagement, then 7 years Contractual, tax, accounting, and professional insurance requirements
Spam and bot submissions Deleted on identification No reason to keep them
Host server logs Set by GitHub under its own policy — generally a matter of days to a few weeks Security, abuse prevention, and service operation
Privacy rights requests and our responses 24 months Required by CCPA record-keeping rules, and to demonstrate compliance

Where a longer period is required by law, or where information is relevant to a legal claim that is live or reasonably anticipated, we keep it until that requirement ends.

12How we protect it

We take appropriate technical and organisational measures to protect personal information against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, and unauthorised access. These include:

  • HTTPS with HSTS across the whole site, so traffic between you and us is encrypted in transit;
  • a static architecture with no database, no user accounts, and no server-side code of ours to compromise;
  • no third-party scripts, which removes an entire class of supply-chain risk;
  • multi-factor authentication on the accounts that can reach enquiry email and the site repository;
  • access limited to the few people who genuinely need it;
  • encryption at rest by our email and hosting providers.

No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours where the UK/EU GDPR requires it, notify affected individuals without unreasonable delay where US state breach-notification laws — including Cal. Civ. Code § 1798.82 — require it, and tell you what happened and what to do.

13International transfers

SD Digital operates in the United States, and our hosting, email, and form-delivery providers are US companies. If you contact us from the United Kingdom, the European Economic Area, Switzerland, or anywhere else outside the US, your personal information will be transferred to and processed in the United States, which may not provide the same level of protection as the law of your own country.

Where such a transfer takes place, we rely on one or more of the following safeguards:

  • the EU–US Data Privacy Framework and its UK Extension, and the Swiss–US Data Privacy Framework, where the receiving provider is actively certified;
  • the European Commission's Standard Contractual Clauses, together with the UK International Data Transfer Addendum or the UK IDTA, supported by a transfer risk assessment;
  • your explicit consent, or the fact that the transfer is necessary to perform a contract with you or to take pre-contractual steps at your request (UK/EU GDPR Article 49), where no other mechanism applies.

You can ask us for a copy of the safeguards that apply to a specific transfer by writing to privacy@sd.digital.

14Your rights if you are in California

The CCPA gives California residents the following rights. Exercising them will never cause us to deny you service, charge you a different price, or provide a different level of quality — that is the statutory right to non-discrimination, and we honour it.

Right to know§ 1798.100, 1798.110, 1798.115
Ask us to disclose the categories and specific pieces of personal information we have collected about you, the sources, the business purpose, and the categories of third party we disclosed it to — covering the 12 months before your request, or longer if you ask and it is not impossible or disproportionately difficult for us to provide.
Right to delete§ 1798.105
Ask us to delete personal information we collected from you. We will also direct our service providers to delete it, unless a statutory exception applies — for example where we still need it to complete a transaction, detect security incidents, comply with a legal obligation, or exercise a legal claim. We will tell you which exception we relied on.
Right to correct§ 1798.106
Ask us to correct inaccurate personal information, taking into account its nature and the purpose of processing.
Right to opt out of sale or sharing§ 1798.120
Direct us not to sell or share your personal information. We do neither, so there is nothing to opt out of — but you may still make the request, and we will confirm.
Right to limit use of sensitive personal information§ 1798.121
Restrict the use of sensitive personal information to what is necessary to provide the service. We collect none, so this right does not arise.
Right to non-discrimination§ 1798.125
Not be penalised for exercising any of the above. We run no financial incentive programmes.
Right to data portability§ 1798.130(a)(3)
Receive the personal information you gave us in a portable and, where technically feasible, readily usable format.

14.1 Authorised agents

You may use an authorised agent to submit a request on your behalf. We will ask the agent for written permission signed by you, and we may ask you to verify your identity with us directly and confirm that you granted the authority — unless the agent holds a valid power of attorney under Cal. Prob. Code §§ 4000–4465.

14.2 Shine the Light

California's “Shine the Light” law, Cal. Civ. Code § 1798.83, entitles California residents to request once a year a list of the third parties to whom we disclosed personal information for their own direct marketing purposes in the previous calendar year. We disclose personal information to no one for their direct marketing purposes, so any such list would be empty. You may still send the request to privacy@sd.digital with “Shine the Light” in the subject line, and we will respond within 30 days.

14.3 Minors under 18

Under Cal. Bus. & Prof. Code § 22581, a California resident under 18 who is a registered user of a site may request removal of content they posted. This site has no registration and no user-posted content, but if you are under 18 and something you sent us is stored, write to us and we will remove it.

15Your rights in other US states

A growing number of states have comprehensive consumer privacy laws — among them Virginia, Colorado, Connecticut, Utah, Iowa, Indiana, Tennessee, Montana, Texas, Oregon, Florida, Delaware, New Jersey, New Hampshire, Kentucky, Nebraska, Maryland, Minnesota, and Rhode Island. Their rights overlap heavily with California's.

Rather than work out whether a given statute technically applies to a business of our size, we extend the following rights to every US resident who asks, regardless of the state you live in:

  • Confirm and access — find out whether we process personal data about you, and get a copy of it.
  • Correct — have inaccuracies fixed.
  • Delete — have personal data about you erased.
  • Portability — receive your data in a portable, readily usable, machine-readable format where processing is automated.
  • Opt out — of targeted advertising, of the sale of personal data, and of profiling with legal or similarly significant effects. We do none of these things.
  • Opt out of processing of sensitive data, and to withdraw consent where consent was the basis. We process no sensitive data.
  • Not be discriminated against for exercising any of these rights.

15.1 Appeals

Most state privacy laws give you a right to appeal if we refuse a request. If we decline to act, we will tell you why, and you may appeal within 60 days by replying to our decision or writing to privacy@sd.digital with “Privacy Appeal” in the subject line. We will respond in writing within 45 days, explaining the reasoning, and we will tell you how to complain to your state Attorney General if you remain unsatisfied.

15.2 Nevada

Nevada residents may direct a business not to sell certain personal information under NRS Chapter 603A. We sell none. You may still submit a verified request to privacy@sd.digital.

15.3 Washington and Nevada health data

The Washington My Health My Data Act and Nevada SB 370 regulate consumer health data. We collect no consumer health data of any kind, and we do not operate a geofence around any healthcare facility.

16Your rights if you are in the UK or the EEA

If you are in the United Kingdom, the European Economic Area, or Switzerland, the UK GDPR (as amended, including by the Data (Use and Access) Act 2025), the EU GDPR, and the Swiss FADP give you the rights below. There is no charge for exercising them unless a request is manifestly unfounded or excessive, in which case we may charge a reasonable fee or refuse — and we will explain why.

Right of accessArticle 15
Obtain confirmation of whether we process personal data about you, a copy of it, and information about how and why we use it.
Right to rectificationArticle 16
Have inaccurate personal data corrected and incomplete data completed.
Right to erasureArticle 17
Have personal data deleted where it is no longer necessary, where you withdraw consent, where you object and we have no overriding grounds, or where it has been processed unlawfully.
Right to restrictionArticle 18
Have processing paused while a dispute about accuracy or our legitimate interests is resolved.
Right to data portabilityArticle 20
Receive personal data you provided to us in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible.
Right to objectArticle 21
Object at any time to processing based on our legitimate interests, on grounds relating to your particular situation. You may object to direct marketing at any time, for any reason, and we must stop immediately.
Right to withdraw consentArticle 7(3)
Where processing is based on consent, withdraw it at any time. This does not affect the lawfulness of what we did before you withdrew it.
Rights on automated decisionsArticle 22
Not be subject to a decision based solely on automated processing that produces legal or similarly significant effects. We make no such decisions — see section 20.
Right to complainArticle 77
Lodge a complaint with a supervisory authority. Details below.

16.1 Complaining to a regulator

We would much rather hear from you first, and we will do our best to resolve the matter. But you have the right to go straight to a regulator, and doing so does not affect any other remedy.

  • United Kingdom — the Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF; telephone 0303 123 1113; ico.org.uk/make-a-complaint.
  • EEA — the data protection authority in the country where you live, work, or where the alleged infringement took place. The European Data Protection Board maintains the list at edpb.europa.eu.
  • Switzerland — the Federal Data Protection and Information Commissioner (FDPIC).

16.2 Representative in the UK and EU

SD Digital markets its services in the United States and is not established in the UK or the EEA. We do not target, monitor, or offer services to individuals in those territories, so we have not appointed a representative under Article 27 of the UK or EU GDPR. We nonetheless extend the rights in this section to anyone who contacts us from those territories. If our activities change, we will appoint a representative and update this policy.

17Other regions

17.1 Canada

Under the Personal Information Protection and Electronic Documents Act (PIPEDA), and provincial equivalents in Quebec, British Columbia, and Alberta, you may access the personal information we hold about you, challenge its accuracy, and withdraw consent subject to legal and contractual restrictions. Complaints may be made to the Office of the Privacy Commissioner of Canada. Canada's anti-spam legislation (CASL) also applies to any commercial electronic message we send you; we send none without consent.

17.2 Everywhere else

If your local law gives you privacy rights we have not listed, write to us and we will honour them to the extent the law requires. In practice, the rights described in sections 14 to 16 are the ones we apply to everyone.

18How to exercise your rights

You can make a request in either of two ways — you do not need to give a reason:

  1. Email privacy@sd.digital, with the right you want to exercise in the subject line.
  2. Call or text (619) 777-1313 and say you are making a privacy request.

18.1 Verifying who you are

Before we act, we have to be reasonably sure the request comes from you — handing your information to an impostor would be a breach in itself. Because we hold so little, this is usually simple: we will ask you to send the request from, or confirm, the email address we already hold, and to identify the enquiry in question. For a deletion request we may ask for a second confirmation. We will not ask for a government identity document unless the sensitivity of the request genuinely requires it, and we will not use anything you send for verification for any other purpose.

If we cannot verify you, we will tell you why, and we will treat a request to know specific pieces of information as a request for categories instead, where the law permits.

18.2 How fast we respond

Response times
Framework Acknowledgement Substantive response Extension
CCPA (California) Within 10 business days Within 45 calendar days A further 45 days where reasonably necessary, with notice to you
Other US state laws — Within 45 calendar days A further 45 days, with notice
UK / EU GDPR — Within 1 month A further 2 months for complex or numerous requests, with notice within the first month
Shine the Light — Within 30 days —

In reality, a studio this size will usually answer within a few days. Requests are free. We limit free requests to twice in any 12-month period per person, as the CCPA permits.

19Children's privacy

This website is a business-to-business marketing site. It is not directed to children, and we do not knowingly collect personal information from anyone under 18.

We do not knowingly collect personal information from children under 13, which would require verifiable parental consent under the Children's Online Privacy Protection Act (COPPA), and we do not knowingly sell or share the personal information of consumers under 16, which would require opt-in consent under Cal. Civ. Code § 1798.120(c). Where the UK Age Appropriate Design Code or the EU GDPR sets a higher age of digital consent, we apply that higher age.

If you are a parent or guardian and believe a child has given us personal information, contact privacy@sd.digital and we will delete it promptly.

20Automated decision-making and profiling

We do not carry out automated decision-making that produces legal effects concerning you or similarly significantly affects you, and we do not profile you. A human reads every enquiry that reaches us.

The only automated step in the process is the honeypot spam filter described in section 4.1, which discards submissions that no human made. If a genuine message of yours is ever caught by it, simply call us — no automated system has the last word here.

We do not use personal information submitted through this site to train machine-learning or generative AI models.

21Third-party links

Our site and our documents link to a small number of external sites — regulators, open-source projects, and the like. Following a link takes you to a service we do not control, with its own privacy policy and its own cookies. We are not responsible for their practices, and this policy stops at our domain boundary. Read theirs before you give them anything.

22Changes to this policy

We review this policy at least annually, and whenever we change how we handle personal information. When we update it, we will revise the “Last updated” date and version number at the top of the page.

If a change is material — for example if we started using analytics, or began collecting a new category of information — we will say so prominently on the site before the change takes effect, and, where the law requires consent, we will ask for it rather than assume it. We will never apply a materially different policy retroactively to information we already hold without telling you.

Previous versions are available on request.

23Contact us

Questions, requests, and complaints about privacy all go to the same place, and a human will read them.

Email
privacy@sd.digital
Phone — call or text
(619) 777-1313
In writing on paper
Ask us by email or phone and we will give you a postal address for correspondence.
Alternative format
Need this policy in large print, plain text, or another accessible format? Ask, and we will send it. See our Accessibility Statement.

SD Digital · Privacy Policy v1.0 · Effective August 11, 2026

All legal documents · Back to top

SD DIGITAL

SAN DIEGO DIGITAL

Apps · Websites · Web Apps · APIs · Devices · IoT

Navigate

Services API Coverage Stack Contact

Legal

Privacy Policy Cookie Notice Terms of Service Accessibility All documents

Direct line

(619) 777-1313

Call or text, human answers.

© 2026 SD Digital · Engineered in San Diego, California

Back to top