Privacy Policy
Your information has a purpose. Here is what we collect, how it supports our work together, and how to reach us about it.
On this page 11 sections
Who we are
Vitamin & Code is the public-facing brand of Vitamin Digital Media LLC (“we,” “us,” or “our”). We provide website development, hosting, maintenance, integrations, and related technology services.
This policy covers our website, contact form, client portal, and communications about our services. It also covers our optional SMS inquiry alerts. For privacy questions or requests, email kevin@vitamin.nyc.
Website inquiries
Our contact form asks for your name, email address, the service you need help with, and a message. You may also provide your organization, website, and how you heard about us. We record an IP address when it is available.
We use this information to understand and respond to your inquiry, discuss a potential project, and keep a record of the conversation. Submissions are stored in Convex, and an email containing the inquiry details is routed to the studio through Brevo. Copies may also remain in our email correspondence.
When configured, Cloudflare Turnstile checks the submission for spam and abuse. Its verification involves a browser-generated token and may include your IP address. Our contact form does not request a mobile number or enroll you in text messages.
Client portal & payments
The client portal brings project work, messages, and billing into one place. Depending on your relationship with us, it handles:
- Accounts and access: your name, email, organization membership, invitations, and authentication information. Better Auth, connected to Convex, handles email/password sign-in, sessions, and password resets. Authentication records can include technical information such as IP addresses and browser details.
- Client and project records: business and billing contact details, project names and descriptions, progress, updates, screenshots, and service-related notes.
- Messages and uploads: support and project conversations, sender details, timestamps, read status, and files you or we upload, including file names, types, and sizes.
- Billing records: invoices, line items, amounts, due dates, payment status, monthly subscription details, and Stripe customer and transaction references.
Stripe collects payment details through its hosted checkout. Our portal stores billing records and payment references, rather than full card numbers or card security codes. Stripe also processes information under its own terms and privacy practices.
We use portal information to provide and administer services, coordinate project work, manage access, answer support requests, and reconcile payments. Information associated with a client organization is available to the studio and that organization’s authorized portal users; messages are not a private channel between individual staff members.
Brevo delivers service emails such as invitations, password resets, invoice notices, and unread-message notifications. These communications are separate from the optional SMS program.
How information is shared
We use service providers to operate the website and deliver our services. Information is sent to providers for the functions they perform:
- Convex: application data, portal authentication through the Better Auth integration, and uploaded-file storage.
- Brevo and email providers: inquiry routing, service notifications, and business correspondence.
- Stripe: payment collection, subscription billing, and payment-status reporting.
- Cloudflare: Turnstile spam and abuse checks.
- Google and Adobe: website analytics and font delivery, respectively.
- Hosting and infrastructure providers: serving the website and processing the technical requests needed to operate it.
The SMS program also uses Twilio and necessary messaging providers, as explained below. Providers may process information in locations other than your own; their practices and any applicable service arrangements govern their handling of that information.
We may disclose information when needed to comply with applicable legal obligations or to address fraud, abuse, or threats to the rights and safety of our clients, users, or business. The specific protections for mobile information and SMS consent below continue to apply.
Information on client websites
An inquiry sent through the Vitamin & Code website is an inquiry to our studio. An inquiry submitted on a client business’s website is directed to that business.
Where our service arrangement includes hosting, maintenance, form integrations, or notifications, we may process information on that client’s behalf to provide the agreed services. The client determines its website’s purposes, requested information, and authorized recipients, subject to the applicable agreement.
Consult the client business’s own privacy notice for its use of information. Requests about that business’s records should normally go to it first. We can assist with information handled through our services as appropriate to our role and agreement; this policy does not replace the client’s notice.
SMS inquiry alerts
Vitamin & Code Website Inquiry Alerts sends branded notifications about contact-form submissions on a client business’s own website to that business’s designated, opted-in owners and authorized staff. It does not enroll website visitors, send marketing texts, or distribute inquiries to unrelated businesses.
Enrollment is by direct email consent during onboarding: each recipient receives the program disclosures, explicitly agrees by email, and confirms their mobile number. Enrollment is voluntary, and SMS consent is not required to purchase website services. The invitation email and a sample consent reply are shown on our SMS opt-in page.
The service processes recipient mobile numbers, the business each recipient belongs to, email consent records (the invitation, the reply, the consent date, and the authorized number), message content, and delivery and opt-out records. Twilio, carriers, and necessary service providers process this information to deliver messages and operate the service.
Mobile information is not sold or shared with third parties for their promotional or marketing purposes. SMS opt-in data and consent are not shared with third parties for their own marketing. This does not prevent necessary processing by providers that help deliver and operate the service.
Message frequency varies with website inquiries. Message and data rates may apply. Reply STOP to unsubscribe; reply HELP for help or email kevin@vitamin.nyc. Carriers are not liable for delayed or undelivered messages.
Alerts are sent only to numbers whose recipient-specific consent is on file. After you reply STOP, your number is removed and receives no further alerts unless you opt in again. Read the SMS program terms for the full program description.
Retention & deletion
Retention depends on the information and why it is held: responding to inquiries, providing ongoing services, maintaining project history, keeping billing records, resolving disputes, and meeting applicable obligations. We do not promise a single retention period for all records or automatic deletion after a fixed interval.
You can request deletion by emailing kevin@vitamin.nyc. We will assess the request in light of our role, your relationship with the client business, and applicable requirements. Some information may need to be retained for contractual, accounting, legal, or security reasons; copies may also remain in email systems, provider records, or backups according to their applicable retention processes.
Removing portal access or canceling a subscription does not automatically delete project, message, or billing records. For information processed on a client’s behalf, we may need the client’s instructions before changing or deleting its records.
Protecting information
Our application uses authenticated portal access, invitation-based account creation, and access checks for client and administrator functions. We use managed providers for authentication, storage, and payment processing. These measures help limit access, but no website, storage system, or transmission method can be guaranteed completely secure.
Keep your account credentials private and use care with uploaded files and shared links. Do not send passwords, full payment-card details, or sensitive information that is unnecessary for the work through contact forms or portal messages. Contact us if you suspect unauthorized access.
Your choices & requests
You can choose what to include in an inquiry, leave optional form fields blank, manage browser cookies, and contact us about your information. Depending on applicable law and our role in processing it, you may have rights to access, correct, delete, or obtain a copy of information, or to object to or restrict certain uses.
Send requests to kevin@vitamin.nyc, describing the information and service involved. We may need to verify your identity and authority to act for a client business before responding. Requests are handled subject to applicable requirements and any relevant exceptions; this policy does not promise rights that do not apply to your circumstances.
For client-website information, contact that business as described above. SMS choices are separate from essential account, billing, and project communications.
Updates & contact
We may update this policy as our services and practices change. The “Last updated” date identifies the latest revision.
For questions about this policy or our handling of information, contact Vitamin Digital Media LLC, operating as Vitamin & Code, at kevin@vitamin.nyc.