Legal & Transparency

Privacy Policy

Fiona Kulnig Web Design

Last updated: August 24, 2026

This Privacy Policy explains how Fiona Kulnig Web Design (“we,” “us,” or “our”) collects, uses, stores, and shares personal information in connection with our website and our website design, hosting, and management services (the “Services”).

By using our website or Services, you acknowledge this Policy. If you do not agree, please do not use the website or Services.

1. Who we are

Fiona Kulnig Web Design is a web design and hosting service operated by Fiona Kulnig.

Email: fkulnig@gmail.com

Text / phone: +1 512 796 4113

For privacy questions or requests, email fkulnig@gmail.com.

2. Scope — our website vs. client websites

This Policy covers visitors to our own website, people who inquire about or purchase our Services, and personal information we handle as part of designing, hosting, and managing a client’s website.

Client websites we host are different. If we host your business website, you (the client) are responsible for the personal information of your visitors (for example, contact-form submissions on your site). We process that information only to provide hosting and management, on your instructions. You should publish your own privacy policy on your website.

3. Information we collect

Information you give us:

• Name, business name, email address, phone number, and mailing or billing address

• Project details, logos, images, text, and other content you send us to build or update your website

• Domain-name information and account credentials needed to register or manage your domain

• Messages you send by email, text, or phone

• Payment and billing details (processed by Stripe; we do not store full card numbers)

Information collected automatically:

• IP address, browser type, device type, and general location derived from IP

• Pages visited and approximate time spent on our website

• Diagnostic logs needed to keep hosting secure and working

We do not currently use advertising pixels or sell your information to data brokers. If we add analytics tools later, we will update this Policy.

Information from others:

• Stripe may provide payment status, last four digits of a card, and billing identifiers

• Domain registrars may provide domain registration status

• Hosting providers may provide uptime, security, and error logs

4. How we use information

We use personal information to:

• respond to inquiries and provide the Services (design, hosting, edits, security, and domain management);

• create and maintain your account, take payment, and send invoices or receipts;

• communicate about your website, including updates, outages, and cancellation;

• protect the security and integrity of websites we host;

• comply with law, enforce our Terms of Service, and resolve disputes;

• keep limited records for tax, accounting, and bookkeeping; and

• with your agreement in our Terms, use non-confidential screenshots of completed websites in our portfolio and marketing. We do not use confidential personal data from your customers for our marketing.

We do not use your information for automated decision-making that produces legal or similarly significant effects.

5. Legal bases (EEA / UK visitors and clients)

If you are in the European Economic Area or the United Kingdom, we process personal information only where we have a legal basis:

• Contract — to provide the Services you request and to take steps before a contract (inquiries, onboarding, billing)

• Legitimate interests — to secure our systems, improve the Services, keep records, and show non-confidential portfolio work, where those interests are not overridden by your rights

• Legal obligation — tax, accounting, and other laws

• Consent — where we ask for it (for example, optional marketing emails). You may withdraw consent at any time

6. How we share information

We do not sell personal information. We do not share it for cross-context behavioral advertising.

We share information only as needed with:

• Stripe — payments and billing (stripe.com/privacy)

• Hosting and website-platform providers (including Hostinger, where used) — to operate our site and client sites

• Domain name registrars — to register and manage domains on your behalf. Some registration data may be published in WHOIS or similar directories as required by the registrar or ICANN rules

• Email and communications providers — including Google (Gmail) for email, and phone/SMS carriers

• Professional advisers — such as an accountant or lawyer, under confidentiality

• Authorities — if required by law, court order, or to protect rights, safety, or security

If we use additional vendors later (for example analytics, backups, or a CRM), we will update this Policy.

7. Payments

Payments are processed by Stripe. Card numbers are submitted directly to Stripe. We may store your name, email, subscription status, and limited billing identifiers. Please also read Stripe’s privacy policy.

8. Cookies and similar technologies

Our website and hosted client sites may use cookies or similar technologies that are:

• Strictly necessary — to load the site, keep a session, or process payment

• Functional / fonts — our site may load fonts from Google Fonts, which can collect your IP address

We do not currently set advertising cookies. You can block cookies in your browser; some features (including payment) may not work without necessary cookies. Stripe and Hostinger may set their own cookies when you use their features. See their policies for details.

9. International transfers

We are based in the United States. If you are outside the U.S., your information will be processed in the United States and possibly in other countries where our providers operate. Those countries may not provide the same legal protections as your home country. Where required, we rely on appropriate safeguards (such as standard contractual clauses used by providers like Stripe).

10. How long we keep information

• Active clients — for as long as we provide the Services

• After cancellation — website files and hosted data may be deleted after a reasonable period following takedown, except for information we must keep

• Invoices, contracts, and tax records — typically up to seven (7) years, or longer if the law requires

• Inquiries that do not become clients — for a limited period so we can follow up, then deleted or archived

• Security logs — for a limited period needed to detect abuse and keep systems safe

11. Security

We use commercially reasonable measures to protect personal information, including access controls, HTTPS where available, and regular security updates on websites we manage. No method of transmission or storage is 100% secure. Please use a unique, strong password for any accounts we set up for you and tell us promptly if you suspect unauthorized access.

12. Your rights

Depending on where you live, you may have the right to:

• request access to personal information we hold about you

• request correction of inaccurate information

• request deletion, with legal exceptions (for example, invoices we must keep)

• object to or restrict certain processing

• request a copy of information you provided to us (data portability)

• withdraw consent where processing is based on consent

• lodge a complaint with a data protection authority

To make a request, email fkulnig@gmail.com. We may need to verify your identity. We will not discriminate against you for exercising privacy rights.

If we hold information only as a processor on a client website, we will direct you to that client where appropriate, or handle the request according to the client’s instructions and the law.

13. U.S. state privacy notices

We do not sell personal information and we do not share it for cross-context behavioral advertising.

Texas: We are a small business. We do not sell sensitive personal information. If Texas law gives you additional rights that apply to us, you may contact us using the details above.

California: We do not meet typical CCPA/CPRA “business” thresholds at this time. If that changes, we will update this Policy. California residents may still contact us to ask what we collect and to request deletion of information we control, subject to legal exceptions.

We do not use or disclose sensitive personal information for purposes that would require a “Limit the Use of My Sensitive Personal Information” link.

14. Children

The Services are for businesses and are not directed to children under 16 (or under 13 in the United States). We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it.

15. Client content and visitor data on hosted sites

You are responsible for having the rights and notices required for content you give us (including photos of people, customer lists, and form data). You are also responsible for telling your website visitors how you use their information.

We will not use personal information collected through your website (such as your customers’ form submissions) for our own marketing. We may access that information only to provide support, make requested edits, maintain security, or comply with law.

16. Third-party links

Our website or a hosted client site may link to third-party sites. Their privacy practices are their own. We are not responsible for those sites.

17. Changes

We may update this Policy from time to time. The “Last updated” date will change, and the revised Policy will be posted on our website. Material changes will be communicated by email when reasonably possible. Continued use of the website or Services after the effective date means you accept the updated Policy.

18. Contact

Fiona Kulnig Web Design

Email: fkulnig@gmail.com

Text: +1 512 796 4113