Privacy

Privacy Policy

Effective and last updated: August 12, 2026

This policy explains how Drop in a Bucket LLC collects, uses, shares, and retains information through this business technology website and its Technology Opportunity Review intake.

Who this policy covers

Drop in a Bucket LLC operates this website and is responsible for the information described below. This policy covers information collected through the public website and Technology Opportunity Review intake. A client engagement may involve additional terms in a master services agreement, statement of work, or other engagement document.

Information collected

The Technology Opportunity Review intake asks for ordinary business contact and workflow information, including:

  • Your name, email address, business name, role, and approximate team size.
  • An optional business website or public page and optional industry or business type.
  • A description of one workflow, its most recent occurrence, frequency, people involved, tools involved, friction, practical consequences, desired outcome, timing, and preferred next step.
  • Your answer about whether the workflow involves regulated or especially sensitive information and your acknowledgement of the intake safety boundary.
  • The page used to submit the request, a limited referrer address, and campaign parameters such as source, medium, or campaign when present in the page address.

The website and its providers may also process technical information needed to deliver and protect the site, such as IP address, browser and device information, request time, requested page, security signals, and submission or delivery status. The application creates a confirmation number for an accepted intake.

How information is used

Drop in a Bucket uses this information to:

  • Review and respond to your Technology Opportunity Review request.
  • Understand the workflow you chose and prepare for a focused conversation.
  • Communicate about a possible or resulting business relationship.
  • Protect the form, detect abuse, troubleshoot delivery, and maintain the website.
  • Keep appropriate business records and comply with legal obligations.

Service providers and sharing

Drop in a Bucket uses service providers to operate this website and deliver intake requests:

  • Cloudflare hosts the website and Pages Function and provides Turnstile abuse prevention. Cloudflare processes website requests and security signals. Its Turnstile Privacy Addendum explains that service's processing.
  • Resend sends each accepted intake as a readable email with a structured JSON attachment and maintains email and delivery data. Its Privacy Policy describes its practices.
  • Microsoft 365 hosts the shared mailbox where the intake email and attachment are received and handled.

These providers process information to provide their services. Drop in a Bucket may also disclose information when reasonably necessary to comply with law, protect rights or safety, investigate abuse, or support a business transaction involving the company, subject to appropriate safeguards.

Drop in a Bucket does not sell personal information and does not share personal information for cross-context behavioral advertising.

Cookies, analytics, and tracking

At the date shown above, this site does not use advertising pixels, advertising cookies, or a visitor analytics service. Cloudflare Web Analytics is not enabled. The application does not place its own cookies or use browser local storage.

The intake loads Cloudflare Turnstile to distinguish legitimate requests from abuse. The current Turnstile configuration does not use pre-clearance, so it does not issue a cf_clearance cookie through this form. Cloudflare may still process device and network signals needed to provide Turnstile and protect its service.

Resend open and click tracking is not configured for intake delivery. The intake email is sent to Drop in a Bucket's own shared mailbox; it is not a marketing email to the person submitting the form.

The site does not collect information about a visitor's activities over time and across unrelated websites for profiling or advertising. Because Cloudflare provides Turnstile on many websites, Cloudflare may receive security signals when a visitor interacts with Turnstile on this site and other sites that use the service. Drop in a Bucket does not receive an across-site activity profile and does not use Turnstile information for advertising.

Do Not Track and browser privacy signals

Because the site does not use cross-site behavioral tracking or advertising technology, it does not change its behavior in response to browser Do Not Track or similar preference signals. If tracking practices change, Drop in a Bucket will reassess this statement and the site's privacy controls before enabling the new technology.

Where information is kept and for how long

The website does not store intake submissions in a site database or prospect CRM. Each accepted intake is delivered through Resend to a Drop in a Bucket Microsoft 365 shared mailbox. At the date shown above, Resend states that it retains email data for 30 days on standard plans. Provider practices may change independently, so current provider terms also apply.

Drop in a Bucket generally keeps inquiry information for up to 12 months after the last substantive interaction. Information may be kept longer when needed for an active or resulting engagement, legitimate business recordkeeping, dispute resolution, security, or legal obligations. Obvious spam and information submitted contrary to the safety instructions may be deleted sooner.

When information is no longer needed, Drop in a Bucket deletes or de-identifies it where reasonably practicable. Deleted information may remain temporarily in service-provider backup, recovery, security, or delivery systems before being removed under those providers' practices.

Access, correction, and deletion requests

You may ask what information you submitted, request a correction, or ask for deletion by emailing privacy@dropinabucket.dev. Include enough information to identify the submission, such as your name, business name, email address, or confirmation number. Drop in a Bucket may need to verify your identity and may retain information when reasonably necessary for an active engagement, legal obligation, security, fraud prevention, or another legitimate exception.

Do not submit sensitive information

Do not use the public intake to send passwords, access or recovery codes, banking or payment information, customer or employee records, medical, legal, student, tax, or other regulated records, confidential documents, system exports, or detailed security information. If a future engagement requires protected information, the collection method and safeguards must be agreed separately.

Changes to this policy

Drop in a Bucket may update this policy when the website, providers, or information practices change. The revised policy will be posted on this page with a new effective or last-updated date. A prominent website notice will be used when a change materially affects how previously submitted information is used.

Contact

For privacy questions or requests, email privacy@dropinabucket.dev.