Scope and operator
This notice describes the current inquiry-handling practices for SteadCo LLC’s SteadCo, Oddfizz, and Knockfolio sites. The brands share a SteadCo-managed intake process. SteadCo’s shared forms accept business inquiries without requiring a customer account. Administrative request records are restricted to the SteadCo owner. SteadCo, Oddfizz and Knockfolio are public marketing websites. Their shared request records and administrative review tools remain restricted to the SteadCo owner. This notice covers website inquiries and related service evaluation; a signed client agreement may need additional provisions for information processed on a customer’s behalf. Contact jaden@steadco.ai for a privacy question or request. Provider logging, retention periods, and applicable regional requirements must be verified before public release.
Information you choose to provide
An inquiry asks for your name, email address, business website, requested brand or service, and details needed to evaluate the request. SteadCo requests include service, territory, and objective. Oddfizz requests include promotion, available assets, channels, studio budget, preferred package, proposed performance goal, current baseline, media-test budget, measurement setup and desired launch window. Knockfolio requests include service, territory, customer criteria, and exclusions. If you write to us or make a booking, we also receive the information you choose to put in that correspondence or appointment. The current forms do not accept file uploads.
Please provide business-relevant information and minimize personal details about others. Do not submit passwords, card numbers, government identifiers, private employee or customer lists, health information, or other sensitive records through these forms. They are intended for adult business representatives, not for children or sensitive-data intake.
Records created when you make a request
The intake system records a signed-in platform user identifier when available (otherwise a guest marker), brand and offer, submitted fields, request purpose, submission and update times, a request identifier, processing status, assigned reviewer, next action, and a linked review job. It can record referral campaign labels (source, medium, and campaign), test status, a marketing choice and consent version, review reasons, deliverable references, and suppression status. Internal audit entries record the actor, action, note, and date. Owner review also stores prerequisite evidence notes, numbered deliverable-reference records and approvals tied to a specific recorded revision. These references are supplied manually and do not freeze or independently verify the contents of another document. Synthetic test requests can record a clearly labeled internal handoff rehearsal; that event is not an actual delivery or a customer message. Submitted website addresses are stored for manual review rather than automatically fetched by the form. Eligible new requests also record a rules-based qualification label, review priority, routing reason, an internal review task with a target time, and a template response draft. Requests matching a brand contact suppression stay stopped and do not generate a new task or draft.
The application does not store IP addresses, browser user-agent strings or referrer headers. Guest intake uses bounded hourly request counters shared across the service and counters based on a hash of the submitted email address. These counters limit spam; expired counter rows are removed during subsequent intake activity. That does not describe all infrastructure logging: hosting and authentication providers may process connection information to deliver and protect the site. Their logging fields and retention remain unverified and must be confirmed before public release.
How information is used
We use inquiry information to evaluate fit, review your stated needs, prepare a requested sample or proposal when accepted, communicate about the request, and administer an agreed service. We use operational records to route requests to the correct brand, prevent duplicate work and abuse, keep an approval history, and address errors or rights requests. Information may also be retained when needed to meet legal obligations or handle a dispute.
Requests enter an owner-reviewed queue. On submission, fixed rules organize each eligible request against stated service and scope criteria, route a review job, create one internal follow-up task and prepare one template response draft. Contact-suppressed requests remain stopped. The qualification label and priority are internal triage aids, not an acceptance, eligibility decision, verified buying intention or promise of delivery. The owner may pause or explicitly retry these checks, limited to three runs per request, or stop and suppress a request. The due time is an internal review target, not a promised customer turnaround. The request workflow does not run recurring customer reminders. A separate hourly owner-alert workflow checks for eligible new inquiries. Human review remains part of qualification, evidence checking, creative approval, and delivery. The website does not automatically email the person submitting a request, create bookings, publish content, enroll customers or process payment. A separate hourly owner-alert workflow notifies the verified SteadCo business inbox about eligible new non-test requests, using only the brand, request reference, received time and a private dashboard link. The alert omits the visitor’s name, email, website and free-text brief. Exact event references in the sender’s Sent folder help avoid duplicates; uncertain sends are paused for review. The database records alert eligibility separately from email delivery evidence. A form submission does not authorize unrelated marketing.
Optional marketing and choices
If a form offers marketing consent, it is optional, brand-specific, and separate from submitting the request. Leaving it unchecked must not prevent an inquiry. The preview does not activate marketing delivery. If marketing is later enabled, messages should provide a working opt-out and the required sender information. You can also request an opt-out at jaden@steadco.ai. Choosing marketing from one brand is not permission to market all brands to you. When the owner records a do-not-contact instruction, we keep the brand, normalized email address and date as a minimal contact-preference record. This stops current and future requests for that email within that brand, cancels internal tasks and excludes pending owner alerts. Other brands retain their separate preferences. Requests about privacy or correcting this preference may still be reviewed manually through the business contact address.
Service providers and sharing
The websites use OpenAI Sites for hosting and platform-managed owner authentication and a Cloudflare Worker with a D1 database for SteadCo’s shared requests, jobs, and audit records. The operator’s signed-in account is checked for administrative queue access. The platform handles authentication; the application does not implement its own customer login. Infrastructure providers process information needed to supply these services. Logging, storage locations, contractual safeguards, retention settings, and any later contractor or AI processing must be documented before this notice is finalized. Access should be limited to the work and governed by suitable privacy and security terms.
Our booking link opens Calendly. Information you enter there is handled through that service and its privacy practices, and appointment details may be made available to the host. Emailing the business also involves email providers. Merely visiting this preview does not enroll you in those third-party services. We may disclose information when required by law or when reasonably necessary to address fraud, security incidents, or legal claims, subject to applicable requirements. This draft does not authorize new transfers to an unreviewed provider.
Knockfolio professional research
Knockfolio evaluates companies using permitted public business sources and any properly licensed sources approved for the work. Research can include company locations, relevant public developments, professional roles, and available business contact information with a stated verification status. A delivered brief distinguishes sourced facts from an interpretation of fit and records research limitations. Source access, reuse restrictions, and the accuracy of professional contact details must be checked.
Inquiry contact information is not offered as a prospect list. Separately researched professional information may be included in a client’s research deliverable for the agreed business purpose. This is a distinct data flow from website inquiries. The treatment of that flow under applicable privacy and data-broker laws must be reviewed before paid delivery. Being publicly accessible does not automatically mean that personal information may be used without limits. Anyone with a concern about information in a brief can contact jaden@steadco.ai to request review, correction, or exclusion, subject to applicable law and source constraints.
Cookies analytics and external content
No third-party analytics, advertising pixels or customer email analytics have been activated in the reported preview implementation. The application does not set custom cookies or use browser localStorage or sessionStorage. The hosting platform manages authentication cookies when someone signs in for owner access. The application audit log supports operational review and does not represent real sales or customer counts. The platform cookie inventory and handling of browser Do Not Track or legally recognized opt-out signals remain to be verified; this draft does not claim they are fully implemented.
Before enabling optional analytics, advertising pixels, embedded booking, or new third-party content, we must assess the information sent, update the notice, and implement any required consent or opt-out controls. External links have their own privacy practices after you follow them. No blanket sale-or-sharing exemption is asserted for every possible future service.
AI tools and confidential information
AI tools may assist with research, drafting, design, or production. Speculative generated visuals used in the preview do not require uploading private inquiry records. The intake process does not automatically send submitted form content to a generation tool. Any project requiring use of customer materials in AI tools needs an approved data flow and review of provider use, retention, and licensing terms. This draft does not promise that every vendor disables training, immediately deletes inputs, or stores data only in one country.
Retention security and international processing
We intend to keep personal information only as long as needed for the request or agreed service, legitimate recordkeeping, legal obligations, and handling disputes, while retaining minimal suppression records when needed to honor contact preferences. Exact retention periods and deletion procedures for inquiries, research records, logs, backups, and completed projects are owner decisions still awaiting implementation and verification. Current deletion requests require manual review. Marking a record “do not contact” stops current and future request/job workflows for the same brand and normalized email. It archives unsent drafts and cancels internal tasks, but does not permanently erase request details, audit history or linked deliverables. A separately reviewed deletion must account for those records and any provider-held copies while preserving contact preferences where appropriate. These procedures must be finalized before public release.
The request queue is intended for authorized owner access rather than public browsing. Reasonable access controls and operating procedures are needed, but no system can be guaranteed perfectly secure. We have not certified the deployment to a security standard. Provider locations and any cross-border processing must also be confirmed; no guarantee of U.S.-only storage or a specific international transfer mechanism is made in this draft.
Requests and regional rights
You can contact jaden@steadco.ai to ask what information we hold about your inquiry, correct inaccurate details, request deletion, or change marketing preferences. Please identify the request or business email concerned without sending an identity document unless an appropriate verification method has been arranged. We may need proportionate verification to protect against unauthorized disclosure or deletion. Some records may need to be retained for legal or security reasons, which should be explained where applicable.
Depending on applicable law, additional access, correction, deletion, portability, opt-out, appeal, or complaint rights may apply. Legal coverage and the procedures and deadlines that implement those rights must be assessed before launch. This preview is not a statement that every state or international privacy law applies, or that a small-business exemption removes all obligations.
Children changes and contact
These services are intended for adult business representatives and are not directed to children under 13. We do not ask for information about children. If you believe a child submitted personal information, contact jaden@steadco.ai so it can be reviewed and addressed.
A final notice will show an effective date. Material changes should be communicated in a way appropriate to the change and applicable law; revised text alone is not permission to repurpose previously collected information incompatibly. Privacy questions and concerns can be sent to SteadCo LLC at jaden@steadco.ai.