Legal

Privacy policy.

Effective September 12, 2026 · Version 2026-09-12

This Privacy Policy explains how Vail Valley AI LLC (“Vail Valley AI,” “we,” “us,” or “our”), a Colorado limited liability company based in Eagle County, Colorado, collects, uses, shares, and protects information when you visit www.vailvalleyai.com (the “Site”) or use our services. The short version: we collect only what you give us through our forms plus standard technical records, we use it to respond to you and provide our services, we never sell it, and we run no advertising trackers or third-party analytics of any kind. The only usage measurement on the Site is our own cookie-free, first-party measurement, described in Section 2.

Contents

  1. Information You Provide to Us
  2. Information Collected Automatically
  3. How We Use Information
  4. Email Communications and Email Tracking
  5. Service Providers We Share Data With
  6. Other Sharing; No Sale of Data
  7. Cookies, Local Storage, and Tracking
  8. How Long We Keep Information
  9. Your Choices and Rights
  10. Security
  11. Children
  12. Do Not Track and Global Privacy Control
  13. International Visitors
  14. Changes to This Policy
  15. How to Contact Us

1. Information You Provide to Us

You can browse the entire Site without giving us any personal information. We collect personal information only when you choose to submit one of our forms:

Form What you provide
Contact form (/contact) Name, email address, phone number (optional), business name (optional), your message, and an optional newsletter opt-in
Newsletter signup (site footer and /guide) Email address; for the guide, also your name and industry
AI Readiness Assessment (/tools/ai-readiness) Your answers to nine questions about your business operations, plus your name, email address, business name, and industry, the resulting score and grade, and an optional newsletter opt-in
Consultation booking (/book) Name, email address, company (optional), notes (optional), your time zone, and the meeting slot you choose

When you submit a form, we also record the version of our Terms of Service in effect at the time of your submission, as evidence of your agreement.

2. Information Collected Automatically

We do not run third-party analytics, advertising pixels, session recording, or trackers of any kind. We do measure how the Site is used ourselves, on our own servers, without cookies and without storing anything that identifies you. For each page view we record: the page’s path on our Site; the website that referred you (its domain name only); any campaign tags in the link you followed (the utm_source, utm_medium, and utm_campaign parameters, and no other part of the address); a coarse estimate of your location — country, state or region, and city — which our hosting provider derives from your IP address before that address is discarded; and an anonymized visitor code. The location estimate identifies an internet provider’s point of presence rather than a person, and is often the wrong town on mobile, corporate, or VPN connections. We use it only to understand which towns our visitors come from. The visitor code is produced by a keyed cryptographic hash of your IP address and browser signature. Your raw IP address and browser details are never stored — only the resulting code, which is meaningless to anyone who does not hold our secret key and cannot be reversed back into your address.

What changed on September 12, 2026. Until that date this code was re-keyed every day, so your visits could not be connected from one day to the next. It is now stable: the same browser on the same connection produces the same code until our secret key changes. We made that change so that one person reading several pages over a week is counted as one visitor rather than seven, and so we can see the order in which pages were read. The practical effect is that the code can link your visits to this Site over time. It still contains no name, email address, account, or cookie; it still cannot follow you to any other website; and it still changes whenever your IP address or browser does, which for most people is often. We regenerate the secret key periodically, which permanently severs every existing code from the visits recorded before it.

We also record a small, fixed set of actions: calls-to-action clicked, forms started and successfully submitted, booking starts and completions, completed AI Readiness Assessments, guide downloads, newsletter confirmations, and Core Web Vitals (LCP, INP, and CLS). An action record contains the action name, a short component identifier, the current page path, the original landing path and acquisition fields described above, the same pseudonymous visitor code, and — for a Core Web Vital only — its numeric measurement and Google’s “good,” “needs improvement,” or “poor” rating. The action vocabulary is fixed in our code and database. We do not collect what you type into a form, link text, search terms, full URLs, prompts, email addresses, phone numbers, or other free text through analytics.

To understand which source led to a later form submission, we keep the first landing path, referring hostname, and approved utm_* fields in your browser’s session storage for the current tab. We also keep short, non-identifying event keys there so a successful submission is not counted twice after a rerender or refresh. These values expire when the tab’s browser session ends; they are not cookies and contain no visitor or account identifier.

We do not record your device type, browser, or operating system. Page-view records created before September 1, 2026 may contain those fields, and page views recorded between September 1 and September 2, 2026 carry no location estimate. Those rows remain subject to the ordinary raw-analytics retention period described below and are not joined to contact details.

When you submit a form, our servers automatically record three technical details along with your submission: your IP address, your browser’s user-agent string, and the page you submitted from (with its query string and fragment removed). For inquiries and bookings we also retain the session’s original landing path, referring hostname, and approved campaign tags alongside the information you submitted. We keep these details as evidence of consent, to understand which outreach produced a request, and to prevent spam and abuse (including rate limiting by IP address). Standard server logs maintained by our hosting provider may also record requests to the Site.

Some pages show information adapted to where you are — for example, our working hours converted to your time zone. Your time zone is read from your own browser settings and never leaves your device. Separately, those pages make one request to our own server, in which our hosting provider derives an approximate country from your IP address. That country is used only to phrase a sentence on the page: it is not stored, not logged, and not associated with you, and your IP address is used only for rate limiting that request. No third-party service is involved, and nothing is written to your device.

3. How We Use Information

  • To respond to your inquiries and provide the services you request;
  • To schedule, confirm, manage, and remind you about consultations you book;
  • To send you the newsletter or content you asked for — only after you confirm your subscription (double opt-in);
  • To generate your AI-readiness results and follow up about them;
  • To prevent spam, abuse, and fraud, and to secure the Site;
  • To keep records that document consent and compliance with law; and
  • To comply with legal obligations and enforce our Terms of Service.

We do not use your information for advertising, and we do not use it to train AI models.

4. Email Communications and Email Tracking

Newsletter subscriptions use double opt-in: you receive a confirmation email, and we only send you the newsletter after you confirm. Every marketing email we send includes an unsubscribe link, including one-click unsubscribe (RFC 8058), and a link to your preference center, where you can change email frequency or unsubscribe. We honor unsubscribe requests within 10 business days, and usually immediately.

Email tracking disclosure: our email delivery provider records, on a per-recipient basis, whether an email was delivered, opened, or bounced, and which links in it were clicked. We use this to understand what content is useful, to stop sending to addresses that bounce, and to maintain sending reputation. If you prefer not to be tracked this way, you can unsubscribe at any time, and many email clients also block open tracking by default.

Transactional emails (such as booking confirmations, cancellation notices, and subscription confirmations) are sent as needed to provide the service you requested.

5. Service Providers We Share Data With

We share personal information only with the service providers that operate the Site’s infrastructure, each acting on our behalf:

Provider What it does
Vercel Hosts the Site and runs our form-processing functions; maintains standard server and application logs
Supabase Hosts our database, where form submissions, subscriptions, bookings, consent records, and the anonymized page-view, action, and performance statistics described in Section 2 are stored
Resend Delivers our transactional and newsletter email, stores contact details for sending, and reports delivery, open, and click events
Google (Google Calendar) When you book a consultation, we may create the calendar event through Google Calendar, which sends the invitation (with your name, email, company, and notes) directly to you
Svix Verifies the authenticity of email-event notifications sent to us by Resend

Each provider processes data under its own security and privacy commitments, and we share only what each needs to do its job.

6. Other Sharing; No Sale of Data

We do not sell, rent, or trade your personal information, and we do not share it with anyone for advertising. Beyond the service providers above, we disclose personal information only: (a) if required by law, subpoena, or court order; (b) to protect the rights, safety, or property of Vail Valley AI, our clients, or the public; or (c) as part of a merger, acquisition, or sale of assets, in which case this policy continues to apply to your information.

7. Cookies, Local Storage, and Tracking

The Site sets no cookies for visitors. There is no third-party analytics service, no advertising pixel, and no cross-site tracking of any kind — our security policy blocks third-party scripts from loading at all. We measure Site use ourselves, on our own servers, without cookies (see Section 2). For visitors, session storage holds only the current tab’s limited acquisition context and deduplication keys described there and is cleared when that browser session ends. Our private staff-only admin page separately uses client-side storage to keep staff logged in. Because we set no cookies and do not use cross-site tracking, we do not display a cookie banner.

8. How Long We Keep Information

  • Inquiries and bookings are kept for as long as needed to serve you and maintain our business records.
  • Newsletter data is kept while you are subscribed. If you unsubscribe, we stop emailing you but retain a suppression record (so we don’t accidentally email you again) and the underlying subscription record.
  • Consent records (the IP address, user-agent, page URL, timestamp, and terms version captured with your submissions) are retained as long-term legal evidence of consent, as permitted by anti-spam and privacy laws.
  • Page-view, action, and performance records (the pseudonymous entries described in Section 2) are kept for up to about 13 months, which is also the longest period over which the visitor code described in that section can connect visits. We can compare a season to the one before it; aggregate statistics derived from them may be kept indefinitely.

You can request deletion of your information at any time — see Your Choices and Rights.

9. Your Choices and Rights

  • Unsubscribe from marketing email at any time via the unsubscribe link in any email or your preference center.
  • Access, correct, or delete your information by asking us through our contact form. We handle these requests manually and will respond within 30 days. We may retain what we are legally required or permitted to keep (for example, suppression records that keep you unsubscribed and consent records that document compliance).
  • Decline to provide information — every form on the Site is optional; browsing requires nothing.

Depending on where you live, you may have additional rights under state or national privacy laws (such as rights of access, correction, deletion, and portability). To the extent those laws apply to us, you can exercise those rights through our contact form, and we will not discriminate against you for doing so.

10. Security

All traffic to the Site is encrypted in transit (HTTPS). Form submissions are protected against spam and abuse, database access is restricted to authenticated server-side systems, our admin tools require verified staff login with an allowlist, and administrative actions are logged. No system is perfectly secure, but we design ours so that the amount of data at risk is as small as possible — we simply do not collect most of what typical websites collect.

11. Children

The Site is a business-services website. It is not directed at children under 13, and we do not knowingly collect personal information from children. If you believe a child has submitted information to us, contact us via our contact form and we will delete it.

12. Do Not Track and Global Privacy Control

The Site does not track visitors across sites — no third-party analytics, no advertising, no third-party cookies — so there is no cross-site tracking for a Do Not Track or Global Privacy Control signal to switch off. We go one step further: when your browser sends either signal, we skip even our own first-party page, action, performance, or session-attribution measurement, and your visit is not recorded in those systems at all. We also do not sell or share personal information, so there is nothing to opt out of under state opt-out laws.

13. International Visitors

We are a United States business based in Colorado, and we serve clients both in the United States and internationally. Information you submit is processed and stored in the United States, where privacy laws may differ from those in your country. If you contact us from outside the United States, you consent to your information being transferred to and processed in the United States.

14. Changes to This Policy

If we change this policy, we will post the updated version on this page with a new effective date. For material changes, we will provide more prominent notice on the Site, and where we have your email address, we may notify you directly. Prior dated versions are available on request via our contact form.

15. How to Contact Us

For any privacy question or request — including access, correction, or deletion — reach us through our contact form at www.vailvalleyai.com/contact.