1. Who we are
CWO Strategy Group, LLC ("we," "us," "our") is a web design, website management, and search engine optimization firm based in Columbus, Ohio. This policy explains how we handle information collected through cwostrategy.com, our client portal, and our direct business communications.
Data controller: CWO Strategy Group, LLC, Columbus, Ohio, United States. Contact: [email protected].
2. What we collect
Information you give us
- Consultation form — name, email, phone (optional), business name, current website (optional), budget range, and your project description.
- Email and phone — whatever you choose to send, plus your address or number.
- Client portal accounts — name, work email, a hashed password, and the change requests you submit.
Information collected automatically
- Server logs — IP address, user agent, referring page, requested URL, timestamp. Used for security, rate limiting, and abuse prevention. IP addresses are stored hashed.
- Essential cookies — a session cookie when you log into the portal, and a CSRF token cookie on forms.
- Aggregate analytics — page views and referrers. See section 4.
What we do not collect
- We do not collect payment card numbers on this site.
- We do not use advertising trackers, third-party ad pixels, or cross-site profiling.
- We do not buy contact lists or enrich your record with data from brokers.
3. How we use it
- To reply to your enquiry and prepare a quote.
- To deliver and support the services you've engaged us for.
- To operate your portal account and process change requests.
- To keep the site secure — rate limiting, bot filtering, abuse investigation.
- To meet legal, tax, and accounting obligations.
We do not sell personal information. We do not share it for cross-context behavioural advertising. We do not use your data to train AI models.
4. Cookies and analytics
We use a small number of strictly necessary cookies and no advertising cookies at all:
cwo_session— identifies your portal session. HttpOnly, Secure, SameSite=Lax. Expires after 12 hours.cwo_csrf— a token that proves a form submission came from our site. Session-length.
Analytics are aggregate and privacy-respecting: we record page views and referrers without cookies, cross-site identifiers, or fingerprinting. We cannot single you out from analytics data.
5. Client portal data
Managed clients get a portal account showing analytics for their own website. Passwords are stored as salted Argon2id hashes — we cannot read them and will never ask you for one. All portal data is scoped to your account on the server; identity is derived from your session, never from anything the browser sends. Editing a hidden field, a cookie, or a request body cannot reach another client's data.
6. Who we share it with
Only the service providers required to run the business, and only the minimum each one needs:
- Hosting and CDN — serves the site and stores server logs.
- Email provider — delivers our replies and your password reset links.
- Analytics provider — aggregate traffic figures only.
We may also disclose information where we are legally required to, or to protect our rights or the safety of others. If the business is ever sold or merged, client data may transfer as part of that transaction; you would be told in advance.
7. How long we keep it
- Enquiries that don't become projects — 24 months, then deleted.
- Client records and correspondence — for the engagement plus 7 years, to meet tax and accounting requirements.
- Portal accounts — until you ask us to close them, then 30 days.
- Server logs — 90 days.
8. How we protect it
- HTTPS enforced everywhere, with HSTS.
- Argon2id password hashing; passwords are never stored or logged in readable form.
- Session cookies are HttpOnly, Secure, SameSite, and rotated on sign-in.
- CSRF tokens on every state-changing request.
- Rate limiting and bot filtering on all public forms.
- Sensitive free-text fields encrypted at rest with AES-256-GCM.
- Least-privilege database access and parameterized queries throughout.
No system is perfectly secure. If a breach ever affects your data, we will tell you and the relevant authorities without undue delay.
9. Your rights
Wherever you live, you can ask us to give you a copy of your data, correct it, delete it, or stop using it. Email [email protected] and we'll respond within 30 days. We won't charge you or treat you differently for asking.
If you're in the EU or UK (GDPR): our lawful bases are consent (for enquiries), contract (for client work), legal obligation (for tax records), and legitimate interest (for security). You may lodge a complaint with your supervisory authority.
If you're in California (CCPA/CPRA): you have the right to know, delete, correct, and opt out of sale or sharing. We do not sell or share personal information, so there is nothing to opt out of.
10. Children's privacy
This is a business-to-business site and is not directed at anyone under 16. We do not knowingly collect information from children. If you believe a child has sent us data, email us and we'll delete it.
11. Changes to this policy
If we change this policy we'll update the date at the top of the page. For material changes affecting existing clients, we'll email you as well.
12. Contact
Questions, requests, or complaints: [email protected]. CWO Strategy Group, LLC — Columbus, Ohio, United States.