Privacy Policy
Last updated: September 9, 2026
Digiloom Web Design (“Digiloom”, “we”, “us”) builds accessible, open-source web platforms for cooperatives, non-profits, and independent creators. We are based in Vancouver, British Columbia, Canada, and work remotely with clients in several time zones.
This policy explains what personal information we collect, why, and what you can do about it. It covers two different situations: visiting this website, and working with us as a client. We have tried to write it in plain language. We hope this works for you.
Our approach
We value your privacy and our own. We don’t collect any information to share with other big corporations that could lead to them using it to advertise to you. So our privacy policy is one where there is very little to disclose. Some deliberate choices behind this site:
- There are no contact forms. Getting in touch means emailing us directly, so your message never passes through a form processor or a third-party service.
- Fonts are served from our own server. This site makes no request to Google Fonts or any other font CDN, so browsing here does not tell a third party that you did.
- There are no advertising networks, no tracking pixels, no session recording, and no social media tracking widgets anywhere on this site.
- We do not sell, rent, or trade personal information. Ever, to anyone, for any purpose.
What we collect when you visit this website
Server logs
Our web host records standard server logs for every request: your IP address, the page requested, the date and time, your browser’s user-agent string, and the referring page if there is one. These logs exist to keep the site running securely and to diagnose problems. We do not use them to build a profile of you, and we do not combine them with any other information.
Cookies
If you are simply reading this site, we set no cookies. WordPress sets cookies only for people who log in to administer the site, or who leave a comment and ask to have their details remembered. There is no consent banner here because there is nothing to consent to.
Analytics
We do not currently run any analytics or visitor-measurement software on this site. If that changes, we will update this policy before turning it on, and we will choose a tool that does not track people across other websites.
Comments
Where commenting is available, we store the name, email address, and website you provide, along with your IP address and browser user-agent, so we can display the comment and moderate spam. Your email address is not published. If you have a Gravatar account, the site may send a hashed version of your email address to Gravatar so your avatar can be displayed; their privacy policy governs that. Comments and their metadata are kept indefinitely unless you ask us to remove them.
Embedded content from other websites
Pages on this site may link out to other websites, including our clients’ sites. Following a link means that site’s own privacy practices apply, not ours. We do not embed third-party media that would load content from another server without you choosing to go there.
What we collect when you email us
When you email us, we receive whatever you choose to send: your name, email address, and the content of your message. We use it to answer you and, if we end up working together, to run the project. We keep business correspondence for as long as it is useful for the working relationship and for the records we are required to keep, and we delete enquiries that do not lead anywhere once they are clearly stale.
We do not add you to a mailing list because you emailed us. If we ever start a newsletter, joining it will be something you opt into deliberately.
Information we handle for clients
This is the part most website privacy policies leave out, and for a web development company it matters most.
Building and maintaining a platform usually means we are given access to systems that hold other people’s personal information: a membership database, a volunteer roster, a mailing list, submitted forms, server backups. In that work we act as a service provider to our client, who remains responsible for that information. We handle it under these commitments:
- We access client data only as far as the work requires, and we prefer anonymised or sample data when it will do the job.
- We do not copy client data onto devices beyond what a task needs.
- We do not use client data to train models, to build our own datasets, or for any purpose beyond the work we were engaged to do.
- At the end of an engagement we hand over everything and, at the client’s request, destroy our remaining copies and access credentials.
- If we become aware of a breach affecting client data, we notify the client promptly so they can meet their own reporting obligations.
If you are a member of the public whose information sits in a system we built, your relationship is with that organisation, not with us. Contact them first; we will support them in responding to you.
Your rights
Under Canadian privacy law (the federal Personal Information Protection and Electronic Documents Act (PIPEDA) and British Columbia’s Personal Information Protection Act (PIPA)) you can ask us to tell you what personal information we hold about you, to correct it if it is wrong, and to explain how it has been used and disclosed. Where we rely on your consent, you can withdraw it.
If you are in the United Kingdom or the European Economic Area, you may also have rights of erasure, restriction, portability, and objection under the UK GDPR or EU GDPR. We are happy to honour those requests regardless of whether we are strictly required to.
To exercise any of this, email us. We will respond within 30 days, and we will not charge you for a reasonable request. We may need to confirm your identity before releasing information.
Security
This site is served over HTTPS. We keep software patched, use unique credentials stored in a password manager with multi-factor authentication where it is available, and limit administrative access to the people who need it. No system is perfectly secure, and we will not claim otherwise — but we treat a breach as a serious failure, not a cost of doing business.
Changes to this policy
When this policy changes we will update the date at the top. If a change materially affects how we handle information we already hold, we will say so clearly rather than quietly revising the page.
Contact us
So that’s our Privacy Policy; perhaps overkill, perhaps a refreshing take. We hope you found it helpful.
Questions, requests, and complaints about privacy all go to the same place: robin@digiloom.com.
If we cannot resolve your concern, you can complain to the Office of the Privacy Commissioner of Canada, or to the Office of the Information and Privacy Commissioner for British Columbia. We would rather you came to us first, but you do not have to.