Legal

Privacy Policy

What we collect, why, who processes it for us, how long we keep it, and your rights. Written for the shop owners we work with and for anyone who visits our site.

Last updated September 30, 2026

The short version

  • We collect what you send us (your shop, your city, how to reach you) and use it to make your report and reply to you.
  • As a client, you give us helper access to your Google listing and, for the social plan, your Facebook and Instagram pages. We see what that access shows. We never hold a password.
  • We do not sell your information, we do not share it for advertising, and our website has no analytics, tracking or advertising cookies.
  • Reply STOP to any text from us and we stop texting you.
  • Ask and we will show you what we have, fix it or delete it: hello@ceriseagency.com.

1. Who we are

This policy covers Cerise Agency (“Cerise,” “we,” “us”), a business name of Silk Creative Labs LLC, dba Cerise Agency, a California limited liability company, Los Angeles, CA. It explains what we collect through our website, the free report and our three services (Reviews, Your Google listing, and Social media), and what we do with it. Questions: hello@ceriseagency.com.

It does not cover Google, Meta, Stripe or any other company’s own use of your information when you deal with them directly. Their policies are linked in section 7.

2. What we collect and where it comes from

When you fill in the form on our website

The form has three fields: your shop’s name, your city, and a phone number or email address where we send the report, plus an optional, unticked box to get occasional tips by email. It also has a hidden field that people never see; automated spam fills it in, and we discard those submissions. The form is handled by Netlify, our website host, which stores the submission and emails it to us; we also keep a copy in our request list in Airtable.

When you book a call

Our booking page is a Google Calendar appointment page. It asks for your name, email address and phone number and creates a Google Meet link. Google processes that booking under its own privacy policy.

When we talk

The emails and text messages you send us, your name if you give it, and notes we make about your shop and what you asked for.

When you become a client

  • Contact and account details. Your name, the shop’s name and address, your email address and the mobile number we send your text template to.
  • Billing. When you pay through a Stripe payment link, Stripe collects your name, business name, phone number, email address and card details. We see the name, business, contact details, what you bought, when, and the last four digits of the card. We never see or store the full card number.
  • Your Google Business Profile. You add our Google account as a Manager. Through that role we can see what any Manager can see: your reviews (with reviewers’ public Google names and what they wrote), your business details, your photos and posts, your Q&A, and your Performance report (calls, direction requests, website clicks, views and the search terms people used). We use it only for the work in your plan.
  • Your Facebook Page and Instagram account. For the social media plan you give our Business Portfolio partner access limited to content tasks. Through it we can see your page’s posts, its insights (reach, follows, profile taps and similar counts), and, depending on the tasks you grant, comments and messages. We do not download follower lists and we do not read private messages unless your plan includes replying to them.
  • Photos and content you send us. Photos of your work, your space, your team and, with their permission, your clients; your logo; your prices and offers; your words. These may include images of people. You are responsible for their permission (see our Terms, section 12). We use them only for your listing, your posts and your cards.

Public information about businesses

To build the free report and the monthly reports, we use information that is public on Google Maps about your shop and nearby shops: names, categories, listed addresses, ratings, review counts and review dates. We get it through a third-party data provider. Public reviews can include a reviewer’s public display name and words. We use this only to describe businesses. We do not build profiles of individual reviewers, and we do not contact them.

When you visit our website

Our hosting provider, Netlify, keeps standard server logs (IP address, browser type, the page requested and the time) for security and to keep the site running. Our fonts are served from our own site. Two pages load a small animation library from cdnjs, a Cloudflare service, so your browser contacts Cloudflare, which receives your IP address as part of delivering the file. That is the only outside request our pages make.

3. Cookies and tracking

We do not use analytics, advertising or tracking cookies, and we do not use tracking pixels. Our pages set no cookies of their own. If you pay online, Stripe’s payment page may set cookies it needs for security and fraud prevention. If you book a call, Google’s booking page may set cookies. If we ever add analytics, we will update this page first and tell current clients by email.

4. How we use it

  • To make your free report and send it to you.
  • To reply to you and talk about your request.
  • To provide the service you bought: the card designs, the text template, replies to your reviews, Google posts and photos, Q&A answers, social media posts, and your monthly reports.
  • To bill you, send receipts, and keep business and tax records.
  • To keep our website and service secure, to prevent fraud, and to follow the law.
  • To tell you about a change to your service, our prices or these pages.

We do not use your information for anything else without asking you first. We do not use it to build advertising profiles, and we do not use your customers’ information for any purpose but replying to their reviews on your behalf.

5. Texts and emails

When you send the form on our website, you agree that we may text or email you about your request. That means your report, a question we need to ask to make it, and at most two follow-ups. It does not put you on a marketing list.

Clients get texts and emails about their service: the welcome message, card designs and drafts for approval, check-ins, reports and receipts. We do not send marketing texts to people who have not asked to hear from us.

To stop: reply STOP to any text from us, or tell us in any reasonable way (a reply, an email, a call), and we stop. We honor a request to stop within 10 business days, and usually the same day. We may send one final text to confirm you have opted out. Message and data rates may apply. Consent to texts is not a condition of buying anything from us.

We do not text your customers. The text template is something you send yourself, from your own phone or app, to customers who gave you their number. We never hold their numbers.

Tips email goes only to people who tick the tips box on our form. Leaving it unticked means we contact you only about your request.

Marketing email, if we ever send it, will identify us as the sender, say what it is, and carry an unsubscribe link that works within 10 business days, as the CAN-SPAM Act requires.

6. Who we share it with

We do not sell personal information, and we do not share it for cross-context behavioral advertising. We disclose it only to:

  • Service providers who process it on our behalf, under contracts that limit them to doing that work for us. They are listed in section 7.
  • The Platforms, when we post a reply, a post, a photo or an answer on your Google listing, Facebook Page or Instagram account at your request. Google’s and Meta’s own policies apply to what happens there.
  • Authorities or others when the law requires it, to respond to a valid legal request, or when needed to protect our rights, your safety or someone else’s.
  • A buyer or successor if the Cerise business is sold or transferred, under this policy’s protections, with notice to current clients.

7. Our service providers (sub-processors)

ProviderWhat it does for usWhat it handlesIts policy
Netlify, Inc.Hosts our website and handles the formServer logs; form submissions (shop, city, contact)netlify.com/privacy
Airtable (Formagrid, Inc.) and Make (Celonis, Inc.)Keep our list of form requests and copy each new request into itForm submissions (shop, city, contact, tips choice)airtable.com/company/privacy · make.com/en/privacy-notice
Stripe, Inc.Processes payments and receiptsName, business, contact details, card details, what you boughtstripe.com/privacy
Zoho Corporation and Google LLC (Gmail and Google Workspace)Our email and calendarEmails, bookings, attachments you sendzoho.com/privacy · policies.google.com/privacy
Google LLC (Google Business Profile)The platform where your listing livesEverything on your listing; our replies, posts and editspolicies.google.com/privacy
Meta Platforms, Inc. (Facebook and Instagram)The platform where your social pages liveEverything on your pages; our posts and captionsfacebook.com/privacy/policy
Buffer (Buffer, Inc.)Schedules social postsApproved posts, captions and photos; page connectionbuffer.com/privacy-policy
A public-data providerSupplies public Google Maps listing data for reportsPublic business listings and review counts; your shop’s name and location as the queryNamed on request
Anthropic, PBCAI writing tools that help draft replies, captions and reportsReview text, your shop’s public details, your notes on voice; never card details or customers’ private detailsanthropic.com/privacy
Cloudflare, Inc. (cdnjs)Serves an animation library on two pagesYour IP address when the file loadscloudflare.com/privacypolicy
Print shopsPrint cards if you order through usThe card file (your shop name, your review link)Named when you order

If we add or change a provider that handles client information, we update this table. Stripe, Google and Meta also act on their own account for fraud prevention and to run their platforms; their policies describe that.

8. How long we keep it

  • Form requests that do not turn into work: deleted within 12 months, or sooner if you ask.
  • Client information, including photos and content you sent us and the drafts we made: kept while you are a client and for up to 12 months after, then deleted, or sooner if you ask.
  • Billing and tax records: kept as long as tax law requires, usually seven years.
  • Public business data used in reports: kept as long as it is useful for reports, then deleted.
  • Server logs: kept by Netlify for its own security period.
  • Anything already posted on your Google listing or social pages stays there. It is yours to edit or delete.

9. Security

We use reasonable safeguards: two-step sign-in on every account we use for client work, access limited to the two people who do the work, encrypted devices, and no passwords of yours anywhere. Card details never touch our systems; Stripe holds them. No system is perfectly secure. If a breach affects your unencrypted personal information, we tell you without unreasonable delay, as California law requires.

10. Your choices and rights

Anyone, anywhere, can ask us to show them the personal information we have about them, correct it, delete it, or stop contacting them. Email hello@ceriseagency.com. Clients can also remove our access to their Google listing and social pages at any time from their own settings; we explain how on request.

If someone whose photo you gave us asks us to take it down, we tell you and remove it from anything we control.

11. California residents

The California Consumer Privacy Act, as amended by the California Privacy Rights Act (together the “CCPA”), applies to businesses that have more than $26,625,000 in annual gross revenue, that buy, sell or share the personal information of 100,000 or more California residents or households a year, or that get half or more of their revenue from selling or sharing personal information. Based on our size and how we work, we believe Cerise does not currently meet any of these thresholds and is not a “business” under the CCPA. We still give every California resident the rights below, voluntarily, and we will keep doing so. If we ever become a covered business, we will update this page and follow the law in full.

What we collected in the last 12 months

CategoryExamplesWhere it comes fromWhyDisclosed to
IdentifiersName, email, phone, IP addressYou; our website hostReplying, the service, securityProviders in section 7
Commercial informationWhat you bought and whenYou; StripeBilling, recordsStripe; our email provider
Professional informationYour shop’s name, city and detailsYou; your Google listingReports, the serviceProviders in section 7; the Platforms
Audio, visual informationPhotos you send us, which may show peopleYouPosts, cards, your listingThe Platforms; Buffer; print shops
Internet activityServer logsOur website hostSecurity, keeping the site runningNetlify; Cloudflare
Public informationPublic business listings and reviews; reviewers’ public namesGoogle Maps via a data provider; your listingReports, repliesAI writing tools (review text only)

We do not collect sensitive personal information as the CCPA defines it. We do not sell or share personal information and have not done so in the last 12 months. We do not knowingly collect the personal information of anyone under 16.

Your rights

  • Right to know what personal information we collect, use and disclose, and to get a copy.
  • Right to delete personal information we collected from you, with limited exceptions (for example, records the law requires us to keep).
  • Right to correct inaccurate personal information.
  • Right to opt out of sale or sharing. We do not sell or share, so there is nothing to opt out of, but you may still ask. We treat a Global Privacy Control signal from your browser as a valid opt-out request for that browser.
  • Right to limit the use of sensitive personal information. We do not collect it.
  • Right not to be treated differently for using any of these rights.

How to ask

Email hello@ceriseagency.com with “Privacy request” in the subject and tell us what you would like. We confirm we received it within 10 business days and answer within 45 days; if we need longer, we may take up to 45 more days and will tell you why. Opt-out requests are honored within 15 business days. To protect you, we confirm your identity by matching details we already have, such as the phone number or email address you used with us; we never ask for more than we need. You may use an authorized agent; we may ask for proof that you gave them permission. We do not charge for requests unless they are clearly excessive, and we tell you before charging.

12. Children

Our services are for businesses, and our website is not directed to children. We do not knowingly collect information from anyone under 16. If you think we have, email us and we will delete it. Clients must not send us photos of children without a parent’s or guardian’s permission.

13. Where your information is processed

We are in Los Angeles, California, and we work from here. Our service providers are United States companies, but some of them process data in other countries (for example, Stripe says it may transfer data to the United States and India, and Zoho to countries where it operates). They do so under their own contracts and transfer mechanisms. We do not otherwise send your information outside the United States.

14. Changes

If we change this policy, we update the date at the top. If a change is significant and you are a client, we email you before it takes effect. Earlier versions are available on request.

15. Contact

Silk Creative Labs LLC, dba Cerise Agency, a California limited liability company, Los Angeles, CA. Email hello@ceriseagency.com.