PRIVACY
What we collect, why, who else touches it, and how to get it back or have it deleted. Last updated August 2026.
Who we are
This site and the Imaginarii client platform are operated by Imaginarii LLC, a California limited liability company. We are the controller of the personal information described here. For any privacy question or request, email hello@imagi-narii.com, or write to us:
Imaginarii LLC2108 N St #9620
Sacramento, CA 95816 USA
(209) 979-2745
What we collect
We collect three different things from three different kinds of people, and it is worth keeping them apart.
If you just visit the website
Your browser sends an IP address and user-agent with every request; our host records those in server logs. We set one cookie to remember your cookie choice. Nothing else is set until you accept — see Cookies and analytics.
If you contact us, book a call, or subscribe
Whatever you type: your name, email address, phone number if you give one, the company you are with, and the content of your message. If you book a meeting we also record the slot you chose and create a calendar invitation.
If you are a client using the portal
Your name, email, phone, and role at the client; the projects and work items associated with you; documents you upload or we share with you; messages you send us through the portal; approvals, feedback and testimonials you submit; and invoices and payment status.
Electronic signatures carry extra evidence by design. When you sign a document in the portal, we record your name, email, the exact time, your IP address and your browser’s user-agent string, and store them with the signed document. That record is what makes the signature meaningful — it cannot be turned off, and it is retained with the document rather than deleted on request.
If you buy merchandise
Your name, email, and shipping address, plus what you ordered. Card details go directly to Stripe and never reach our servers — we store only the last digits and the result.
Why we use it
- To do the work you hired us for — run projects, share deliverables, take approvals, and support your site.
- To bill and get paid — issue invoices, take payment, chase what is overdue, and keep the records tax law requires.
- To answer you — reply to enquiries, schedule calls, and send the notifications you asked for.
- To keep the service working — monitor uptime and errors, and back up what we hold so it survives a failure.
- To improve the site — only with your consent, and only in aggregate.
We do not sell personal information, and we do not share it for cross-context behavioural advertising. We have never done either.
Who else touches it
We use other companies to run the service. They act on our instructions and may only use what we send them to provide their service to us.
| Processor | What they handle | Where |
|---|---|---|
| Vercel | Hosting, server logs, page analytics | USA |
| MongoDB Atlas | The database behind the platform and portal | USA |
| Stripe | Card and bank payments, invoices, receipts | USA |
| Google (Workspace, Analytics, Drive, Calendar) | Email we send and receive, site analytics, backups, meeting invitations | USA |
| Sentry | Error monitoring, so faults are noticed and fixed | USA |
| GitHub | Private encrypted backups of platform data | USA |
| Atlassian Jira | Project and task tracking | USA |
| Printful | Printing and shipping merchandise orders | USA / EU |
We will also disclose information where the law requires it, or to establish or defend a legal claim. If the business is ever sold or merged, client records move with it, and we will say so before that happens.
How long we keep it
Records are kept on a schedule rather than indefinitely, and the platform enforces it rather than relying on anyone remembering.
| Record | Kept for | Why |
|---|---|---|
| Contracts, signed documents, signature evidence | 7 years after the engagement ends | They are the proof the agreement existed and who agreed to it. |
| Invoices, payments, financial records | 7 years | Tax and accounting requirements. |
| Project files, deliverables, messages | Duration of the engagement plus 3 years | So work can be picked back up and questions answered. |
| Enquiries that did not become projects | 2 years | Long enough to recognise a returning conversation. |
| Analytics | 14 months (Google Analytics default) | Trend comparison year over year. |
| Error and uptime monitoring | 30–90 days | Long enough to diagnose a fault. |
| Backups | Rolling, overwritten on schedule | Deleted records disappear from backups as they rotate. |
Your rights
If you are in California, the CCPA/CPRA gives you the right to know what we hold about you, to get a copy, to have it corrected, to have it deleted, and not to be treated differently for asking. If you are in the UK or EU, the UK GDPR and GDPR give you equivalent rights plus the right to object to processing and to data portability.
To exercise any of them, email hello@imagi-narii.com. We will verify who you are — usually by replying to the address we already hold for you — and respond within 45 days. There is no charge.
Two honest limits. We cannot delete what we are legally required to keep, such as issued invoices and executed contracts, until its retention period ends. And signature evidence stays attached to the document it proves, because a signature you can ask us to erase is not worth having.
Clients can see and change much of this themselves: your marketing permissions and sign-in options live in your portal account and take effect immediately.
How we protect it
Traffic is encrypted in transit with TLS, and data is encrypted at rest by our database and storage providers. Access to client data requires an account with an explicit permission for it, and privileged accounts require a second factor. Portal sign-in is passwordless by default — a one-time link to your email — so there is no password of yours for us to lose. Backups are encrypted and held in more than one place. We monitor for errors and outages continuously.
No system is perfectly secure. If personal information is ever exposed in a way that creates a real risk to you, we will tell you and the relevant regulator without undue delay, and we will tell you what actually happened.
Children
The service is for businesses. It is not directed at children under 13 and we do not knowingly collect their information. If you believe a child has given us information, email us and we will delete it.
Changes to this policy
If we change this policy we will update the date at the top. If a change materially affects how we use information we already hold about you, we will email you before it takes effect rather than relying on you re-reading this page.
Questions, requests, or something here that does not match your experience: hello@imagi-narii.com · contact form.