Privacy Policy
Last updated: October 8, 2026
This Privacy Policy explains how Cuanto Labs LLC, a Florida limited liability company ("Cuanto Labs," "we," "our," or "us"), collects, uses, shares and protects personal information when you visit cuantolabs.com and pay.cuantolabs.com (the "Site"), contact us, book a call, use our free tools, pay us online or work with us. We are the controller of the personal information described here.
It does not cover the websites and apps we build for our clients, which are governed by those clients' own privacy notices (see Section 9), or our separate products, which have their own policies, except where this policy says otherwise.
1. The Short Version
- We do not sell your personal information or share it for targeted advertising, and we run no advertising pixels or ad networks on the Site.
- Our only analytics tool is OnyxMetric, which we operate ourselves. It is cookieless.
- Payments are handled by Stripe. We never see or store your full card or bank account number.
- You can ask us to access, correct or delete your information at any time by emailing office@cuantolabs.com.
2. Information We Collect
Information you give us
- Inquiries and requests. When you use our contact, project, audit or "request a time" forms, we collect your name, email address, company, website address, business type and message, along with which form you used.
- Newsletter. When you subscribe, we collect your name and email address.
- Scheduling. When you book a call through our scheduler, which runs on MeetSynq, our own self-hosted booking system, we collect your name, email address, time zone, chosen time and any notes you add, and send calendar invitations to the addresses you provide.
- Payments. When you pay an invoice or a proposal deposit, you enter your payment details directly into Stripe's secure form. We receive your name, email address, billing details, the amount, the payment method type and whether the payment succeeded. We keep invoice and payment records in our accounting system, Bigcapital, which we host ourselves.
- Client work. When we work together, we collect the messages, files, account access and project information you share with us.
Information collected automatically
- Analytics (OnyxMetric). Our analytics script records the pages you visit, the referring page and campaign tags (such as UTM parameters), clicks, form submissions (the fact that a form was sent, never what you typed), copied text, outbound links, errors, page performance (Web Vitals), your browser, operating system, device type and screen size, and an approximate location (country, region and city) derived from your IP address. It also records session replays, which reconstruct how pages were used so we can find usability problems; password and email fields are masked, and payment fields are inside Stripe's secure frame and are not captured. To tell visits apart, the script stores a random visitor identifier in your browser's local storage. It does not use cookies.
- Linking a visit to an inquiry. When you submit a form or book a call, we link your analytics session to the resulting record using an internal ID. We do not send your name or email address to our analytics tool. Our servers also record conversion events, such as a new inquiry or a completed payment, and send your IP address and browser type with them so they join the right session.
- Where you came from. For the length of your browser session, we keep a short note of how you arrived (for example, from search or a referral, and your landing page) in session storage, and send it with any form you submit.
- Error monitoring (Sentry). If something breaks, our error monitoring service, Sentry, receives technical details about the error, including your IP address, browser, the page and the steps that led to it. Sentry also records replays of a sample of sessions and of sessions where an error occurs. Those replays mask all text and form inputs.
- Server logs. Our hosting provider, Vercel, records standard request logs, including IP address, user agent, the page requested and the time.
- Links we send you. Buttons in documents and some links we send may be tracked links that tell us when they are opened, so we can follow up at the right time.
- Preferences. If you choose a color theme, the choice is saved in your browser's local storage.
Information from others
- Stripe tells us whether a payment succeeded and the details listed above.
- LinkedIn provides the information described in Section 4 when you connect an account to Cuanto Socials.
- Referrals and public sources. We may receive your contact details from someone who refers you to us, or find business contact information you have made public.
3. Cookies and Similar Technologies
- No advertising cookies. We do not use advertising or retargeting cookies, social media tracking pixels or third-party marketing tags.
- Our own storage. The Site uses browser local storage for the analytics visitor identifier and your theme choice, and session storage for how you arrived. These are not cookies and are not shared with other websites.
- Third parties on specific pages. On payment and proposal pages, Stripe sets cookies and uses similar technologies to prevent fraud, keep payments secure and support its Link feature for saved payment details. Our scheduler may use storage it needs to work. These are governed by the providers' own policies.
- Your choices. You can clear or block local storage, session storage and cookies in your browser settings, and content blockers will stop our analytics script from running. Blocking Stripe's cookies may prevent online payment.
4. Cuanto Socials and LinkedIn Data
We use the LinkedIn API to provide social media management features to our clients through Cuanto Socials (also known as Cuanto Marketing), available at socials.cuantolabs.com. When you connect your LinkedIn account or LinkedIn Page:
- Data collected from LinkedIn. Profile name, profile picture, LinkedIn member ID, company page names and IDs, and post engagement metrics, as permitted by LinkedIn's API.
- How we use it. Solely to schedule, publish and manage posts on the LinkedIn personal profiles and company pages you authorize.
- Sharing. LinkedIn data is never sold or shared with third parties. It is stored securely and used only to provide the social media management service.
- Revoking access. You can disconnect your LinkedIn account at any time in Cuanto Socials or in your LinkedIn security settings.
- LinkedIn's policy. Use of LinkedIn data is also governed by LinkedIn's Privacy Policy.
5. How We Use Information
For people in the European Economic Area and the United Kingdom, we name the legal basis for each use in brackets.
- To reply to you and prepare proposals [steps you ask for before entering a contract, and our legitimate interest in responding to inquiries].
- To provide the Services and manage our relationship with you [performance of a contract].
- To process payments, keep accounting records and meet tax obligations [performance of a contract and legal obligation].
- To send our newsletter [consent, which you can withdraw at any time using the unsubscribe link].
- To understand how the Site is used and improve it, using analytics, session replays and error reports [legitimate interest in running a usable, reliable website].
- To alert our team. When you submit a form, book a call or make a payment, we notify our team by email and messaging apps (such as WhatsApp) with the details needed to follow up [legitimate interest in responding promptly].
- To keep the Site and our systems secure, prevent fraud and spam, and enforce our Terms of Service [legitimate interest and legal obligation].
- To comply with the law and respond to lawful requests [legal obligation].
We do not use your personal information for automated decision-making that has legal or similarly significant effects on you.
6. How We Share Information
We do not sell, rent or trade your personal information, and we do not share it for cross-context behavioral advertising. We share it only as follows:
- Service providers who process it on our behalf under contracts that limit their use of it:
- Vercel, Inc. (website hosting and file storage)
- Neon (database hosting)
- Stripe, Inc. (payment processing)
- Plunk and Amazon Web Services (email delivery through Amazon SES)
- Functional Software, Inc., doing business as Sentry (error monitoring)
- WhatsApp (messages to our own team about new inquiries and payments)
- Tools we operate ourselves. OnyxMetric (analytics), MeetSynq (scheduling) and Bigcapital (accounting) run on infrastructure we control.
- People working on your project, such as subcontractors, who are bound by confidentiality obligations.
- Professional advisors, such as accountants and lawyers, under a duty of confidentiality.
- Legal and safety reasons, when required by law, court order or a lawful government request, or to protect the rights, property or safety of our clients, the public or us.
- Business transfers, if we are involved in a merger, acquisition, financing or sale of assets, subject to the commitments in this policy.
- With your consent or at your direction.
7. How Long We Keep Information
- Inquiries that do not lead to an engagement: deleted or anonymized after 3 years without contact.
- Client, contract and billing records: for the length of the relationship and 7 years after it ends, to meet tax and accounting requirements.
- Newsletter subscriptions: until you unsubscribe. We then keep only your email address on a suppression list so we do not email you again.
- Analytics and session replays: detailed event and replay data for up to 24 months, after which we delete it or keep it only in aggregated form that does not identify you.
- Error monitoring data: up to 90 days in Sentry.
- Server logs: according to our hosting provider's standard retention, which is short.
We may keep information longer when the law requires it or to resolve disputes and enforce our agreements.
8. Security
We protect personal information with encryption in transit (HTTPS), access controls limited to people who need it, encrypted storage of credentials, signed and unguessable payment links, and payment processing by a PCI DSS Level 1 certified provider. No system is perfectly secure. If a breach affects your personal information, we will notify you and the authorities as the law requires, including within the time limits set by Florida law.
9. Data We Process for Our Clients
When we build, host or maintain systems for a client, we may process personal information about that client's customers or users on the client's behalf, as a service provider or processor. The client's privacy notice governs that information. If you are one of our clients' users and want to exercise your rights, please contact that client first; we will help them respond.
10. Your Privacy Rights
Everyone. Wherever you live, you can ask us to tell you what personal information we hold about you, give you a copy, correct it or delete it, and you can unsubscribe from our newsletter at any time. We extend these rights to everyone, whether or not a particular privacy law applies to a business of our size.
European Economic Area, United Kingdom and Switzerland (GDPR). You also have the right to object to processing based on legitimate interests, to restrict processing, to data portability, and to withdraw consent at any time without affecting earlier processing. You may lodge a complaint with your local data protection authority. We process information in the United States. When we transfer personal information from the EEA, the UK or Switzerland, we rely on the European Commission's Standard Contractual Clauses or the EU-U.S. Data Privacy Framework and its UK and Swiss extensions, where our providers are certified.
California (CCPA/CPRA). In the past 12 months we have collected these categories of personal information: identifiers (such as name, email address and IP address); commercial information (such as invoices and payments); internet or other electronic network activity (such as pages viewed and interactions); approximate geolocation; and professional information (such as company and role). We collect them from the sources and use them for the purposes described above, and we disclose them to the categories of recipients in Section 6. We do not sell or share personal information, as those terms are defined in California law, and we have no actual knowledge of selling or sharing the information of anyone under 16. We do not use or disclose sensitive personal information for purposes that would give you the right to limit it. California residents have the right to know, to access, to delete and to correct their personal information, to opt out of sale or sharing, and not to be discriminated against for exercising these rights. You may use an authorized agent, and we may ask the agent for proof of authorization.
Florida. Florida residents have rights under Florida law, including the Florida Digital Bill of Rights, to confirm whether we process their personal data and to access, correct, delete and obtain a copy of it, and to opt out of its sale, targeted advertising and profiling. We do not sell personal data or use it for targeted advertising or profiling, and we honor these requests whether or not the law applies to a business of our size.
Other US states. Residents of states with comprehensive privacy laws, including Colorado, Connecticut, Texas, Virginia and others, have similar rights, and we honor them in the same way.
Global Privacy Control. If your browser sends a Global Privacy Control signal, we treat it as a valid request to opt out of the sale or sharing of your personal information for that browser. Because we do not sell or share personal information, nothing about your experience changes.
How to make a request. Email office@cuantolabs.com with the subject "Privacy request." We will verify your identity, usually by confirming control of your email address, and respond within 30 days, or within the shorter period your law requires. If we need more time, as some laws allow, we will tell you why. If we decline your request, we will explain why, and you may appeal by replying to our decision; we will respond to an appeal within 45 days. If your appeal is denied, you may contact your state attorney general.
11. Children
The Site and our Services are intended for adults and businesses. We do not knowingly collect personal information from anyone under 18. If you believe a child has given us personal information, contact us and we will delete it.
12. Emails From Us
Every marketing email includes an unsubscribe link, which takes effect promptly. We will still send messages you need, such as invoices, receipts, booking confirmations and project communications.
13. Links to Other Sites
The Site links to other websites, including the sites of clients in our portfolio. Their privacy practices are their own, and we encourage you to read their policies.
14. Changes to This Policy
We may update this Privacy Policy as our Site and Services change. We will post the updated version here with a new "Last updated" date, and if a change is material, we will also tell you by email if we have an ongoing relationship with you or by a notice on the Site.
15. Contact Us
Questions about this Privacy Policy or a privacy request can be sent to:
Cuanto Labs LLC
1314 E Las Olas Blvd, Unit #2570, Fort Lauderdale, FL 33301
Email: office@cuantolabs.com