fiamma blu works

Privacy Policy

Effective August 8, 2026

Fiamma Blu Works operates fiammabluworks.com. This policy covers what we collect, who receives it, how long we keep it, and your choices. Questions: team@fiammabluworks.com.

What we collect

Newsletter email address

If you subscribe, we use your address to send the newsletter and occasional notices about this site. We do not sell or rent it. Every newsletter includes an unsubscribe link, or write to us and we will remove you.

Client portal accounts

Clients are given individual accounts; there is no self-signup. We hold the account’s email address, a sign-in password, which client it belongs to, and when documents were uploaded. Passwords are stored as hashes by our authentication provider and cannot be read by us.

The portal records the exact version and server time when an authenticated client representative accepts a portal term, privacy notice, or permission certification. These records document the instruction given; they do not replace a separately required agreement or a release signed by the person whose name, image, voice, story or testimonial is used.

Documents you upload

The portal is how clients send us documents for the work we are doing together. You choose what to send and when. We use them only for that work.

Please do not upload Social Security numbers, individual tax identification numbers, dates of birth, financial account numbers, medical information, or personnel records. If a document you need to send contains one, redact it first or contact us.

Uploads are PDF only. Each file is held in private storage, inspected on our server, and refused if it fails inspection.

Board directory

Clients may keep a private board directory in the portal. It can include a director’s name, title, term start, biography, contact information and portrait. This information is used for our work together and is not published on the website or included in notification emails.

Fundraising and communications workspace

Clients may also record organization facts, programs, impact statistics, funding opportunities and history, financial summaries, events and campaigns, approved messages, stories, media references, goals, assignments and deadlines. These records are private working information. A permission or consent field records a client’s instruction; entering a story, name, quote, image reference or statistic does not by itself authorize public use.

Clients may upload approved logos in Organization Profile and photographs in Organization Photos. These images stay in private storage with their caption, alternative text, source credit, and usage-permission record. An upload does not by itself authorize publication.

The Testimonials section may include written comments and an optional photograph or video supplied by the client. Testimonial media stays in private storage. Uploading it does not grant permission to publish it; attribution, consent and permitted uses are recorded separately.

A client may instead record a YouTube, Google Drive or other external link. We store the link and its access and permission notes; the portal does not automatically download, copy, publish or change access to linked media. The external service handles the linked file under its own privacy terms.

Material involving an identifiable minor is accepted only after the client representative certifies that the organization has the actual parent or legal-guardian permission and identifies where that underlying release is kept. We ask clients not to include unnecessary medical, educational, location, family or other sensitive details about minors.

Analytics, only if you accept

Google Analytics 4 may record page views, session activity, referring source, approximate location and device information, using a randomly generated client ID. Advertising storage, ad personalization and Google Signals stay off even after you accept.

Technical information

Netlify hosts the site and processes the newsletter form. In doing so it handles request information such as IP address, browser, time and page requested.

Outside the client portal, we do not collect names, mailing addresses, payment information, or comments through this site.

Cookies and storage

No advertising cookies. Analytics cookies are set only if you accept. Your cookie choice and, if you sign in, a portal session are stored in your browser. The cookie policy lists every item by name.

How portal information is protected

Access is enforced by database and storage rules on the server, not by what the portal chooses to display. One client cannot read another’s documents, board directory, workspace, logos, photos or testimonial media. Clients upload and view their own documents and media and may remove their own board, workspace and media records. They cannot change checklist status or administer users; document deletion is handled by Fiamma Blu Works. Documents are never published or attached to email, and open through links that expire in about a minute. Only the client organization’s authorized members and authorized Fiamma Blu Works personnel can reach them. If a breach affects your information we will notify you as required by law.

Who receives information

We do not sell or share personal information for cross-context behavioral advertising. It goes only to the providers that operate this site, and to no one else unless the law requires it:

Their handling is governed by the Netlify, Supabase, Resend and Google privacy policies.

Links to other sites

The awareness calendar links out. Those sites collect information under their own policies, which we do not control.

How long we keep it

Client documents, board directory, workspace and accounts. Deleted from the active portal when your engagement ends. Ask sooner and we will remove them sooner. Expiring backup copies may remain until their normal backup cycle ends, unless the law, a documented legal hold, a client-approved handoff or another written agreement requires different handling.

Our business record. We keep a record that we worked together: the client name, the dates, and the checklist as titles and whether each item arrived. No documents, no email addresses, no names of individuals. Ask and we will show you what we hold.

Newsletter addresses. Kept until you unsubscribe, then removed apart from the minimum needed to avoid emailing you again.

Analytics. Google Analytics applies a retention period to event data; aggregated reports may remain longer. We will tell you the current period if you ask.

We may keep information longer where the law requires it, or to resolve a dispute.

Your choices

Cookie settings, at the bottom of any page, turns analytics on or off at any time.

Whatever your state requires of us, we offer everyone the same rights: ask what we hold about you, ask for a copy, ask us to correct it, ask us to delete it, and unsubscribe. We will not treat you differently for asking. Write to team@fiammabluworks.com and we answer within 45 days.

Requests about a client’s documents should come from someone authorized to speak for that client.

Do Not Track

Browsers do not share one Do Not Track standard, so the site does not respond to that signal separately. Cookie settings controls analytics directly.

Changes

If this policy changes materially we will update the effective date and post a notice on the homepage first.

Contact

team@fiammabluworks.com

← Back Cookie policy Accessibility