Skip to content
pyr0.dev

pyr0.dev Privacy Policy

Last updated: 2026-08-11 · Effective: 2026-08-11

John Venice DBA pyr0.dev ("pyr0.dev," "we," "us," "our") is a web development practice — custom websites, e-commerce storefronts, install-ready plugins, and bespoke development — run on our own servers in the United States. This Privacy Policy explains, in plain language, what personal data we collect, how we use and share it, and the rights available to you. It applies to the pyr0.dev website and to the services we provide through it (together, the "Service") and supplements our Terms of Service.

Our promise on your data. We believe you own your data. Any user, in any jurisdiction — not only those covered by GDPR or CCPA — may ask us to delete or anonymize their personal data, and we will honor that request. Any user may ask us for a full export of the personal data we hold about them, after we confirm their identity — everything we have, to the extent the law allows us to provide it. The one practical limit is offsite backups; see §9 for exactly how we handle deletion in backups.

We do the work ourselves. pyr0.dev is a small independent practice, not an advertising business. We do not sell personal data, and we do not share it for cross-context behavioral advertising. We disclose identifying data to a service partner only where that partner is strictly required to deliver something you asked for — see §5 for exactly who receives what, and why.

Our role. For personal data of visitors, enquirers, account holders, and customers of pyr0.dev, we are the controller. Where we build or operate a site, store, or plugin for a client, and we handle end-user data on that client's behalf, the client is the controller and we act as a processor under our agreement with them; this policy describes our own practices, not theirs.

Contact: Privacy questions and requests — hello@pyr0.dev. Postal: John Venice DBA pyr0.dev, 19363 Willamette Dr, #152, West Linn, OR 97068, USA.


1. Who this policy covers


2. Personal data we collect

a) Data you send us directly. When you use the contact form or email us, we receive your name, email address, and the contents of your message, plus anything else you choose to include. The form does not require an account, and we ask for no more than this. Some of our enquiry forms also store your submission on our own server — name, email address, message, and a timestamp — before we attempt to deliver it, so that a mail delivery failure cannot lose your enquiry. That stored record does not include your IP address. It stays on infrastructure we operate and is sent to no additional third party.

b) Account and profile data (when we offer accounts). Name, email address, password (stored hashed, never in plain text), and any profile or preference settings you provide.

c) Sign-in data from identity providers (when we offer third-party sign-in). If you choose to sign in with Google, Apple, Microsoft, or a similar provider, we receive from that provider — under the scopes you approve — your name, email address, a stable account identifier, and, where you have one, your profile picture, together with the OAuth tokens needed to keep you signed in. We request the minimum scopes needed for the features you use. See §7 for Google-specific commitments.

d) Purchase, order, and transaction data (when we offer purchases). For a purchase, subscription, or paid engagement, we and our payment processor receive what the transaction needs: your name, email address, IP address, billing address, the items or services purchased, amounts, currency, timestamps, and the processor's transaction, invoice, and refund references. pyr0.dev does not store card numbers, full payment-card details, or bank credentials — those go directly to the payment processor, which is PCI-DSS compliant. We keep only the billing metadata the processor returns to us, which is what we need to fulfil the order, answer questions about it, handle refunds and cancellations, and meet our tax and accounting obligations.

e) Fulfilment and support data (when we offer purchases). Order status, delivery or licence-issuance details, download or install records, support correspondence about an order, and refund or cancellation requests.

f) Usage, device, and log data. IP address, browser and device type, pages requested, referring URL, and timestamps, recorded in our server access logs. Our contact and enquiry endpoints also hold a requesting IP address in memory for one hour purely to enforce a rate limit; it is never written to a database and is discarded when the hour elapses.

g) Analytics — anonymized, aggregate, and ours alone. Where we look at how the Service is used, we do so from anonymized, aggregated data, for our own operational purposes only: identifying errors and defects, and troubleshooting when a user asks us for support. The intent is to know that something broke or that an action occurred — not who did it.

We run no third-party analytics, advertising, or tracking services — there is no Google Analytics, no advertising or conversion pixel, no tag manager, and no cross-site tracking on pyr0.dev. We use no session-replay product and no live user-tracking product of any kind, and we do not record your screen, your mouse, your keystrokes, or your session. Analytics data is never sold, rented, or offered to any other company in any form.

h) Communications. Messages you send us and our replies, and — when we offer purchases — the transactional messages we send you about an order, such as order confirmations, receipts, delivery or licence notices, and refund or cancellation notices. These purchase-related messages are part of the service you bought, not marketing, and are sent regardless of any marketing preference.

We do not intentionally collect special-category or sensitive personal data, and we ask that you not send it to us through the contact form or in free-text fields.


3. How we use personal data

We send marketing communications only where permitted, and you can opt out at any time. Opting out of marketing does not stop transactional messages about an order or engagement.


4. Legal bases (GDPR Art. 6)

We treat all users as data subjects with the rights set out in §11, regardless of where they live. Where GDPR applies, we rely on:

PurposeLegal basis
Answering your enquiry and taking steps at your request before a contractContract / pre-contractual steps — Art. 6(1)(b)
Providing the Service, an account, or a purchase you asked forContract — Art. 6(1)(b)
Security, abuse prevention, error and defect diagnosis, and support troubleshootingLegitimate interests — Art. 6(1)(f)
Marketing emails; any non-essential cookie or non-essential browser storageConsent — Art. 6(1)(a) (withdrawable)
Keeping financial, tax, and record-keeping recordsLegal obligation — Art. 6(1)(c)

Our GDPR position. We are based in the United States and do not currently target the EEA, the UK, or Switzerland. We do not turn users there away, and we apply GDPR-equivalent treatment to every user as a matter of policy. Nothing in this policy is an assertion that we are established in the EU or the UK.


5. How we share personal data (sub-processors and recipients)

We share personal data only where it is needed to deliver something you asked for. The table below is the complete list of outside recipients for pyr0.dev today, what each receives, and why.

RecipientWhat it receivesWhy it receives it
DartNode (US) — infrastructure and hostingEverything the Service stores or processes on our servers, including server access logs containing IP addresses, as the operator of the machines we rentWe run pyr0.dev on our own containers on rented hardware; the provider necessarily hosts the disks and network those run on
Backblaze B2 (US) — offsite backup storageEncrypted backup archives only. Backups are encrypted by us before they leave our servers, so B2 stores ciphertext it cannot readDisaster recovery, so an outage or hardware failure does not lose data
MXroute — email delivery for hello@pyr0.devThe name, email address, and message text you submit through the contact form, and the content of email correspondence with usTo carry your message to our mailbox and our reply back to you
Porkbun — domain registrar and authoritative DNSDNS queries for pyr0.dev, which carry the IP address of the resolver making the lookup rather than your browsing historyTo make pyr0.dev resolvable on the internet
Simple Icons CDN (cdn.simpleicons.org) — technology logos on our homepageYour IP address and browser user-agent, as an unavoidable part of any HTTP request. It sets no cookie, receives no identifier from us, and is sent nothing about who you are or what you do on the siteTo serve the technology logo images shown in the homepage "built with" strip

We also disclose personal data to professional advisors and to authorities where the law requires it, and, in a merger, acquisition, or sale of assets, to the acquiring party (with notice). Where such a transfer involves your Google user data (see §7), we will obtain your explicit prior consent before that data is transferred.

When we offer purchases, one further recipient applies:

When we offer third-party sign-in, identity providers (for example Google, Apple, or Microsoft) receive the fact that you are authenticating to pyr0.dev and return the profile fields described in §2(c). They operate under their own policies — see §14.

We do not sell personal data, and we do not "share" it for cross-context behavioral advertising as those terms are defined under California law. We do not sell, rent, or offer analytics data to any other company in any form, and we run no advertising network, data broker relationship, or ad-tech integration of any kind.

Our own tooling is not on this list, on purpose. Source control, the container registry, CI, log storage, and monitoring all run on infrastructure we operate ourselves. No third party receives that data, so there is no sub-processor to name for it.


6. International data transfers

We are US-based and process personal data on servers in the United States. If you are outside the United States, using the Service means your personal data is transferred to, and processed in, the United States. Where we transfer personal data out of the EEA, the UK, or Switzerland, we rely on appropriate safeguards such as the EU Standard Contractual Clauses (and the UK Addendum), or another lawful transfer mechanism. Contact hello@pyr0.dev for more information or a copy of the relevant safeguards.


7. Google API Services User Data Policy — Limited Use

pyr0.dev's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. This commitment applies to any data we obtain from Google APIs, including Google account and profile data received when you choose to sign in with Google. Specifically, that data:

We request the minimum scopes needed for the sign-in features we offer, and we do not request restricted or sensitive scopes we do not use.

You can review and revoke pyr0.dev's access to your Google data at any time at https://myaccount.google.com/permissions.


8. Cookies, local storage, and similar technologies

Today pyr0.dev sets no cookies. Not first-party cookies, not third-party cookies, not analytics cookies, not advertising cookies — none. We have verified this against the running site: with no account features enabled, loading pyr0.dev writes no cookie of any kind to your browser.

The only thing we store in your browser in that state is a single local storage entry named theme, holding the value light or dark. It is written only if you click the theme toggle, it records nothing but that preference, it contains no identifier, and it is never sent to our servers or to anyone else. You can remove it at any time by clearing site data for pyr0.dev in your browser settings.

When we offer accounts or third-party sign-in, the site sets essential authentication and session cookies. These are strictly necessary to sign you in and to keep you signed in across requests: they hold a session identifier rather than any tracking identifier, they are first-party, and they are removed when you sign out or clear site data. Because they are strictly necessary to provide the account and sign-in features you asked for, they are set without a consent prompt. We set no non-essential cookie as part of signing in.

Because the only cookies we set are strictly necessary, and we set no non-essential browser storage, there is nothing non-essential to consent to, and pyr0.dev shows no cookie consent banner. That is a statement of what the site does, not a claim that a consent mechanism exists. If we ever introduce a non-essential cookie or non-essential browser storage — including any analytics or advertising technology — we will implement a consent mechanism in which refusing is as easy as accepting, and nothing beyond strictly necessary storage will be written before you consent.

One third party is contacted by your browser when you load our homepage: cdn.simpleicons.org serves the technology logo images. It sets no cookie and receives no identifier from us; see §5 for what it does receive. Decorative imagery from other sources is fetched by our server and re-served from pyr0.dev, so your browser never contacts those origins. Our web fonts are downloaded at build time and served from pyr0.dev, so your browser never contacts Google Fonts.


9. Data retention, deletion, and backups

We keep personal data only as long as we need it for the purposes described, then delete it or, where deletion would break something we are required to keep, anonymize it. Anonymization is our default disposition; we delete outright where anonymization is insufficient.

DataRetention
Contact-form submissions and email correspondence24 months after our last exchange with you, then deleted — unless the correspondence forms part of a project or financial record we must keep longer, in which case the row below governs
Enquiry records stored on our server (see §2(a))Held in an append-only file with no automatic expiry; we remove a record by hand when you ask us to, through the request process below. We do not run a scheduled deletion job over these records, so we do not claim a fixed window for them
Account and profile data (when we offer accounts)Life of the account + 90 days after closure, then deleted or anonymized
Sign-in tokens from identity providers (when we offer third-party sign-in)Until you disconnect the provider or close the account, then purged
Order, transaction, and fulfilment records (when we offer purchases)7 years, because US tax and accounting law requires it — longer than we would otherwise keep them
Rate-limit records for our contact and enquiry endpoints1 hour, held in memory only and never written to a database
Server access logs (including IP addresses)30 days in the log store we run ourselves, then deleted
Application and container logsA small rolling buffer on the server — roughly 30 MB per service, oldest entries overwritten first. Not archived and not backed up
Theme preference in your browser's local storageUntil you clear site data; we never receive it
Encrypted offsite backups6 months, kept for disaster recovery — see "Offsite backups" below. This 6-month figure applies to offsite backups only and is not a general retention period for anything else

Deletion and anonymization on request. Regardless of your jurisdiction, if you ask us to delete or anonymize your personal data, we will do so across our live systems — production databases, mailboxes, and application state — promptly after we verify your identity. Enquiry records stored on our server (§2(a)) are covered by this: because they live in an append-only file, we remove them manually as part of that same request, rather than through an automated erasure job.

Offsite backups. We maintain 6 months of encrypted offsite backups, and we keep them for one purpose: disaster recovery — restoring the service and its data after hardware failure, data corruption, or an outage. When you request deletion, we remove your data from live systems straight away, but a copy may persist in an offsite backup until that backup naturally expires under our rotation schedule, approximately 6 months. During that window the backup data is not restored into live use for any purpose other than disaster recovery, and is kept encrypted and access-controlled. If we ever do restore from a backup, we commit to re-applying any deletion or anonymization request that was pending at the time of that backup, so erased data does not silently reappear. After the rotation window, the backup, and your data within it, is permanently overwritten. Deleting from live systems now and letting backups purge on rotation are what we do; re-erasing on restore is a commitment we make. Together they are how we reconcile prompt erasure with the operational reality of backups.


10. Security

We use administrative, technical, and organizational measures to protect personal data, including:

No method of transmission or storage is 100% secure, and we cannot guarantee absolute security. If a personal data breach occurs, we act in accordance with §12.


11. Your privacy rights

11.1 Everyone — our baseline promise

Independent of any specific law, any user may (a) request a full export of the personal data we hold about them, after identity verification, with no questions asked and no artificial limitation, to the extent we are legally permitted to disclose it; and (b) request deletion or anonymization of their personal data. To exercise these, email hello@pyr0.dev.

11.2 GDPR / UK GDPR rights

We extend these rights to every user, whether or not GDPR applies to them. Subject to conditions and exemptions, you may: access your data; rectify inaccurate data; erase it ("right to be forgotten"); restrict or object to processing, including processing based on legitimate interests and direct marketing; request data portability; and withdraw consent at any time. If you are in the EEA, the UK, or Switzerland, you may also lodge a complaint with your supervisory authority.

We respond to verified requests within one month, extendable by two further months for complex requests, with notice to you.

11.3 California rights (CCPA/CPRA)

California residents may: know and access the categories and specific pieces of personal information we collect; delete it; correct it; and opt out of the "sale" or "sharing" of personal information. We do not sell personal information and do not share it for cross-context behavioral advertising, so there is nothing to opt out of. We will not discriminate against you for exercising these rights. We respond within 45 days, extendable by a further 45 days with notice. You may use an authorized agent. The categories we collect and the purposes we collect them for are described in §2 and §3.

11.4 How to exercise

Email hello@pyr0.dev. We verify your identity before acting on a request, because releasing an export to an impersonator would itself be a breach.


12. Data breach response

If we become aware of a personal data breach affecting personal data we control, we will assess it promptly and, where required, notify the relevant supervisory authority within 72 hours (GDPR Art. 33) and notify affected individuals without undue delay. Where we process personal data on a client's behalf as a processor, we will notify that client without undue delay so they can meet their own obligations. We keep internal breach-documentation and escalation procedures.


13. Children

The Service is not directed to children under 13, or the applicable minimum age in your jurisdiction, and we do not knowingly collect their personal data. If you believe a child has provided us personal data, contact hello@pyr0.dev and we will delete it.


14. Third-party services

We are not responsible for how third parties handle data under their own policies. If you choose to connect a third-party account — Google, Apple, Microsoft, or similar — or if you select a particular payment provider at checkout, that provider's own privacy policy and terms govern what it collects, how it uses what it receives, and how long it keeps it. This policy does not cover their practices, and we do not control them. Review their policies before connecting an account or completing a payment.

The same applies to any third-party site we link to. A link is not an endorsement, and we are not responsible for the content or privacy practices of sites we do not operate.


15. Changes to this policy

We may change this policy. We will give advance notice where reasonably possible, and we will always post the new version with an updated "Last updated" date. For material changes we will provide reasonable notice through the Service or by email where we have your address. Continued use after the effective date constitutes acceptance where permitted by law.


16. Contact