Back to the website

Gabriele Creative privacy notice

Effective date: October 3, 2026

Gabriele Creative is the studio name of Kaden Gabriele, sole proprietor. This notice covers our website at https://gabriele-creative.com/, its client enrollment and account pages, including /client/ and /account/, and related business correspondence. Contact kaden@gabriele-creative.com with privacy questions or requests.

Websites we build for clients need notices appropriate to their own visitors, features and providers. This studio notice does not replace a client's website notice or authorize additional collection on that website.

Information we handle

When you enquire about or purchase services, we handle your name, business name, email, role and signing authority, business eligibility details, intended domain, project requirements, website materials, correspondence and attachments. Please avoid sending passwords, complete card details or sensitive personal records through an enquiry form or ordinary email.

For enrollment and service administration, we keep the completed project record, scope and design, agreed terms, signatures, separate payment authorization, dates and actions, agreement-copy records, launch approvals, billing and refund records, and cancellation requests. Account records connect your email and order with your access to the service. We retain versions of relevant service and agreement records rather than silently replacing the original evidence.

Stripe collects card details through its hosted payment pages and account portal. We receive payment-related information such as customer and transaction references, amounts, payment/refund status and limited billing or payment-method information. Our own enrollment forms do not collect complete card numbers or security codes.

Our infrastructure providers also process technical information used to operate and protect the service, including network/IP information, request and error records, browser/session identifiers and email-delivery status. Some records are linked to your account or transaction.

How we use information and your choices

We use information to answer enquiries, define and provide work, give you account access, record agreements and approvals, send service messages and copies, administer payments and refunds, process cancellations, investigate problems or misuse, resolve disputes and meet applicable obligations.

An enquiry or service agreement does not automatically enroll you in marketing. If you choose the offer signup and agree to receive GC emails, we record your email, consent and offer reservation. You can ask us at the address above to stop marketing emails. Unsubscribing does not revoke an already-reserved offer or cancel service messages needed to administer your agreement. Offer eligibility otherwise follows the stated offer terms.

We use an AI-assisted workflow called AI Codex to edit and process materials provided for designing your website and connecting tools to that website. This can involve transferring the information needed for those tasks to the tools and service providers used in that workflow. Public business content and personal information are different: a publicly listed person's name, image or contact details can still be personal information. We limit personal information used in this workflow to what is needed for the agreed work. This disclosure is not permission to transfer unrelated information to arbitrary services. Additional features or uses outside these purposes will be addressed separately before that processing begins, including any required notice, agreement or permission.

Use of a client's name, logo or work in a portfolio follows the permission agreed for that purpose.

Providers and disclosures

We use Cloudflare for website/application hosting, stored service records and transactional email; Google Workspace for business correspondence; and Stripe for hosted payments and billing. Sign-in and agreement-copy emails also pass through your receiving mail provider. Agreement copies include the completed record and signing/payment-authorization evidence, so protect your mailbox and saved copies.

Providers have responsibilities that vary by service and purpose. They do not all process every category solely on GC's instructions. Their information is available in Cloudflare's privacy policy, Google's privacy information, applicable Workspace data-processing terms, and Stripe's privacy policy.

Kaden Gabriele is the only human operator whom GC authorizes to access its business accounts and client files, and GC does not use mailbox forwarding. This describes GC's own access arrangements; hosting, communications, payment and AI-assisted design/tool-connection providers process information as applicable to their services. We may also disclose information where law requires or where reasonably necessary to address disputes or protect legal rights, consistent with applicable duties. Provider processing can occur outside your state or country.

Browser storage and sign-in

StoragePurposeIntended lifetime
__Host-gc_client_sessionMaintains an authenticated client/provider sessionUp to 30 minutes; signout clears the browser cookie and revokes the session
__Host-gc_offerRemembers the browser's offer/reservation sessionUp to one year; this does not extend the one-hour signup window or delete the stored reservation when the cookie expires

One-time email sign-in links expire after ten minutes and cannot be used again after a successful exchange. Blocking necessary storage may prevent the corresponding functions from working. Stripe's hosted pages have their own storage and privacy information. Session expiry and signing out do not delete agreements, reservations or billing history.

Retention and protection

Our retention schedule distinguishes routine contact information from records needed to establish agreements, rights and financial activity. We review records due for disposal monthly and apply the periods and criteria below. Shorter operational expiry or maximum-retention limits continue to apply; the monthly review does not extend them.

InformationRetention period or criterion
Enquiries that do not become client projects12 months after the last meaningful exchange, then disposal at the next monthly review, unless a documented continuing enquiry or hold applies. Automated messages do not restart this period.
Entirely unsigned, unpaid abandoned intake90 days after expiry, withdrawal or last substantive activity, whichever is later. Records with a signature, unresolved payment, complaint or hold are reviewed under the appropriate category instead.
Expired, unclaimed offer sessionsRaw troubleshooting details for 90 days after expiry; only minimal eligibility/window evidence afterward while needed to prevent an improper restart of the offer window.
Claimed but unredeemed offersMinimal reservation/eligibility evidence until redeemed, expressly released by the holder or ended under the existing offer terms, with annual review for excess information. Unsubscribing does not cancel a reserved benefit.
Marketing consent and opt-out recordsConsent evidence for 3 years after last reliance or withdrawal, subject to a specific dispute or hold. Minimal suppression information remains while marketing to that address may resume, until a new valid opt-in replaces it or that marketing use permanently ends.
Signed or partly executed agreements, payment authorizations, scope/design evidence, material approvals and copy receipts, payments, refunds, cancellations and material disputes7 years after the later of service/project closure or final financial/dispute resolution, then review for any continuing duty or hold.
Tax-supporting records7 years after the later of the relevant return's actual filing date, its due filing date or final financial resolution, with longer applicable requirements retained.
Continuing rights, title and licensesMinimum grant, license and provenance evidence while we rely on the right, plus applicable claim or hold needs afterward.
Routine correspondence and email-delivery recordsGeneral service correspondence for 24 months after service closure; routine sign-in/notification delivery records for 90 days after resolution of delivery issues. Enquiry records and material agreement, receipt, cancellation or dispute evidence follow their applicable categories above.
Sign-in links and sessionsLinks expire after 10 minutes and sessions after 30 minutes. Expired authentication rows are eligible for removal by the next running cleanup after 24 hours past expiry. This does not delete agreement, email or billing records.
Routine application/security logs under GC's controlA 30-day maximum, retaining shorter provider defaults unless a documented need applies. Selected incident evidence follows the incident rule below.
Privacy requests, identity checks and incidentsMinimal request/response records for 3 years after closure; incident decisions/evidence for 6 years after closure, subject to applicable holds or longer duties. Temporary identity-verification material is deleted within 30 days after completion unless specifically required.
Working exports and backups under GC's controlWorking exports for 30 days after the task ends unless classified into the appropriate archive; routine rolling backups for 30 days. Intentional archives follow the relevant record category.

Relevant records may be kept longer for a documented dispute, audit, legal process, unresolved payment/refund, mandatory duty or insurance requirement. We limit a hold to the necessary records, review it and apply the appropriate retention rule when it ends. Continuing rights and required evidence can outlast routine service records. We do not erase an earned offer or shorten an agreed access or handover obligation through routine disposal.

Copies held independently by service providers or email recipients can follow separate retention rules. Provider backups may remain until their applicable recovery periods end. We keep a record of authorized disposal and address prior disposal decisions if we restore controlled backups; deletion is not an immediate erasure of every provider or recipient copy.

We use access restrictions and technical controls to protect the information we handle. No transmission or storage method eliminates every risk.

Questions and requests

Email kaden@gabriele-creative.com to ask about your information or request access, correction or deletion. Kaden Gabriele handles these requests. We may request proportionate information to verify your identity and locate the relevant records. Available rights and exceptions depend on applicable law. We will explain the handling of your request, including applicable retention limits, as required. Do not send a government ID or card credentials unless an appropriate secure process has been established.

We may update this notice and will show the new effective date. Where required, we will provide additional notice or obtain appropriate permission for a change in processing.