Privacy policy

Last updated August 26, 2026

This is what we collect, why we collect it, and what we will never do with it — written to be read, not to cover us. The short version: we collect what we need to build and run your website, we never sell it, and you can have all of it deleted by sending one email.

Who holds your data

Everything described here is the responsibility of Kusa Solutions LLC, a limited liability company registered in Tbilisi, Georgia — the country, not the US state — under identification code 404818122, trading as Kusa. In data-protection language, that company is the controller: the one that decides what is collected and why, and the one you can hold to this policy.

Every question, request and complaint about your data goes to hello@kusasolutions.com and is handled by a person, not a form.

What we collect

You give us information in three places, and each one collects only what that step needs:

  • Forms (consultation, custom-build application): your name, business name, city, email, and optionally a phone number and website address.
  • The growth audit: the same business details, plus whatever you tell us about how the business runs — your services, how customers find you today, your booking method, your biggest struggle, your marketing budget range, and your goals. Every field on that form is optional except your business name and city.
  • Your account: your name, email, and a password we store only as a hash — or your Google profile name and email if you sign in with Google. We never see your Google password.
  • Your website content: the business details, photos, prices and text you add to your site. That content exists to be published on your website — that is the product.

If you share a public link to your business (for example your Google Maps listing), we read the publicly visible details — name, hours, photos, reviews — to pre-fill your site. We only do this when you paste the link.

The growth audit also checks public information about the business itself: your Google Business Profile, your ranking against nearby competitors for your trade, and your website if you have one. Nothing here requires you to log in to anything — we only read what is already publicly visible.

What we use it for

  • Building, hosting and running your website.
  • Replying to the inquiry you sent — that is the only thing form submissions are used for.
  • Account emails: verification, password reset, and answers to your questions.
  • A plain-English monthly report about your own site, if you are a customer.

We do not run advertising trackers on this site, we do not sell or rent your information to anyone, and we do not send marketing you did not ask for.

Cookies

We use two cookies, both functional, neither for tracking:

  • A session cookie that keeps you signed in to your account.
  • A temporary cookie that remembers your in-progress site draft if you try the builder without an account. It expires after 7 days.

There is no third-party analytics or advertising cookie on this site.

Visitor statistics

We count page visits so we know which pages are worth keeping. We do it ourselves, in our own database, with no analytics company involved and no cookie set for it.

For each visit we record the page address, the site that linked you here (the website name only, never the full address), your country if our network provider tells us, and whether you are on a phone, tablet or computer. To count one person once instead of ten times, we combine your IP address and browser into a scrambled code using a secret that changes every day. We never store your IP address, and the code cannot be turned back into it.

Because that secret changes daily, the code for the same person is different tomorrow. That is on purpose: it means we can tell you how many people visited on a given day, and we cannot follow anyone from one day to the next, build a profile, or recognize you when you come back.

Counting happens in your browser, so any script or content blocker stops it, and nothing on this site depends on being counted. We do not act on the browser "Do Not Track" signal, because there is nothing here for it to switch off — no cookie, no third party, and no identifier that outlives the day.

One outside measurement tool, and it is cookieless too

Alongside our own counting we use PostHog (an analytics company, on their United States servers) to see which parts of a page people actually use — where they click, where they stop reading, where a page loses them.

We run it in its cookieless mode, which is the only reason it is here without a banner asking your permission: it sets no cookie, writes nothing to your browser’s storage, and identifies a visit through a code calculated on their servers that changes daily — the same approach, and the same deliberate limit, as our own counting above. It cannot follow you from one day to the next either.

Because of that mode it does not and cannot record your screen. Anything you type into a form is masked before it leaves your browser regardless. Any script or content blocker stops it, and nothing on this site depends on it.

Where it lives and who touches it

Your account, your website content and your audit results sit in our own database and our own file storage, running on a server we rent and administer ourselves — not in someone else’s product. We are a small in-house team: the people who build the systems are the people who can reach the data, and access is limited to doing the work you asked for.

A short list of outside companies processes some of it, each because one specific feature needs them to. This is the entire list. There is no advertising network on it, no data broker, and nobody who receives your information to use for their own purposes:

  • DigitalOcean (United States) — rents us the server our database and file storage run on, and takes its backups. They provide and secure the machine; they do not read or use anything stored on it.
  • Cloudflare (United States) — carries traffic between your browser and our servers and handles the encryption. It sees requests in transit; it does not hold your account or your site content.
  • Vercel (United States) — hosts the finished website we build for a customer, so it is fast wherever their customers are. It holds the published site itself: the business details, photos and text you approved for publication.
  • Resend (United States) — sends the emails described above. Receives your name, your email address, and the contents of that email, including your audit report when you ask for it by email.
  • Cal.com (United States) — runs the consultation calendar. When you book, it receives your name, email address, time zone, anything you typed into the notes, and your phone number if you gave one, and it issues the calendar invitation.
  • Google (United States) — three separate and individually optional touches: your name and email address if you choose Google sign-in (never your password); the calendar invitation for a consultation you booked; and, if you use the business-name autocomplete on one of our forms, the text you type into that one field.
  • Anthropic (United States) — writes the plain-English summary inside a growth audit. It receives the measured findings our own engine produced about the business — public listing data and scores — and returns the wording. It never receives your password, your account credentials or your website content.
  • PostHog (United States) — cookieless measurement of which parts of a page get used. Receives the page address and the clicks, never a cookie, never your form contents. Described in full above.

If we ever add another one, it appears on this list before it starts receiving anything.

Your data crosses borders, and here is how

We are a Georgian company and most of the companies above are American, so your information does travel between countries. That is not incidental — it is how the service works, and you should know it rather than find it in a footnote.

Two things make that safe rather than merely disclosed. Each company on the list above holds only the narrow slice its one feature needs, under a contract that lets them use it for that and nothing else. And the substantial part — your account, your site content, your audit results — never leaves our own database on our own server; it is the narrow slices that move.

Where the law of the country you are in gives you rights over data that leaves it, those rights follow the data and we honor them at the address below, whichever country you are writing from.

If something goes wrong

If your personal information is ever exposed by a breach of our systems, we will tell you by email without waiting to be asked and without waiting to have every answer — what happened, what of yours was involved, what we have done, and what you should do. We would rather tell you early and update you than go quiet while we investigate.

We will also notify whichever regulator the law requires, within the time it requires.

How long we keep it

Inquiry emails and form submissions: as long as the conversation is live, then archived.

Customer sites and content: for as long as you are a customer. If you cancel, we hold your content for 60 days in case you come back, then delete it. You can request an export of your content at any time — including on the way out.

To have your account and everything attached to it deleted, email hello@kusasolutions.com from the account address. We confirm when it is done.

Your rights

You can ask us at any time to show you what we hold about you, correct it, export it, or delete it. Email hello@kusasolutions.com and a person will handle it — there is no form and no phone tree.

Changes to this policy

If we change this policy in a way that matters, we update the date at the top and, for customers, say so in the monthly report. We will never quietly loosen it.

Questions about any of this go to hello@kusasolutions.com — a person reads it, and replies within 24 hours, every working day.