Privacy Policy — Stella Implementation

Stella Implementation LLC

Privacy Policy

What we collect, what we do with it, who else touches it, and how to make us delete it. Written to be read.

EffectiveSeptember 9, 2026 Last updatedSeptember 9, 2026 EntityStella Implementation LLC, Florida

01Scope, and the two different roles we play

This policy covers stellaimplementation.com and the work Stella Implementation LLC does for its clients. It is written to be read, not to be survived.

We handle information in two distinct roles, and the rules are different for each. Confusing them is the most common mistake in policies like this one, so we separate them here and keep them separate throughout.

Role one — our own visitors and prospects

When you browse this site, submit a form, or email us, we decide what happens to that information. We are the controller of it, and sections 02 through 05 describe what we do.

Role two — information belonging to our clients

When a client engages us, we look at information about their business and sometimes at records they give us access to. That information belongs to the client. We handle it on their instructions and under the agreement we signed with them, which governs it in preference to this page. Section 06 describes that role.

If you are a member of the public trying to reach a public agency we work for, this policy does not cover that agency's own handling of your information. Contact the agency directly.

02What we collect from you

What you type into a form

Our forms ask for the fewest fields the work actually requires:

  • Your first and last name
  • Your email address
  • Your organization and your role there
  • Your website address
  • Which kind of organization you are (operator, franchisor, public agency)
  • How many locations you operate, or the population you serve

The last two decide whether we are the right firm for you at all. We ask because sending the wrong answer wastes your time more than ours.

What you send us directly

Email you write to us, documents you attach, and anything you say on a call we schedule. We keep correspondence so we can pick up where we left off.

What the site records on its own

Standard technical information that any web server receives: IP address, browser and device type, the pages you opened and roughly when. Our forms and pages are served through our customer relationship platform, which sets cookies necessary to make forms work and to attribute a submission to the page it came from.

The site does not run advertising trackers, third-party ad pixels, or cross-site behavioural profiling. If that changes, it will be described here before it is switched on.

03What we do with it

  • To answer you. A form submission creates a record and a task for a human. That is its entire purpose.
  • To run the free front-door pass, if you asked for one — which means looking at what public AI engines and public listings already say about your organization, using the information you gave us to find you.
  • To scope and price work, and to send you a proposal.
  • To send you occasional email about the work we do, if you gave us your address. Every one of those has an unsubscribe link and we honour it on the first click.
  • To keep our own records — proposals sent, engagements run, invoices issued.

What we do not do

We do not sell personal information. We do not share it with advertisers or data brokers. We do not trade contact lists. We have no advertising business, so there is nothing here to monetise even if we wanted to.

04Who else touches it

We are a small firm and we run on other people's infrastructure. These are the services that hold information you give us:

ServiceWhat it holds
HighLevel (LeadConnector)Our CRM. Form submissions, contact records, email we send you, scheduling.
Google WorkspaceEmail correspondence, documents, and the drafts of deliverables.

Each is bound by its own agreement with us to handle information only as we direct. We keep this list current: if we add a service that holds your information, it gets added here.

We will also disclose information where the law requires it — a subpoena, a court order, a lawful government request — and where it is necessary to establish or defend a legal claim. If we ever receive such a request about you, we will tell you unless we are prohibited from doing so.

05How long we keep it

InformationKept
An inquiry that goes nowhere24 months, then deleted
Correspondence with a client or prospectFor the relationship, plus 4 years
Engagement deliverables and working filesPer the signed agreement; by default returned or deleted within 90 days of the engagement closing, except one archived copy of the final deliverable
Invoices and financial records7 years, because tax law says so

Ask us to delete you earlier and we will, subject to the records we are legally required to keep.

06Information belonging to our clients

An engagement means looking at a client's business closely. Here is what that involves and what we do with it.

What an audit actually collects

  • Public AI engine outputs — what several major engines say when asked about the client's locations, captured logged out, with dated screenshots. This is public information. We are recording what anyone could see.
  • Public listings and website content — business listings, hours, phone numbers, location pages, and the accessibility characteristics of public-facing pages.
  • Materials the client gives us — call logs, listing management access, analytics, and similar records, where they choose to provide them.

How we treat it

  • We use it only to do the work we were engaged to do.
  • Redaction is the default. Where a record contains a member of the public's name, phone number, address, or account details, we redact it before it enters any deliverable, example, or internal reference.
  • We do not publish, quote, or use a client's materials as a case study, reference, or marketing example without their written permission — and we ask for that separately, after the work, never as a term buried in an engagement.
  • The signed agreement controls. Where it says something different from this page about the client's own information, the agreement wins.

Public agencies: public records

Correspondence with a Florida public agency may itself be a public record under Chapter 119, Florida Statutes, regardless of anything on this page. We do not control that and we do not claim to. Public-sector clients should assume our correspondence with them is subject to their own records obligations.

07Call recordings and transcripts

As of the effective date of this policy, our engagements do not include recording or transcribing calls. The audit reads public sources and client-supplied records. It does not sit on the phone line.

Where a future engagement does include call handling, all of the following apply and this page will be updated to say so plainly before it begins:

  • Consent is the client's obligation and it is not optional. Florida is an all-party consent state for the interception of communications under section 934.03, Florida Statutes. A client who engages us for call handling is responsible for the disclosure and consent its callers receive, and for meeting the law of every state its callers are in — which is not always Florida.
  • Recordings and transcripts belong to the client, not to us.
  • They are redacted before they are used for anything other than delivering the engagement.
  • They are never used as a public example without separate written permission.

08How we use AI systems

Two different things get called "AI" in our work and they deserve separating.

The AI engines we examine

Most of what we do is asking public AI assistants what they say about a business, logged out, and writing down the answer. We are the audience for those systems, not a customer of them. Asking a public engine about a public business does not disclose anything confidential.

The AI tools we use to produce work

We use AI tools in the course of producing documents, in the same way we use a spreadsheet or a browser. Where we do:

  • We use business-tier accounts configured so that submitted content is not used to train the provider's models.
  • We do not paste a client's confidential materials into consumer-grade or free AI tools.
  • A human reads and is accountable for every deliverable that leaves this firm. No document goes out because a model produced it.

We do not use your information to train any model of our own, and we do not sell it to anyone who does.

09Your choices, and how to use them

State privacy laws grant these rights to some people and not others, depending on where they live and how large the company is. We find that distinction hard to defend, so we honour these requests from anyone who asks, regardless of whether a statute requires it of us.

  • Ask what we hold about you. We will tell you, in plain language.
  • Correct it if it is wrong.
  • Have it deleted, except records we are legally required to keep.
  • Get a copy in a portable format.
  • Stop the email. Unsubscribe on any message, or ask us. It takes effect immediately, not in "up to ten business days."

Email [email protected]. We answer within 30 days and usually much sooner, because there is one of us and she reads her own mail. We may need to confirm you are who you say you are before acting on a request about someone's records.

We do not discriminate against anyone for exercising any of this.

10Security, stated honestly

  • Accounts holding client or prospect information require multi-factor authentication.
  • Access is limited to people who need it for the engagement in front of them. Today that is a very short list.
  • Client materials are held in the platforms named in section 04, not on unmanaged personal devices or in personal accounts.
  • Redaction happens at intake, not at publication — the unredacted version does not get carried further than it has to.

No one can promise a system is impenetrable, and a firm that tells you otherwise is selling something. What we can say is what the controls are, which is above, and that if information you gave us is compromised we will tell you promptly and tell you what we know rather than what sounds best.

11Children

This site and our services are for businesses and public agencies. They are not directed to children, and we do not knowingly collect personal information from anyone under 18. If you believe a child has given us information, email us and we will delete it.

12Visitors from outside the United States

We are a Florida firm serving clients in the United States. Our systems are hosted in the United States, and information you send us is processed there. If you are contacting us from elsewhere, you are sending your information to the United States, where the privacy laws are different from those where you live.

13Changes to this policy

When this page changes we update the date at the top. If a change materially affects what we do with information we already hold about you, we will email the people it affects rather than quietly reposting the page and calling it notice.

14Contact

One address, read by a person:

Stella Implementation LLC
7901 4th St N, STE 300
St. Petersburg, Florida 33702
[email protected]

Questions about this policy, requests about your information, and complaints all go to the same place. Say what you want and we will do it or tell you why we cannot.