Privacy Policy
A clear explanation of what we collect, why we use it, and the choices available to you.
Effective date: September 15, 2026
Chrisorah respects your privacy. This Privacy Policy explains how Chrisorah (“Chrisorah,” “we,” “us,” or “our”) collects, uses, discloses, and protects personal information when you interact with our websites and related online services.
1. Scope
This Privacy Policy applies to:
- chrisorah.com and its pages, forms, booking experiences, and payment links;
- My Chrisorah at my.chrisorah.com, including its invitation-only client portal and public knowledge base; and
- personal information we receive through or in connection with those Chrisorah-owned online services.
This Privacy Policy does not apply to personal information processed on websites, applications, or systems controlled by a client. That processing is performed for the client and is governed by the client’s instructions, the applicable client agreement, and the client’s own privacy notice. A third-party website or service linked from or embedded in our websites is governed by that third party’s own privacy practices.
2. Personal information we collect
The information we collect depends on how you interact with us.
Information you provide
We may collect:
- Contact and business information, such as your name, email address, phone number, company name, and the nature of your inquiry.
- Client portal and project information. If you become a client or an authorized client contact and are given access to My Chrisorah, we may collect your email address, account and authentication information, organization, role and permissions, authorized-user details, messages or comments, meeting notes, support requests, project and task details, milestones, project activity and files, website or whiteboard content, domain or service-account information, approvals, contracts, subscriptions, invoices, payment records, and other information you choose to provide through the client portal. The information involved depends on the portal features made available to you and how you use them.
- Booking information, such as your name, email address, optional phone number, optional guests, meeting preferences, time zone, selected date and time, meeting type, notes, and any reason you provide when canceling or rescheduling.
- Transaction information, such as the amount, date, status, processor, invoice or transaction reference, and limited billing details associated with a payment. Chrisorah does not collect or store full payment-card numbers through its WordPress website. Payment-card information is entered directly with the applicable payment processor.
Please do not send passwords, full payment-card numbers, Social Security numbers, health information, or other highly sensitive information through a public contact or booking form. If a project requires credentials or other sensitive materials, use the method specified by Chrisorah or in your agreement.
Information collected automatically
When you use our websites, we and our service providers may automatically collect:
- IP address and approximate location derived from it;
- browser, device, operating system, and language information;
- pages viewed, referring page, links selected, dates, times, and interaction data;
- cookie identifiers, consent choices, and similar online identifiers;
- accessibility and display preferences stored in your browser; and
- security and anti-abuse signals used to prevent spam, fraud, and unauthorized access.
Some of this information is collected through cookies, local storage, pixels, tags, server logs, embedded content, and similar technologies. Section 7 explains these technologies and your choices.
Information from other sources
We may receive information from:
- a client or organization that invites you to My Chrisorah or identifies you as its representative;
- calendar, email, meeting, and collaboration providers connected to a booking;
- payment processors that confirm a transaction;
- analytics, security, consent-management, and website-service providers.
3. How we use personal information
We may use personal information to:
- operate, maintain, secure, and improve our websites and My Chrisorah;
- respond to inquiries and communicate with you;
- schedule, administer, and follow up on meetings;
- prepare proposals, coordinate projects, provide support, and deliver requested services;
- create and manage invitation-only portal access;
- issue invoices, process and confirm payments, and maintain transaction records;
- synchronize bookings with Microsoft 365 calendars, Microsoft Teams, and, when applicable, Google Calendar;
- remember consent, accessibility, and site preferences;
- measure website use and diagnose performance or usability issues;
- prevent spam, fraud, misuse, security incidents, and unauthorized access;
- comply with law, enforce agreements, establish or defend legal claims, and protect our rights and the rights of others; and
- evaluate or complete a proposed sale, merger, reorganization, or transfer of all or part of Chrisorah, subject to appropriate confidentiality and legal protections.
Chrisorah does not use contact, booking, or client information to send promotional marketing emails or text messages. We may send replies, scheduling messages, invoices, security notices, portal notices, support communications, and other transactional or service-related messages.
4. How we disclose personal information
We may disclose personal information to the following categories of recipients when reasonably necessary for the purposes described above:
- Website, hosting, and infrastructure providers that help us operate, secure, back up, and maintain our websites and portal.
- Email, calendar, meeting, and collaboration providers, including Microsoft 365, Microsoft Teams, and, when connected to a booking, Google Calendar.
- Payment processors, including PayPal and Stripe. These processors collect payment information directly and handle it under their own privacy policies.
- Analytics providers, including Google Analytics, when analytics consent is available or otherwise permitted.
- Consent-management providers, including Cookiebot by Usercentrics, which records and applies cookie choices on the public Chrisorah website.
- Security and anti-abuse providers, including Cloudflare Turnstile on public forms and Google reCAPTCHA on My Chrisorah.
- Embedded-content providers, including YouTube or Google when you allow or interact with embedded video content.
- Portal, communications, and support providers that enable account access, notifications, and client interactions.
- Professional advisers, such as accountants, attorneys, insurers, and consultants, when necessary for legitimate business or legal purposes.
- Government authorities, courts, and other parties when disclosure is required by law or reasonably necessary to protect rights, safety, security, or property.
- A potential buyer, successor, or transaction adviser when reasonably necessary to evaluate or complete a proposed or completed sale, merger, reorganization, or transfer of all or part of Chrisorah, subject to appropriate confidentiality and legal protections.
We may also disclose information at your direction or with your consent.
We do not sell personal information. We do not use contact, booking, or client information for cross-context behavioral advertising on behalf of Chrisorah, and we do not intentionally disclose personal information to third parties for their own direct-marketing purposes. Section 7 describes collection that may occur through allowed third-party analytics and embedded-content technologies.
5. Contact forms, bookings, portal use, and payments
Contact forms
Our public contact form is provided through Quform and protected by Cloudflare Turnstile. Submitted information is delivered to Chrisorah by email. Quform’s global entry-saving and IP-address-saving settings are disabled, so the submitted form content is not retained as a Quform entry in the WordPress database. Copies of the resulting email and any later correspondence may be retained in our business email system as described in Section 8.
Bookings
Our booking pages use Fluent Booking. Booking records are stored in WordPress and may synchronize with Microsoft 365 calendars, Microsoft Teams, and, depending on the calendar selected, Google Calendar. Booking information is used to arrange and administer the requested meeting and related communications.
My Chrisorah
My Chrisorah is a customer relationship management (CRM) service with an invitation-only client portal. Client self-registration is disabled, and authenticated client areas are limited to authorized users. My Chrisorah also includes a public knowledge base that may be accessed without a client account. The features available to an authenticated user depend on the client relationship, project, and assigned permissions. The current client-facing configuration supports user profiles and authorized contacts; projects, tasks, comments, milestones, Gantt views, and project activity; project and client files; whiteboards; announcements; contracts; subscriptions; invoices; and payment records and payment links. Some features may not be used for every client. Depending on their permissions, a client contact may identify or invite another authorized contact.
My Chrisorah may support optional features and integrations that are not currently enabled or used by Chrisorah. If Chrisorah activates a portal feature that materially changes the categories of personal information collected, the purposes for which it is used, or the parties that receive it, we will update this Privacy Policy as appropriate. Google reCAPTCHA and other security or infrastructure providers may process technical information to protect the portal. Cookiebot is not used on My Chrisorah.
A separate agreement may govern a client’s project, portal access, and service relationship. If that agreement conflicts with this Privacy Policy regarding project-specific processing, the agreement controls to the extent permitted by law.
Payments
Online payments are processed by PayPal, Stripe, or another identified payment processor. Payment details are submitted to the selected processor through its hosted or integrated payment interface. Chrisorah receives transaction confirmation and related business records but does not receive or store the full payment-card number submitted to the processor. Review the processor’s privacy policy before submitting payment information.
6. Third-party privacy policies
Third-party services process information under their own terms and privacy policies. Representative policies include:
These links are provided for convenience. Chrisorah does not control and is not responsible for a third party’s independent privacy practices.
7. Cookies, analytics, embedded media, and browser signals
Public Chrisorah website
The public Chrisorah website uses Cookiebot to manage cookies and similar technologies. Depending on the technology and your choices, Cookiebot may classify them as:
- Necessary, for security, network management, form operation, consent records, and essential website features;
- Preferences, for accessibility, display, language, or other remembered choices;
- Statistics, for audience measurement and website analytics; or
- Marketing, which may include technologies associated with third-party embedded media such as YouTube, even though Chrisorah does not use the information to market to clients.
Cookiebot is configured to keep nonessential technologies disabled until you select the applicable category where consent is required. You may accept, reject, or change your choices through the site’s Cookie Settings control. The current Cookie Declaration identifies the technologies detected on the public website, their purposes, providers, and stated durations.
We use Google Analytics 4 to understand aggregate website use and improve site performance. Google Consent Mode is configured to restrict nonessential storage before the applicable consent choice. Analytics information may include online identifiers, device and browser information, approximate location, and interaction data.
The Web Design Process page includes a YouTube video using YouTube’s privacy-enhanced youtube-nocookie.com domain. YouTube or Google may receive device, network, and interaction information when the player loads or you interact with it, subject to your cookie choices and Google’s practices.
My Chrisorah
Cookiebot is not used on My Chrisorah. The portal may use cookies or similar technologies that are necessary for login, security, session management, preferences, and portal functionality. It also uses Google reCAPTCHA and infrastructure services that may receive technical and security information.
Do Not Track and Global Privacy Control
Some browsers offer a legacy “Do Not Track” signal. Because there is no generally accepted standard for interpreting that signal, our websites do not currently respond to it separately. Use the public website’s Cookie Settings control to manage optional cookies.
Global Privacy Control is designed to communicate an opt-out of the sale or sharing of personal information. Chrisorah does not sell personal information. If our websites receive a legally valid Global Privacy Control signal and applicable law requires us to apply it to a covered activity, we will treat the signal as an opt-out of that activity. Global Privacy Control is not a substitute for managing all optional cookies; use the public website’s Cookie Settings control for those choices. A browser signal does not disable technologies that are strictly necessary to provide or secure the service.
Third parties may collect information about your online activities over time and across different websites when their technology is allowed to operate on our websites. Their collection is governed by their own policies and your available browser, device, account, and cookie-consent choices.
8. Data retention
We retain personal information only for as long as reasonably necessary for the purpose for which it was collected, including to provide requested services, maintain appropriate business and transaction records, comply with legal obligations, resolve disputes, enforce agreements, and protect our systems.
Retention depends on the type of information and context:
- Public contact-form content is not retained as a Quform entry in WordPress. Email copies and correspondence are retained only as reasonably necessary to handle the inquiry and maintain appropriate business records.
- Booking and calendar information may be retained for scheduling, follow-up, recordkeeping, and dispute-resolution needs.
- Portal, support, and project records may be retained while an account or client relationship is active and afterward as required by the applicable agreement, legal obligations, limitation periods, and legitimate recordkeeping needs.
- Invoice and transaction records may be retained for accounting, tax, fraud-prevention, and legal purposes.
- Analytics, consent, security, and cookie information is retained according to the applicable configuration, cookie duration, provider terms, and operational need.
We may delete, aggregate, or deidentify information when it is no longer needed. Information deleted from active systems may remain for a limited period in routine backups until those backups rotate or are securely deleted. We may retain information longer when required by law, a legal hold, or an unresolved dispute.
9. Security
We use reasonable administrative, technical, and organizational safeguards designed to protect personal information. These safeguards may include access controls, encrypted connections, anti-abuse tools, authentication measures, software maintenance, backups, and service-provider controls.
No website, transmission, or storage system is completely secure. We cannot guarantee that personal information will never be accessed, used, altered, or disclosed without authorization. You are responsible for maintaining the confidentiality of your portal credentials and for notifying us promptly if you suspect unauthorized account access.
10. Your privacy choices and requests
You may:
- change public-website cookie choices through Cookie Settings;
- ask us to review or correct personal information we maintain about you;
- request deletion of personal information, subject to legal, contractual, security, recordkeeping, and other permitted exceptions; or
- ask questions about our privacy practices.
To submit a privacy request, use our Contact Us page and clearly describe your request. We may need to verify your identity and authority before acting. If an authorized agent submits a request, we may require proof of authorization and direct identity verification where permitted by law.
We will consider and respond to privacy requests in accordance with applicable law. We will not unlawfully discriminate against you for exercising an applicable privacy right. We may retain a record of the request as needed to document our response and comply with law.
11. California privacy information
The disclosures throughout this Privacy Policy describe the personal information we collect, how we use it, the categories of recipients to which we may disclose it, how to submit a request concerning information we maintain, how we communicate material policy changes, and our practices concerning browser signals and third-party collection across websites.
Chrisorah does not sell personal information or disclose personal information to third parties for their own direct-marketing purposes. Based on our current practices, we have not sold personal information during the preceding 12 months. We do not knowingly sell the personal information of anyone under 16. Section 7 describes collection that may occur through allowed third-party technologies.
California residents may submit the requests described in Section 10. Additional rights may apply if Chrisorah becomes subject to a broader California privacy law or if a particular activity falls within that law.
12. Children
Our websites and services are intended for businesses and adults in the United States. They are not directed to children under 13, and we do not knowingly collect personal information online from children under 13. If you believe a child under 13 has provided personal information through our websites, please use our Contact Us page so we can review and, when appropriate, delete it.
13. United States operations and international visitors
Chrisorah operates in Southern California and directs its services primarily to the United States. If you access our websites from another country, your information may be processed in the United States and in other locations where our service providers operate. Those locations may have privacy laws that differ from the laws where you live. We will honor rights required by applicable law.
14. Changes to this Privacy Policy
We may update this Privacy Policy to reflect changes in our websites, services, providers, or legal obligations. We will post the revised policy on this page and update the effective date. If a change is material, we may also provide a more prominent notice on our website, within My Chrisorah, or through another appropriate communication. Changes apply prospectively from the stated effective date unless otherwise required by law.
15. Contact us
The preferred way to submit a privacy question or request is through our Contact Us page.
You may also contact Chrisorah at:
- Email: contact@chrisorah.com
- Phone: (951) 223-1515