Carverpoint home

This is a draft for a Colorado lawyer to review before it goes on the site. It is not legal advice and it was not written by a lawyer.

Last changed: 15 September 2026

Everybody Carverpoint relies on who could see information about you or about your customers. It is short and it is meant to stay short.

If you are a client, dpa.md section 6 says that we tell you before anybody joins this list, and that you can leave the affected service with no fee if you object. This page is how you check.

The list

Who What they do What they can see Where
CloudflareHosting, the database, file storage, the network in front of everythingEverything the product holds, and the ordinary record every web host keeps of requests, including the internet address a visitor connected fromUnited States, with a global network
StripeTaking paymentsYour name, email and card, all typed on Stripe's own page. We never see the card. Stripe holds it as its own controller, under its own privacy policy at https://stripe.com/privacyUnited States
ResendSending email: sign in codes, alerts about your inquiries, and review invitations sent as youThe email address it is sending to, and what the message saysUnited States
Cloudflare RegistrarRegistering and holding domainsThe registrant details on a domain, which are yoursUnited States

Cloudflare appears twice on purpose. The first row is the hosting and the network; the second is the domain registration, which is a separate service from the same company and is listed separately because it is the row that holds a registrant's name and postal address when nothing else here does.

Resend is on the list because the DNS already says so: carverpoint.com signs its outbound mail with a Resend DKIM key and posts to api.resend.com.

What is deliberately not on this list

  • No analytics company. There is no analytics.
  • No advertising network. There is no advertising tag anywhere, on our site or on any site we build.
  • No customer relationship or marketing platform. Nothing is synced anywhere.
  • No artificial intelligence service that is handed your data or your customers' data. Tools are used to write code and copy. None of them receives a client's customer list, a client's inquiries or a client's account information, and none of them is wired into the product.
  • No text message provider. Marketing texts are not sent, at any price. See acceptable-use.md section 3.
  • No font, script or image loaded from anybody else's server, on carverpoint.com or on any site built for a client. Fonts are hosted on the same domain as the page. This is why there is no cookie banner: there is nothing to consent to.

Two honest notes

The hosting log is the only place a website visitor's details reach us on a site we built for you. Every web host on earth keeps one, and you would have one with any provider. It is not a Carverpoint specific exposure. It is here because a list that leaves out the boring true thing is not a list you can rely on.

If your inquiry form is set up to send mail directly rather than through us, which is the default, then your inquiries do not appear in this table at all, because they never reach anybody on it. They go from the person's own mail program to your inbox. If that ever changes for your site, you will be told first, in writing, and this page will change on the same day.

Changing this page

Whenever it changes, the date at the top moves and every client is emailed. Not a footnote in a release note. An email.