Get an estimate

Privacy notice

We keep an inquiry for 36 months and store nothing from an ad click until you allow it.

Vorngix is a four-person brand studio in Austin doing website design and identity work for small businesses. This notice covers what this site receives from you, which advertising platforms send visitors here, and what you can make us do with the record.

Effective and last updated

October 6, 2026

Replaces every earlier version. Read with the cookie ledger and the terms of engagement.

The eight answers people come here forVorngix privacy notice ยท October 6, 2026
Who holds your dataVorngix, 83 River Road, Office 12, Austin, Texas 02757, United States.
What we takeWhat you type into the inquiry form or the chat, plus the IP address, browser string, referring page and two timestamps.
Where it livesOn the hosting provider that serves this site, and in the studio inbox the mail provider delivers to.
How longInquiries 36 months. Chat 6 months. Server logs 90 days. Consent record 12 months.
Who else sees itGoogle, Microsoft and Meta receive ad signals only after you press Allow. The host and mail provider carry the inquiry. Nobody buys it.
Ads on this siteGoogle Ads, Microsoft Advertising and Meta Ads send paid clicks here today. Consent Mode v2 keeps all four storage signals denied until you choose.
How to get it outAsk for a copy, a correction or deletion. Answer within 10 days. Use the request form or write to the address below.
Who to write to[email protected] or +1 (448) 555-0161. A person reads it, usually the director.
A paper sample book fanned open to cool grey and off-white stocks
Fig. 01Uncoated stock samples from the studio flat file. We are fussy about paper. Data gets the same treatment: small, labelled, thrown out on a date.

01Who runs this site

This site, vorngix.com, is run by Vorngix, a website design and brand identity studio trading under that name since 2016. The postal address is 83 River Road, Office 12, Austin, Texas 02757, United States. For the purposes of European law Vorngix is the controller of what this site collects: we decide what is taken and why, and we answer for it.

There is no parent company, no reseller and no agency behind the studio. Four people work here. When you write about your data, one of them reads it.

02What the site receives

Less than most. There is no account, no password, no checkout and no card field anywhere on this site, because nothing is sold or paid for here. What arrives falls into five groups.

  • The inquiry form. Name, phone, email, the street or city you work in, the kind of project, your message, any specification you carried over from the estimator, and the consent tick. With it the server records your IP address, the browser's user-agent string, the referring URL, the moment the form was rendered and the moment it was sent.
  • The support chat. The conversation itself, and if you add them, a name, phone and email. A token is kept in your browser so you can come back to the same thread.
  • Server and access logs. IP address, requested page, time, status code and user-agent, written by the web server on every request.
  • Your consent choice. Stored in your browser under the key site_consent_v2. Nothing else on this site persists a choice.
  • Advertising click identifiers. When you arrive from a paid ad, the link carries a gclid, msclkid or fbclid value. It is only written to storage, and only passed back to the platform, if you press Allow.

03What each piece is used for

Form and chat content is used to answer you, to prepare a quote, and if you hire us, to run the project. The IP address, user-agent and the two timestamps on a form are there to catch spam: a form sent four seconds after it loaded, from a known bad range, is a bot, and it is dropped. Server logs are read when something breaks and when someone attacks the site. The consent record exists so we do not ask you twice. Click identifiers tell an ad platform that a paid click turned into an inquiry, which is how we decide whether a campaign is worth its money. We do not use any of it to build a profile of you, and we do not sell it.

04The legal basis for each use

European law asks us to name one for every purpose. Here they are.

  • Answering an inquiry or chat rests on steps before a contract, and consent. You asked us something. We need your details to reply.
  • Running a hired project rests on contract. We cannot send proofs to someone we cannot reach.
  • Spam filtering and server logs rest on legitimate interest. Keeping the site up and the inbox usable.
  • Storing your consent choice rests on legal obligation. We have to be able to show what you chose.
  • Ad measurement and click identifiers rest on consent. Off until you press Allow, off again the moment you decline.

05The advertising platforms that send visitors here

This site receives paid traffic. Three platforms send it, and each one adds its own identifier to the link you click.

  • Google Ads appends gclid to the address.
  • Microsoft Advertising, which places ads on Bing and its partner sites, appends msclkid.
  • Meta Ads, where a campaign runs on Facebook or Instagram, appends fbclid.

The identifier is a random string. On its own it means nothing to us. Matched back by the platform, it tells the platform which ad you clicked. If you allow storage, the site keeps that value and reports a conversion when you send an inquiry. If you do not, the value sits in the address bar, is never written down, and never goes back. No platform has a say over what this studio writes, makes or charges.

07Who receives data, by name

Five outside parties, listed by name so you know exactly where an inquiry or a click signal goes.

  • Google Ireland Ltd and Google LLC run Google Ads. They receive the gclid and the consent signals, and conversion data only when you allow it.
  • Microsoft Ireland Operations Ltd runs Microsoft Advertising. It receives the msclkid under the same rule. Its handling is described in the Microsoft privacy statement at privacy.microsoft.com/privacystatement.
  • Meta Platforms Ireland Ltd runs Meta Ads and receives the fbclid where a campaign runs there, again only after Allow.
  • The hosting provider that serves this site stores the inquiry database, the chat transcripts and the server logs.
  • The mail provider carries the notification of each inquiry to the studio inbox.

Nobody else. We do not hand inquiry lists to printers, partners or anyone who asks nicely. If a project needs a print vendor, we share what the job needs, with you knowing first.

08Data that crosses a border

The studio and the site are in the United States. If you write to us from Europe or the UK, your message travels here, and that is a transfer under the GDPR. It rests on two things: the transfer is necessary to answer a request you made, and the advertising platforms we name are certified under the EU-US Data Privacy Framework and also use the European Commission's standard contractual clauses. Google, Microsoft and Meta move data between their own European and US entities on those terms.

09How long each record is kept

  • Inquiries and their email copies are kept for 36 months, then deleted from the database and the inbox.
  • Chat transcripts are kept for 6 months, then deleted; the token in your browser stops working.
  • Server and access logs are kept for 90 days, then rotated out and overwritten.
  • The record of a consent choice is kept for 12 months, then expires; the banner asks again.

Thirty-six months for inquiries is not arbitrary. Clients come back for a reprint or a second site two years later and expect us to know what was quoted. If you become a client, the project record falls under the contract and the tax rules that apply to it, and we tell you that in writing.

10How it is protected

Every page and form is served over HTTPS. The inquiry database sits behind a password-protected operator panel that only the four people in the studio can reach, and it is not linked from anywhere public. The form carries hidden trap fields and a render timestamp, so automated submissions are thrown out before they reach anyone. We collect no card data and no passwords, which removes the two things most worth stealing. No system is unbreakable; if a breach ever touched your data, we would tell you and the authority that needs to know, without waiting to be asked.

11Your rights under the GDPR

If you reach this site from the European Economic Area or the UK, the GDPR gives you these rights, and we honour all of them:

  • access: a copy of everything we hold about you;
  • rectification: fixing what is wrong or out of date;
  • erasure: deleting it, unless a contract or tax rule makes us keep part of it;
  • restriction: freezing its use while a dispute is settled;
  • portability: getting it back in a plain machine-readable file;
  • objection: stopping use based on our legitimate interest;
  • withdrawing consent at any time, without affecting what was done lawfully before.

12Your rights under US state law

The studio is in Texas and most of our clients are too, so US state privacy law is the first regime that applies. California residents have rights under the CCPA as amended by the CPRA: to know what personal information we collect and why, to see it, to correct it, to delete it, and to opt out of its sale or sharing for cross-context behavioural advertising. Texas, Colorado, Virginia, Connecticut, Oregon and the other states with laws in force give similar rights, and we apply the same process to everyone regardless of state.

We do not sell personal information for money. Passing a click identifier to an ad platform after you press Allow can count as sharing under the CCPA. Declining on the banner, or sending a Global Privacy Control signal, opts you out of it. We do not treat you differently for using any of these rights.

13Global Privacy Control

If your browser sends the Global Privacy Control signal, the Sec-GPC header, the site reads it as an opt-out of sale and sharing. The four consent signals stay denied and the banner does not ask you to reconsider. You do not need to do anything else.

14Children

This is a studio site for businesses. It is not meant for children under 16 and we do not knowingly take data from them. If a parent finds that a child has sent us an inquiry, write to us and we delete it the same week.

15Complaining to a regulator

Talk to us first if you can; most things get fixed in one email. You can also complain to the Attorney General of your state, and in California to the California Privacy Protection Agency. Visitors in Europe may complain to the data protection authority of the country where they live or work.

16How to use these rights

The fastest route is the data request form. Email works too: write to [email protected] with the address you used when you contacted us. Post goes to Vorngix, 83 River Road, Office 12, Austin, Texas 02757, United States. We answer within 10 days. If we need to confirm it is really you, we ask one question by reply to the email we already hold, never for an ID scan.

17When this notice changes

The date at the top of this page changes with it, and the earlier version is kept on request. A change that widens what we collect or who receives it is also shown as a line on the cookie banner, so it asks again rather than relying on your old answer.

18Reaching a person

Email [email protected], call +1 (448) 555-0161, or write to 83 River Road, Office 12, Austin, Texas 02757. Visits to the studio are by appointment. If your question is really about a project, the contact page is the better door.