Legal
Privacy Policy
This policy explains what SnagLabs AI LLC collects through this website, why we collect it, who we share it with, how long we keep it, and how to get a copy of it or have it deleted. We have tried to write it in plain language and to describe what the site actually does, rather than everything a website might conceivably do.
- Last updated
- July 30, 2026
- Applies to
- Visitors and clients in the United States
Who we are and what this covers
SnagLabs AI LLC is a Texas limited liability company operating as Snag Labs in the United States. We are the controller of the information described here, which means we decide what is collected and why, and we are the party you can hold responsible for it.
This policy covers this website and the enquiry and booking forms on it. It does not cover a client’s own systems that we may work inside during an engagement: where we handle information on your behalf as part of paid work, we act on your instructions, and the terms of that engagement govern it. See section 12 of our Terms.
For anything privacy-related, including a request to see or delete your information, email privacy@snaglabs.ai.
The short version
- We collect what you type into our contact and booking forms. Nothing else about you is gathered for marketing purposes.
- The contact form saves your answers as you go, before you press submit, once you have entered an email address or a phone number. We explain that fully in section 4, including how to have a partial entry deleted.
- We run no analytics, no advertising trackers, and no cross-site tracking. We set no cookies of our own.
- We do not sell your information, we do not share it for targeted advertising, and we do not use it to train AI models.
- Four vendors are involved in running the site: our host, our database, our email provider, and our spam filter. They are named in section 8.
- You can ask us for a copy of your information or ask us to delete it, and we will do it. No account needed, no forms to fill in. Just email us.
What you give us directly
The contact form
Our enquiry form is a short wizard, and it collects only what is on it. In order, that is:
- About you: your name, work email address, phone number, your role, and optionally your company or organization.
- About your situation: the kind of visitor you are (an individual, a local business, a growing company, or an enterprise), your industry, your team size, a description of what feels slower than it should, where you think time is lost, and optionally the tools you currently use.
- What you want: the results you are looking for, selected from a list.
- What happens next: whether you want an audit, an introduction call, or an answer to a question, the question itself if you have one, and your consent to be contacted about the request.
The free-text fields are yours to fill as you see fit. Please do not put sensitive personal information in them, and please do not include other people’s personal information without their permission. We do not need either to answer your enquiry.
The booking form
If you book a call or an audit session, we collect your name, email address, phone number, the time slot you chose, and anything you type into the optional notes field. Booking takes no payment details and no card number.
The calculator
The time-and-cost calculator on this site runs entirely in your browser. The numbers you set on its sliders are not transmitted to us or stored, and we do not see them.
What we do not ask for
We do not ask for, and do not want, government identification numbers, financial account numbers, health information, biometric data, precise location, or any of the categories that state law treats as sensitive. We do not buy information about you from data brokers, and we do not build profiles from third-party sources.
Forms you start but don’t send
This one deserves its own section, because it is the part of our collection that is least obvious from using the site.
Why we do it. People are interrupted part-way through enquiry forms all the time. Someone who has told us their email address and what is going wrong has told us enough for us to follow up, and we would rather follow up than lose the conversation to a closed tab.
What is saved. The same contact and enquiry fields listed in section 3, as far as you had filled them in, plus how far through the form you got. Nothing is saved until an email address or a phone number is present, so simply landing on the page and leaving records nothing about you.
What happens to it. One record is kept per attempt at the form. If you go on to submit, that partial record is deleted and replaced by your actual submission. Otherwise it is deleted after 90 days from the last time the form was edited, or sooner if you ask.
Your consent. The consent checkbox sits on the last step of the form, so if you leave before reaching it, you will not have ticked it. We therefore treat a partial entry narrowly: we use it only to follow up on the enquiry you appeared to be making, we do not add it to any list, and we delete it on request without question.
How to have it removed. Email privacy@snaglabs.ai from the address you entered, or tell us the phone number you used, and we will delete the partial entry. You do not need to give a reason and we will not ask for one.
What is collected automatically
Much less than most websites. Specifically:
- Your IP address is read from the network request when you submit a form or book a session. We use it to enforce a rate limit, so that one source cannot flood us with submissions, and it is passed to our spam filter for the same purpose. We do not store it in our database and we do not use it to identify or profile you.
- Ordinary server logs are generated by our hosting provider as a normal part of serving a website, and can include IP address, the pages requested, and timestamps. Those logs are held by the host under its own retention schedule. We do not mine them, and we do not use them for analytics.
- Error diagnostics. When something breaks, we record what went wrong so we can fix it. These records are deliberately built to exclude the values you type into forms, and hold technical detail such as an error message and which part of the site failed.
- Timestamps are attached to submissions and bookings, because a record of when you contacted us is part of responding to you.
We do not collect precise geolocation, we do not access your camera, microphone, or location (the site actively switches those permissions off), and we do not fingerprint your device.
Why we use it
We use the information described above for these purposes and no others:
- To answer your enquiry and have a conversation with you about it.
- To scope, schedule, deliver, and support The $499 Business Friction Audit and any work that follows from it.
- To send you transactional email: a confirmation, a booking, a reply.
- To keep records of our engagements for tax, accounting, and legal reasons.
- To keep the site working and secure, including blocking spam and abuse and fixing errors.
- To comply with the law and to enforce our Terms where we have to.
If we ever want to use your information for something outside this list, we will ask you first.
What we don’t do with it
We do not sell your personal information, and we have not sold or shared personal information for cross-context behavioral advertising in the last 12 months, or ever.
We do not use your information, your enquiry, or your business details to train artificial-intelligence models, ours or anyone else’s.
We also do not rent or trade your information, do not pass it to data brokers, do not use it for automated decision-making or profiling that produces legal or similarly significant effects, and do not add you to a marketing list you did not ask to join. We do not run a marketing list at all.
How long we keep it
We keep information for as long as we need it for the purpose we collected it, and then we delete it. Concretely:
- Enquiries that don't become engagements
- 24 months from your last contact with us, then deleted
- Enquiries and bookings that become paid engagements
- 7 years from the end of the engagement, to meet tax, accounting, and contract-limitation requirements
- Booking records for sessions that were never held
- 24 months from the scheduled date, then deleted
- Partially completed contact forms that were never submitted
- 90 days from the last time the form was edited, then deleted automatically. Deleted immediately if you go on to submit the form, or sooner on request
- Transactional email delivery logs held by our email provider
- Per that provider's own retention schedule, typically under 30 days
- Application error logs
- 30 days, then deleted automatically. These are configured to record diagnostic detail only and to exclude the values you type into forms
Where we are required to keep something longer — a tax record, or information subject to a legal hold — we keep only what is required, and only for as long as it is required. If you ask us to delete your information we will, unless one of those obligations applies, in which case we will tell you what we are keeping and why.
How we protect it
Here is what we actually do, rather than a list of adjectives:
- All traffic to and from this site is encrypted in transit using HTTPS/TLS.
- Stored data sits in a managed Postgres database that is encrypted at rest and reachable only with credentials held as server-side secrets, never exposed to your browser.
- Form submissions pass through a hidden spam trap and per-address rate limiting before anything is stored, and, where third-party bot verification is enabled, a bot check as well.
- The site sends hardening response headers, including a deny-by-default framing policy, MIME-type protection, a restrictive referrer policy, and a permissions policy that switches off camera, microphone, and geolocation access.
- Access to submitted enquiries is limited to the people at our firm who need it to respond to you.
- Diagnostic logging is written to exclude the values you type into forms.
What we don’t claim
We want to be straight with you about this, because the industry usually is not. Snag Labs holds no security or privacy certification. We are not SOC 2 audited. We are not HIPAA-certified, and HIPAA and GDPR are not certifications anyone can hold in any case. We have not had a third-party penetration test. We take the measures above because they are sound practice, not because an auditor signed them off.
Please help us keep your information safe: send us the least you need to, avoid putting sensitive detail in a free-text box, and do not email us credentials in plain text. If you believe your information has been compromised, or you find a security problem with this site, tell us at legal@snaglabs.ai.
Your choices and your rights
Whatever state you live in, and whether or not a privacy statute happens to cover us, you can ask us to do any of the following, and we will:
- Know and access. Tell you what information we hold about you, where it came from, why we have it, and who we have shared it with, and give you a copy in a portable format.
- Correct. Fix anything inaccurate.
- Delete. Erase what we hold, including a partial form entry, subject only to what we are legally required to keep.
- Opt out. Stop sending you anything that is not strictly necessary to respond to you.
- Object or complain. Tell us you are unhappy with how we have handled your information, and have a person look at it.
How to make a request
Email privacy@snaglabs.ai and say what you want. There is no form and no account to create. So that we do not hand your information to somebody else, we may ask you to confirm a detail we already hold, such as replying from the email address you gave us. We will not ask you for more information than we need to verify the request, and we will not use what you send for anything else.
We will acknowledge your request promptly and respond substantively within 45 days. If it is genuinely complicated we may need more time, and we will tell you before the 45 days are up. Making a request is free. We will never charge you for it, refuse you service, or give you a worse price because you exercised a privacy right.
An authorized agent may make a request for you if you give them written permission and we can verify it.
If we turn a request down, we will tell you why, and you can ask us to reconsider by replying to the same address. We will have someone who was not involved in the original decision look at it again.
State privacy rights
Several states have comprehensive privacy laws, including Texas, California, Virginia, Colorado, Connecticut, Utah, Oregon, Texas, Montana, and others. Most of them only bite above a revenue or volume threshold that a business of our size does not meet, and most exempt information collected in a purely business-to-business context.
For California residents
Under the CCPA as amended by the CPRA, the categories of personal information we collect are identifiers (name, email address, phone number, IP address), commercial information (the service you enquired about), professional or employment-related information (your role, your company, your team size), and the contents of the messages you send us. We collect them from you directly, for the business purposes in section 6, and we disclose them for a business purpose only to the service providers in section 8. We have not sold or shared personal information, and we do not collect or process sensitive personal information for the purpose of inferring characteristics. We do not use personal information for automated decision-making. You have the rights to know, access, correct, delete, limit, opt out, and to be free from retaliation, and you can exercise them as described above.
California’s “Shine the Light” law lets residents ask about disclosure of personal information to third parties for direct marketing. We make no such disclosures, so there is nothing to report, but you are welcome to ask.
Do Not Track and Global Privacy Control
There is no industry consensus on Do Not Track, and we do not track you across sites in the first place, so there is nothing for the signal to switch off here. We honor the Global Privacy Control as an opt-out signal to the extent it applies to us, which given that we neither sell nor share information is, in practice, not at all.
Children
This site and our services are for businesses and for adults. They are not directed to children, and you must be at least 18 to use them. We do not knowingly collect personal information from anyone under 18, and we have no interest in doing so. If you believe a child has given us information, email privacy@snaglabs.ai and we will delete it promptly. We do not knowingly collect information from anyone under 13 within the meaning of COPPA, and we do not sell the personal information of anyone under 16.
We operate in the United States only
We are a US business, we serve clients in the United States, and our vendors and our data are in the United States. This site is directed to users in the United States.
We do not offer goods or services to people in the European Economic Area, the United Kingdom, or Switzerland, and we do not monitor anyone’s behavior there. If you are outside the United States and choose to contact us anyway, understand that your information will be sent to and stored in the United States, under US law, which may not provide the same protections as the law where you live. Please do not use the forms on this site if that is not acceptable to you.
Email from us
Email we send you is transactional: a confirmation that we received your enquiry, a booking detail, or a reply from a person. It relates to something you asked us for.
We do not run a newsletter or a marketing list. If we ever start one it will be opt-in, and every message will carry a working unsubscribe link and our postal address. We will not add you to it because you once sent us an enquiry.
You can tell us to stop sending you anything non-essential at any time by emailing privacy@snaglabs.ai, and it will stop. We may still need to send you email about an engagement that is actually running.
Links to other sites
This site links to other websites, and our guides cite third-party tools and articles. We do not control those sites, we are not responsible for their content or their privacy practices, and this policy does not apply once you leave. Please read the privacy policy of any site you visit.
Business changes
If we are involved in a merger, acquisition, financing, reorganization, or sale of all or part of our business, information covered by this policy may be transferred as part of it. If that happens we will require the recipient to honor this policy for the information it receives, or to give you notice and a choice before using it in a materially different way. If we wind down, we will delete what we are not required to keep.
If something goes wrong
If we discover a breach of security that has compromised your personal information, we will investigate promptly, take steps to contain it, and notify you and any regulator required, in the manner and within the timeframes the applicable state breach-notice law requires. Our notice will tell you what happened, what information was involved, what we have done, and what we suggest you do. We will not sit on bad news.
Changes to this policy
If this policy changes we will update the date at the top of this page and post the new version here. If a change materially affects how we handle information we have already collected about you, we will make it prominent, and where we have your email address and an open matter with you, we will tell you directly.
We will not retroactively use information we already hold in a materially different way without giving you notice and, where the law requires it, asking your permission first.
How to reach us
SnagLabs AI LLC, a Texas limited liability company operating as Snag Labs.
- Privacy questions, access requests, and deletion requests: privacy@snaglabs.ai
- Security reports and legal notices: legal@snaglabs.ai
- Anything else: hello@snaglabs.ai
A real person reads these. If you have raised something with us and are not satisfied with the answer, say so and we will look at it again. You may also have the right to complain to your state attorney general.