Version privacy-v2026-08-21

Privacy Notice

Plumb Bob Services · 4128 Emmett Dr, Montgomery, TX 77316 · [email protected]

Scope and information collected

This notice covers the Texas business-to-business marketing site and the well-list audit request form. The form collects first and last name, phone number, email, company name, a P-5 operator number, and a well API number. Security processing includes IP address, browser information, request metadata, Cloudflare Turnstile results, and the versioned acceptance record.

How information is used

Information is used to secure the form, respond to the requested audit, operate the request workflow, and maintain evidence of the disclosure accepted. Submission does not enroll the requester in marketing. Targeted advertising, sale of personal information, session replay, chat widget, or biometric processing is not part of this launch.

Service providers

The processors are Cloudflare for CDN, Access, and Turnstile; Google Workspace for one transactional owner notification sent through the Gmail API over HTTPS; DigitalOcean for application hosting; Supabase for the server-owned database; and HubSpot for customer-relationship workflow when the separately controlled delivery gate is enabled. Email is used to notify the owner so the business can respond to the submitted audit request. No requester receipt is created or sent.

Analytics and customer relationship management

The application uses Google Analytics 4 (GA4) measurement and HubSpot customer-relationship tracking when their separately controlled browser gates are enabled. GA4 uses an approved measurement event list without Google Signals, advertising features, User-ID, or ad-personalization features; names, email addresses, phone numbers, P-5 numbers, well API numbers, and raw form contents are not sent to GA4, and sensitive URL values are redacted. HubSpot records first-party site activity, page clicks, referrers, and source information and can link a successful custom audit-form submission to the visitor's work email after the form is accepted. Neither browser integration enrolls a visitor in marketing. If server-side HubSpot delivery is enabled, only approved CRM fields for an audit request are delivered; secrets and raw field evidence are excluded.

Cookies and similar technologies

Essential security, session, and form-protection technologies remain active. When the browser gates are enabled, GA4 and HubSpot tracking load by default for a new visitor after the page becomes interactive. A visitor can revoke either optional choice at any time through Cookie choices; revocation prevents future tracking, expires relevant first-party cookies, and Global Privacy Control opts the visitor out of optional tracking. Advertising, session replay, User-ID, and automated marketing enrollment remain excluded.

Retention

Audit requests and acceptance evidence are retained for 24 months, integration delivery records for 90 days, and application audit events for 12 months. Provider deletion settings and backups are maintained against this schedule, subject to legal holds and documented deletion procedures.

Choices, security, and contact

Reasonable access, correction, and deletion requests may be sent to [email protected], whether or not a particular privacy statute applies. Reasonable administrative, technical, and physical safeguards are used, but no system can be guaranteed completely secure. Global Privacy Control is recognized; because no sale or targeted-advertising sharing is proposed, it does not change the launch processing described here.

Changes

Effective notices are dated, versioned, and archived. Portal accounts, well records, uploads, field photos, location data, e-signatures, invoicing, payments, or advertising integrations require a notice update before they are introduced.