Godd Technologies, LLC (“Godd Technologies,” “we,” “us,” or “our”) provides this Privacy Policy to explain how we handle personal information in connection with:
- our public corporate websites, including
goddtechnologies.comandsamgov.goddtechnologies.com; - inquiries, support communications, project intake, and a submitted checkout or other service request (an “Order Request”), as well as an accepted quote, statement of work, order form, purchase order, government contract, and its related invoice (each accepted engagement, an “Accepted Order”);
- Stripe-hosted payment pages, receipts, invoices, refunds, and payment administration that we make available.
A contract, Government Order, or product-specific notice may provide additional terms for a particular engagement. This Policy is a notice of our practices; it is not a request to agree to data uses unrelated to the service requested.
1. Information we collect
Information you provide directly
Depending on how you interact with us, we may receive:
- Contact and communication information: name, organization, business email address, subject, message, support request, and other information you choose to provide.
- Quote and service information: requested service, project purpose, scope, deliverable preferences, schedule, agency or business office, procurement or order reference, and communications about performance.
- Project-intake information: project title, script or content requirements, desired format and length, rights and authorization attestations, third-party asset disclosures, delivery instructions, and an optional opaque payment reference. Public intake is not payment confirmation.
- Business and government purchasing information: purchaser and agency or organization contact details, billing information, purchase-order or invoice references, tax-exemption documentation, and records required by the Accepted Order.
- Materials provided for an accepted engagement: files, content, and other project materials transferred through a channel approved for that Accepted Order.
Do not send full payment-card numbers, card security codes, passwords, private keys, Social Security numbers, government identification numbers, health information, biometric source material, classified information, Controlled Unclassified Information, nonpublic Federal Contract Information, export-controlled technical data, or other regulated or sensitive information through a public form, ordinary support email, Stripe custom field, or other channel not expressly approved for it. Ordinary transaction and payment information specifically requested to place an Order Request or process an Accepted Order may be submitted through the designated checkout.
Payment and transaction information
If you use a Stripe-hosted payment page that we provide, Stripe collects and processes the payment credentials and related information needed to complete and protect the transaction. Depending on the checkout configuration and the transaction, Stripe may collect your name, business name, email address, billing address, tax information, payment method information, and fraud- and device-related signals.
We receive transaction and administration information from Stripe, such as the product or service, amount, currency, customer contact and billing details made available to us, payment status, receipt or invoice information, and payment, refund, or dispute references. We do not receive the full card number or card security code from Stripe-hosted checkout.
Website and device information
When a browser requests our websites, we and our hosting or security providers may process technical information such as IP address, browser and device type, operating system, requested page, date and time, referring page, response status, and security or diagnostic events. This information may be present in ordinary server, platform, and security logs.
Cookies and similar technologies
The corporate site uses first-party session and cross-site-request-forgery (CSRF) cookies needed to operate and protect forms. Cloudflare Turnstile may process a verification token, IP address, browser or device signals, and related technical information to distinguish people from automated abuse. Pages may load Google Fonts, which causes the browser to make a request to Google for the font files.
As of the effective date, the current website code does not use advertising cookies or cross-site behavioral-advertising analytics. If that practice changes, we will update this Policy and provide any notice or choice required by law before using the new practice.
2. How we use information
We use personal information as reasonably necessary to:
- operate, secure, troubleshoot, and improve our websites and services;
- respond to inquiries and provide customer support;
- prepare and evaluate quotes, Orders, scope, rights, and purchasing authority;
- process and reconcile payments, invoices, receipts, refunds, and disputes;
- perform, communicate about, document, and deliver accepted work;
- prevent fraud, misuse, duplicate transactions, and security incidents;
- maintain accounting, tax, contract, audit, and legal records;
- protect our rights, customers, systems, and the public; and
- comply with an accepted contract, lawful request, or other legal obligation.
We do not use project materials for unrelated advertising. We do not make decisions that bind a government agency or determine a purchaser’s procurement authority.
3. How we disclose information
We may disclose personal information only when reasonably necessary for the purposes described above, including to:
- Microsoft Azure, for website and cloud hosting, infrastructure, diagnostics, and security;
- Microsoft Graph and Microsoft-hosted email services, to deliver contact, intake, and business communications. Those messages may be retained in the configured recipient mailbox and in the sending mailbox’s Sent Items under the applicable business retention settings;
- Stripe, for hosted checkout, payment processing, fraud prevention, compliance, receipts, invoices, refunds, and disputes. Stripe also processes some information for purposes described in its own privacy notice and legal terms;
- Cloudflare, when Turnstile is enabled, for bot detection and form abuse prevention;
- Google, when a page requests Google Fonts from Google’s servers;
- professional advisers, auditors, insurers, or subcontractors who need the information for an accepted engagement. We require confidentiality, security, or data-handling terms where applicable law, the Accepted Order, or the sensitivity of the information requires them;
- a party to a proposed or completed merger, financing, reorganization, sale, or transfer of all or part of the business, subject to lawful safeguards; or
- a court, government authority, or other person when required by law or reasonably necessary to protect rights, safety, systems, or the integrity of a transaction.
We will not send customer information or project materials to a third-party AI service unless the Accepted Order or a linked notice first identifies the provider or provider category, data, purpose, permitted use, and relevant confidentiality, security, and retention terms, and the customer expressly authorizes the transfer.
For the services covered by this Policy, we do not sell personal information for monetary or other valuable consideration, rent it, or share it for cross-context behavioral advertising. If applicable law characterizes a disclosure differently or grants an opt-out right, we will honor that law.
4. United States Government information
Public websites, ordinary email, and standard Stripe checkout are intended for ordinary business contact, procurement, billing, and payment information. They are not authorized systems for classified information, Controlled Unclassified Information, nonpublic Federal Contract Information, export-controlled technical data, agency credentials, or other agency-restricted information. FAR 52.204-21 excludes simple transactional information necessary to process payments from its definition of Federal Contract Information.
For a United States Government engagement, a valid solicitation, award, purchase order, contract, or applicable federal privacy or information-security clause may impose additional or stricter handling requirements. Applicable law and the valid Accepted Order govern our handling. Before we receive protected agency information, the parties must define the applicable requirements and approve an appropriate channel in writing, and we will provide any additional notice required before materially different processing.
Nothing in this Policy represents that every engagement is subject to the Privacy Act or involves Federal Contract Information or Controlled Unclassified Information. Nothing represents that a service is FedRAMP authorized, holds a stated CMMC status, implements or conforms to a specified NIST standard or framework, or satisfies applicable Section 508 requirements unless that exact claim is supported by current evidence and accurately stated in the controlling Accepted Order. SAM.gov registration or use of a Governmentwide commercial purchase card does not create those representations.
5. Retention
We retain each category only for as long as reasonably necessary for the purpose for which it was collected, including to perform and support an Accepted Order, maintain accounting and tax records, document rights and authorization, meet contractual recordkeeping duties, prevent fraud, resolve disputes, and comply with law.
Retention varies by record type and controlling contract. Relevant criteria include whether an inquiry or Accepted Order remains active, whether the information is needed to provide support, the sensitivity of the information, configured provider log periods, limitation periods, and legal or government-records requirements. When information is no longer needed, we take reasonable steps to delete, deidentify, or securely dispose of it. A customer or agency may request the retention rule applicable to a particular Accepted Order.
6. Security and incident response
We use reasonable administrative, technical, and physical safeguards appropriate to the nature of the information we handle. These include using hosted payment pages rather than asking customers to send full card data, limiting public intake, using access and form-abuse controls, and using secured cloud and email services. No Internet transmission or storage system is completely secure, and we cannot guarantee absolute security.
If a security incident triggers a legal or contractual notification duty, we will provide notice as required by the applicable law or contract. If you believe information sent to us has been compromised, contact us promptly and do not include additional sensitive information in the initial message.
7. Your choices and privacy requests
Depending on applicable law and your relationship with us, you may request access to, correction of, or deletion of personal information about you; a copy of information you provided; restriction of or objection to certain processing; or review of a decision on a prior request. You may also withdraw a consent for future processing where consent is the basis, without affecting earlier lawful processing.
Submit a request to support@goddtechnologies.com with the subject Privacy Request. We may ask for information reasonably necessary to verify identity, authority, and the records involved. We may deny or limit a request where the law permits or requires us to retain information, protect another person, preserve security or legal claims, or comply with a Government Order. We will explain a denial when required by law.
For the services covered by this Policy, we do not currently sell personal information or share it for cross-context behavioral advertising, so we do not currently operate an opt-out mechanism for those practices. If applicable law requires one for a present or future practice, we will provide and honor it. You may use browser settings to control cookies, but blocking a security or CSRF cookie may prevent a protected form from working.
8. Children
The corporate and government-procurement services covered by this Policy are not directed to children under 18. We do not knowingly solicit personal information from children through those services. If you believe a child provided personal information through them, contact us so we can investigate and take appropriate action. Product-specific rules apply to any separately offered consumer application.
9. Third-party sites and international processing
Our sites may link to third-party websites. Their privacy practices are their responsibility, and their policies apply when you use them. Our providers may process information in the United States or other locations where they operate, subject to their legal terms and applicable transfer requirements.
10. Changes to this Policy
We may update this Policy to reflect verified changes in our services, data practices, providers, or legal obligations. We will post the revised Policy and change the effective date. We will provide additional notice or obtain consent when applicable law or a controlling contract requires it. A revision does not override a Government Order or retroactively authorize a materially different use of information.
11. Contact
Godd Technologies, LLC
Homestead, Florida, United States
Email: support@goddtechnologies.com
Telephone: +1 (786) 481-8611