LEGAL
Privacy Policy
Effective August 25, 2026
Information collected
We collect information reasonably needed to sell, build, host, support, bill for, secure, and administer our services. Depending on how you interact with us, this can include names, account and billing contact details, business information, website/project intake and notes, uploaded project assets, domain and registrar information, order and transaction records, accepted legal-policy evidence, support communications, authentication/security events, and limited technical identifiers used for security and abuse prevention.
How information is used
Information is used to respond to inquiries, provide services, manage projects and hosting, register or administer domains, maintain records, process billing, prevent abuse, investigate disputes, improve operational quality, and comply with legal obligations.
AI-assisted processing and automation
God's Plan may use artificial intelligence, machine-learning systems, automated agents, code-assistance tools, content-analysis tools, design-assistance tools, and similar technologies to help perform research, drafting, development, testing, quality review, administration, and other ordered services. This means project materials, instructions, uploaded content, or business information may be processed by automated systems when reasonably necessary for service delivery.
AI-assisted systems can produce errors or unexpected output. God's Plan uses human review or approval appropriate to the task but does not represent AI output as infallible. Customers should not submit passwords, secret keys, full payment-card numbers, Social Security numbers, PHI/ePHI, or other specially regulated information to an AI-assisted workflow unless God's Plan has expressly approved a secure workflow for that data type.
Service providers
We may disclose or transmit information to service providers when reasonably necessary to perform the requested service. Current or planned service categories include web hosting and infrastructure providers such as Bluehost, payment processing through Stripe, domain/registrar services such as OpenSRS or the applicable registrar, email providers, customer-selected integrations, security tooling, and AI or automation service providers used for service delivery. A provider may process information under its own terms and privacy practices.
Payments
Payment processing is performed through payment-service providers such as Stripe. God's Plan does not require customers to send full payment-card numbers through ordinary project forms, support notes, uploads, or email. Provider transaction identifiers, amounts, status, billing records, and related evidence may be retained in God's Plan systems.
Cookies, browser storage, and analytics
The current public commerce experience uses essential session cookies where PHP sessions are required and first-party browser storage for functions such as cart contents, hosting-billing selection, and checkout request state. Nonessential analytics, advertising, sale/share, or cross-context behavioral tracking must not be activated until the applicable disclosure and consent or opt-out controls are implemented.
Retention and security
Retention depends on the data class and why it is needed. Account/contact, project, support, and prospect records are generally targeted for no more than about 24 months after the relevant relationship or activity ends unless a longer period is requested or reasonably required. Billing, transaction, accepted-contract evidence, domain/registry, fraud, dispute, tax, accounting, or other legally significant records may be retained for up to 7 years or longer when law or an active dispute requires it. Security/audit records are generally targeted for up to 24 months unless an investigation requires longer retention. Reasonable safeguards are used, but no internet system can be guaranteed completely secure.
Your privacy choices
Clients can use the authenticated Privacy & Data center to download a JSON export of core account records and submit access, correction, or deletion/anonymization requests. Deletion requests are reviewed before destructive action because some billing, tax, domain, contract, fraud, security, dispute, or legal records may need to remain. When approved, direct account/contact fields can be anonymized while required transactional and legal records are retained.
Sensitive and regulated information
Do not send passwords, secret keys, full payment-card numbers, Social Security numbers, medical/health information, or other specially regulated information through website forms, project notes, uploads, support notes, email, or AI-assisted workflows unless God's Plan has expressly provided an approved secure workflow for that specific data type. God's Plan does not currently offer or represent this platform as HIPAA compliant and does not intentionally collect, store, or process PHI/ePHI. If a requested project would require PHI/ePHI or another specially regulated data class, stop submission and contact us so the work can be declined, redirected, or separately scoped before such data is received.
Contact
Privacy requests may be sent to privacy@godsplanholdingsllc.com.