Privacy Policy

Last updated: February 14, 2026

Introduction

Xandev ("we," "our," or "us") is the online identity under which freelance web development services are offered at xandev.us. We respect your privacy and are committed to being transparent about the data we collect. This policy explains what information we gather, why we gather it, and how it is used.

Information You Provide Directly

When you fill out our contact form, we collect:

  • Your name and email address
  • Phone number (optional)
  • Budget range and project timeline (optional)
  • Your message describing your project

If you interact with our engagement popup (which may appear after browsing several pages), we collect your name, email, and any optional message you provide.

If we initiate a live chat with you while you are browsing, the contents of that conversation are stored.

Information Collected Automatically

When you visit our website, we automatically collect certain data to understand how visitors use our site and to improve our services. We use a self-hosted, first-party analytics system—no data is sent to Google Analytics or other third-party analytics platforms.

Browsing Data

  • Pages visited and time spent on each page
  • Referrer URL (the page that linked you here)
  • Timestamps of your visits

Device and Browser Information

  • Browser type and version (user agent string)
  • Screen resolution
  • Browser language and timezone

Browser Fingerprinting

We generate a browser fingerprint based on your device characteristics (screen size, browser type, installed plugins, and a canvas rendering test). This is used to recognize returning visitors across sessions without requiring cookies or sign-in. The fingerprint is stored as a one-way hash and cannot be used to identify you personally.

Visitor Identification

We assign a randomly generated visitor ID stored in your browser's localStorage. This allows us to recognize you across visits so we can provide a better experience (for example, not showing the same popup twice). This is not a traditional cookie but functions similarly for persistence.

IP Address and Geolocation

We collect your IP address when you visit. We use a third-party service (ip-api.com) to determine your approximate geographic location (country, city, and region). Your IP address is transmitted to ip-api.com for this lookup and the result is cached on our server. A hashed version of your IP (first three octets only, with a salt) is stored alongside pageview records.

Session and Presence Data

While you are actively browsing, your browser sends periodic updates (approximately every 30 seconds) to let our system know which page you are on and how long you have been there. This data is used for real-time analytics and is automatically purged when you leave the site.

How We Use Your Information

Contact and Lead Information

  • To respond to your inquiries and provide quotes or proposals
  • To communicate about ongoing projects if you become a client
  • To send follow-up communications related to your inquiry

Analytics and Behavioral Data

  • To understand which pages and services are most popular
  • To identify potential leads based on browsing behavior (we calculate an internal "lead score" based on pages visited, return visits, and time on site)
  • To determine when to show the engagement popup (after sufficient browsing activity)
  • To detect and prevent spam or abuse (rate limiting on forms)

Live Chat

  • To proactively reach out to visitors who may benefit from our services
  • Chat messages are delivered through the same periodic browser updates used for analytics
  • Chat history is stored in your browser's localStorage and on our server

Data Storage and Security

All data is stored on our own web server within protected directories that are not publicly accessible. We do not share data with third-party database or storage providers. Access to stored data is restricted to the site administrator through a secured admin panel.

We implement industry-standard security measures to protect your information, including encrypted passwords, form protection against common web attacks, rate limiting, and secure session handling. However, no method of electronic storage or transmission is 100% secure, and we cannot guarantee absolute security.

Third-Party Services

We use the following external services:

  • ip-api.com — For IP geolocation lookups. Their privacy policy is available at ip-api.com/docs/legal.
  • Google Fonts — For web typography. Google may collect usage data as described in their privacy policy.
  • Font Awesome (cdnjs) — For icons, served via Cloudflare's CDN.

We do not use Google Analytics, Facebook Pixel, or any other third-party tracking or advertising platform.

Information Sharing

We do not sell, trade, rent, or share your personal information with third parties for marketing purposes. We may disclose information only:

  • To service providers who help operate our hosting infrastructure
  • If required by law or legal process
  • To protect our rights or the safety of others

Data Retention

  • Analytics sessions are automatically purged after 30 days
  • Real-time presence data expires within 2 minutes of your last page interaction
  • Visitor profiles and lead submissions are retained until manually deleted by the administrator
  • Chat messages are retained on the server until manually deleted; messages in your browser's localStorage can be cleared by you at any time

Consent

By using this website, you consent to the collection, use, and storage of your information as described in this policy. If you do not agree with this policy, please do not use our website. Your continued use of the website following the posting of any changes to this policy constitutes acceptance of those changes.

Your Rights and Choices

You have the right to:

  • Request a copy of the personal information we hold about you
  • Request correction of inaccurate information
  • Request deletion of your data from our systems
  • Clear local data by clearing your browser's localStorage (this removes your visitor ID, chat history, and conversion flags)
  • Block tracking by disabling JavaScript, which will prevent the analytics tracker from running

To exercise any of these rights, contact us at hello@xandev.us. We will make reasonable efforts to respond within 30 days.

Disclaimer and Limitation of Liability

We take reasonable measures to protect your information, but no method of electronic storage or transmission is 100% secure. We provide this website and all data handling "as is" without warranties of any kind, express or implied, including but not limited to warranties of security, accuracy, or fitness for a particular purpose.

To the maximum extent permitted by applicable law, Xandev and the individual behind Xandev shall not be liable for any unauthorized access to, alteration of, or loss of your personal data, or for any damages arising from your use of this website or reliance on information provided herein.

Children's Privacy

Our services are not directed at individuals under the age of 13. We do not knowingly collect personal information from children. If you believe we have inadvertently collected information from a child under 13, please contact us and we will promptly delete it.

Changes to This Policy

We may update this privacy policy at any time at our sole discretion. The "last updated" date at the top of this page reflects the most recent revision. Your continued use of our website after changes constitutes your acceptance of the updated policy. It is your responsibility to review this policy periodically.

Contact

Questions or concerns about this privacy policy? Contact us at hello@xandev.us.