Last updated 2 August 2026
Privacy policy
Xandev is one person, so this is short and in plain language. It says what I collect, why, how long I keep it, and how to make me delete it.
Who this is
Xandev is a sole proprietorship based in Sycamore, Illinois. There is no company behind it and no staff: when this page says "I", it means one person. You can reach me at hello@xandev.us about anything on this page.
What I collect, and why
When you use the contact form
Your name, email address, and whatever you write in the message, plus your phone number, company, budget range, and the service you asked about if you fill those in. I need these to answer you. Along with the message I store the page you sent it from, the referring page if your browser sent one, your IP address, and your browser's user agent string.
Those last three are for spam filtering and nothing else. The contact form scores each submission, and if I could not see where a submission came from I would have to either publish an email address for harvesting or lose real inquiries to filtering. Submissions that score as spam are flagged rather than deleted, so a wrongly-filtered inquiry can still be found.
If you reply to my email
When I answer an inquiry, my reply and anything you send back are kept together with the original message, so the whole exchange is in one place instead of scattered through my mailbox. Your reply is stored as plain text, along with the address it came from and when it arrived.
This only ever reaches conversations I started by answering you. It works by recognising the specific message you replied to, so nothing else in my mailbox is read, searched, or copied here, and nobody can get a message into your inquiry by sending mail that claims to be from you. If you would rather not have a reply kept this way, say so and I will delete it.
When you sign in to the client portal
If you are a client, the portal holds your name and email address, the projects and files belonging to your account, messages you send me through it, and a record of when you last signed in and from which IP address. Sign-in links are stored as a one-way hash rather than as the link itself, so a copy of the database does not yield a working way in.
Files you upload are stored outside the web root under a random filename and are served only to your own account. Nobody else's account can reach them and they are not linked from anywhere public.
Cookies
A session cookie keeps you signed in to the client portal and carries the token that stops other sites submitting forms as you. It is marked HttpOnly and SameSite and expires when your session does.
Two more are set for the analytics described below: one that identifies your browser for a year, and one that identifies the current visit and expires when you close the browser. Both are set by my server, are marked HttpOnly so no script on the page can read them, and are never sent anywhere but this site.
Your theme choice, dark or light, is kept in your browser's local storage. That never leaves your device and never reaches me.
There are no advertising cookies, no third-party tag managers, and no social media pixels on this site.
Analytics
This site tracks visitors, and in more detail than most small business sites. There is no consent banner, so I am telling you here instead, specifically rather than generally. All of it runs on my own server. No third party receives any of it: there is no Google Analytics, no advertising network, and no data broker involved at any point.
What is recorded
- Every page you open, its title, and the page you came from.
- How long you spend on each page, counted only while the tab is actually visible.
- Your screen size, browser language, timezone, and the browser and operating system your browser reports.
-
Any
utm_tags on the link you arrived through, which is how I tell one campaign from another. - A one-way hash of your network address, with the last part removed before hashing. I cannot turn it back into your address, and everyone in your household or office produces the same value.
Fingerprinting, named plainly
A short code is calculated from your browser: its user agent, language, screen size and color depth, timezone offset, processor and memory counts, plugin count, and the result of drawing a line of text onto an invisible canvas, which comes out subtly differently on different hardware and software. Those are combined and hashed into one value.
That value is a browser fingerprint. Its purpose is to recognize you as the same person on a later visit, and it works even if you delete the cookies described above. I use it to see whether the person reading the pricing page today is the person who read the services page last week. It is not shared with anyone and it cannot be used to identify you by name.
If you would rather not be tracked, see "Turning it off" below. Ad blockers and browsers that resist fingerprinting also work against this, and I have made no attempt to defeat them.
Scoring
From the above I calculate a score out of 100 estimating how likely you are to be looking to hire someone, along with the reasons for it, such as having read the pricing page or having come back more than once. Visiting pricing or contact counts for more than reading the blog. It is a sorting aid for my own follow-up. No decision is made automatically from it, nobody is refused anything because of it, and it is never shared or sold.
The popup and the chat
If that score passes a threshold, a small box may appear once, offering to help and asking for an email address. Giving one is entirely optional, and if you do, it is attached to everything above. That is the point at which an anonymous record becomes a record about a named person, which is why it is worth saying twice. Closing the box is a complete answer and it will not come back.
I can also send you a message while you are on the site, which opens a small chat window. Those messages are stored with your visitor record. I cannot see your screen, your keystrokes, or anything you type outside that chat box.
How long it is kept
The individual records, meaning your pageviews, visits, fingerprint and score, are deleted automatically after 90 days. Daily totals such as "412 pageviews on 3 March" are kept indefinitely, but those are counts with nobody attached and cannot be traced back to any person.
Turning it off
If your browser sends Do Not Track or Global Privacy Control, nothing on this page is recorded about you. Not anonymised, not aggregated: no row is written, and the tracking script is not sent to your browser in the first place. Both are honoured in full, every time, and neither requires you to ask me.
You can also email me and I will delete everything tied to you.
Server logs
The web server keeps ordinary access logs: IP address, timestamp, the URL requested, and the user agent. Every web server does this, and without it a break-in attempt would be invisible. Application errors are logged too, with enough detail to fix them.
Payments
Card payments are handled by Stripe. Card numbers are entered directly into fields that Stripe serves and are sent from your browser to Stripe without passing through this site. I never see, store, or have any way to retrieve your card details. What I do see is the amount, the date, the last four digits, and whether it succeeded.
Invoices themselves are kept in InvoiceNinja, which I host. Stripe's own privacy policy covers what Stripe does with the payment data it collects.
Who else sees any of this
Nobody, with these exceptions, and none of them are advertisers:
- Stripe, to take a payment, and only when you make one.
- Microsoft, because email from this site is sent through a Microsoft 365 mailbox. That means Microsoft handles the contents of emails I send you, as it would for any business using Outlook.
- The hosting provider, which stores the server and the database in the ordinary course of hosting them.
I do not sell your information, I do not share it for advertising, and I have no arrangement with anyone that would let them use it for their own purposes. If I am ever legally required to hand something over, I will tell you unless I am prohibited from doing so.
How long I keep things
- Contact form inquiries, and the email exchange that follows one, are kept while they might still lead somewhere, and deleted after two years if they did not. Deleting the inquiry deletes the messages with it.
- Client records, projects, and files are kept for as long as you are a client and for seven years afterwards, because invoices and the work they relate to have to be kept for tax and accounting purposes.
- Server and audit logs are kept for twelve months.
- Sign-in links expire in fifteen minutes and are deleted once used.
What you can ask me to do
Email hello@xandev.us and ask, and I will do it. You can ask for a copy of everything I hold about you, ask me to correct something wrong, or ask me to delete it. There is no form and no process; it is one person reading the email.
The one thing I cannot delete on request is a record I am legally required to keep, which in practice means paid invoices and the accounting behind them. If that applies I will say so and delete everything else.
I will answer within thirty days, and usually within one business day. If you are in the UK or EU, or in a US state with its own privacy law, you have these rights under that law rather than as a favor, and you can complain to your local regulator if you think I have handled this badly.
Security
The site runs over HTTPS. Passwords are not used for the client portal at all; sign-in is by a single-use link that expires. The admin area is behind Microsoft sign-in. Database queries use prepared statements, uploads are stored outside the web root, and the browser is told through a content security policy which scripts it may run. None of that makes a site unbreakable, and anyone claiming otherwise is selling something, but it removes the ways sites like this usually get broken.
If you find a security problem, email hello@xandev.us and I will take it seriously and reply.
Children
This is a business-to-business site. It is not aimed at children and I do not knowingly collect anything from anyone under 16.
Changes
If this policy changes, the date at the top changes with it. If a change materially affects existing clients, I will email you rather than rely on you noticing this page.
Contact
hello@xandev.us
Xandev, Sycamore, Illinois