Privacy Policy

This Privacy Policy explains what personal information we collect when you use atomikengine.com, why we collect it, who we share it with, and the rights you have over it.

Effective August 2, 2026

1. Who We Are

AtomikEngine ("AtomikEngine", "we", "us", "our") is a digital agency based in Miami, Florida, United States. We build websites, AI integrations, and digital marketing programs for business clients.

For the purposes of the EU/UK General Data Protection Regulation (GDPR), AtomikEngine acts as a data controller for information collected through this website, and as a data processor for client data we handle while delivering services under a client agreement.

2. Information We Collect

Information you give us. When you submit a project brief, contact form, or billing request we collect your name, email address, company name, website URL, budget range, timeline, preferred call date and time, and any message content you choose to provide.

Billing information. When you purchase a package we collect your billing email and transaction records. Card numbers are entered directly into Stripe's hosted checkout and are never transmitted to or stored on our servers.

Account information. If you use the billing portal we store your email address and a one-time login code to verify you own the address.

Technical information. Server logs may record IP address, browser user agent, referring page, and timestamps for security, abuse prevention, and diagnostics.

Cookie and analytics data. Only where you have consented to non-essential cookies. See our Cookie Policy for the full list and controls.

We do not knowingly collect information from anyone under 16, and we do not intentionally collect special-category data (health, biometrics, precise geolocation, government ID numbers) through this website.

3. How We Use Information

  • Respond to inquiries, prepare proposals, and schedule discovery calls.
  • Deliver, support, and invoice the services you engage us for.
  • Process payments, subscriptions, refunds, and chargebacks.
  • Verify identity before granting access to the billing portal.
  • Secure the site, prevent fraud and spam, and debug technical issues.
  • Send service and transactional messages related to an active request or engagement.
  • Send marketing email only where you have opted in or where permitted by law, always with a working unsubscribe link.
  • Meet accounting, tax, and other legal obligations.

4. Legal Bases for Processing (GDPR)

Contract. Processing necessary to respond to your request or perform a services agreement.

Legitimate interests. Securing our site, preventing abuse, understanding aggregate demand for our services, and reaching out about a brief you submitted. We balance these interests against your rights.

Consent. Non-essential cookies, analytics, marketing email, and any SMS notifications. You may withdraw consent at any time without affecting prior lawful processing.

Legal obligation. Retaining financial records and responding to lawful requests.

5. How We Share Information

We do not sell personal information, and we do not share personal information for cross-context behavioral advertising as those terms are defined under the CCPA/CPRA.

We disclose information to service providers who process it on our behalf under contract:

  • Stripe — payment processing, subscription billing, and the customer billing portal.
  • Supabase — database, authentication, and storage infrastructure for form submissions and billing records.
  • Resend / email delivery providers — sending transactional and notification email.
  • Hosting and CDN providers — serving the website and retaining short-lived security logs.

We may also disclose information when required by law, to enforce our Terms of Service, to protect rights and safety, or in connection with a merger or acquisition (with notice to affected individuals where required).

6. International Transfers

Our infrastructure and service providers are primarily located in the United States. If you access the site from the EEA, UK, or Switzerland, your information will be transferred to the United States. Where required, these transfers rely on the EU Standard Contractual Clauses or another approved transfer mechanism maintained by the relevant provider.

7. Data Retention

  • Project briefs and contact submissions: up to 24 months after last contact, unless you ask us to delete them sooner.
  • Client project records: for the duration of the engagement plus 7 years where needed for tax and legal purposes.
  • Billing and transaction records: 7 years, as required by financial recordkeeping rules.
  • Security and server logs: typically 30–90 days.
  • Cookie consent records: 12 months, so we can demonstrate the choice you made.

8. Your Rights

If you are in the EEA, UK, or Switzerland (GDPR): you have the right to access, rectify, erase, restrict, or object to processing of your personal data, the right to data portability, the right to withdraw consent, and the right to lodge a complaint with your local supervisory authority.

If you are a California resident (CCPA/CPRA): you have the right to know what personal information we collect and how we use and disclose it, the right to delete it, the right to correct it, the right to opt out of sale or sharing (we do neither), the right to limit use of sensitive personal information (we do not collect it for this purpose), and the right not to receive discriminatory treatment for exercising these rights.

Other US state privacy laws (including Virginia, Colorado, Connecticut, Utah, and Texas) grant substantially similar rights, and we honor them for all residents of those states.

To exercise any right, email info@atomikengine.com with the subject line "Privacy Request". We will verify your identity by confirming control of the email address on file, or by other reasonable means, before acting. You may use an authorized agent; we may ask for proof of authorization.

We respond within 30 days (GDPR) or 45 days (US state laws), with an extension where permitted. There is no fee for reasonable requests.

9. Do Not Track and Global Privacy Control

Our cookie banner defaults to rejecting non-essential cookies until you opt in. Where a Global Privacy Control (GPC) signal is present, we treat it as a valid opt-out of any sale or sharing of personal information.

10. Security

We use HTTPS/TLS across the entire site, row-level security on our database, scoped access controls, one-time-code authentication for the billing portal, signature verification on payment webhooks, and least-privilege service credentials. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security.

If we become aware of a breach affecting your personal information, we will notify you and any required regulator within the timeframes the applicable law requires.

11. Third-Party Links

Our site links to third-party websites and tools we do not control. This Privacy Policy does not apply to them; review their policies before providing information.

12. Changes to This Policy

We may update this policy. The effective date at the top always reflects the current version. Material changes will be highlighted on this page and, where required, communicated by email.

Contact Us

Questions about this policy can be sent to info@atomikengine.com.

AtomikEngine, Miami, Florida, United States.

We aim to respond to all policy and privacy inquiries within 30 days.