1. Who is responsible for your information
Iro, based in Colorado, United States, is the data controller for information collected through the Site. Reach us at hello@iro.studio for any privacy question.
2. What we collect
We try to collect as little as possible. From visitors to the Site, that comes down to:
- Server request data — IP address, user-agent string, requested URL, referrer, timestamp, and basic geographic information (country / region) derived from IP. Standard web-server logs, recorded by our hosting provider.
- Booking information — when you book a call via the /book page, the Reclaim.ai embed collects the time you select, your name, email address, and any optional notes you choose to share. This information flows through Reclaim.ai's systems and ends up on our calendar.
- Email content — if you write to hello@iro.studio, we receive your email address, any name you've configured in your mail client, and the message you sent.
We do not run advertising trackers, third-party analytics SDKs, fingerprinting scripts, session recording, or A/B testing tools on the Site.
3. How we use it
We use the information collected above only to:
- Operate, secure, and improve the Site (server logs, debugging, fixing broken pages).
- Schedule and run the call you booked, and send the related calendar invite.
- Reply to your email, and continue any conversation you started.
- Comply with legal obligations and enforce our Terms of Use.
We do not use this information to build advertising profiles, sell to third parties, or train machine-learning models.
5. Third-party services we rely on
We use a small number of third-party services to run the Site. Each receives only the information needed to do its job:
- Vercel — hosts the Site and stores standard server access logs (IP, user-agent, requested URL, referrer, timestamp).
- Reclaim.ai — powers the booking embed on /book. Receives the booking details you submit (time, name, email, optional notes).
- Google Fonts — serves the Inter Tight and JetBrains Mono webfonts. Google receives standard request data (IP, user-agent) when your browser fetches the font files.
- Email provider — when you email hello@iro.studio, our mail provider stores your message until we reply and archive it.
We don't sell your personal information to anyone, and we don't share it with third parties beyond the providers listed above except where required by law (for example, a valid subpoena).
6. How long we keep it
Server access logs are retained by our hosting provider for the period set in their standard log-retention policy (typically 30 days). Booking information stays in our calendar and Reclaim.ai account until you ask us to delete it. Email correspondence is kept for as long as it remains useful for the conversation, then archived.
7. Where information is processed
Iro is based in the United States, and most of the providers above also process information in the United States. If you're contacting us from outside the US — for example, from the EU/UK — please be aware that your information will be transferred to and processed in the US, which has different data-protection laws than your home jurisdiction.
We rely on appropriate safeguards (such as the providers' own contractual data-transfer mechanisms) for international transfers where required.
8. Your rights
Depending on where you live, you have rights over the information we hold about you:
- Colorado residents (Colorado Privacy Act): right to know what personal data we process, right to correct inaccuracies, right to delete, right to data portability, and right to opt out of targeted advertising, sale, or profiling. We don't engage in any of those, but the rights still apply.
- Other US residents with state privacy laws (California, Virginia, Connecticut, and others): equivalent rights apply where the relevant law covers us.
- EU / UK residents (GDPR / UK GDPR): right of access, rectification, erasure, restriction, portability, and objection to processing.
To exercise any of these rights, email hello@iro.studio. We'll respond within the timeframe required by the law that applies to you (typically 30–45 days). We may need to verify your identity before acting on requests that involve specific records.
You also have the right to lodge a complaint with your local data-protection authority (for example, the Colorado Attorney General's office, or your EU Member State supervisory authority).
9. Children
The Site is intended for adults evaluating professional services. We do not knowingly collect personal information from anyone under 16. If you believe a child has shared information with us, email hello@iro.studio and we'll delete it.
10. Security
We use industry-standard measures to protect the information we hold — TLS for data in transit, providers with strong security practices, and limited access on a need-to-know basis. No system is perfectly secure; if we ever become aware of a breach affecting your information, we'll notify you and the relevant authorities as required by law.
11. Do Not Track and Global Privacy Control
We don't run cross-site advertising trackers, so there isn't much for a "Do Not Track" or Global Privacy Control signal to disable. We honour those signals where they map to a meaningful control on our end.
12. Changes to this policy
We may update this policy by posting a revised version on this page with a new Last updated date. Material changes will be summarised at the top of this page for at least 30 days after they take effect.
13. How to reach us
Questions about this policy, or about the data we hold on you? Email hello@iro.studio. We aim to reply within one business day, weekdays, Mountain Time.