Website privacy

Privacy Policy

This policy describes the current public website and contact workflow. It does not replace a client agreement governing project or proprietary data.

Effective

Production policyThis policy reflects the canonical website and its active Contact and analytics configuration.

Information the website collects

The contact form asks for a name, work email, company, topic, and an optional short message. The form also uses a hidden spam field and a submission-start timestamp. Do not include confidential project documents, credentials, or other sensitive information in the message.

The production website uses Google Analytics 4 for website measurement. Pegasus sends a canonical page location limited to an approved path and campaign-tag allowlist, a referring-site origin when available, and a small allowlist of interactions such as Contact calls to action, form start, coarse failure class, acknowledged form success, Insight filtering, and outbound GAIA Civil links. Google Analytics also collects standard user and session measurements, approximate location, browser and device information, language, screen information, and ordinary network metadata. Pegasus does not send Contact names, email addresses, company names, messages, search phrases, delivery IDs, CRM identifiers, arbitrary URLs, raw errors, or other form contents as custom analytics data.

Google Analytics normally uses first-party _ga and _ga_<container-id> cookies to distinguish users and preserve session state. Google documents a default expiration of up to two years, subject to browser limits and the approved property settings. Pegasus does not configure a user ID. The site code denies advertising storage and advertising-user-data consent, disables Google Signals and advertising personalization, and does not initialize Google Analytics when a browser sends Global Privacy Control or a Do Not Track value of1. The approved Google Analytics stream must keep unreviewed Enhanced Measurement and advertising features disabled.

Hosting and server systems may process technical request data such as IP address, request time, user agent, response status, and diagnostic logs. The Pegasus website stores only the selected color-theme preference in browser-local storage so the Light, Dark, or System choice persists on this site. GAIA Civil keeps its theme preference separately on its own domain. The hosting or edge provider may set an operational cookie such as Cloudflare's __cf_bm for bot-management purposes; that is provider infrastructure, not an application or marketing cookie set by Pegasus.

How contact information is used

When inquiry delivery is enabled, submitted contact information will be used to review and respond to the selected business inquiry, operate spam and rate-limit controls, and diagnose delivery failures. The website does not include a public chatbot or a project-file upload surface.

Website analytics is used to understand which sources and public pages lead to business interest, where the Contact path loses visitors, and which content merits improvement. Pegasus does not configure analytics for advertising audiences, session replay, user-provided identifiers, or automated decisions about a submitted inquiry.

Validated inquiries are sent through the canonical website's same-origin server function to the selected Zoho Flow and Zoho CRM path. The website reports success only after the delivery workflow returns its required acknowledgement.

Providers, subprocessors, and processing locations

The canonical website uses Firebase Hosting and a Firebase server function in the configured production region. Provider account settings and deployment region can affect operational logging, retention, and processing location.

Zoho Flow and Zoho CRM are the selected contact-delivery workflow and destination. Accepted inquiries are routed to the business records used for review and response; provider settings govern access, retention, processing region, and operational logs.

Google processes website analytics for Pegasus under the approved Google Analytics account and applicable terms. Processing locations, subprocessors, data-sharing settings, account access, two-factor authentication, retention, deletion, and any cross-border transfer terms remain part of the production approval record. The repository disables advertising signals in code; the account must also be verified to have no unapproved Google Ads link, audience, user-provided-data collection, or Enhanced Measurement feature.

Provider agreements and account settings govern relevant subprocessors, retention practices, and any applicable cross-border processing.

Retention and deletion

Contact-request and diagnostic-log retention must follow the approved production provider settings, deletion process, and legal or operational exceptions. Those controls remain subject to final production review.

Website analytics is retained under the approved Google Analytics property settings. Retention, deletion handling, and dashboard access are limited to the reviewed account configuration and approved users.

Security and data-handling boundaries

The repository configures transport and browser security headers and keeps delivery credentials out of the browser bundle. Final header behavior remains subject to verification on each deployed host and has not been approved as a production control. This policy does not claim a certification, audit result, encryption specification, access-control model, tenant-isolation design, or model-training policy that has not been verified against the production environment.

Project or proprietary data provided during a client engagement must be governed by the approved agreement and implementation controls for that engagement, not by assumptions made from this public website.

Your questions and requests

Pegasus has not published a dedicated privacy inbox. Use the Contact form and choose "General inquiry" for a privacy question or request.

View contact options

Policy changes

Pegasus may revise this policy when the website’s actual data collection, providers, retention, or contact process changes. The effective date will be updated only for a substantive revision.