Trust Center

How we handle your data

We run websites for small businesses. That means we hold your content, your leads, and your billing details — so here is exactly what we do with them, who else touches them, and what we will never do.

Last updated August 21, 2026

What we never do

The short version, first, because it is the part people actually want to know.

We never sell your data. Not to advertisers, not to data brokers, not to anyone.

We never share your customer or lead data with third parties for their own marketing.

We never put third-party advertising or tracking pixels on your site unless you ask us to.

We never train models on your customers’ personal information.

We never hold your domain hostage. It is yours, and we will point it anywhere you say.

We never lock your content in. Ask and we export it, whether you are staying or leaving.

What we collect

Three buckets, and nothing outside them.

Your account

Business name, your name, email, phone number, and billing details held by our payment processor. This is what we need to bill you and reach you.

Your site content

Copy, photos, service lists, hours and everything else that appears on your site, plus the change requests you send us. It stays yours.

Your site’s visitors

Privacy-friendly analytics with no cross-site tracking and no advertising cookies, plus whatever your contact form collects — which goes to you, not to us.

Who else touches it

Every third party involved in running your site, what they do, and what they see. We update this list when it changes.

ProviderWhat it doesWhat it sees
CloudflareHosting, CDN and SSL for customer sitesSite content, visitor IP addresses in transit
VercelHosting for hicurb.com and the customer portalRequest logs
RailwayApplication database and background workersAccount, site content and support requests
StripePayments and subscription billingName, email, billing details. Card numbers never touch our servers.
AnthropicContent generation and support triageSite content and support message text. Not used to train models.
Google AnalyticsTraffic measurement on hicurb.comAnonymous usage data on this marketing site
Print and mail providerPhysical mail we send to prospective customersBusiness name and mailing address only

How we keep it safe

Your site is static

Customer sites are built ahead of time and served as files from a CDN. There is no database behind your homepage and no application to exploit — which is why a Curb site does not get hacked the way a plugin-based site does.

Encrypted everywhere

Every site we run is served over HTTPS with a certificate we issue and renew automatically. Data in transit is encrypted; data at rest in our database is encrypted by the provider.

Access is narrow

We are a small team, and the number of people who can reach production is smaller still. Access requires multi-factor authentication and is reviewed whenever the team changes.

Backups and recovery

Your content is versioned. Every publish is a new version, and rolling a site back to a previous one takes minutes, not a restore ticket.

No plugins to patch

The most common way a small business site gets compromised is an out-of-date plugin. We do not use them. There is nothing on your site for you to keep updated.

Accessibility, checked at launch

Every site must pass an automated accessibility scan with zero violations, keyboard navigation, and contrast checks before it goes live. We describe this as targeting WCAG 2.2 AA — we do not claim legal compliance, because no vendor honestly can.

AI, specifically

We are an AI-native company, which makes this the question we get asked most.

What AI does here

It audits sites, drafts and edits content, reviews screenshots for defects, and triages support messages. It does the work that used to take an agency two weeks.

What it doesn’t do

It does not get your customers’ personal information. It does not train on your data — our model provider’s API does not use submitted content for training. And it never handles a cancellation or a complaint: a person does that, every time.

Your rights

Export

Ask and we send you your content and your site files. No fee, no notice period, and no conversation about why.

Deletion

Ask us to delete your data and we do, within 30 days, except records we are required to keep for tax and accounting purposes.

Reporting a security issue

If you have found a vulnerability in a site we run or in our own systems, email security@hicurb.com. We will acknowledge within one business day and keep you updated until it is closed. We will not pursue legal action against anyone reporting in good faith who does not access or alter other people’s data.

See your site before you decide

We build your new homepage first, free. Look at the real thing, then decide.