What we never do
The short version, first, because it is the part people actually want to know.
We never sell your data. Not to advertisers, not to data brokers, not to anyone.
We never share your customer or lead data with third parties for their own marketing.
We never put third-party advertising or tracking pixels on your site unless you ask us to.
We never train models on your customers’ personal information.
We never hold your domain hostage. It is yours, and we will point it anywhere you say.
We never lock your content in. Ask and we export it, whether you are staying or leaving.
What we collect
Three buckets, and nothing outside them.
Your account
Business name, your name, email, phone number, and billing details held by our payment processor. This is what we need to bill you and reach you.
Your site content
Copy, photos, service lists, hours and everything else that appears on your site, plus the change requests you send us. It stays yours.
Your site’s visitors
Privacy-friendly analytics with no cross-site tracking and no advertising cookies, plus whatever your contact form collects — which goes to you, not to us.
Who else touches it
Every third party involved in running your site, what they do, and what they see. We update this list when it changes.
| Provider | What it does | What it sees |
|---|---|---|
| Cloudflare | Hosting, CDN and SSL for customer sites | Site content, visitor IP addresses in transit |
| Vercel | Hosting for hicurb.com and the customer portal | Request logs |
| Railway | Application database and background workers | Account, site content and support requests |
| Stripe | Payments and subscription billing | Name, email, billing details. Card numbers never touch our servers. |
| Anthropic | Content generation and support triage | Site content and support message text. Not used to train models. |
| Google Analytics | Traffic measurement on hicurb.com | Anonymous usage data on this marketing site |
| Print and mail provider | Physical mail we send to prospective customers | Business name and mailing address only |
How we keep it safe
Your site is static
Customer sites are built ahead of time and served as files from a CDN. There is no database behind your homepage and no application to exploit — which is why a Curb site does not get hacked the way a plugin-based site does.
Encrypted everywhere
Every site we run is served over HTTPS with a certificate we issue and renew automatically. Data in transit is encrypted; data at rest in our database is encrypted by the provider.
Access is narrow
We are a small team, and the number of people who can reach production is smaller still. Access requires multi-factor authentication and is reviewed whenever the team changes.
Backups and recovery
Your content is versioned. Every publish is a new version, and rolling a site back to a previous one takes minutes, not a restore ticket.
No plugins to patch
The most common way a small business site gets compromised is an out-of-date plugin. We do not use them. There is nothing on your site for you to keep updated.
Accessibility, checked at launch
Every site must pass an automated accessibility scan with zero violations, keyboard navigation, and contrast checks before it goes live. We describe this as targeting WCAG 2.2 AA — we do not claim legal compliance, because no vendor honestly can.
AI, specifically
We are an AI-native company, which makes this the question we get asked most.
What AI does here
It audits sites, drafts and edits content, reviews screenshots for defects, and triages support messages. It does the work that used to take an agency two weeks.
What it doesn’t do
It does not get your customers’ personal information. It does not train on your data — our model provider’s API does not use submitted content for training. And it never handles a cancellation or a complaint: a person does that, every time.
Your rights
Export
Ask and we send you your content and your site files. No fee, no notice period, and no conversation about why.
Deletion
Ask us to delete your data and we do, within 30 days, except records we are required to keep for tax and accounting purposes.
Reporting a security issue
If you have found a vulnerability in a site we run or in our own systems, email security@hicurb.com. We will acknowledge within one business day and keep you updated until it is closed. We will not pursue legal action against anyone reporting in good faith who does not access or alter other people’s data.
See your site before you decide
We build your new homepage first, free. Look at the real thing, then decide.