Privacy Policy
Last updated: August 9, 2026
This policy explains what information Hub City Web collects, who else can see it, and how to get it deleted. It covers hubcityweb.com and the work done for clients.
It's written in plain English on purpose. If something here is unclear, email contact@hubcityweb.com and ask. Where there's a gap, this policy says so instead of dressing it up.
The short version
- No accounts, no logins, no passwords on hubcityweb.com.
- No analytics scripts and no tracking pixels on the site. I checked the source myself.
- Card numbers are handled by Stripe. I never see them and never store them.
- Your information isn't sold, rented, or handed to advertisers. There are no advertisers.
- Want your information deleted? Email contact@hubcityweb.com and ask.
Who this policy is from
Hub City Web is a one-person web business in Lubbock, Texas, owned and operated by Oscar Napoles. There are no employees. Some work is done with an independent contractor, and this policy says where.
Legal entity: Hub City Web is a trade name used by NapCarr LLC. The assumed-name certificate for “Hub City Web” is not yet on file, so NapCarr LLC is the contracting party for everything on this page.
Email: contact@hubcityweb.com
What I collect
Contact form. If you fill out the form on hubcityweb.com, I get whatever you type into it — usually your name, email address, business name, and message. Submissions go through Netlify Forms and land in my email inbox.
Email. If you email me, I have your email. The message, your address, and any attachments sit in my inbox on Google Workspace.
Booking. The "Book a consult" button opens Calendly. When you book, Calendly collects your name, email, the time you picked, and anything you type into the booking form, then passes it to me. Calendly is a separate company with its own privacy policy.
Payments. Payments run through Stripe — the $149 one-page starter site, the $249 Full Build, the $100 build deposit, and monthly service billing. You enter your card details on Stripe, not on my site. I never see or store your card number. What I can see in my Stripe dashboard is the ordinary stuff: your name, email, the amount, the date, whether it went through, and the last four digits of the card.
Whatever you send me during a project. Logos, photos, menus, copy, hours, service lists — whatever you hand over so I can build the thing.
One more, added when the intake form launched: when you submit the contact form it records the page you came from, so I know which post or page sent you. That is the only tracking on this site, it lives inside your own submission, and it happens only when you press Send.
What I do NOT collect
- No user accounts. There's nothing to sign up for on hubcityweb.com. No profiles, no dashboards.
- No passwords. The site has no login, so there's no password of yours for me to store or lose.
- No analytics scripts. As of the date at the top of this policy there's no Google Analytics, no Meta pixel, no heatmap tool, and no visitor-tracking script anywhere in the site's files — I checked. Netlify, as the host, handles standard server request data the way any web host does, and I have not turned on their analytics product. If I ever do, this policy changes before it goes live.
- No ad trackers, no retargeting, no data brokers. I don't sell your information. I don't trade it. I don't build profiles on visitors.
If that changes — for example if I install analytics, or when the planned AI chat widget goes live — this policy gets updated and the date at the top changes before the thing is turned on. Today that widget is an empty placeholder in the page and does nothing.
Cookies and browser storage
hubcityweb.com is a static site. It doesn't set advertising cookies.
The site stores exactly three small things in your own browser:
hcw_themein local storage — whether you picked light or dark, so the site looks the way you left it.hcw_seenin session storage — a single yes/no marker so the intro animation doesn't replay on every page during one visit.hcw_bubin session storage — whether you dismissed the floating “Book / Free Quote” button, so it stays hidden for the rest of your visit.
The site's own code reads those two values so it can remember your theme and skip the intro. Nothing is sent to me and I never see them. Clearing your browser data wipes them.
Third-party code is a different story. Loading a page on hubcityweb.com means your browser talks to these companies, and each of them sees your IP address and browser details when it does:
- jsDelivr — a content delivery network that serves the animation library the site uses. Its code runs in your browser on every page.
- Google Fonts (fonts.googleapis.com and fonts.gstatic.com) — the typefaces, on every page.
- Netlify — the host, and its edge network serves the site's own files.
- Calendly — nothing from Calendly loads until you click the booking button. When you do, Calendly's widget code loads into the page and can set its own cookies or storage from that point on. What you enter goes to them and then to me, under their privacy policy.
What those companies do with that is governed by their policies, not mine. I don't receive that data.
Who else touches your data
Running even a small business means using other companies' tools. Here's the honest list of who can technically see information connected to you.
| Company | What it does | What it can see |
|---|---|---|
| Netlify | Hosts hubcityweb.com, serves the files, runs the contact form | Contact form submissions; standard server request data |
| Google Workspace | My email | Any email between us, and form submissions once they arrive |
| Stripe | Payments | Card details you enter, your name, email, amount, billing and shipping address |
| jsDelivr | Serves the animation library | Your IP address and browser, on every page load |
| Google Fonts | Serves typefaces | Your IP address and browser, on every page load |
| Calendly | Booking | Your IP and browser once you click the booking button, plus whatever you enter when you book |
| Cloudflare | DNS for hubcityweb.com | Domain routing; standard network data |
| An independent contractor | The private AI service only | See the next section |
These are ordinary, widely used vendors. Each has its own privacy policy and its own security staff — which is more than I can say for myself. I haven't audited any of them.
Client data and the private AI service
This is the section that matters most, so it gets the most direct language.
The monthly private AI service would index your business documents — PDFs, SOPs, contracts, invoices — so you can ask questions against your own material.
Here's what's honest to say about it today:
- No client has been onboarded to this service yet. What follows describes the design I intend to build, not a system I have run. If you buy it, you're first, and you should hear that from me rather than find out later.
- The design commitment is that your documents stay on infrastructure you control, and are never copied into a Hub City Web system or into a shared system with other clients. Before you pay anything, your written scope will state exactly where your documents live, who can reach them, and whether any copy exists outside your own infrastructure. If the build can't deliver that, I'll tell you before you spend money.
- No training use of your documents is permitted. That will be a written requirement in your scope and in my agreement with the contractor, and the scope will name every model or API your documents touch so you can read its data-use terms yourself. I have not independently audited those vendors — I'm telling you what will be contractually required, not what I've personally verified.
- An independent contractor does the technical work. During setup, troubleshooting, and support, that contractor may have access to the system your documents are in. There's no way around that — someone has to have hands on the machine to make it work. You should know it isn't me. Clients whose contracts and invoices are being indexed have every right to know who can touch them, so ask and I'll tell you.
- No certifications and no verified security controls are claimed here. See the section below.
If your documents include health records, financial account data, or anything else legally sensitive, say so before we start. It may mean this isn't the right fit, and that's a fine answer.
Data about your customers
Some of the monthly work — contact-form routing, automated customer intake, Google Business Profile setup — means your customers' information passes through a site I built or manage.
In that arrangement, it's your data and your customers. You decide what gets collected and what it's used for. I set up the plumbing and can see what passes through it while doing the work. I don't use your customers' information for anything of my own, and I don't market to them.
Your business needs its own privacy policy covering what you do with that information. This policy doesn't cover your site or your customers.
Access to your accounts and passwords
Doing the work sometimes means getting into accounts you own — Shopify, Google Business Profile, your domain registrar, your hosting.
Use delegated access wherever the platform offers it. Shopify has staff and collaborator accounts. Google Business Profile lets you add a manager. Most registrars have delegated access or a sub-user. Those methods let you see exactly what I can reach and cut it off in one click when we're done. That's the right way to do it, and it protects both of us.
Please don't email me passwords. Email is a bad place to keep them. Once a password is in my inbox, it's also in Google's systems and in your sent folder indefinitely.
If a password genuinely has to be shared because a platform offers no other option, we'll agree on how before you send it, and you should change it once the work is finished. To be straight with you: I don't currently run a company password vault or a formal credential-management system. That's a gap, not a feature.
When a project ends, ask me to be removed from your accounts. If I forget and you catch it, tell me and I'll remove myself.
How long I keep things, and how to delete yours
Honest answer up front: there's no automatic deletion schedule in place yet. I'm not going to publish a retention period I'd need a reminder system to honor. If that changes, this section changes with it.
What happens today:
- Contact form submissions sit in the Netlify forms dashboard and in my email until I clear them out.
- Email stays in Google Workspace until deleted.
- Booking records stay in Calendly.
- Payment records stay in Stripe. Receipts, invoices, and payment records have to be kept for tax and accounting purposes — generally for several years — so those can't be deleted on request.
- Project files — logos, photos, copy, documents you sent — stay on my working machine and in the project's storage until the project is closed out and you ask for them to be removed.
To get your information deleted: email contact@hubcityweb.com, say what you want removed, and I'll delete what I control — inquiry emails, form submissions, booking records, and project files — except for payment and tax records I'm required to keep.
I'm one person. I'll do it as fast as I reasonably can and email you when it's done. I'm not going to promise a number of days I can't guarantee.
Security — only what's actually true
What I can honestly state:
- hubcityweb.com is served over HTTPS.
- Email runs on Google Workspace.
- Payments run through Stripe, and card numbers never touch my systems.
- The vendors listed above are established companies with their own security programs and published documentation.
What I'm not going to claim:
- I have not had a security audit or a penetration test.
- I do not have a formal written information-security program, 24/7 monitoring, or an incident-response contract.
- Beyond HTTPS on the site and whatever those vendors do on their end, I have not independently verified how any given piece of data is encrypted at rest. I'm not going to tell you it is when I haven't checked.
If data I hold is exposed and I find out about it, I'll tell the people affected. I'm not putting a guaranteed number of hours on that, because I have no monitoring system that could honor it.
If your industry requires documented security controls from vendors, tell me before we start. I'd rather lose the job than pretend.
No certifications and no compliance claims
To be completely clear, because this matters:
- Hub City Web is not HIPAA compliant and is not a HIPAA business associate. No Business Associate Agreement has been signed. Nothing in this setup — the contact form, my email, project storage, or the private AI service — is built for protected health information. If you're a medical, dental, therapy, or health-adjacent business, do not send patient information through the contact form, by email, or into any system I set up. There's no BAA and no infrastructure that supports it today.
- There is no SOC 2 report.
- There is no PCI certification. Stripe handles card data precisely so that I don't have to.
- There is no ISO certification, no GDPR certification, and no audit or accreditation of any kind.
Anyone at this size telling you otherwise is either confused or lying.
Children
These services are sold to businesses. hubcityweb.com isn't directed at children and isn't intended for anyone under 13. I don't knowingly collect information from children. If a child has sent me information through the site, email contact@hubcityweb.com and I'll delete it.
Texas and US law
Hub City Web operates in Lubbock, Texas, and serves clients in the United States. This policy is governed by the laws of the State of Texas and applicable United States federal law.
Texas has a consumer data privacy law, the Texas Data Privacy and Security Act. Whether it applies to a business this small is a lawyer's question, and I'm not one. It doesn't change what I'll do: ask what I have about you and I'll tell you; ask me to delete it and I will.
This isn't legal advice.
If you're in the EU or the UK
Hub City Web doesn't target or market to the EU or the UK, and this operation isn't built for GDPR. There's no data protection officer, no EU representative, no records of processing, and no certification. If you're in the EU or the UK and you've contacted me, email contact@hubcityweb.com and I'll delete what I have.
Changes to this policy
When something real changes — analytics get installed, the AI chat widget goes live, a new vendor gets added, retention periods get set — this policy gets updated and the date at the top changes. Existing clients get an email about anything that materially affects their data.
Questions
Email contact@hubcityweb.com. Ask anything — what I have, who can see it, or why something here is written the way it is. A plain question gets a plain answer.
Hub City Web — Lubbock, Texas