Updated 7 August 2026

Privacy Policy

This describes what this website actually does today, not what a template says a website might do. When that changes, this page changes with it.

Who we are

Bowers Business Solutions is a software auditing consultancy based in Devine, Texas, United States. This policy covers this website only. Work we do inside a client’s own systems is governed by the written agreement for that engagement, not by this page.

What this site collects

Reading the site collects nothing about you. There is no analytics, no tracking pixel, and no third-party script anywhere on it. Typefaces are served from our own domain, so viewing a page does not send a request to Google Fonts or any other outside host. Browsing the public site sets no cookies; the only cookies that exist at all belong to the administration sign-in, described below.

Two things you can choose to do send us data: downloading a white paper or case study, and submitting the contact form. Both are described in full below, and neither happens unless you act.

Resource downloads

When you download a white paper or case study from the resources page, we record that the download happened. Every personal detail in that step is optional — there is a “Just download” button beside the form, and the file you get is identical either way. We record:

  • which resource was downloaded, and the date and time
  • your email address, name, and company — only if you typed them; otherwise these are stored empty
  • whether you asked to hear about future publications
  • the IP address the request came from, and your browser's user-agent string

The IP address and user-agent are recorded for every download, including when you skip the form. They are there to tell genuine interest apart from automated traffic and to investigate abuse. They are not used to identify you, and they are not combined with anything else. We recognise that an IP address can be personal data, which is why it is named here rather than buried.

If you give an email address, we use it for one thing immediately: a confirmation message repeating the download link. That message is a receipt, not marketing. If you also ticked the box asking to hear about new publications, that preference is stored — but no newsletter exists yet, so nothing is sent to you beyond the receipt. When one exists, only people who ticked that box will be contacted, and every message will carry a way to stop.

The PDFs themselves sit on public storage. Anyone with the link can fetch a file without going through the download step, which also means a shared link is not recorded here.

Cookies

The public pages of this site set no cookies. The site has a private administration area, and signing in to it sets strictly necessary cookies: a session cookie that keeps the administrator signed in, and short-lived security cookies that protect the sign-in form against cross-site request forgery. These cookies exist only on the browser of the person who signs in — in practice, us — and are never set by simply reading this website. They contain no advertising or analytics identifiers and are not used to track anyone.

The contact form

The contact form asks for your name, an email address, an optional company name, which of our services you are after, and a description of the codebase. Name, email, service, and description are required, because an enquiry we cannot read or reply to is not an enquiry.

When you submit it, two emails are sent through Resend, our email provider: your submission goes to our own company inbox, and a short confirmation goes to the address you gave, so you have proof it arrived. Both are transactional. You are not added to any list, and no marketing follows.

Nothing from the form is stored in a database. There is no contact table and no record of your submission on this website. The email in our inbox is the only copy, and it stays there for as long as the conversation is useful, in the same way any business email does. The reply-to address on it is yours, so replying to you is what our inbox does by default.

If the email to us fails to send, the form tells you so and asks you to try again. It will not show you a confirmation for a message that went nowhere.

Server logs

The site runs on infrastructure operated by a hosting provider, which may record standard request logs as part of keeping the service running and defending it from abuse. Those logs typically contain:

  • the IP address the request came from
  • the browser user-agent string
  • the URL requested, and the time of the request

We do not use these logs to build a profile of you, and we do not combine them with anything else.

Stopping abuse

Signing in, downloading a resource, and sending the contact form are all rate limited, so nobody can guess at passwords or flood our inbox by repeating a request thousands of times. To count requests we have to know which ones came from the same place, so a short-lived counter keyed on the IP address — and, for sign-in attempts, on the email address typed into the form — is kept in a Redis database operated by Upstash.

These counters expire on their own within fifteen minutes. Nothing else about the request is stored with them, they are never used to identify you or linked to your download or enquiry, and there is no permanent record of them once the window has passed.

Who processes it, and where

Download records are stored in this site’s own database, hosted by Neon. Every email this site sends — the download confirmation, your contact-form receipt, and the copy of your enquiry that reaches us — goes through Resend, which therefore handles the addresses and the text of those messages. The short-lived rate-limiting counters described above sit with Upstash. The site itself runs on infrastructure operated by a hosting provider. Those four, plus the storage provider holding the PDFs, are the only third parties involved, and each acts on our instructions rather than for its own purposes.

How long we keep it

Download records are kept while they are useful for understanding which resources people actually read — there is no fixed expiry today, and saying otherwise would be a promise no code enforces. If you ask us to delete yours, we delete the record rather than anonymising it.

Contact-form submissions are not in that database at all. They exist as email in our inbox, and are kept as long as the conversation warrants.

Sharing and selling

We do not sell personal data, we do not share it for advertising, and we have no data-broker relationships. Nothing collected on this site is passed to anyone beyond the processors named above.

Your rights

Depending on where you live, you may have the right to ask what personal data an organisation holds about you, to have it corrected, or to have it deleted. If you gave an email address on a download, the simplest route is to reply to the confirmation message you received — that reply reaches us and identifies the record. Otherwise, use the contact form, which reaches the same inbox, or message us on LinkedIn. Say what you want deleted; you do not have to explain why.

If you skipped the download form entirely, the record holds no name or address, so there is nothing we could match a request against beyond an IP address. Tell us the resource and roughly when, and we will delete what we can identify.

Children

This site is aimed at businesses and is not directed at children. We do not knowingly collect personal data from anyone under 13.

Changes

Material changes will be reflected in the updated date at the top of this page. Adding a feature that collects data means updating this page in the same change, not afterwards.