LEGAL
Privacy Policy
LAST UPDATED: 2026-07-20
THIS POLICY HAS NOT YET BEEN REVIEWED BY AN ATTORNEY. IT DESCRIBES CURRENT PRACTICE ACCURATELY BUT SHOULD NOT BE TREATED AS FINAL LEGAL LANGUAGE UNTIL COUNSEL REVIEW IS COMPLETE.
What this policy covers
This policy covers the Sovereign-Minds website and its connected agent sites (Augur, Mercury, Aion, and Vulcan), operated by Sovereign-Minds ("we"). It explains what information is collected when you use these sites, why, and what your choices are.
Data we collect
- Contact form submissions. Name, email address, and the details you choose to share (business or project name, service interest, and your message). Submitting the form requires your explicit consent checkbox.
- Abuse-prevention signals. The contact endpoint records a salted, truncated hash of your IP address for rate limiting and abuse forensics. Raw IP addresses are not stored with your submission.
- Server logs. Our hosting provider (Vercel) generates standard request logs used for operating and securing the sites.
- First-party usage events. We record a small, fixed set of named events (for example: a page was viewed, a call-to-action was clicked, a form was started, a form submission succeeded or failed) together with the page path. Where you arrived from another website, we also record that website's domain name only — for example
example.com— never the full address you came from, which could contain a search query or a session token. These events use no cookies, carry no identifier, and are not linked to you. - Campaign tags. If you arrive through a link we published that carries campaign tags (
utm_sourceand similar), those short tags are recorded so we can tell which of our own posts brought you here.
What we do not collect
- No advertising trackers and no cross-site tracking cookies.
- No sale or rental of personal information to third parties.
- No collection of financial account details, passwords, or government identifiers through these sites.
Purpose of collection
Form submissions are used to evaluate your request, respond to you, and — if you become a client — carry your project through intake, scoping, and delivery. Abuse-prevention data is used only to keep the sites available and spam-free.
Cookies and analytics
These sites run no third-party analytics scripts, no advertising tags, and no cookies — essential or otherwise. Measurement is first-party and deliberately minimal: the site posts an event name from a fixed allowlist to our own endpoint, and the record is written to a database we control. The server rejects any event name or label that is not on that allowlist, which means form message contents, email addresses, financial details, strategy specifics, and query strings cannot be recorded through it even by mistake. Referring domains are likewise accepted only as a bare hostname; anything else is discarded before storage.
This is a deliberate trade. Hosted analytics products would tell us more, with less work, and we do not use one — knowing where our visitors come from is not worth loading someone else's script into your browser.
We honor the browser Do Not Track signal: if your browser sends it, no usage events are sent at all.
Third-party providers
- Vercel — site hosting and serverless form processing.
- n8n / Supabase — workflow automation and CRM storage for inquiries, on infrastructure we control.
Data retention
Inquiry records are retained while the conversation or engagement is active, and for up to 24 months after last contact so we can respond to follow-ups, unless you request earlier deletion.
Your choices and deletion requests
You can request a copy of the information we hold about you, or ask us to delete it, by contacting us through the intake form and stating your request. Deletion requests are honored within 30 days unless we are legally required to retain the record.
Security practices
Form submissions are validated and sanitized server-side, transmitted over HTTPS, rate limited, and stored on access-controlled infrastructure. Secrets are held in environment variables, never in client code. See the Data Policy for how client engagement data is handled.
Changes to this policy
Material changes will be posted on this page with an updated date. Continued use of the sites after a change constitutes acceptance of the revised policy.
Contact
Questions about this policy: use the contact form on the main site.