Privacy Policy
This Privacy Policy describes how Pieter Inc., a Delaware corporation doing business as Pieter Studio ("Pieter Studio," "we," "us," or "our"), collects, uses, and shares information when you visit pieterstudio.com (the "Site"). Our principal address is 447 Sutter St, Ste 405, San Francisco, CA 94108. The "Last Updated" date above changes each time we revise this Policy; the posted version is the version in effect.
This Policy covers the public Site only. The member portal and member services are governed by the Master Services Agreement and its Data Processing Addendum, which control for members where they apply.
The short version: the Site uses no cookies, no third-party advertising or analytics networks, and sells no personal information. We run our own privacy-conscious, first-party measurement, we honor Global Privacy Control and Do Not Track by not measuring you at all, and we keep what we collect brief and mostly aggregated.
1Definitions
In this Policy:
- (a) "Personal Information" means information that identifies, relates to, or could reasonably be linked with a particular individual or household. It does not include aggregated or deidentified information.
- (b) "Processing" means any operation performed on information, including collection, use, storage, disclosure, and deletion.
- (c) "Service Provider" (or "processor") means an entity that processes information on our behalf and under our instructions.
- (d) "Aggregated Data" means information combined across users so that no individual can be identified.
- (e) "Deidentified Data" means information that cannot reasonably be used to infer or be linked with a particular individual. We maintain and use such data without attempting to reidentify it.
- (f) "Device Identifier" means the salted, truncated cryptographic hash we derive from a browser fingerprint, as described in Section 2. We never store the raw fingerprint.
- (g) "Site" means pieterstudio.com. "GPC" means Global Privacy Control. "DNT" means Do Not Track.
2Information We Collect
We collect the following categories of information when you use the Site.
2.1Information You Provide
If you email us at membership@pieterstudio.com or hello@pieterstudio.com, we receive your email address, your name if you include it, and the contents of your message, including any application materials you choose to send. The Site's forms do not transmit form contents to us: the Access page's sign-in fields are submitted only to the separate member portal, and our measurement never captures anything you type (see Section 2.2).
2.2Information Collected Automatically (First-Party Analytics)
We operate our own analytics. No third-party analytics or advertising service runs on the Site. If your browser sends a Global Privacy Control or Do Not Track signal, this measurement never starts. Otherwise, we collect:
- (a) a random session identifier, stored in your browser's sessionStorage and discarded when your browsing session ends;
- (b) a device signature: a browser fingerprint computed in your browser by the open-source ThumbmarkJS library, which our server immediately converts to a salted, truncated cryptographic hash. The raw fingerprint is never stored. The hash lets us count returning devices without cookies and support the security functions in Section 2.3;
- (c) device and browser information: screen and viewport size, pixel ratio, browser family and version, operating system, device class, language, timezone, connection type, and dark-mode preference;
- (d) usage information: pages viewed, time on page, referring page, UTM campaign parameters, scroll depth, aggregated click and cursor-position grids (heatmaps), clicks on links and buttons, hover times, outbound-link destinations, file-download names, the length (never the content) of text you copy or select, page-performance metrics, and JavaScript errors;
- (e) form interaction metadata: which form fields you focus and for how long, and whether a form was submitted or abandoned. We record field names and timings only. Our code structurally excludes password fields, hidden fields, and payment-related fields, and never records what you type into any field; and
- (f) approximate location: your country, region, and city, derived by our content-delivery network from your IP address. Our analytics systems do not store your IP address.
2.3Security Information
To protect the Site against bots, fraud, and abuse, our security service receives the device signature described above along with coarse signals (browser family, operating system, timezone, language, screen size, automation indicators such as headless-browser flags) and simple behavior counters (page count, interaction count, hidden "honeypot" trap-field activity, form timing). From these we compute an anonymous risk score. Your IP address is used transiently to build a salted hash for rate and reputation purposes and is not stored in raw form.
2.4Local Storage (No Cookies)
The Site sets no cookies. It uses browser storage for a small number of first-party items: a session identifier (sessionStorage), a returning-visitor flag, your light/dark theme preference, and a 24-hour cache of your city name for the clock display. You can clear these at any time through your browser settings without breaking the Site.
2.5IP-Based City Lookup (Third Party)
To show your city in the Site's navigation clock, your browser requests your approximate city directly from ipapi.co, a third-party geolocation service, which necessarily receives your IP address to answer. We receive only the resulting city label, which is cached in your browser for 24 hours. ipapi.co's own privacy policy governs its processing.
2.6Third-Party Fonts
Some pages load fallback fonts from Google Fonts (fonts.googleapis.com and fonts.gstatic.com). When your browser fetches them, Google receives your IP address and browser information under Google's privacy policy. Our primary brand fonts are self-hosted and involve no third party.
3What We Do Not Collect
We do not collect: precise geolocation; the contents of any form field; keystrokes; payment card information (the Site processes no payments); biometric information; or information from data brokers. We do not use third-party advertising, social-media pixels, or cross-site tracking of any kind.
4Data Minimization and Privacy by Design
Pieter Studio is designed around the principle of collecting the minimum amount of information reasonably necessary to operate, secure, and improve the Site. Privacy protections are built into the Site by default, not added afterward:
- (a) the Site sets no cookies;
- (b) our analytics are first-party and never leave our own infrastructure for an advertising or analytics network;
- (c) we run no third-party advertising or social-media pixels;
- (d) we do not sell or share personal information;
- (e) we honor GPC and DNT by not measuring you at all;
- (f) we hash device and network identifiers rather than store them raw, and we automatically expire the data we keep; and
- (g) password, hidden, and payment fields are structurally excluded from measurement at the code level.
5How We Use Information
We use the information above to:
- (a) operate, secure, and improve the Site, including understanding which pages and features are used and how the Site performs;
- (b) detect and prevent bots, fraud, abuse, and security threats, including scoring the risk that a device is automated;
- (c) respond to your inquiries and evaluate membership applications;
- (d) comply with legal obligations and enforce our Terms of Service; and
- (e) produce aggregated, non-identifying statistics.
We use the least identifying form of information that will accomplish each purpose, and we rely on aggregated or deidentified data wherever it is sufficient.
6Legal Bases
Where a law requires a legal basis for processing, we rely on: our legitimate interests in operating, measuring, and securing the Site (Sections 2.2 through 2.6); performance of steps you request before entering an agreement (membership inquiries); and compliance with legal obligations. The Site is not directed to the European Economic Area or the United Kingdom, and access from outside the United States, Canada, and Mexico is generally blocked at our network edge. A summary of purposes, categories, and legal bases appears in Appendix A.
8Data Retention
We keep information only as long as needed for the purposes above: raw analytics events, 90 days; aggregated daily analytics summaries, 24 months; aggregated heatmap data, 12 months; security event records, 30 days; device and network reputation records, 90 days; email correspondence and application materials, as long as needed to handle your inquiry and meet legal requirements; and the local city-name cache in your browser, 24 hours. Aggregated statistics that identify no one may be kept indefinitely.
9Security
We use commercially reasonable administrative, technical, and organizational safeguards designed to protect information, including:
- (a) encryption in transit (HTTPS everywhere) and encryption at rest for stored data;
- (b) least-privilege access controls and periodic access review;
- (c) audit logging and infrastructure monitoring;
- (d) managed secret storage and key rotation;
- (e) a web application firewall with rate limiting and geographic controls;
- (f) salted hashing of device and network identifiers;
- (g) closed-schema validation of everything our collection endpoints accept;
- (h) vulnerability management and patching of our infrastructure; and
- (i) automatic expiry and routine backup of stored data.
No system is perfectly secure, and we cannot guarantee absolute security.
9.1Incident Response
If we become aware of unauthorized access that affects personal information, we will investigate promptly, take reasonable steps to contain and mitigate the issue, and provide notifications to affected individuals and to regulators where required by applicable law.
10Automated Decision-Making and AI
Our security systems automatically score the risk that a device is a bot or is engaged in abuse, using the signals in Section 2.3. A high score can restrict access to sensitive actions in the member portal or trigger rate limiting. These systems use fixed, rule-based scoring; they are advisory, fail open (errors default to allowing access), and do not produce legal effects without the possibility of human review. To contest a restriction, contact privacy@pieterstudio.com.
10.1Artificial Intelligence
We do not use Site visitor information to train artificial-intelligence models. Specifically, we do not train public or foundation models on your information; we do not sell your information for AI training; and we do not share your information with third-party foundation-model providers. The first-party analytics and security systems described in this Policy do not use machine-learning models trained on your data. AI-related data practices for member services (the member portal and Platform) are governed by the Member Agreements and their Data Processing Addendum, not this Policy.
11Your Choices and Rights
11.1Universal Opt-Out Signals
We honor Global Privacy Control (GPC) and Do Not Track (DNT). If your browser sends either signal, our analytics does not run at all, and our servers additionally discard any GPC-flagged submissions. This is our supported opt-out mechanism and requires no account or request.
11.2Access, Deletion, and Correction
You may request access to, deletion of, or correction of personal information we hold by emailing privacy@pieterstudio.com. Note an honest limitation: our analytics and security records are keyed to pseudonymous hashed identifiers, not to names or contact details, so in most cases we cannot link those records to you and therefore cannot retrieve or delete them for a specific person, as permitted by applicable law. Email correspondence and application materials can be retrieved, corrected, and deleted on request, subject to legal retention needs.
11.3Marketing
We send marketing email only if you have asked to hear from us, and any such email will include an unsubscribe mechanism. Transactional and relationship messages (for example, replies to your inquiry) are not marketing.
12State Privacy Rights (Including California)
Depending on your state of residence, you may have rights under state privacy laws, including the California Consumer Privacy Act as amended by the CPRA, such as the rights to know, access, correct, delete, and to opt out of sale or sharing, along with the right not to be discriminated against for exercising them. Whether or not a given statute applies to us at our current size, we voluntarily extend the rights in Section 11 to all United States residents.
For California residents: the categories of personal information we collect are identifiers (pseudonymous session and hashed device identifiers, and email address if you write to us), internet or other electronic network activity information, coarse (non-precise) geolocation, and inferences limited to security risk scores; the sources, purposes, and recipients are described in Sections 2, 5, and 7; we do not sell or share personal information as those terms are defined in the CCPA; and we honor GPC as an opt-out preference signal. You may submit requests via privacy@pieterstudio.com, and you may use an authorized agent as permitted by law. We will verify requests to the extent verification is possible given the pseudonymous nature of our data.
13Cross-Border and U.S. Processing
The Site is operated from the United States, and all information is stored and processed in the United States on cloud infrastructure operated by our service providers. Access to the Site is generally limited to the United States, Canada, and Mexico, and access from outside those countries is generally blocked at our network edge.
If you access the Site from Canada or Mexico, you understand and agree that your information is transferred to and processed in the United States under this Policy. The Site is not directed to the European Economic Area, the United Kingdom, or Switzerland. Where an international transfer mechanism is ever required for a specific processing activity, we will implement an appropriate safeguard (such as standard contractual clauses) before that transfer occurs.
14Government and Law Enforcement Requests
We may receive requests from government agencies, courts, or other parties for information. We review every request for legal validity and appropriate scope before responding, we disclose only the information we are legally required to disclose, and we object to requests that are overbroad or improper.
We may preserve information when reasonably necessary to investigate abuse, to protect our legal rights or the rights and safety of others, or to comply with a valid preservation request. Where we are legally permitted to do so, we will endeavor to notify affected individuals of a request for their information.
15Children's Privacy
The Site is a business site for real estate professionals and is not directed to children. We do not knowingly collect personal information from anyone under 18. If you believe a child has provided us personal information, contact privacy@pieterstudio.com and we will delete it.
16Business Transfers
If Pieter Studio is involved in a merger, acquisition, financing, reorganization, or sale of assets, personal information may be transferred as part of that transaction. This Policy will continue to apply to your information until the successor entity provides updated terms, and where required by applicable law we will notify you of any material change resulting from the transaction.
17Changes to This Policy
We may update this Policy from time to time. We will post the updated version with a new Last Updated date, and material changes will be indicated on the Site. For material changes, we will provide notice on the Site at least 15 days before the change takes effect where practicable. Your continued use of the Site after the Last Updated date constitutes acceptance of the updated Policy. Prior versions are summarized in Appendix C.
18Accessibility
If you need this Policy in an alternative format, contact privacy@pieterstudio.com and we will work with you to provide it.
19Contact Us
Privacy questions or requests: privacy@pieterstudio.com. General: hello@pieterstudio.com. Mail: Pieter Inc. d/b/a Pieter Studio, Attn: Privacy, 447 Sutter St, Ste 405, San Francisco, CA 94108.
AData Processing Summary
The following table summarizes the main categories of information, why we process them, the legal basis, how long we keep them, and who they are shared with.
| Information | Purpose | Legal Basis | Retention | Shared With |
|---|---|---|---|---|
| Email and message | Respond to inquiry; evaluate application | Legitimate interest; pre-contract steps | Until resolved + legal needs | Google Cloud |
| Session identifier | First-party analytics | Legitimate interest | Session (sessionStorage) | None |
| Device Identifier (hash) | Returning-device counting; fraud prevention | Legitimate interest | 90 days | Google Cloud |
| Device and browser info | Analytics; performance | Legitimate interest | 90 days raw / 24 mo aggregated | Google Cloud |
| Usage and heatmap data | Understand and improve the Site | Legitimate interest | 90 days raw / 12-24 mo aggregated | Google Cloud |
| Form interaction metadata | Improve forms (names/timings only) | Legitimate interest | 90 days | Google Cloud |
| Approximate location (geo) | Localize content; analytics | Legitimate interest | With the related event | Google Cloud |
| Security signals and risk score | Detect and prevent abuse | Legitimate interest; legal obligation | 30-90 days | Google Cloud |
BService Providers
The third parties that process information for the Site, and where they operate.
| Provider | Purpose | Location |
|---|---|---|
| Google LLC (Google Cloud Platform) | Hosting, CDN, serverless compute, data warehousing | United States |
| Google Fonts | Fallback web-font delivery | United States |
| ipapi.co | IP-based city lookup (requested by your browser) | United States |
CVersion History
Prior and current versions of this Policy.
| Version | Date | Summary |
|---|---|---|
| 1.00 | July 28, 2026 | Initial publication. |