/ PRIVACY

MAXSONORO / DATA PRACTICES

Privacy
Policy

What information Maxsonoro collects, why it is used, who receives it, how disclosure happens, and how it is safeguarded.

EFFECTIVE / AUGUST 14, 2026

This policy covers maxsonoro.com, the Maxsonoro booking and upload workflows, project communications, and the personal information handled to provide Maxsonoro services.

01

Scope + operator

Maxsonoro ("Maxsonoro," "we," "us," or "our") provides audio engineering and production services from New York and remotely. This Privacy Policy explains our practices when you visit maxsonoro.com, send a project inquiry, request or pay for a booking, use the project portal, upload materials, receive a quote or invoice, communicate with us, or otherwise use our services. A third-party website or service linked from Maxsonoro is governed by that party's own privacy policy.

02

Information you provide

We collect information you choose to provide, including your name, email address, project or company name, requested service, preferred timing, booking date, package selection, project description, creative references, notes, feedback, communications, and other details in an inquiry or booking. If you upload project materials, we collect the audio files, documents, filenames, file types, file sizes, upload notes, and related project identifiers needed to receive and organize them.

03

Payment + transaction information

When you pay or receive an invoice, Maxsonoro receives limited transaction and business records such as your name, email, customer or checkout identifier, purchased service, currency, amount, payment status, invoice details, and transaction timestamps. Stripe collects and processes your full payment-card and billing information on its hosted systems. Maxsonoro does not receive or store your full payment-card number or card security code.

04

Information collected automatically

When you use the website, hosting and embedded-service providers may automatically receive technical information such as your IP address, browser and device type, operating system, referring page, requested URL, date and time, approximate location derived from IP, and security or error logs. Maxsonoro uses local browser storage to remember a language preference and temporary session storage to keep an in-progress booking brief on your device. Maxsonoro does not currently use advertising or cross-site behavioral-tracking cookies. Embedded services, such as Google Maps or Stripe, may use their own cookies or similar technologies under their policies.

05

How information is used

We use personal information to answer inquiries; prepare quotes; confirm identity and project access; schedule studio or remote work; create and administer bookings, checkout sessions, invoices, calendar events, upload folders, and delivery records; process and reconcile payments; send confirmations and service messages; receive, edit, store, and deliver project materials; provide support and revisions; prevent fraud and misuse; maintain and improve website reliability; protect clients, Maxsonoro, and our providers; keep financial and business records; enforce agreements; and comply with legal obligations.

06

Parties that receive information

We disclose information only as reasonably needed for the purposes above. Current service-provider categories and parties include Stripe for checkout, payments, invoices, and fraud prevention; Supabase for booking, project, invoice, access, and upload records; Google for Drive file storage, Calendar scheduling, and an embedded Maps view; Resend for transactional email; and Netlify for website hosting, security logs, and inquiry-form processing. These providers may process related technical or account data under their own contracts and privacy practices.

07

How disclosure happens

Provider disclosures are made electronically through encrypted HTTPS or TLS connections, secured application interfaces, controlled server-to-server requests, or a provider's hosted page. For example, the browser redirects to Stripe's hosted checkout; limited booking information is sent to Stripe to create a payment session; authorized uploads are transferred to a project folder in Google Drive; project records are written to Supabase; confirmations are sent through Resend; scheduling details are sent to Google Calendar; and inquiries are submitted through Netlify Forms. Maxsonoro may also share relevant information through a secure provider dashboard, project portal, or direct project email. We do not publicly disclose client files or personal information without permission.

08

Other permitted disclosures

We may disclose information when you direct or consent to it; to professional advisers who owe confidentiality duties; to investigate fraud, chargebacks, security incidents, infringement, or misuse; to protect rights, safety, property, clients, or services; to comply with a subpoena, court order, tax rule, or other lawful request; or as part of a proposed or completed financing, reorganization, merger, sale, or transfer of business assets. In a business transfer, the recipient may use information only as permitted by this policy unless it provides a new notice.

09

No sale of personal information

Maxsonoro does not sell or rent personal information and does not disclose personal information for cross-context behavioral advertising. We do not use client audio, project files, or private creative materials to train generative artificial-intelligence models. If these practices change, this policy will be updated before the new practice begins where required by law.

10

Security practices

Maxsonoro uses reasonable administrative, technical, and physical safeguards appropriate to the nature of the information. Practices include HTTPS encryption in transit; Stripe-hosted payment collection so full card details do not pass through Maxsonoro systems; server-side storage of private service credentials; access controls for booking, invoice, and upload records; database rules that block direct public access to private records; private project and upload codes; provider authentication and restricted dashboards; limiting access to people and providers who need it for the workflow; and review of access or retention when a project closes. We select service providers expected to maintain appropriate safeguards and adjust protections as the business and risks change.

No online transmission or storage system is completely secure. Maxsonoro cannot guarantee absolute security, but we investigate suspected incidents and provide notices when required by applicable law. Please email hello@maxsonoro.com if you believe your project access or information has been compromised.

11

Retention + deletion

We keep information only as long as reasonably needed for the purposes described in this policy, including active project work, revisions, delivery, client support, accounting, tax, dispute, fraud-prevention, security, and legal obligations. Retention periods vary by record type. Project files may be retained temporarily for continuity or archival recovery, but long-term file storage is not guaranteed. We may delete or de-identify information when it is no longer needed, subject to lawful holds, backup cycles, transaction records, and provider retention requirements.

12

Your choices + privacy requests

You may ask to access, correct, or delete personal information held by Maxsonoro, or object to or restrict certain uses, by emailing hello@maxsonoro.com. Rights depend on where you live and may be limited by identity verification, transaction records, legal duties, active disputes, security needs, and exceptions under applicable law. We will not discriminate against you for making a privacy request. You can remove locally stored preferences and draft data through your browser controls. Payment-data requests concerning information held by Stripe may also need to be directed to Stripe.

13

Children + clients under 18

The website is not directed to children under 13, and Maxsonoro does not knowingly collect personal information from a child under 13. A client under 18 must involve a parent or legal guardian in the booking and project as described in the Terms of Service. If you believe a child provided information without appropriate permission, contact Maxsonoro so the situation can be reviewed and the information deleted where required.

14

U.S. processing + international users

Maxsonoro operates from the United States. Information may be processed in the United States or other countries where our service providers operate. Those locations may have different privacy laws than your location. Where required, Maxsonoro and its providers use recognized contractual or legal mechanisms for cross-border processing. By requesting services, you understand that project administration may involve this processing, subject to rights that cannot be waived under applicable law.

15

Changes to this policy

We may update this Privacy Policy to reflect changes in services, providers, technology, or law. The effective date at the top shows when the current version began. Material changes will be presented on the website or communicated directly when required. Continued use after an update means the revised policy applies prospectively, subject to any consent required by law.

16

Contact

For privacy questions, requests, or security concerns, email hello@maxsonoro.com with the subject line "Privacy Request." Include enough information to identify the relevant inquiry, booking, invoice, or project, but do not send payment-card numbers, passwords, or other unnecessary sensitive information by email.