Frame & Ledger LLC (“Frame & Ledger,” “F&L,” “we,” “us,” or “our”) is a Florida limited liability company that designs and licenses Shopify infrastructure for hybrid (B2B2C) custom manufacturers. This Privacy Policy describes how we collect, use, disclose, and safeguard personal information when you visit frameandledger.com and any related subdomains (the “Website”), submit an inquiry, communicate with us, or engage F&L for professional services.
This Policy applies to information collected through the Website and through our business operations. It does not apply to information you provide to third-party platforms (for example, Shopify, Klaviyo, HubSpot, your accounting system, or your ad networks), even where F&L operates inside those platforms on your behalf. Your relationship with those platforms is governed by their own terms and privacy notices.
§ 01Who We Are
Frame & Ledger LLC is the entity responsible for the personal information processed under this Policy.
- Entity: Frame & Ledger LLC
- Formation: Florida limited liability company
- Website: https://frameandledger.com
- Primary contact for privacy inquiries: privacy@frameandledger.com
- Founders & principals: Adam Wells (CEO), Jonathan Wells (CTO)
§ 02Scope and Audience
The Website is directed at owners, founders, executives, and operators of business entities — not at consumers, and not at children. By using the Website, you represent that you are at least eighteen (18) years of age and are visiting in connection with a business purpose, including evaluating Frame & Ledger as a service provider.
Frame & Ledger is a business-to-business firm. We do not sell consumer products through the Website, and we do not build behavioral profiles of consumers for advertising purposes.
§ 03Information We Collect
We collect personal information in three ways: (a) information you provide to us directly, (b) information we collect automatically when you use the Website, and (c) information we receive from clients in the course of delivering professional services.
3.1 Information You Provide Directly
When you complete the Request Consultation form, send us an email, schedule a discovery call, sign an engagement document, or otherwise interact with us, you may provide:
- Your full name, business email address, and role or title;
- The name, website, and general description of the business you represent;
- Information you share about your operations, goals, current technology stack, sales motion, financials, or challenges, including any documents or screenshots you attach;
- Calendaring and scheduling information necessary to coordinate calls;
- Signature, billing, and entity-formation information required to execute and administer an engagement agreement (for example, a Master Service Agreement, Application License Agreement, Statement of Work, or Ad Pricing Schedule).
3.2 Information Collected Automatically
When you visit the Website, we and certain trusted service providers may collect technical information automatically, including:
- IP address, approximate location derived from IP, and time zone;
- Browser type, operating system, device type, and screen characteristics;
- Pages viewed, links clicked, referring URL, and session duration;
- Cookie and similar identifiers (see Section 7);
- Server log data necessary to operate, secure, and improve the Website.
We use this information for analytics, security, debugging, and product improvement. We do not use it to build cross-site advertising profiles.
3.3 Information Received Through Client Engagements
If your organization engages Frame & Ledger under a signed engagement agreement, we will necessarily process information you make available to us in order to perform the services. This typically includes administrative access to your Shopify store, CRM, email and SMS platforms, ad accounts, analytics, accounting system, and similar systems. The categories of personal information involved may include:
- Employee, contractor, and stakeholder contact information you provide to us;
- End-customer records held inside your platforms (for example, order records, lead inquiries, customer service notes);
- Business operating data, financial data, and performance metrics.
When we process information of this kind on behalf of a client, we act as a service provider, processor, or business contractor (depending on the applicable law). Our handling of that information is governed by the executed engagement documents — most commonly the Master Service Agreement, Application License Agreement, and applicable Statement of Work — which control over any conflicting language in this Policy with respect to that information.
§ 04How We Use Information
We use the information described in Section 3 for the following purposes:
- Respond to inquiries. To evaluate fit, schedule discovery calls, send Discovery proposals, and follow up on conversations you initiate.
- Deliver professional services. To perform the work scoped in an executed engagement agreement, including diagnostics, infrastructure design, application licensing, and ongoing services.
- Operate the business. To send invoices, administer agreements, process payments, maintain records, and manage client relationships.
- Improve the Website and our work product. To analyze how the Website is used, debug issues, prevent abuse, and refine our positioning, content, and case studies.
- Communicate. To send transactional emails, scheduling messages, engagement updates, and — only with appropriate consent or a clear business relationship — occasional emails relating to F&L’s work.
- Comply with law and protect rights. To meet legal, regulatory, tax, audit, and recordkeeping obligations; to enforce our agreements; and to defend against claims.
- Marketing materials, case studies, and content. Subject to the marketing and case study rights granted in our engagement agreements (which generally cover business-level information, anonymized operating data, performance metrics, screenshots, and recreated visualizations), and subject to the confidentiality carve-outs in those agreements (which protect end-customer names, end-customer personally identifiable information, and similar sensitive items), we may use information about a client engagement in case studies, articles, and other promotional content.
We do not use the personal information of Website visitors or prospects for purposes materially different from those described above without a fresh, lawful basis to do so.
§ 05Legal Bases for Processing (EEA, UK, Switzerland)
Where the EU/UK General Data Protection Regulation or the Swiss Federal Act on Data Protection applies, we rely on one or more of the following legal bases:
- Performance of a contract or steps taken at your request prior to entering into a contract (for example, responding to a consultation request, scoping an engagement, performing services under an executed agreement);
- Legitimate interests in operating, securing, and improving the Website and our business, in marketing F&L’s services to business audiences, and in defending or asserting legal rights, where those interests are not overridden by your rights and freedoms;
- Consent, where we ask for it (for example, for non-essential cookies in jurisdictions that require opt-in, or for inclusion in a specific marketing list);
- Legal obligation, where processing is required by applicable law.
§ 08Data Retention
We retain personal information for as long as reasonably necessary to fulfill the purposes described in this Policy, including to provide our services, comply with legal and tax obligations, resolve disputes, defend claims, and enforce our agreements.
Specific retention periods depend on the context. In general:
- Inquiry submissions that do not lead to an engagement are retained for a reasonable period to permit follow-up and to preserve a record of the inquiry, then deleted or anonymized.
- Engagement records — including agreements, statements of work, deliverables, communications, and operating data — are retained throughout the engagement and for the period required to administer the engagement, meet legal and accounting obligations, and exercise the marketing and case study rights granted in our agreements.
- Server logs and analytics are retained for the period needed for security, debugging, and analytics, and then aggregated or deleted.
§ 09Data Security
We maintain administrative, technical, and physical safeguards designed to protect personal information from loss, misuse, and unauthorized access, disclosure, alteration, and destruction. These safeguards include access controls, encryption in transit, vendor diligence, and least-privilege principles for client system access.
No system is perfectly secure. We do not guarantee that personal information will remain free from loss, compromise, or breach, and we expressly disclaim any such warranty to the extent permitted by applicable law. Without limiting the foregoing, Frame & Ledger does not represent or warrant that our Website, services, or operations are compliant with any specific regulation, standard, or certification framework — including HIPAA, PCI-DSS, COPPA, GDPR-specific certifications, SOC 2, ISO 27001, ADA/WCAG, or industry-specific regimes — unless and except as expressly committed in a signed agreement with you that scopes and prices such commitments.
§ 10Your Rights and Choices
Subject to applicable law and the verification process described below, you have the following rights with respect to your personal information.
10.1 General Rights
You may:
- Access the personal information we hold about you;
- Correct inaccurate or incomplete information;
- Delete personal information, subject to exceptions for information we are required or permitted to retain;
- Opt out of marketing communications by using the unsubscribe link in any marketing email or by emailing privacy@frameandledger.com;
- Withdraw consent where processing is based on consent (without affecting the lawfulness of prior processing).
10.2 California Residents (CCPA / CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act, including the right to know what categories and specific pieces of personal information we have collected, the sources, the purposes, and the categories of recipients; the right to delete; the right to correct; and the right to limit the use of sensitive personal information.
We do not “sell” personal information and we do not “share” personal information for cross-context behavioral advertising as those terms are defined under California law. You will not be discriminated against for exercising your California privacy rights.
To submit a request, email privacy@frameandledger.com. You may use an authorized agent to make a request on your behalf, in which case we will verify the agent’s authority.
10.3 EEA, UK, and Swiss Residents (GDPR / UK GDPR)
If you are located in the European Economic Area, the United Kingdom, or Switzerland, you have the rights to access, rectify, erase, restrict, port, and object to the processing of your personal data, and the right to lodge a complaint with a supervisory authority in your jurisdiction. Where we rely on legitimate interests, you may object on grounds relating to your particular situation.
10.4 Florida Residents (FDBR)
If you are a Florida resident and meet the applicability thresholds of the Florida Digital Bill of Rights, you may have rights to confirm, access, correct, delete, obtain a portable copy of, and opt out of certain processing of your personal data, including the sale of sensitive data, targeted advertising, and certain profiling. Frame & Ledger does not engage in the sale of sensitive personal data and does not conduct targeted advertising of the kind addressed by the FDBR.
10.5 Other Jurisdictions
If you reside in a jurisdiction not specifically named above that grants similar rights, we will honor those rights to the extent required by applicable law.
10.6 Verification
To protect your information, we will take reasonable steps to verify your identity before responding to a rights request. We may ask you to confirm information we already hold or to provide additional information sufficient to confirm the request is genuine. If we cannot verify the request, we may decline it and will explain why.
§ 11Do Not Track
Some browsers transmit a “Do Not Track” signal. There is no industry standard for how to interpret this signal, and the Website does not currently respond to Do Not Track signals. You can manage cookies through your browser settings as described in Section 7.
§ 12International Transfers
Frame & Ledger is based in Florida, United States. If you access the Website or engage with us from outside the United States, you understand that your information will be transferred to, stored, and processed in the United States and in any other country where our service providers operate. Data protection laws in the United States may differ from those in your country.
Where required by applicable law, we will implement appropriate safeguards for international transfers — for example, by relying on Standard Contractual Clauses, applicable adequacy decisions, or equivalent mechanisms.
§ 13Children’s Privacy
The Website is not directed to children, and we do not knowingly collect personal information from anyone under the age of eighteen. If we learn that we have collected information from a child in a manner inconsistent with applicable law, we will delete it.
§ 14Third-Party Links and Embedded Content
The Website may link to or embed content from third parties (for example, LinkedIn profiles, video platforms, or partner sites). Those third parties operate independently and have their own privacy practices. We are not responsible for the content or privacy practices of any third party. We encourage you to review the privacy notice of any third-party site you visit.
§ 15Changes to This Policy
We may update this Policy from time to time. When we do, we will revise the “Last Updated” date at the top of the Policy and, where required by law or where changes are material, take additional steps to notify affected individuals. Your continued use of the Website after an update constitutes acceptance of the updated Policy.
§ 16Contact Us
If you have questions about this Policy or wish to exercise a privacy right, contact us at:
Frame & Ledger LLCAttn: Privacy
privacy@frameandledger.com
Frame & Ledger LLC is a Florida limited liability company. This Privacy Policy and any non-contractual obligations arising from or in connection with it are governed by the laws of the State of Florida, without regard to its conflict-of-laws principles, except where mandatory local law of your jurisdiction provides otherwise.
See also our Terms of Service.