Legal · Privacy Policy

Privacy Policy

Effective: 
June 8, 2026
Last updated: 
June 8, 2026

Frame & Ledger LLC (“Frame & Ledger,” “F&L,” “we,” “us,” or “our”) is a Florida limited liability company that designs and licenses Shopify infrastructure for hybrid (B2B2C) custom manufacturers. This Privacy Policy describes how we collect, use, disclose, and safeguard personal information when you visit frameandledger.com and any related subdomains (the “Website”), submit an inquiry, communicate with us, or engage F&L for professional services.

This Policy applies to information collected through the Website and through our business operations. It does not apply to information you provide to third-party platforms (for example, Shopify, Klaviyo, HubSpot, your accounting system, or your ad networks), even where F&L operates inside those platforms on your behalf. Your relationship with those platforms is governed by their own terms and privacy notices.

§ 01Who We Are

Frame & Ledger LLC is the entity responsible for the personal information processed under this Policy.

§ 02Scope and Audience

The Website is directed at owners, founders, executives, and operators of business entities — not at consumers, and not at children. By using the Website, you represent that you are at least eighteen (18) years of age and are visiting in connection with a business purpose, including evaluating Frame & Ledger as a service provider.

Frame & Ledger is a business-to-business firm. We do not sell consumer products through the Website, and we do not build behavioral profiles of consumers for advertising purposes.

§ 03Information We Collect

We collect personal information in three ways: (a) information you provide to us directly, (b) information we collect automatically when you use the Website, and (c) information we receive from clients in the course of delivering professional services.

3.1 Information You Provide Directly

When you complete the Request Consultation form, send us an email, schedule a discovery call, sign an engagement document, or otherwise interact with us, you may provide:

  • Your full name, business email address, and role or title;
  • The name, website, and general description of the business you represent;
  • Information you share about your operations, goals, current technology stack, sales motion, financials, or challenges, including any documents or screenshots you attach;
  • Calendaring and scheduling information necessary to coordinate calls;
  • Signature, billing, and entity-formation information required to execute and administer an engagement agreement (for example, a Master Service Agreement, Application License Agreement, Statement of Work, or Ad Pricing Schedule).

3.2 Information Collected Automatically

When you visit the Website, we and certain trusted service providers may collect technical information automatically, including:

  • IP address, approximate location derived from IP, and time zone;
  • Browser type, operating system, device type, and screen characteristics;
  • Pages viewed, links clicked, referring URL, and session duration;
  • Cookie and similar identifiers (see Section 7);
  • Server log data necessary to operate, secure, and improve the Website.

We use this information for analytics, security, debugging, and product improvement. We do not use it to build cross-site advertising profiles.

3.3 Information Received Through Client Engagements

If your organization engages Frame & Ledger under a signed engagement agreement, we will necessarily process information you make available to us in order to perform the services. This typically includes administrative access to your Shopify store, CRM, email and SMS platforms, ad accounts, analytics, accounting system, and similar systems. The categories of personal information involved may include:

  • Employee, contractor, and stakeholder contact information you provide to us;
  • End-customer records held inside your platforms (for example, order records, lead inquiries, customer service notes);
  • Business operating data, financial data, and performance metrics.

When we process information of this kind on behalf of a client, we act as a service provider, processor, or business contractor (depending on the applicable law). Our handling of that information is governed by the executed engagement documents — most commonly the Master Service Agreement, Application License Agreement, and applicable Statement of Work — which control over any conflicting language in this Policy with respect to that information.

§ 04How We Use Information

We use the information described in Section 3 for the following purposes:

  • Respond to inquiries. To evaluate fit, schedule discovery calls, send Discovery proposals, and follow up on conversations you initiate.
  • Deliver professional services. To perform the work scoped in an executed engagement agreement, including diagnostics, infrastructure design, application licensing, and ongoing services.
  • Operate the business. To send invoices, administer agreements, process payments, maintain records, and manage client relationships.
  • Improve the Website and our work product. To analyze how the Website is used, debug issues, prevent abuse, and refine our positioning, content, and case studies.
  • Communicate. To send transactional emails, scheduling messages, engagement updates, and — only with appropriate consent or a clear business relationship — occasional emails relating to F&L’s work.
  • Comply with law and protect rights. To meet legal, regulatory, tax, audit, and recordkeeping obligations; to enforce our agreements; and to defend against claims.
  • Marketing materials, case studies, and content. Subject to the marketing and case study rights granted in our engagement agreements (which generally cover business-level information, anonymized operating data, performance metrics, screenshots, and recreated visualizations), and subject to the confidentiality carve-outs in those agreements (which protect end-customer names, end-customer personally identifiable information, and similar sensitive items), we may use information about a client engagement in case studies, articles, and other promotional content.

We do not use the personal information of Website visitors or prospects for purposes materially different from those described above without a fresh, lawful basis to do so.

§ 06How We Share Information

We do not sell personal information, and we do not share personal information with third parties for cross-context behavioral advertising. We disclose personal information only as described below.

6.1 Service Providers

We share information with vendors and contractors who help us operate the Website and the business, under written terms requiring confidentiality and appropriate use. Categories include:

  • Website hosting, content delivery, and infrastructure (for example, our Website host and CDN);
  • Content management (for example, our headless CMS provider for Website content);
  • Customer relationship management (for example, the CRM we use to track prospects, accounts, and engagements);
  • Email, calendaring, and document collaboration;
  • Electronic signature and contract administration;
  • Telephony, call tracking, and meeting recording, where used;
  • Analytics;
  • Accounting, payment processing, and banking;
  • File storage and backup;
  • Counsel, accountants, and other professional advisors, where engaged.

We use commercially reasonable efforts to engage providers that handle information securely and lawfully. We do not authorize providers to use information about our visitors or clients for their own marketing.

6.2 With Your Direction or Authorization

We share information when you direct us to do so or when sharing is reasonably necessary to perform the engagement (for example, when we coordinate with a third-party developer, agency, or platform on your behalf with your knowledge).

6.3 Legal, Safety, and Enforcement

We may disclose information when we believe in good faith that disclosure is necessary to: comply with applicable law, regulation, legal process, or governmental request; enforce our agreements, terms, and policies; investigate, prevent, or address fraud, security, or technical issues; or protect the rights, property, or safety of Frame & Ledger, our clients, our personnel, or the public.

6.4 Business Transactions

If Frame & Ledger is involved in a merger, acquisition, reorganization, financing, sale of assets, or similar transaction, information may be transferred as part of that transaction, subject to customary confidentiality protections and the requirements of applicable law.

6.5 Aggregated or De-Identified Information

We may create and share aggregated, anonymized, or de-identified information that does not reasonably identify any individual — for example, benchmark statistics, operating insights, and conversion-lag patterns derived from the engagements we have performed. This information is not personal information and is not subject to this Policy.

§ 07Cookies and Similar Technologies

The Website uses cookies and similar technologies (pixels, local storage, server logs) to:

  • Operate the Website and keep it secure;
  • Remember preferences (for example, theme or language, where supported);
  • Measure how the Website is used so we can improve it;
  • Diagnose problems.

You can configure your browser to refuse cookies or to alert you when cookies are being set. If you reject essential cookies, parts of the Website may not function correctly. Where applicable law requires it, we will request your consent before setting non-essential cookies.

We do not use third-party advertising cookies for retargeting on the Website.

§ 08Data Retention

We retain personal information for as long as reasonably necessary to fulfill the purposes described in this Policy, including to provide our services, comply with legal and tax obligations, resolve disputes, defend claims, and enforce our agreements.

Specific retention periods depend on the context. In general:

  • Inquiry submissions that do not lead to an engagement are retained for a reasonable period to permit follow-up and to preserve a record of the inquiry, then deleted or anonymized.
  • Engagement records — including agreements, statements of work, deliverables, communications, and operating data — are retained throughout the engagement and for the period required to administer the engagement, meet legal and accounting obligations, and exercise the marketing and case study rights granted in our agreements.
  • Server logs and analytics are retained for the period needed for security, debugging, and analytics, and then aggregated or deleted.

§ 09Data Security

We maintain administrative, technical, and physical safeguards designed to protect personal information from loss, misuse, and unauthorized access, disclosure, alteration, and destruction. These safeguards include access controls, encryption in transit, vendor diligence, and least-privilege principles for client system access.

No system is perfectly secure. We do not guarantee that personal information will remain free from loss, compromise, or breach, and we expressly disclaim any such warranty to the extent permitted by applicable law. Without limiting the foregoing, Frame & Ledger does not represent or warrant that our Website, services, or operations are compliant with any specific regulation, standard, or certification framework — including HIPAA, PCI-DSS, COPPA, GDPR-specific certifications, SOC 2, ISO 27001, ADA/WCAG, or industry-specific regimes — unless and except as expressly committed in a signed agreement with you that scopes and prices such commitments.

§ 10Your Rights and Choices

Subject to applicable law and the verification process described below, you have the following rights with respect to your personal information.

10.1 General Rights

You may:

  • Access the personal information we hold about you;
  • Correct inaccurate or incomplete information;
  • Delete personal information, subject to exceptions for information we are required or permitted to retain;
  • Opt out of marketing communications by using the unsubscribe link in any marketing email or by emailing privacy@frameandledger.com;
  • Withdraw consent where processing is based on consent (without affecting the lawfulness of prior processing).

10.2 California Residents (CCPA / CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act, including the right to know what categories and specific pieces of personal information we have collected, the sources, the purposes, and the categories of recipients; the right to delete; the right to correct; and the right to limit the use of sensitive personal information.

We do not “sell” personal information and we do not “share” personal information for cross-context behavioral advertising as those terms are defined under California law. You will not be discriminated against for exercising your California privacy rights.

To submit a request, email privacy@frameandledger.com. You may use an authorized agent to make a request on your behalf, in which case we will verify the agent’s authority.

10.3 EEA, UK, and Swiss Residents (GDPR / UK GDPR)

If you are located in the European Economic Area, the United Kingdom, or Switzerland, you have the rights to access, rectify, erase, restrict, port, and object to the processing of your personal data, and the right to lodge a complaint with a supervisory authority in your jurisdiction. Where we rely on legitimate interests, you may object on grounds relating to your particular situation.

10.4 Florida Residents (FDBR)

If you are a Florida resident and meet the applicability thresholds of the Florida Digital Bill of Rights, you may have rights to confirm, access, correct, delete, obtain a portable copy of, and opt out of certain processing of your personal data, including the sale of sensitive data, targeted advertising, and certain profiling. Frame & Ledger does not engage in the sale of sensitive personal data and does not conduct targeted advertising of the kind addressed by the FDBR.

10.5 Other Jurisdictions

If you reside in a jurisdiction not specifically named above that grants similar rights, we will honor those rights to the extent required by applicable law.

10.6 Verification

To protect your information, we will take reasonable steps to verify your identity before responding to a rights request. We may ask you to confirm information we already hold or to provide additional information sufficient to confirm the request is genuine. If we cannot verify the request, we may decline it and will explain why.

§ 11Do Not Track

Some browsers transmit a “Do Not Track” signal. There is no industry standard for how to interpret this signal, and the Website does not currently respond to Do Not Track signals. You can manage cookies through your browser settings as described in Section 7.

§ 12International Transfers

Frame & Ledger is based in Florida, United States. If you access the Website or engage with us from outside the United States, you understand that your information will be transferred to, stored, and processed in the United States and in any other country where our service providers operate. Data protection laws in the United States may differ from those in your country.

Where required by applicable law, we will implement appropriate safeguards for international transfers — for example, by relying on Standard Contractual Clauses, applicable adequacy decisions, or equivalent mechanisms.

§ 13Children’s Privacy

The Website is not directed to children, and we do not knowingly collect personal information from anyone under the age of eighteen. If we learn that we have collected information from a child in a manner inconsistent with applicable law, we will delete it.

§ 14Third-Party Links and Embedded Content

The Website may link to or embed content from third parties (for example, LinkedIn profiles, video platforms, or partner sites). Those third parties operate independently and have their own privacy practices. We are not responsible for the content or privacy practices of any third party. We encourage you to review the privacy notice of any third-party site you visit.

§ 15Changes to This Policy

We may update this Policy from time to time. When we do, we will revise the “Last Updated” date at the top of the Policy and, where required by law or where changes are material, take additional steps to notify affected individuals. Your continued use of the Website after an update constitutes acceptance of the updated Policy.

§ 16Contact Us

If you have questions about this Policy or wish to exercise a privacy right, contact us at:

Frame & Ledger LLC
Attn: Privacy
privacy@frameandledger.com

Frame & Ledger LLC is a Florida limited liability company. This Privacy Policy and any non-contractual obligations arising from or in connection with it are governed by the laws of the State of Florida, without regard to its conflict-of-laws principles, except where mandatory local law of your jurisdiction provides otherwise.

See also our Terms of Service.

⬢ The Frame is set. The Ledger is clear.