This policy is provided by Wynkoop Consulting LLC (“we”, “us”, “our”), which operates the Make it Real website builder, Inbox, and related services (the “Service”). It describes how we collect, use, and share information when you use the Service, including website builder, hosting, domain, email, scheduling, analytics, integrations, and related features. It also covers our public website, pilot applications, and support communications.
Information we collect
- Account data: your name, email address, password hash, account identifiers, permissions, preferences, and sign-in and account activity. We use this information to authenticate you and manage access to the Service.
- Inquiries and pilot applications: contact details, business name, portfolio link, answers about your work and software needs, referral or campaign information, and messages you send us.
- Site and file content: files, HTML, assets, and configuration you upload or create for your projects, and metadata needed to serve and manage them, such as paths, build output, project settings, custom domains, DNS records, redirects, and publishing settings. For server scripts, this also includes source code, configured credentials, execution inputs, outputs, and logs, which can contain information submitted by your visitors.
- AI assistant: prompts, conversation history, uploaded attachments, generated responses, and project context used by the assistant. Relevant information is sent to the AI service configured for the feature. See “AI tools and connected services” below.
- Email services: if you use hosted email, we process email addresses, aliases, forwarding rules, contacts, signatures, message metadata, message content, attachments, delivery logs, spam or abuse signals, and related configuration needed to send, receive, route, store, and display mail.
- Domains and DNS: if you register or connect a domain, we process domain names, DNS records, registration status, registrar operation details, renewal settings, and contact information required by registrars, registries, ICANN, DNS providers, or applicable law.
- Scheduling and calendar data: if you use scheduling features, we process availability, booking details, invitee contact information, calendar event data, cancellation details, and related notification metadata.
- Form and data collection submissions: if you publish a form or data collection on your site, we receive and store what your visitors submit — which may include names, email addresses, phone numbers, messages, and any other fields you choose to collect — along with submission timestamps and delivery records for any webhooks you have configured.
- Website analytics: hosted sites include analytics that collect visitor IP addresses, page paths, hostnames, timestamps, referring domains, campaign tags, device type, browser, operating system, language, browser window width, and page and session identifiers. We also record active time, scroll depth, and interaction events such as link clicks, downloads, form submissions, bookings, and events configured by the site operator. A visitor identifier derived from IP address and browser information helps recognize visits within a project; this is pseudonymous information, not anonymous data. When location enrichment is configured, visitor IP addresses are sent to MaxMind to estimate country, region, city, time zone, and approximate coordinates and accuracy radius. These estimates do not establish a visitor’s exact location. Authorized project users can view analytics reports, and platform administrators can access individual visit details, including IP addresses.
- Search visibility: if you use search-performance or SEO features, we process domain and page addresses, sitemap information, search queries and performance metrics, and the keywords, questions, and targeting settings you use for research.
- Usage and technical data: such as IP address, browser type, device information, timestamps, and diagnostic logs needed to operate, secure, troubleshoot, and improve the Service.
- Billing: if you subscribe to paid features or bundles, our payment processor (e.g. Stripe) collects and processes payment details according to their policies; we receive limited billing-related information needed to manage checkout, invoices, subscriptions, renewals, cancellations, and access to paid features.
How we use information
We use the information above to:
- Provide, operate, and improve the Service
- Authenticate users and enforce access controls
- Host and deliver your sites, assets, domains, DNS records, email, and scheduling pages
- Send, receive, route, filter, store, and display email at your request
- Generate or edit website content when you use AI-assisted features
- Receive, store, and display form and data collection submissions on your behalf
- Deliver submissions to webhook endpoints or integrations you configure
- Provide project analytics and usage summaries
- Process payments and communicate about your account, billing, inquiries, or pilot application
- Measure use of our public pages and features, including pilot applications and setup activity
- Detect abuse, fraud, and violations of our Terms of Service
- Comply with legal obligations and respond to lawful requests
How we share information
We use providers to deliver the features you use. Depending on the feature and its configuration, these include:
- Amazon Web Services: hosting, file storage, content delivery, DNS, and email delivery and receipt.
- Stripe: checkout, payment processing, invoices, and subscription management.
- Domain providers: the registrar or DNS provider managing your domain, such as Porkbun, OpenSRS, or Amazon Route 53, receives the registration, contact, DNS, or renewal information needed for its role.
- AI services: the model provider or routing service configured for the assistant receives the prompts and context needed to answer your request.
- MaxMind: when location enrichment is configured, visitor IP addresses are used for approximate location lookup.
- Google reCAPTCHA: when enabled on a form, Google receives verification and technical signals, including IP address, to help detect automated abuse.
- Search services: when enabled, Google Search Console receives site, sitemap, and page addresses for search-performance features, and DataForSEO receives research keywords or questions, target domains, and search settings.
- Error monitoring: when configured, Rollbar receives diagnostic information that may include account ID, name, and email address to help investigate errors.
Collaborators and delegated users can access information their permissions allow. Email recipients, webhook destinations, connected clients, and services called by your scripts receive the information you direct to them. Payment services, registrars, and services you connect may also process information for their own purposes under their terms and privacy notices, such as fraud prevention or legal compliance.
We do not sell your personal information. We may disclose information if required by law, to protect rights and safety, to investigate abuse or security issues, or in connection with a merger, acquisition, or transfer of the business.
We operate from the United States. Information may be stored or processed in the United States and other countries where the providers involved in your service operate. Contact us before providing data if you require a particular storage location or a data-processing or international-transfer agreement; this policy does not itself establish those arrangements.
AI tools and connected services
The in-product assistant can receive your prompts, recent conversation history, attachments, project files, and information retrieved by tools it is allowed to use. That context can contain personal information from your projects. We store conversations and related records to provide the feature. Do not put passwords, payment card details, or information you are not authorized to share into a prompt or project context.
When you authorize an external AI tool or other client through our MCP integration, the client can receive data and perform actions within the permissions you grant. Project access can include website files, data collections and submissions, analytics, and site changes. Separately authorized Inbox access can include email bodies, attachments, sender and recipient details, drafts, and scheduling information. Review the authorization screen and the connected service’s privacy, retention, and model-training settings before connecting.
You can turn off MCP access in Integrations to block further requests through our MCP servers. Disconnecting a client does not remove information it already received. We do not train our own AI models on the personal information your visitors submit; that statement is not a promise about a separate provider’s processing or the settings of a tool you connect.
Stopping Search Console syncing leaves previously collected metrics and does not remove Google property ownership or domain verification records.
Cookies and browser storage
The app uses cookies for sign-in, sessions, and related functionality, and browser storage to remember preferences such as theme and navigation settings. Session information may also retain campaign tags associated with a pilot application.
Hosted-site analytics uses browser session storage for session identifiers and attribution. It does not set analytics cookies, but it still processes the visitor information described above. Blocking browser storage alone does not stop analytics requests. Browser cookie and storage controls can affect sign-in, saved preferences, and other functionality.
Site operators may add their own scripts, embeds, or tracking tools, with separate data practices. They are responsible for explaining those tools and obtaining any required consent. Our built-in hosted-site analytics does not currently provide a per-project consent manager or automatically act on Do Not Track or Global Privacy Control signals. Contact us about privacy choices or a deployment that requires additional controls.
Content you publish and data from your visitors
Much of what the Service stores is content you create or collect: pages, files, images, copy, form fields, collection schemas, and the submissions, bookings, and messages your visitors send you. When we process that information on a customer’s instructions to provide hosting, email, forms, or other features, we act as a processor or service provider. The person or organization deciding why and how it is collected is the controller. If an agency manages a site for a client, the agency and client must determine their respective roles; the account holder is not necessarily the controller in every case.
We separately determine how account administration, billing, support, and platform security information is used for our own operations. Where applicable, we act as controller for that processing. A privacy notice does not replace a required data-processing agreement; contact us to address any contractual requirements before sending us the affected data.
Because you decide what your site collects and why, you are responsible for:
- Publishing your own privacy notice that accurately describes what you collect, why, how long you keep it, and who you share it with
- Having a lawful basis — including consent where it is required — for collecting, storing, and using visitor information, and for any marketing you send afterward
- Responding to requests from your visitors to access, correct, delete, or export their information, and honoring opt-outs
- Not collecting payment card numbers, government identifiers, health records, precise location, or other sensitive categories through the Service unless you have the safeguards and permissions applicable law requires
- Satisfying yourself that any webhook, integration, or AI provider you enable handles submissions appropriately — once data leaves the Service at your direction, the recipient’s own terms govern what happens to it
We do not use the personal information your visitors submit to you to build our own marketing profiles or train our own models. Authorized account users can manage submissions, bookings, and messages using the controls available for each feature.
Anything you publish — pages, files, and whatever a form or booking page displays — is visible to anyone who can reach your site, and may be indexed by search engines or cached by third parties. If you turn on the showcase setting for a project, its published site, screenshots, and recorded previews also appear on our public showcase page until you turn it off. Do not publish information you are not willing to make public.
If you visited a site built with Make it Real
If you filled in a form, booked an appointment, or sent an email to the operator of a site hosted on the Service, that operator decides how the information you submit is used. We store and transmit that content on their behalf. Visits can also generate the analytics and technical information described in this policy.
Please send requests to access, correct, delete, or stop the use of your information to the site operator, who can act on them directly. If you cannot identify or reach the operator, contact us at the address below and we will pass your request on, or act on it ourselves where the law requires. We also process limited technical data about your visit, such as IP address and request logs, to keep the Service secure and operating.
Retention and deletion
Retention depends on the information, the features in use, and deletion actions or requests. We consider whether the data is needed to provide an active service, maintain security, comply with legal or accounting obligations, resolve disputes, or enforce our agreements. We do not currently apply a single automatic deletion deadline to all data.
- Project data: site content, conversations, submissions, and related records remain until removed through the relevant controls or a deletion request is fulfilled. Removing a submission or collection removes its active records; copies previously delivered to email recipients or webhooks remain with those recipients.
- Analytics: visit records, including raw IP addresses, and interaction events do not currently have an automatic age-based deletion schedule. Project deletion removes that project’s analytics records. Separate IP-to-location cache records can remain after a project is deleted; their refresh interval is not a deletion deadline.
- Email, scripts, and scheduling: messages, attachments, script execution records, and booking data may remain separately from website files. Canceling a booking, closing an account, or disabling a feature does not necessarily erase its history.
- Business and operational records: billing, domain registration, support, pilot applications, security, and audit records may remain where needed for the purposes above. Providers may also retain records under their own obligations.
Deleted information may remain in backups or logs until those copies are replaced or removed, or longer where a legal retention obligation applies. Public pages and messages may also have been copied by search engines, recipients, or others outside our control. Contact us for a deletion request or information about retention for a particular feature.
Closing your account
The account deletion control currently closes your login and signs you out. It does not automatically erase all stored information, take your sites offline, cancel paid subscriptions, or stop domain renewals. Sites and associated records can remain after login access ends.
Before closing your account, save any information you need, arrange ongoing access for collaborators or clients, and separately manage subscriptions, domain renewals, and resources you want removed. If you want your personal information erased, need an export, or have already closed your login, email support@wynkoopconsulting.com. We handle those requests separately, subject to identity checks, applicable rights, and the retention exceptions described above.
Security
We implement reasonable administrative, technical, and organizational measures designed to protect information. No method of transmission or storage is completely secure.
Your choices and rights
Depending on where you live, you may have rights to access, correct, delete, or object to certain processing of your personal information, restrict processing, obtain a portable copy, withdraw consent where processing depends on it, or complain to a privacy regulator. The rights and exceptions that apply depend on your location and our role in the processing. You can also update some information directly in your account settings.
Email the contact address below with the account email or relevant site address and a description of your request. We may need to verify your identity or authority before releasing or deleting information. Please do not send passwords or payment card details. We respond within the time required by applicable law. If we cannot fulfill a request, you can contact us to ask for a review and, where available, appeal or complain to the relevant regulator.
You can delete projects, remove email addresses, delete individual submissions or an entire data collection, cancel bookings, turn off the showcase setting, manage domain renewal settings, and cancel subscriptions through the product or billing portal where those controls are available.
Children
The Service is not directed at children under 16. If you believe a child under 16 has provided personal information to us, contact us so we can investigate and address it. Site operators are responsible for any age restrictions, parental permissions, and privacy requirements applicable to the audiences of their own sites.
Changes
We may update this Privacy Policy from time to time. We will post the revised policy on this page and update the “Last updated” date. Where required by law, we will provide additional notice or obtain consent before making a change to the way we use information.
Contact
For privacy questions or requests, contact us at support@wynkoopconsulting.com.