This policy states what happens to data sent through kzoo.us.
KZOO Studio runs a small service site and receives paid advertising traffic. The disclosures below cover the inquiry form, support chat, consent storage, advertising identifiers and rights requests.
This policy took effect on September 29, 2026.
This privacy policy took effect on September 29, 2026. It applies to the public website at kzoo.us and the data handled through its forms, chat and advertising measurement.
Kzoo operates this site from its stated Kalamazoo address.
Kzoo, trading at kzoo.us, is the operator and controller for this site. The postal address is 1200 ACADEMY STREET, KALAMAZOO, MI 49006, KALAMAZOO, MI, United States. KZOO Studio is a two-person branding and communications studio.
The site receives inquiry, chat, technical, log, cookie and click data.
The inquiry form writes name, phone, email, address, the kind of enquiry, the message, the requested specification and the consent tick. Automatically with it, the system records the IP address, browser user-agent string, referring URL, the moment the form was rendered and the moment it was sent.
The support chat receives a name, phone when supplied, email when supplied, consent and message text. It keeps the conversation and a token in the visitor's browser so the conversation can be returned to. The browser stores the consent choice under site_consent_v2. Server and access logs contain technical request information. Advertising links can carry gclid, msclkid and fbclid.
This site has no account, password, payment or card data. Nothing is sold on this site and no payment is taken.
Each category is used for a defined operational reason.
Inquiry data is used to understand a requested scope, answer the person and keep the working record. Chat data is used to continue a support conversation. Technical and log data is used to deliver the site, protect its forms and investigate faults. Consent data records the visitor's storage choice. Click identifiers and permitted measurement data show which paid advertising link produced a visit or inquiry.
Consent, contract and legitimate interest are named for each purpose.
Consent is the legal basis for advertising storage, ad measurement and analytics storage. Contract or steps requested before a contract are the basis for handling an inquiry and preparing agreed work. Legitimate interest is the basis for site security, fraud prevention, service operation and retaining a necessary business record. Where a visitor withdraws consent, the consent-based processing stops for future collection.
Paid traffic currently arrives through Google Ads, Microsoft Advertising and Meta Ads.
Google Ads, Microsoft Advertising and Meta Ads send traffic here today. Google Ads attaches gclid to a click, Microsoft Advertising attaches msclkid, and Meta Ads attaches fbclid where a campaign runs there. These identifiers help attribute a visit or inquiry to its advertising link only when the applicable storage is allowed. The records name the routes google ads and microsoft advertising.
Consent Mode v2 keeps the four storage signals denied until permission is given.
Consent mode v2 holds ad_storage, ad_user_data, ad_personalization and analytics_storage denied until the visitor allows storage. It sets them back to denied the moment the visitor declines or withdraws. Consent is explicit and reversible through the visible preferences control; the consent mode setting is visible in the choice.
Named service providers receive only the data needed to perform their route.
Google Ireland Ltd / Google LLC receives Google Ads measurement and consent signals. Microsoft Ireland Operations Ltd receives Microsoft Advertising data and handles it under its Microsoft privacy statement at privacy.microsoft.com. Meta Platforms Ireland Ltd receives Meta Ads data where a campaign runs there. The hosting provider serves this site and stores the enquiry database. The mail provider carries the notification to the operator's inbox.
Some providers may process data outside the country where it was collected.
Advertising, hosting and mail providers may transfer or access data outside the country of collection. Those transfers use the provider's contractual safeguards, applicable adequacy decisions or other lawful mechanism available to that provider. A visitor can ask where a particular request was sent by writing to [email protected].
Every stored category has a stated retention period.
Enquiries and their email copies are kept for 24 months. Chat transcripts are kept for 12 months. Server and access logs are kept for 30 days. The record of a consent choice is kept for 12 months. A data request is answered within 5 days; its correspondence is retained with the relevant request record.
Access controls and ordinary server safeguards protect the records.
Data is sent over encrypted transport, stored behind hosting access controls and limited to the operator and the providers needed for delivery. Form fields are checked, honeypots reduce automated abuse and logs are limited to 30 days. No internet service can promise perfect security, so a suspected incident should be reported promptly.
Visitors covered by the GDPR can use the full set of data rights.
For visitors who reach the site from Europe, the GDPR rights are access, rectification, erasure, restriction, portability, objection and withdrawing consent. A request can be made using the contact route below. We may ask for information that safely confirms which record belongs to the requester.
US state privacy rights include California opt-out rights.
US state privacy law applies, including California's CCPA and CPRA and other state laws in force. Depending on the state, a person may request access, correction or deletion and may opt out of sale or sharing. This site does not sell data. California residents may also contact the California Privacy Protection Agency.
Global Privacy Control is honoured as an opt-out signal.
Global Privacy Control, including the Sec-GPC header, is honoured as an opt-out without asking again. Consent mode signals are set to denied when the visitor declines or withdraws.
This service site is not for children and takes no data from them.
The site is intended for businesses and adults making service inquiries. It is not for children, and KZOO Studio does not knowingly take data from children. If a child has sent information, a parent or guardian can contact [email protected] to request its removal.
A visitor may complain to a relevant data protection authority.
A visitor may complain to their state Attorney General, to the California Privacy Protection Agency in California, or to a data protection authority with jurisdiction over their location. Contacting the studio first is useful, but it is not required before making a complaint.
Data requests go to the real address and receive an answer within 5 days.
Write to [email protected] or to 1200 ACADEMY STREET, KALAMAZOO, MI 49006, United States. State whether you want access, correction, deletion, restriction, portability, objection or consent withdrawal. Include enough detail to identify the request without sending unnecessary sensitive information. KZOO Studio answers a data request within 5 days.
A changed policy carries a new date and appears on this page.
When this policy changes, the revised text is published on this page and the “Last updated” date changes. A material change may also be called out at the point where consent is requested. The current page controls the handling of new data.
The contact route reaches a human at KZOO Studio.
Email [email protected] or call (269) 337-7248. Postal contact is 1200 ACADEMY STREET, KALAMAZOO, MI 49006, United States.