Privacy Notice

Last updated: 22 July 2026

This notice describes the processing that the current website code can perform. Individual integrations are used only when the site owner has configured and enabled them.

Information you choose to provide

Depending on the feature you use, we may receive a website address for a website check; your name, email address, phone number, business, selected services and project description for an enquiry or estimate; or your AI chat messages. Chat requests can also contain a random session identifier, page name, language and a phone number if you type one into the conversation. Free-text fields can contain personal information that you choose to enter. Before relevant free text is sent to the AI model, the API applies best-effort redaction for common contact details and secret patterns, but automated redaction is not perfect. Do not submit passwords, API keys, payment details, identity documents or other secrets.

Technical and attribution information

The site can read an allowlist of source and UTM parameters, the necessary language value and a safely formatted page fragment. These values can be kept in session storage and carried between pages or languages; arbitrary query parameters such as tokens and email addresses are not propagated by the shared helper. Chat history can also be held in session storage for the current browser tab. For abuse prevention, the API derives a pseudonymous, salted, one-way hashed rate key from limited request signals. Rate counters use managed KV or D1 storage when a compatible binding is configured, with best-effort serverless-isolate memory as the fallback. The hosting provider may separately process ordinary request and security logs under its own terms.

How the information is used

Service providers that may receive data

These services may process data outside Malaysia. Their own privacy terms govern their processing.

Analytics is separate from submitted content

Google Analytics 4, Meta Pixel or Google Tag Manager can load only when valid public IDs are configured, tracking is enabled and the required consent has been granted. The shared event helper accepts a fixed field allowlist and conservative code formats for page, CTA, source and UTM values. It strips obvious contact details, URLs, secret-like tokens, names in common title-case forms and arbitrary prose. This is a risk-reduction control, not a guarantee that software can identify every possible name or personal detail. Submitted form and chat content is not intentionally placed in analytics events.

Retention and your choices

No single fixed retention period is stated because retention depends on which integrations the owner enables and the settings of the relevant provider or spreadsheet. Do not submit secrets, confidential material or unnecessary personal information. You can close the browser tab to clear session-only site data, decline optional analytics, or contact us to ask about access, correction or deletion. Some information may need to be kept where reasonably required for security, records or applicable law.

Security and updates

Reasonable technical safeguards are used, but no internet transmission or third-party service is risk-free. This notice may be updated when features or providers change; the date above identifies the current version.

Contact

Questions or privacy requests can be sent to wcdigitalstudio@wcwebdev.com. “WC Digital Studio” and these contact details are taken from the current public site; the legal entity name and postal address remain pending owner confirmation.