Effective Date: April 10, 2026
1. Introduction
CoFabrix("we," "us," or "our") operates the website cofabrix.com. This Privacy Policy explains what personal information we collect, how we use it, and your rights regarding that information.
We are committed to protecting your privacy and handling your data transparently. By using our website, you agree to the practices described in this policy.
Our privacy practices are designed to comply with applicable Utah, U.S. federal, and other relevant regulatory requirements.
2. Information We Collect
2a. Information You Provide
- Contact form submissions: Name, email address, company name, phone number (optional), and your message.
- AI Readiness Assessment:Your answers to assessment questions about your organization's AI maturity, including company size, industry, goals, timeline, and budget authority. Optionally, your email address if you choose to save or share results.
- Website Health Check: The URL you submit for analysis. Optionally, your email address if you request a results report.
- Consultation scheduling: Name, email, and scheduling preferences when booking a consultation through our scheduling tool.
2b. Information Collected Automatically
- Analytics data: Pages visited, time on site, scroll depth, button clicks, and navigation patterns. GA4 tracking requires your consent. Vercel Analytics collects aggregate page-view data without cookies. Additionally, we record behavioral events (scroll depth, time on page, exit intent on desktop browsers only, and clicks on tracked page elements) on all pages in our secure database, linked to your anonymous session identifier and approximate location.
- Device and browser information: Browser type, operating system, screen resolution, and device type.
- Approximate location: City, region, and country derived from your IP address (we do not store your full IP address).
- Referral information: How you arrived at our site (search engine, social media, direct visit, or external link), classified by channel type. We also capture UTM campaign parameters when present in the URL. Referral data is stored as the referring domain only, not the full URL. When you submit a form or return to our site, we update the UTM campaign parameters associated with your contact record to reflect your most recent referral source (last-touch attribution). This helps us understand which marketing channels were most influential in your decision to contact us.
- Session data:A randomly generated session identifier to correlate your actions during a single visit. We also store a visit count and visit timestamps in your browser's local storage to distinguish new from returning visitors; this data stays on your device. If you submit a form with your email, we may associate your current and future session identifiers with your contact record.
- Server-side engagement tracking: When you visit any page on our site, we record behavioral events in our secure database. When you use our interactive tools (website health check, AI readiness assessment) or submit forms, we additionally record tool-specific usage events. All events include the type of action, the page URL, approximate location, and your anonymous session identifier. This data helps us improve our tools and prioritize responses.
3. How We Use Your Information
- To respond to your inquiries: We use contact form data to reply to your questions and provide requested information.
- To deliver tool results: Assessment scores and health check reports are generated from the data you provide and may be emailed to you if requested.
- To improve our services: Aggregated, anonymized analytics help us understand how visitors use our site and which content is most valuable.
- To personalize recommendations:Assessment results help us tailor service recommendations to your organization's needs.
- To communicate with you: We may send follow-up emails related to your inquiry, assessment results, or health check report. We do not send unsolicited marketing emails.
- To prioritize and personalize responses: We use information from your interactions with our tools and forms to prioritize and personalize our communications and to provide an optimal customer experience. No automated adverse decisions are made solely based on this information.
4. Third-Party Services
We use the following third-party services to operate our website:
- Vercel: Website hosting and deployment. Vercel Analytics collects first-party, privacy-friendly performance data without cookies. Vercel Privacy Policy
- Google Analytics 4: Website analytics (loaded only with your consent). Collects anonymized usage data. Google Privacy Policy
- Supabase: Secure database for storing form submissions, assessment results, and health check data. Hosted in the United States with encryption at rest. Supabase Privacy Policy
- Resend: Transactional email delivery for form confirmations and report delivery. Resend Privacy Policy
- Cal.com: Consultation scheduling. Collects your name, email, and scheduling preferences. Cal.com Privacy Policy
- Google PageSpeed Insights API: Powers the Website Health Check tool. Analyzes publicly available website data for the URL you submit.
5. Cookies and Tracking Technologies
We use a privacy-first approach to cookies and tracking:
- Essential cookies: We use localStorage (not cookies) to store your cookie consent preference and session data. This is necessary for the site to function.
- Analytics cookies: Google Analytics 4 sets cookies to measure site usage. These are only loaded after you provide consentvia our cookie banner. You can withdraw consent at any time by clearing your browser's localStorage for cofabrix.com.
- No advertising cookies: We do not use advertising cookies or retargeting pixels.
Vercel Analytics does not use cookies and is loaded by default as a privacy-friendly, first-party analytics service.
6. Data Storage and Retention
- Form submissions, assessment results, and health check data are stored in a secure database hosted in the United States (Supabase, with encryption at rest and in transit).
- We retain your data for as long as necessary to provide our services and respond to your inquiries, generally no longer than 24 months from your last interaction.
- Anonymized, aggregated analytics data may be retained indefinitely for trend analysis.
- You may request deletion of your data at any time (see Section 8).
7. Data Security
We implement appropriate technical and organizational measures to protect your personal information:
- All data is transmitted over HTTPS with TLS encryption.
- Database access is restricted via row-level security policies. Server-side operations use a separate, restricted service key.
- No sensitive data (API keys, database credentials) is exposed in client-side code.
- Form submission endpoints are rate-limited to prevent abuse.
- We regularly review our security practices and update them as needed.
8. Your Rights
Depending on your location, you may have the following rights regarding your personal information:
All Users
- Access: Request a copy of the personal data we hold about you.
- Correction: Request correction of inaccurate data.
- Deletion: Request deletion of your personal data.
- Withdraw consent:Withdraw analytics consent at any time by clearing your browser's localStorage for cofabrix.com or contacting us.
California Residents (CCPA)
- Right to know what personal information is collected and how it is used.
- Right to request deletion of personal information.
- Right to opt out of the "sale" of personal information. We do not sell your personal information.
- Right to non-discrimination for exercising your rights.
European Residents (GDPR)
- Right to data portability (receive your data in a structured format).
- Right to restrict processing of your personal data.
- Right to object to processing based on legitimate interest.
- Right to lodge a complaint with your local data protection authority.
To exercise any of these rights, contact us at hello@cofabrix.com. We will respond within 30 days.
9. Children's Privacy
Our website and services are intended for business professionals. We do not knowingly collect personal information from children under 16. If we learn we have collected data from a child under 16, we will delete it promptly.
10. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated effective date. We encourage you to review this page periodically.
11. Contact Us
If you have questions about this Privacy Policy or wish to exercise your data rights, please contact us:
CoFabrix
Email: hello@cofabrix.com