Skip to content
Privacy

What this site collects, and what it does not.

Short, specific, and written against the code rather than from a template. If something here does not match what the site does, that is a bug and I want to hear about it.

The short version

  • There is no third-party analytics, no tracking pixel, no advertising cookie and no cross-site tracking on this site. What there is: a first-party counter that records which pages were opened. It sets no cookie, stores no IP address and follows you nowhere.
  • There is no account to create and nothing to sign up for.
  • The quote form goes to an inbox. It is not stored in a database and it is never sold, shared or added to a mailing list.
  • The demo keeps what you type for 24 hours and then deletes it, on a schedule, whether you come back or not.
  • If Bighorn Byte runs your business's website and you connect QuickBooks to it, what is held here is the authorization itself and nothing out of your books. There is no copy of an invoice, a customer or an amount anywhere in this service.
  • The only third parties involved are the ones named further down: Cloudflare, Intuit, Anthropic, Google Maps on the contact page, and the host.

When you ask for a quote

The quote form asks for your name, your business, where you are, an email address or a phone number, what you sell, what you are running now, and what is not working. It also records which page you opened it from. All of it is optional except the fields marked required on the form itself.

That message is emailed to contact@bighornbyte.com through Cloudflare’s email sending service. It is not written to a database, and there is no CRM behind it. It stays in that mailbox until it is deleted, the same as any other email you would send me.

Your IP address is used for one thing: holding a single sender to three submissions a minute. It is kept in memory on the server handling the request, for sixty seconds, and it is never written to disk or attached to your message.

The form carries one hidden field that a person never sees. If it arrives filled in, the submission is treated as automated. That is the whole of the spam handling on the marketing side of the site.

The visitor counter

Every page outside the demo runs a small first-party script that reports which page you opened, and nothing else. It is my own code on my own server. There is no Google Analytics, no Meta pixel, no third party of any kind involved, and nothing about it is shared with or sold to anybody.

What it sends is the path you opened, the site that linked you here if there was one, whether this is a new visit, and if you tap a phone number, an email address or the quote form’s send button, which of those it was. The server adds two things from the request itself: the hour of day, and whether the browser looks like a phone, a tablet or a desktop. All of it becomes a counter. Nothing is stored per person, and there is no record with your name, your address or your visit in it.

Your IP address is used to hold one sender to a burst of twenty requests, and then discarded. It is not written down. The counter sets no cookie. It keeps three values in your browser’s own storage instead: hb_last, when you were last here, so a return after thirty minutes counts as a new visit; hb_src and hb_fs1, which remember what linked you here so I can tell which pages are worth writing. All three stay on your device, are readable only by this site, and are removed by clearing this site’s data.

I also read Google Search Console for this domain, which tells me which searches showed the site and how often it was clicked. Google reports that in aggregate; it names nobody.

The demo

The demo at /demo gives you a private sandbox: a working copy of the dealer admin, filled with invented inventory. Nothing you do in it touches a real dealership.

While it exists, the sandbox stores what you change: the units, prices, descriptions and settings you edit, held as one record against a random identifier. That identifier is what the cookie carries, and it is the only credential the sandbox has. Every sandbox is deleted 24 hours after it is created. The clock is never extended, including by resetting it, and a sweep runs hourly to remove the expired ones.

If you use the phone upload feature, the photographs you take are stored under that sandbox’s own prefix and are deleted within two days by a storage lifecycle rule, separately from the sandbox itself.

If you press the button that writes a listing description, the text on that unit is sent to Anthropic’s API to generate one, and the result comes back to your sandbox. Nothing else in the demo sends anything to a model.

Please do not type real personal information into the demo. It is a sandbox for trying an admin, not a place to keep anything. Treat it as a whiteboard that gets wiped.

The bot check on the demo

Getting into the demo costs a Cloudflare Turnstile check, which is a privacy-preserving alternative to a CAPTCHA. It renders on /demo and nowhere else on this site, and it is not shown again while your pass is valid.

To decide whether you are a person, Cloudflare processes your client IP address, your TLS fingerprint, your User-Agent header and the site key for this widget. Cloudflare states that Turnstile does not access, store or transmit your form entries or other page inputs, and that it cannot directly identify an individual from those signals. Their full Turnstile Privacy Addendum covers what they do with it. That addendum directs questions about Turnstile data to the website operator, which for this site is me.

If you connect QuickBooks

This section is for businesses whose website Bighorn Byte builds and hosts. It does not apply to anybody browsing this site.

Bighorn Byte holds your QuickBooks authorization centrally and hands your own website a short-lived key each time it needs one, so that your website can post sales to your books. Your website talks to QuickBooks directly. Bighorn Byte is the keyholder, not a copy of your accounting.

What is stored against your connection is the identifier QuickBooks uses for your company, the access and refresh tokens Intuit issued, when each expires, and which permissions you granted. Both tokens are encrypted before they are written down, with a key that is not kept in the database, and each ciphertext is tied to your company and its own field so it cannot be moved to another record.

No accounting data is stored here at all. Not an invoice, not a customer, not an amount, not a line item. The endpoint your website calls to get a key does not read a request body, so there is no field through which any of it could arrive. The only permission requested from Intuit is the standard accounting scope, and Bighorn Byte does not use it to read your books.

There is a record of the connection itself: when it was made, refreshed, verified or ended, which of your sites asked for a key and how often, and the reason an attempt failed when one did. It is kept so that a problem can be explained later. If the site that started the connection tells us who pressed the button, that name is stored on the attempt too.

You can disconnect at any time from inside QuickBooks, under Apps, and it takes effect immediately without going through Bighorn Byte. When a connection ends, whether you ended it or we did, both tokens are deleted from the database. The record that the connection existed stays, without the keys, so the history remains explainable. To have that history removed as well, email contact@bighornbyte.com and it will be deleted.

Nothing about your QuickBooks connection is sold, shared with advertisers, or used for anything other than running the website you are paying for. The connection record lives in a Postgres database in the United States, separate from the one behind the public demo, and is reachable by nobody outside Bighorn Byte.

Bighorn Byte does not handle any of this on Intuit’s behalf. Intuit and Bighorn Byte each decide independently what to do with what they hold, and this policy covers only the Bighorn Byte side. What Intuit does with your QuickBooks company is governed by Intuit’s own terms and privacy policy.

The map on the contact page

The contact page embeds a Google Map showing Sheridan. Loading it requests content from Google, which means Google receives your IP address and may set its own cookies in your browser under its own terms. It is on that one page. If you would rather not load it, the address, the phone number and the email are all written out on the page in text.

Cookies

Four, all of them set by the demo, none of them for marketing or advertising. Browsing the rest of this site sets no cookie at all.

CookieWhat it doesLasts
bb_demo_sandboxNames your demo sandbox, so the lot you are editing is yours.24 hours
bb_demo_passRecords that you passed the bot check, so it is not shown again.24 hours
bb_demo_tourRemembers that you took or declined the guided walkthrough.1 year
bb_demo_pagesRemembers which per-screen guides you have already seen.1 year

Two things keep state in your browser’s own storage rather than in a cookie: the demo, which remembers how far through the walkthrough you were, and the visitor counter’s three values above. Neither ever leaves your device, and clearing this site’s data removes both.

Hosting and server logs

The site runs on Deno Deploy with Cloudflare in front of it. Both keep the ordinary request logs any web host keeps, which include IP addresses, for operating the service and defending it from abuse. I do not build anything on top of those logs and I do not use them to profile visitors.

What never happens

Your information is not sold. It is not shared with advertisers, ad networks or data brokers. It is not used to build a profile of you, and asking for a quote does not put you on a mailing list. There is no mailing list.

Your choices

Email contact@bighornbyte.com and ask for a copy of what I hold about you, or ask me to delete it. In practice that is whatever you sent me, so deleting it means deleting the emails, and I will confirm when it is done. You do not need a legal reason and I will not ask you for one.

A demo sandbox deletes itself within 24 hours with no action from you. Clearing this site’s cookies ends it immediately.

Children

This is a business-to-business site for dealerships. It is not directed at children and it does not knowingly collect anything from them.

Changes

If what the site does changes, this page changes with it and the date below moves. There is no archive of previous versions; if you need to know what it said on a given day, ask.

Last updated August 27, 2026.

Who to contact

Bighorn Byte LLC, Sheridan, Wyoming. contact@bighornbyte.com or (307) 285-3500. A person reads both.