Privacy

What's collected, where it goes, and how to get it deleted.

Ventus Optera is one person. This page names each vendor, each field and how long it is kept, so you can check the policy against the site.

The form asks for
Name · email · message
Sold or rented
Never
Analytics
PostHog
To delete your data
One email

Effective 27 September 2026. Ventus Optera, LLC operates ventusoptera.com. I do not sell your information, I do not rent it, and I do not share it with anyone who is not listed on this page. If you want any of it removed, email me and I will remove it.

What you give on purpose

The contact form asks for seven things. Three are required: your name, your email address, and a description of what you are trying to build or fix. Four are optional: your phone number (only if you would rather get a call than an email), your company, your team size and your industry. Nothing else on this site asks you for anything.

Those details are used for exactly one purpose: to answer you, and to keep track of the conversation if it turns into an engagement. There is no newsletter, no drip sequence, and no list you are added to by submitting the form. The one exception, described in full under Google Ads below, is a one-way hash of your email sent to Google to help measure whether an ad led to your submission.

What gets recorded without you typing it

When you submit the form, six things are attached to your submission on the server: your IP address, your browser's user-agent string, the page you submitted from, the time, a session identifier for that visit, and the Turnstile result, the one word described under Cloudflare below. The IP address is there to rate-limit the form, which is what stops it being used as a spam relay. It is capped at three submissions per address every ten minutes.

Also attached is how you found the site: campaign tags in the link you clicked (the utm_ parameters), advertising click identifiers if you arrived from an ad (Google, Microsoft, Meta, or LinkedIn), the site that referred you, and the first page you landed on. This is an allowlist of sixteen named values, each truncated at 200 characters. Nothing else from the address bar is stored.

Before you submit anything, that same arrival information is held in your own browser, in localStorage under the keys vo_attr_first and vo_attr_last, and it expires after 90 days. A page-view identifier lives in sessionStorage as vo_session_id and disappears when you close the tab. If you never get in touch, that information never leaves your browser, and clearing your site data removes it.

The services this passes through

These are the only third parties involved, and each one is here because the site needs it to work.

Supabase

The database that stores form submissions, hosted in the United States. This is where your details live.

Resend

Sends Ventus Optera the notification email when the form is submitted. Your submission is in the body of that email, and your address is set as the reply-to, so the reply goes to you directly.

Cloudflare

Hosts the site itself and serves every page you load, so it processes the standard web-server request data in the course of delivering them.

On the contact form, Cloudflare also runs Turnstile, a check that the form is being sent from a person's browser rather than by a script. It runs in the background when the page loads and shows a check box only if it can't tell. It reads signals from your browser to decide, under Cloudflare's own privacy policy. When you send the form, the site asks Cloudflare to confirm the check and passes along your IP address with it. The site receives one word back, such as "pass", and that word is stored with your submission.

The Google Ads tag loads on every page and sets a cookie, so that a click on an ad can be matched to a later submission or booking. If you submit the contact form, I send Google a one-way SHA-256 hash of the email address (and phone number, if you gave one) you provided, hashed in your browser before it ever leaves the page, so Google never receives it in plain text. This is Google's "Enhanced Conversions" feature, and its only purpose is to help Google Ads tell which ad, if any, led to a real submission. It draws on the same fields described above under what you hand me on purpose, and is not a separate list: it is one more place ad-measurement data goes, alongside the advertising domains already contacted from these pages as part of measuring whether an ad worked. Retention of that hash follows Google's own policy, not mine, the same as the rest of this section.

PostHog

Product analytics, United States region, on an account belonging to Ventus Optera alone. Two settings here were chosen on purpose, and neither is a default. Session replay is disabled in the code, so there is no recording of your screen. Automatic event capture is restricted to links and buttons, which puts form inputs structurally out of its reach. Both are set by the page's own code rather than left to a setting in the PostHog account, so they apply regardless of how that account is configured.

Heatmaps are switched on, also in the page's code. PostHog records where on a page you click and where the pointer moves, as coordinates on the screen, so I can see which parts of a page draw attention. A heatmap covers the whole page, so it includes clicks inside the contact form, but it records a position only: not which field it was, and not what you typed.

Until you contact Ventus Optera, PostHog knows your visit only by a random identifier. When you send the contact form, that visit history is linked to the name and email you gave, and the random identifier is stored with your submission so the two can be matched later. The same happens if you book a call and Cal.com passes your email back to the page. Two more things are recorded as you browse: how far down a page you scroll (25, 50, 75 or 100 percent), and, if you start the contact form and leave without sending it, the name of the last field you were in. What you typed is never part of it.

Cal.com

Runs the scheduler on the Schedule page. If you book a call there, the name, email, and time you give it are entered directly into Cal.com's own booking form, embedded on this page but hosted and processed by Cal.com rather than by Ventus Optera. The booking appears on Ventus Optera's calendar, and what you typed into that form is not stored separately. Attached to the booking, visible only to Ventus Optera, is the same arrival information described above under what gets recorded without you typing it: how you found the site, and the advertising click identifier if you arrived from an ad. That is what lets a booking be credited to the ad that produced it. It comes from the same allowlist of values, plus the random PostHog identifier for your visit, so the booking can be matched to it.

Google Fonts

Serves the typefaces the site is set in, which means Google receives the request for them, including your IP address.

Figma

The portfolio embeds design previews from Figma. Those load only on pages that contain one, and only when you open them.

How long I keep it

Form submissions are kept indefinitely, until you ask me to delete them. I would rather say that than name a period I have not built anything to enforce. If that changes, this page changes with it. Analytics data follows the retention settings of Google Ads and PostHog respectively.

What you can ask me to do

Email michael.obrien@ventusoptera.com and I will tell you what I hold on you, correct it, or delete it. I am not going to make you prove a jurisdiction first. There is one person to ask, and asking is the whole process.

Independently of me, you can turn most of the measurement off yourself. Any modern browser will block or clear cookies and site data per site. A Do Not Track or Global Privacy Control signal sent by your browser is honored to the extent the services above act on it, which is a limit I can describe but cannot enforce for them.

Security, and what this page won't claim

The site is served over HTTPS with a content security policy that restricts which outside domains a page may contact at all. The form posts to a server-side function rather than exposing the database, submissions are validated and rate-limited before anything is written, and access to the stored data is Ventus Optera's alone. None of this makes it impossible to breach, and no honest policy could say that about anything connected to the internet.

Children

Ventus Optera works with businesses. The site is not directed at children under 13, and Ventus Optera does not knowingly collect anything from them. If you believe a child has submitted the form, email the address below and the record will be deleted.

Changes to this policy

If what the site does changes, this page gets updated and the effective date at the top moves. You won't be notified individually, so the date is how you tell.

Who to contact

Ventus Optera, LLC. Michael O'Brien, michael.obrien@ventusoptera.com. That is a personal inbox, with no ticket queue in front of it.