Worthy
Services Contact

Legal

Privacy Policy

This policy explains what Worthy collects when you use this site, why we collect it, how long we keep it, and what you can ask us to do with it. It reflects how the site actually works — not a generic template.

Last updated August 31, 2026

Who we are

Worthy is operated by Esposito Enterprises LLC d/b/a Worthy, based in New York, United States. We build and maintain websites for our clients. For the purposes of this policy, we are the business responsible for the personal information described below.

If you have a question about anything here, or want to exercise any of the rights in this policy, email us at [email protected]. A real person answers.

What we collect

We only collect information you give us, plus the minimum our servers need to run the site securely. We do not buy personal information from third parties.

When you send an enquiry

The contact form asks for your name and email address, and optionally your phone number, company name, project type, budget range, timeline, and the message you write. Everything past your name and email is optional — leave it blank and the form still works.

When you create an account

We store your email address, a display name if you set one, and a hash of your password. We store a hash, not the password itself, so nobody at Worthy can read your password. Signing in always requires a code we email you, so we also store that code — hashed, and only until it is used or expires. If you sign in with Google, we store the identifier that service uses to recognize you. We also record whether you want email about your tickets and projects, which you can turn off in your account settings.

When you open a support ticket

We store the ticket subject, every message on the thread, who wrote it and when, and any files you attach. Attachments are limited to PNG, JPEG and WebP images, PDFs, and plain text files. Please do not attach anything you would not want stored on our servers — do not send passwords, card numbers, or government ID through a ticket.

When we work on a project for you

We keep a project record: its title, a description, its current status, and the agreed amount. This is what lets you and we both see the state of the work in the dashboard.

Automatically

Our servers keep standard operational logs — the request made, the time, the IP address it came from, and technical details such as browser type — which we use to keep the service running and to investigate abuse or errors. If you have an account, we also store the IP address and browser description of each sign-in against that account: it is what lets us show you the list of signed-in devices in your settings, and what lets us email you when your account is used from somewhere it has not been used before. We keep a record of administrative actions taken on the service, which includes the IP address they came from, and we record failed sign-in attempts by IP address so we can shut down brute-force attacks. We do not use any of this to build a profile of you or to track you across other websites — see “Cookies and local storage” below for what we keep on your device.

Why we use it

We use the information above for these purposes and no others:

  • To answer your enquiry and give you a quote.
  • To create and secure your account, and to sign you in.
  • To run support tickets and reply to you.
  • To deliver the project you have hired us for, and to invoice it.
  • To keep the service secure — detecting abuse, debugging faults, and preventing fraud.
  • To email you about your own tickets and projects — replies and status changes. You can turn this off in your account settings. We do not send marketing email.

We do not sell your personal information. We do not share it with advertisers, and we do not use it to build advertising profiles. We run no advertising or cross-site tracking technology on this site at all.

Cookies and local storage

We set one cookie, and only during Google sign-in. Everything else we keep on your device is in your browser's local storage, and only for features that cannot work without it. We do not use cookies, local storage, or any similar technology for advertising, profiling, or tracking you across other websites.

The complete list of what we keep on your device:

  • A sign-in token, so you stay logged in between pages. Removing it signs you out.
  • A short-lived verification token during email verification or a password reset, held only until you close the tab.
  • One cookie, set only if you use “Continue with Google”. It holds a random value that lets us confirm the sign-in that comes back is the one you started, which is what stops someone signing you into an account that is not yours. It contains nothing about you, is unreadable to JavaScript, and is deleted the moment the sign-in finishes.

Analytics

We use Cloudflare Web Analytics to see which pages are visited. It is cookieless: it sets no cookies, stores nothing on your device, and does not fingerprint your browser. It gives us aggregate counts only, so we cannot identify you from it and it cannot follow you to other sites. We use no other analytics product.

Security and error reporting

Cloudflare Turnstile runs on our forms to distinguish people from bots. Sentry receives a report when something breaks, so we can fix it; we have configured it not to send cookies, IP addresses, or the contents of form fields, and we strip query strings and anything you typed before the report leaves your browser.

Your choices

We do not currently use advertising or other non-essential cookies. The cookie used during Google sign-in is necessary to securely complete the authentication process, and does not require consent where applicable law provides an exemption for strictly necessary cookies. You can clear this data at any time in your browser's settings for this site, which will sign you out. If we ever introduce a non-essential cookie, we will update this policy and ask for consent where the law requires it.

Who we share with

We share personal information only where it is necessary to run the business:

  • Service providers who host our servers, database, and email, acting on our instructions and bound to keep it confidential.
  • Google, if you choose to sign in with them — the exchange is limited to confirming your identity with that provider.
  • Professional advisers such as our accountants or lawyers, where they need it to advise us.
  • Law enforcement or a regulator, where we are legally required to hand it over or need to protect someone's safety or our legal rights.
  • A buyer or successor, if the business is sold or merged — in which case this policy continues to apply to the information transferred.

How long we keep it

We keep information for as long as it serves the purpose we collected it for, then delete it.

  • Enquiries that do not become projects: kept while we follow up, then deleted.
  • Account data: kept while your account is open.
  • Tickets and attachments: kept while your account is open, and retained after you close it as the record of work we did, unless you ask us to delete them.
  • Project and billing records: kept for as long as tax and accounting law requires us to keep them, even after your account closes.
  • Sign-in and security records: session records are removed when the session expires or you sign it out; the record of devices used to sign in is deleted with your account; failed sign-in attempts and administrative audit records are kept for a limited period for security and then deleted.

When you delete your account, we remove your password, unlink any connected sign-in services, and release your email address so it can be used again. Records we are legally required to retain, such as invoices, are kept for the required period and then deleted.

How we protect it

Passwords are stored as hashes, never in plain text. Sessions use signed, expiring tokens. Uploaded files are renamed on arrival so an uploaded file cannot overwrite anything on our servers, and we accept only a conservative set of file types. Access to production data is limited to the people who need it.

No system is perfectly secure, and we will not pretend otherwise. If a breach affects your personal information and creates a real risk to you, we will notify you and any regulator we are required to tell, without undue delay.

Your rights

You can ask us to do any of the following, at any time, by emailing [email protected]:

  • Tell you what personal information we hold about you.
  • Give you a copy of it.
  • Correct anything that is wrong — you can also edit most of it yourself in your account settings.
  • Close your account. We remove your password and any linked sign-in service and release your email address; your ticket and project history is retained as described in “How long we keep it”. Ask us and we will delete what we are not legally required to keep.
  • Stop sending you email about your tickets and projects — you can also turn this off yourself in your account settings.

We will not charge you for these requests, and we will not treat you differently for making one. We aim to respond within 30 days.

Where we operate

We are a United States business. We offer our services to clients in the United States, and we do not market or target our services outside it. Information you send us is stored and handled in the United States, which may not offer the same legal protections as another country. If you would prefer that we did not hold your information in the United States, please do not send it to us.

If you believe we have mishandled your information, we would like the chance to put it right first — email [email protected]. You may also have the right to complain to the privacy regulator in your state.

If you live in California

The California Consumer Privacy Act gives you the right to know what personal information we collect, to have it deleted, to correct it, and to not be discriminated against for exercising those rights. We do not sell or share personal information as those terms are defined by the CCPA, so there is nothing to opt out of — but the rights above are yours regardless, and the same email address handles them.

Children

This site is for people running businesses, and is not directed at children. We do not knowingly collect personal information from anyone under 13. If you believe a child has given us their information, email [email protected] and we will delete it.

Changes to this policy

If we change how we handle personal information, we will update this page and the date at the top. If a change materially affects your rights, we will tell account holders directly rather than relying on you to notice.

Worthy

Pages

HomeServicesContact

Home

WorthyOur workFAQ

Services

Pre-made websitesCustom websitesProcessPricing

Legal

Privacy PolicyTerms of Service

© 2026 Worthy. All rights reserved.