Skip to content
Creative AI Solutions

Legal Compliance

Privacy Policy

Last Updated: August 28, 2026

1. Introduction and Scope

This is the privacy policy for caismd.com, the website of Creative AI Solutions (“we”, “us”, or “our”). It covers the whole site: the free scorecard, the diagnostic behind it, the guides, our contact form, our booking page, and the emails we send you as a result of using any of them.

This Privacy Policy describes how we collect, use, store, share and protect your information when you take the free scorecard, submit a form, book a call, or otherwise use the site.

2. Data We Collect

What we collect depends on what you do on the site. Each item below is listed against the place it comes from.

The free scorecard

  • Contact Information: your email address and first name, which we need to send you your result. Your last name and phone number, if you choose to give them.
  • Business Details, all optional: business name, website, location, number of employees, years in business, how soon you want to act, an approximate budget, and a short description in your own words of the main thing you want fixed.
  • Scorecard Answers: your answers to up to eleven multiple-choice questions about how your business runs, plus three figures you give us yourself: your typical job or order value, roughly how many enquiries you get in a week, and roughly how many hours a week go on admin. If you adjust the assumptions the estimate uses, we record the adjusted values too.
  • What We Generate From Those Answers: a monthly cost estimate, the arithmetic behind it (each component of the estimate, the figures it was built from, and the assumptions applied), and the ranked list of builds your answers point to. All of it is calculated by a fixed formula from what you entered. There are no per-area or per-category scores: we do not compute them.
  • Your Follow-Up Preference: whether you ticked the box that says it is fine for us to follow up with you. The box is optional and you get your result either way. Section 3 explains what ticking it allows.
  • Campaign Attribution: if you arrive from an ad or a link carrying campaign parameters (utm_source and similar), we keep those parameters, the page you landed on, and the referring address, so we can tell which ad or article brought you here.

A part-finished scorecard

From the first question onward we save your answers so far against a random session id, so that a reload, a switch of browser, or a link reopened from a message does not send you back to the start. Once you enter your email address at the result step, it is saved with that session as well, along with your follow-up preference. Sessions are deleted automatically 30 days after you last touched them.

The contact form

Your name, email address, the topic you choose, your message, and your business name and phone number if you give them. We also record the IP address, browser identifier and referring page the message was sent from, so that we can spot abuse of the form. We use what you send to answer you, and only for that.

Booking a call

The booking itself happens inside Cal.com (section 4). On our side we record that a booking took place, as a count, together with the campaign parameters described above. We do not store the details of the booking in our own database.

Abuse prevention

To stop automated abuse of our forms we keep short-lived counters keyed by IP address and, for form submissions, by email address. They exist only to count requests within a short window and are deleted within hours. Our hosting provider also keeps ordinary server logs, which include IP addresses, as every host does.

The funnel counter

A plain tally of how many people reach each step of the scorecard and how many go on to book a call, split by campaign. It contains no name, email, IP address or device identifier, which is why it runs without asking for consent. Section 3 of our Cookie Policy explains it in full.

3. Why We Process It

We use your data to do what you asked for, and for a small number of things around it. Where the GDPR applies to you, the legal basis for each is given in brackets.

  • To calculate and show you your monthly cost estimate, the arithmetic behind it, and the builds your answers rank highest (performing the service you requested).
  • To email you that result, so you keep it whether or not we ever work together (performing the service you requested).
  • To schedule a free consultation if you book one (performing the service you requested).
  • To notify the CAIS team of a new scorecard result or contact message so a person can follow up (our legitimate interest in running the business).
  • Only if you ticked the follow-up box: to send you one reminder if you entered your email but left the scorecard unfinished (a single email, roughly 24 hours later, never a sequence), and to follow up about your result, including practical suggestions and the build we would start with. Every one of those emails carries a working way to stop them (your consent, which you can withdraw at any time).
  • To measure, in aggregate, whether the site works, and, if you accepted analytics or advertising cookies, to understand which pages and which ads bring people here (our legitimate interest for the aggregate count; your consent for the rest).
  • To protect the site and our forms against abuse (our legitimate interest).

We do not run a newsletter or a mailing list. If we ever start one, it will be a separate, clearly labelled opt-in, and ticking the follow-up box today will not put you on it.

4. Third-Party Data Processing

To run the site we share relevant portions of your data with these subprocessors:

  • Vercel: hosts the site and runs the code behind it. Like every host, it keeps ordinary server logs, including IP addresses, for security and operations.
  • Firebase and Cloud Firestore (Google): our database. This is where your scorecard record, any part-finished session, your contact form message, and the counters described in section 2 are stored.
  • Resend: sends your result to your inbox, the reminder and follow-up emails described in section 3, and the alert that tells the CAIS team a new enquiry has arrived.
  • Twilio: when a scorecard result marks an enquiry as high priority, a text message goes to a member of the CAIS team so someone can get back to you quickly. That message contains your business name, your name, your phone number, your email address and the budget you stated. It is sent to our own phone, through Twilio.
  • Google reCAPTCHA v3: protects the scorecard and the contact form from bots. When you use either form, Google’s reCAPTCHA script loads, may set a cookie called _GRECAPTCHA, and sends information about your browser and your IP address to Google, which returns a score we use to decide whether a submission is likely automated. Google’s Privacy Policy and Terms of Service apply to that processing. We do not use reCAPTCHA for advertising.
  • OpenRouter (AI model routing): your scorecard result is not written by an AI model. It is calculated by a fixed formula from your answers, and the same inputs always produce the same result. OpenRouter is used in one place only: our internal dashboard, when a member of the CAIS team asks for an AI-written follow-up brief about an enquiry before contacting you. In that case your business name if you gave one, website, location, employee count, years in business, stated challenge, budget and timing, your scorecard answers and your estimate are sent through OpenRouter to the model that drafts the brief. We do not send your name, your email address or your phone number. If nobody on the team requests a brief, nothing about you is ever sent to OpenRouter.
  • PostHog Analytics: we use PostHog to analyze user paths and form engagement. PostHog is off by default and loads only if you accept analytics cookies in the consent banner.
  • Google Analytics 4: measures which pages and which ads bring people to the site. Its script loads for every visitor, but it starts in a cookieless mode: until you accept analytics cookies it sets no cookies, stores no identifier, and sends Google only a cookieless ping that lets it estimate visit counts. Accepting analytics cookies switches it to full measurement.
  • Meta (Facebook and Instagram): our ads run on Instagram and Facebook, and the Meta pixel tells us which ad a visit came from. The pixel loads only if you accept advertising cookies. If you have accepted them and go on to book a call, we also tell Meta from our server that a booking happened, sending a hashed (SHA-256) version of your email address so Meta can match the booking to the ad you clicked. If you have not accepted advertising cookies, the pixel never loads and nothing about you or your booking is sent to Meta by either route.
  • Cal.com: if you book a free consultation, the name, email and any note you type go to Cal.com so it can create the appointment, together with the campaign parameters from the link you arrived on. Cal.com then tells our server that a booking was made, which is how the count in section 2 is kept.

5. Storage, Retention, and Security

Your data is held in Cloud Firestore, in US-based Google Cloud data centres. We implement appropriate technical and organizational measures to safeguard it: HTTPS/TLS encryption for all data in transit; Firestore security rules that deny direct client access to every collection, so records can be read or written only by our own server, using a service account through the Firebase Admin SDK; an admin dashboard behind authentication and a separate short-lived server session cookie; and rate limiting on the public API routes.

How long we keep each thing

  • Scorecard records and contact form messages: a maximum of 24 months, after which they are deleted or anonymized, unless a longer retention period is required for an active client relationship or by law.
  • Part-finished scorecard sessions: 30 days after your last activity, automatically.
  • Abuse-prevention counters: within hours of the window they cover.
  • The funnel counter and the shareable result page: contain no personal data and are kept for as long as we need them.

Where your data goes

Our servers and every subprocessor in section 4 are in the United States. If you use the site from the EU, the UK or anywhere else, your data is transferred to and processed in the United States. Where the GDPR applies, we rely on your consent for the optional processing described in section 3 and on the contractual protections our subprocessors provide for the rest.

6. Your Privacy Rights (MODPA, GDPR and CCPA)

You have rights over the information we hold about you. Which law gives you those rights depends on where you live, but every request we receive goes through the same process, wherever it comes from.

Maryland residents: the Maryland Online Data Privacy Act (MODPA)

Creative AI Solutions is a Maryland business, based in Annapolis, Maryland. If you are a Maryland resident, you can ask us to do any of the following:

  • Confirm and give you access: tell you whether we hold personal data about you, and let you see it.
  • Correct it: fix anything we hold that is wrong, out of date or incomplete.
  • Delete it: erase the details you gave us and the scorecard answers attached to them.
  • Give you a copy you can take elsewhere: send you your data in a portable, readily usable format.
  • Tell you who we shared it with: list the categories of third parties we have disclosed your personal data to.
  • Stop targeted advertising: stop your information being used to target ads at you.
  • Stop any sale of your personal data: see the plain-English note below on what we do and do not do here.
  • Stop profiling: stop us using automated processing to make decisions about you that would have a legal or similarly significant effect.

None of this costs anything, and we will not treat you worse for asking. You keep your result either way, the service does not get slower or smaller, and the price of anything we later quote you does not change.

Being straight with you about advertising, sale and profiling

We do not sell your personal data for money, and we do not sell it to data brokers. We do advertise on Instagram and Facebook, and if you accept advertising cookies, information about your visit is shared with Meta so we can tell which ad worked. Some privacy laws, including MODPA and California’s, treat that kind of sharing as a “sale” or as “targeted advertising” even though no money changes hands. So here it is plainly:

  • Advertising and analytics cookies are off unless you turn them on. If you close the banner, choose “Essential Only”, or do nothing at all, you are already opted out.
  • If your browser sends a Global Privacy Control signal, we treat it as a standing opt-out from analytics and advertising cookies. You will not see the banner, and nothing non-essential loads. You do not have to do anything else.
  • You can change your mind at any time by clearing this site’s data in your browser, after which the banner asks again, or by emailing us and asking us to record your opt-out.
  • To stop follow-up emails, reply to any of them with “Unsubscribe”, use the unsubscribe link in the email, or email us. Stopping emails does not affect your result.
  • We do not use automated profiling to make decisions that have a legal or similarly significant effect on you. Your scorecard result is an estimate and a set of suggestions. No automated system decides whether you can buy from us, at what price, or on what terms.

How long we keep your data

We keep scorecard data for a maximum of 24 months, after which lead details are deleted or anonymized, unless a longer period is needed for an active client relationship or required by law. Section 5 above sets this out in full, item by item. You do not have to wait 24 months: ask us to delete it and we will.

If you are in the EU, the UK or California

The rights above cover most of what the GDPR and the CCPA/CPRA give you. On top of them, the GDPR lets you object to processing or ask us to restrict it, and lets you withdraw consent at any time without affecting anything we did before you withdrew it. The CCPA/CPRA lets you ask what categories of personal information we collected and why, opt out of the sale or sharing of personal information, and limit the use of sensitive personal information. California residents also have the right not to be discriminated against for exercising any of these rights.

How long we take, and what happens if we say no

We aim to answer a verified request within 30 days. If a request is complicated we may take one extension, up to the further 45 days the law allows, and we will tell you before we do rather than going quiet on you.

If we refuse a request, we will tell you in writing why, and how to appeal. You have the right to appeal. Reply to our refusal, or send a new message with “Appeal” in the subject line, to the address in section 7. We will review the decision and give you a written answer within 60 days explaining our reasoning. If we still refuse after that appeal, we will give you a link you can use to submit a complaint to the Maryland Attorney General’s Consumer Protection Division.

7. How to Make a Data Request

There are two ways to reach us, and both go to the same people. You do not have to be a customer.

Tell us what you want us to do (see it, correct it, delete it, send you a copy, or opt you out) and the email address you used when you took the scorecard, so we can find your record. We may ask you one question to check you are who you say you are. We will not ask you to send a copy of your ID or any document we do not need.

Someone can make a request for you. If an authorized agent contacts us on your behalf, we will ask for proof that you authorized them before we act.

8. Children

This site is for businesses and the people who run them. It is not directed at anyone under 18, and we do not knowingly collect personal data from anyone under 18. If you believe we have, email us at the address in section 10 and we will delete it.

9. Changes to This Policy

When what we do with your data changes, this page changes with it, and the “Last Updated” date at the top is revised. If a change would let us use data you have already given us in a way you did not agree to at the time, we will ask you first rather than rely on the new wording.

10. Contact Information

If you have questions about this Privacy Policy, your rights, or wish to make a request, please contact us:

Creative AI Solutions

Annapolis, Maryland

Email: info@caismd.com

Website: caismd.com

A note on what this page is

This page explains what we do with your information and what you can ask us to do about it. It is not legal advice, and it is not a legal opinion on whether MODPA, the GDPR or the CCPA formally apply to us. Those laws switch on at thresholds that depend on how much personal data a business handles in a year, and only we can confirm our own numbers. We have written the rights above as commitments we intend to honor whether or not a threshold is met. If you are relying on this page for your own compliance work, have a lawyer check it.