Rosson & Associates · effective 21 September 2026
We never receive your card details
Payment is completed on Stripe's own hosted page, or with a single-use payment token scoped to this business. Card numbers, security codes and bank details never reach our servers and are never stored by us. Free-text fields are screened, and a submission containing something that looks like a card number is rejected outright rather than saved.
What we collect
- Your name and email address — to schedule the session and send the invitation.
- The session time you chose, and any notes you provide about what you want to discuss.
- Payment metadata from Stripe — the payment and checkout identifiers, amount, currency and status. Not card data.
- Timestamps and an audit record of the booking, payment, cancellation and refund, for accounting and dispute evidence.
- Ordinary web server logs (IP address, user agent, requested URL, timestamp), used for security and abuse prevention.
Why we hold it
To schedule and deliver the session you paid for, to take and refund payment, to apply the published refund policy, to keep the business and tax records we are required to keep, and to defend a payment dispute if one is raised.
Who it is shared with
| Who | What they get | Why |
|---|---|---|
| Stripe, Inc. — privacy policy | Your email address, the amount, and your payment details, which you give directly to them | Processing the payment and any refund |
| Microsoft (Microsoft 365, Teams) — privacy statement | Your name and email address as a meeting attendee, plus the meeting itself | Sending the calendar invitation and hosting the Teams meeting |
That is the complete list. We do not sell your information, do not share it with advertisers or data brokers, and do not use it to market anything to you unless you separately ask to hear from us.
If an AI agent books on your behalf
This service can be booked directly by an AI assistant acting for you. In that case the assistant sends us only your name, email address, chosen time and any notes, together with a payment credential that is scoped to this business, capped to the session price, and usable once. We do not receive your card details through that route either, and the assistant does not receive them from us.
How long we keep it
- Booking and payment records: retained for as long as tax and accounting rules require, then deleted.
- Calendar invitations: removed when a booking is cancelled; past sessions remain on the business calendar as a record of work done.
- Web server logs: rotated and discarded on a short cycle.
Your choices
Email marc@rosson-associates.com to ask what we hold about you, to correct it, or to ask for it to be deleted. We will do so except where a transaction record must be kept for tax purposes, and we will tell you if that applies.
Security
Traffic is encrypted in transit. Card data is out of scope because we never hold it. Access to booking records is limited to the proprietor. Payment notifications are cryptographically verified before they are acted on, and the booking endpoint is rate limited.
Where we are
Rosson & Associates is a consulting practice based in Washington State, USA, and the information described here is processed in the United States.
Changes
If this policy changes materially, the effective date above changes with it.