What Climbology collects, why, and how long it keeps it — written down so you can check it against what the site actually does. That text has not been written yet.
This page is not a privacy policy. It is the outline of one, published so the gaps are visible rather than hidden. Nothing here describes a commitment Climbology has made.
What this page has to cover.
Each section below names what is already known and what is still open. The known parts are taken from how the site is actually built, so they can be checked rather than assumed.
01
What the enquiry form collects
The form on the contact page asks for four things: a name, an email address, which level you are asking about, and a message. Sending it emails exactly those four things to Climbology and nothing else, with your address attached as the reply address so an answer comes back to you. The site itself stores no copy — there is no database behind the form — but the message does pass through the outside services named below, and it stays in Climbology’s mailbox after it arrives.
Still to settle
Who inside Climbology reads that mailbox, and how quickly.
How long a message is kept after it has been answered.
Whether anything in it is used for anything other than answering it.
02
What booking a course will collect
Booking is not built. When it is, the intended shape is a guest checkout that takes a name and an email and hands the payment to an outside provider, so card numbers are never held by Climbology at all.
Still to settle
Which payment provider, and what it sees that Climbology does not.
Whether an account is created automatically at checkout, and what that account stores.
What is kept after a course has been delivered, and for how long.
03
Who else handles it
Every outside service that touches a name or an email has to be named, because naming them is the only way a reader can check them. Three touch an enquiry today. Cloudflare hosts this site and runs the spam check on the form, which means it sees the address you connect from. Resend carries the message from the form to Climbology. Hostinger runs the mailbox it arrives in. Beyond those three, the site has no analytics, no tracking pixel and no advertising tag of any kind — a claim worth keeping true.
Still to settle
How long Cloudflare and Resend each keep what passes through them, which Climbology has not established.
The payment provider, once one is connected.
Whatever sends booking confirmations and reminders.
The content system the course pages will be managed in.
Whether any measurement is ever added, and if so what it records.
04
How long anything is kept
Retention is the part of a privacy policy people actually rely on, and the part most often left vague. It cannot be written until the booking and payment records exist and someone decides what has to be kept.
Still to settle
A period for enquiries, for bookings, and for payment records — they are unlikely to be the same.
What happens to a record when someone asks for it to be deleted.
Whether anything has to be kept for longer than Climbology would choose, and why.
05
Who to ask, and how to complain
A policy nobody can act on is decoration. This section needs an address that is monitored and answerable for a formal request — a different commitment from the enquiry address on the contact page — and Climbology has not confirmed one.
Still to settle
The address a question or a deletion request goes to.
How long a reply should take.
Where someone can take it if the reply does not satisfy them.
Where this text will come from
Not from here.
A privacy policy has to be accurate about systems that do not exist yet, and answerable by someone who can be held to it. It will be written once booking and payments are built and the business details are confirmed — not drafted to fill the space in the meantime.