Legal · Privacy

Privacy Policy.

Redoubt Fastener Co. operates a public marketing and due-diligence site. This page describes the personal data we collect through the site, how we use it, who we share it with, how long we retain it, and the rights you can exercise. For data-access, correction, or deletion requests, email the address below.

Effective 2026-08-01
Public · no login required
1 · Data we collect

Site telemetry and contact intake.

We keep the personal-data surface narrow: anonymous page-visit telemetry, a single browser-side visitor identifier, and the data you submit through our contact forms. We do not run advertising pixels, third-party trackers beyond Google Analytics, or fingerprinting beyond what GA4 already performs.

Site telemetry — Google Analytics 4

The GA4 loader (G-F2Z3PRXPSK) is loaded after the page is interactive. It reports a GA4 client-id, page-view, and referrer to Google on every page view. Data is transferred to Google for processing; Google operates as the data processor for that telemetry.

  • Identifiers: GA4 client-id, page-view, referrer.
  • Transfer: https://www.google-analytics.com (US-region processing).

Site telemetry — platform visitor beacon

A small client script fires a per-page-load beacon against the platform’s analytics endpoint. It generates a crypto.randomUUID() visitor id on first visit and stores it in the browser’slocalStorage under the key polsia_vid.

  • Identifiers: visitor id, page slug, page-load event.
  • Storage: localStorage, per-visitor, unset on site-data clear.

Contact-form submissions

Site visitors who submit a contact form (general inquiry, material sample request, or Series A NDA request) send the fields of the relevant form to POST /api/contact. Submissions are reviewed by the company and routed to the appropriate internal team. The payload shape for each kind is broken out below.

Cookies

The site does not set authentication cookies; there is no login on the public site. Google Analytics sets its standard cookies (_ga,_ga_*) to disambiguate sessions and users. The platform visitor beacon stores a single localStorage entry rather than a cookie.

  • App-set cookies: none.
  • Third-party cookies: GA4 (_ga, _ga_*).
  • Browser storage: one localStorage entry (polsia_vid).

Telemetry identifier reference

A copy-paste-able list of every measurement identifier that appears on the site, so a reviewer can match this disclosure to the live scripts in the page source.

SourceIdentifierNotes
Google Analytics 4G-F2Z3PRXPSKLoaded by next/script (afterInteractive). Reports a GA4 client-id, page-view, and referrer to Google.
Platform visitor beaconlocalStorage key: polsia_vidA crypto.randomUUID() visitor id is stored in the browser and reused across page loads.
GA4 cookies_ga, _ga_*Set by Google Analytics on the visitor’s browser to disambiguate sessions and users.
2 · Contact intake

What POST /api/contact collects.

The POST /api/contact endpoint accepts three payload shapes, dispatched on the body’s kind field. The two structured kinds are written alongside a parent contact-message row in a single transaction so the routing team can filter submissions by kind.

kind: sample-request

Material sample request

Captured for engineering and operations to evaluate a material sample for a qualified program.

Fields captured
  • Name
  • Email
  • Organization (optional)
  • CAGE code (optional)
  • Part description
  • Material grade
  • Quantity
  • Target delivery date
  • Ship-to address (line 1, line 2, city, state, postal, country)
  • Notes (optional)
kind: nda-request

Series A NDA intake

Captured for investor relations to route a mutual-NDA request to the right legal contact.

Fields captured
  • Name
  • Email
  • Organization (optional)
  • Title (optional)
  • Representing firm
  • Fund stage
  • Check size
  • Timeline
kind: (any other)

General inquiry

Captured for the team to triage. Includes the contact-form module, the DFARS quote form, and the product inquiry form.

Fields captured
  • Name
  • Email
  • Message
3 · Third-party processors

Who we share data with.

The set of organizations that receive personal data from this site is small. Each is listed below along with the data shared.

Google Analytics

Site-visit telemetry (GA4 client-id, page-view, referrer) is reported to https://www.google-analytics.com on every page load. Google operates as the data processor for that telemetry.

Stripe Connect (payment processing)

When and if payment flows are enabled on this site, payment data is handled by Stripe. The stripe-billing module is not currently installed; this disclosure is conditional and accurate. The site does not collect card numbers today.

Beyond Google Analytics and any future payment processor, we do not share submission data with third parties. The platform that hosts this site may transit request metadata (IP address, user agent, request path) to its own infrastructure for security and rate-limiting; that data is not used for advertising or profiling.

4 · Retention

How long we keep data.

Retention follows the principle of keeping data only as long as we have a defensible reason to keep it. The defaults below apply unless a specific legal, tax, or audit obligation requires otherwise.

Contact submissions

Retained while the relationship is commercially active and thereafter for the period required by applicable tax, audit, and corporate-records obligations. Operational retention periods are set by the company and not enumerated here.

Google Analytics 4 telemetry

Retained on Google’s infrastructure per Google Analytics 4 default retention settings (currently 14 months for event data). Google’s retention controls govern event-level data; user-id and traffic-source dimensions follow their own defaults.

Platform visitor beacon

A visitor id is stored in your browser’s localStorage under the key polsia_vid. It persists until you clear site data or browser storage; clearing site data immediately invalidates it.

5 · Your rights

Access, correction, deletion.

You can ask us to do any of the following with the personal data we hold that is attributable to you. We respond within a reasonable timeframe; the contact for both requests is below.

Request access

Ask for a copy of the personal data we hold that is attributable to you — contact submissions, identifiers tied to your email, and any structured-sample or NDA intake you submitted.

Request correction

Ask us to correct inaccurate or out-of-date personal data associated with a submission. Reasonable requests are honored within a reasonable timeframe.

Request deletion

Ask us to delete your submission data. We retain what we are required to keep (tax / audit / corporate-records) and delete the rest.

6 · Contact for data requests

How to reach us.

For data-access, correction, or deletion requests (and any privacy-related question), email us. Include enough context for us to locate your submission — typically the email address you submitted with and the kind of form (sample-request, nda-request, or general inquiry).

Effective: 2026-08-01.

Last reviewed: 2026-08-01.