Kustreba.
Privacy policy · kustreba.com.au

What this site collects and what it doesn't

There's no analytics on this site, no ad pixels, no login and no mailing list. The only thing I hold about you is what you typed into the contact form. This page sets that out in full, including the parts that aren't mine.

Last updated15 August 2026
AnalyticsNone
AccountsNone
CollectedContact form only
The short version

Four things worth knowing

If you read nothing else on this page, read this.

No analytics in the build

No Google Analytics, no Tag Manager, no Meta Pixel, no heatmaps. Nothing in this site's code is measuring you.

Nothing to sign up for

There are no accounts and no logins, so there's no profile to build. I can't tell one visitor from another.

One form, one inbox

The contact form sends your message to my email. It doesn't go on a list and it isn't used for anything else.

Never sold

I don't sell, rent, trade or share contact details for marketing. Not to anyone, not for any price.

What I collect

Four fields and a server log

The contact form is the only place this site asks you for anything. Here is every field, and why it exists.

Name — required

So I know who I'm replying to.

Email — required

So I can reply. It's the only address I'll use, and only for that conversation.

Phone — optional

Leave it blank and nothing changes. It's there for people who'd rather I called.

Message — required

Whatever you choose to tell me. Please don't send anything sensitive through a web form — health information, financial details, government identifiers. Email or a phone call is better for that.

Server logs

Like every website, the hosting server records requests as they come in: IP address, timestamp, page requested, browser and referring page. I don't read these routinely and I don't build anything from them. They exist for troubleshooting and abuse handling, and the host rotates them out on its own schedule.

A note on the honeypot

The contact form contains one hidden field that real visitors never see and never fill in. Automated spam bots do, and the submission is discarded. It's a spam filter, not a fingerprint — it collects nothing about you.

Who else touches it

The parts that aren't mine

A static site still depends on other people's infrastructure. These are the three services involved in loading this page or delivering your enquiry, and what each one sees.

Form delivery

Formspree

When you press send, the four form fields go to Formspree, which passes them straight to my inbox at mike@kustreba.com.au.

  • Sees: name, email, phone, message
  • Only on submit — not on page load
  • Servers located in the United States
Typefaces

Google Fonts

The Archivo and IBM Plex typefaces load from Google's font CDN. Your browser has to ask Google for them, and that request carries your IP address and browser details.

  • Sees: IP address, browser, page URL
  • On every page load
  • Sets no cookies
Hosting

GoDaddy

The site's files sit on GoDaddy shared hosting. Every request to this site passes through their servers and is recorded in the standard access logs described above.

  • Sees: everything in a web server log
  • On every request
  • Australian and overseas infrastructure
One thing I don't control

My host adds two of its own JavaScript files to pages served from this account — tccl.min.js and scc-c2.min.js — along with a couple of related network calls. They are injected by GoDaddy at the server, not written into this site's source, and they are used for GoDaddy's own traffic measurement.

I'd rather they weren't there. Turning the injection off is a setting in the hosting account, and it's on my list. Until it's done, you should know they load, and you should assume they can see your IP address and which pages you visited. I get no reports from them and I don't use them for anything.

Cookies

None from me

This site sets no cookies of its own. There's nothing to log into, no preferences to remember and no cart to keep, so there's nothing a cookie would be for. That's also why you don't see a consent banner — there's nothing to consent to on my side.

The host-level scripts described above are the exception, and they may set cookies of GoDaddy's own. If you'd rather they didn't, browser tracking protection or a script blocker will stop them, and nothing on this site breaks when they're blocked — the page is plain HTML and CSS and works fine without any JavaScript at all.

Where it goes, how long it stays

Kept as long as the conversation matters

Enquiries that go nowhere

If we exchange a couple of emails and nothing comes of it, the thread stays in my mailbox while it's still useful context and then gets cleared out. I do a pass on this roughly once a year.

Enquiries that become work

Once there's an engagement, the correspondence becomes a business record and I keep it for seven years, in line with standard Australian record-keeping expectations for a business.

Overseas storage

Formspree is a United States company and processes form submissions on US infrastructure. My email is also hosted on servers that may sit outside Australia. By sending the form you're accepting that your details are handled overseas. This is disclosed here rather than buried, because it's the sort of thing people reasonably want to know.

Security

Accounts holding your details use unique passwords and two-factor authentication, and the site is served over HTTPS. That's the honest extent of it — this is a one-person consultancy, not a security operations centre. No system is perfect, and I'd rather say so than imply otherwise.

Your data, your call

Ask and it's done

Email me and I'll act on any of the following, usually the same week and at no charge:

Tell me what you hold. I'll go through my mailbox and tell you exactly what's there.
Fix it. Wrong number, wrong spelling, wrong company — say so and I'll correct it.
Delete it. I'll delete the enquiry and confirm when it's gone. The only reason I'd keep anything is if it's part of a business record I'm required to retain, and I'll tell you if that's the case.

I don't require you to prove your identity through any formal process. I'll just make sure the request is coming from the address I have.

How this policy is written

Michael Kustreba Consulting is a small business and sits under the turnover threshold in the Privacy Act 1988, so it isn't legally bound by the Australian Privacy Principles. I've written this page to them anyway.

Partly because it's the right standard, and partly because a site whose whole argument is careful engineering doesn't get to skip the page that proves it. If anything here turns out to be wrong or out of date, tell me and I'll fix it.

Questions or complaints

Talk to me first

If something on this page doesn't sit right, or you think I've handled your details poorly, tell me directly. It's one person reading the inbox and I'd rather hear it than not. If you want an independent view on privacy in Australia, the Office of the Australian Information Commissioner publishes guidance at oaic.gov.au.

LocationSydney NSW, Australia
This version15 August 2026

If I change how any of this works, I'll update the page and move the date above. There's no archive of old versions — it's a one-page policy for a one-person business, and the current version is the one that applies.