Effective August 23, 2026
Privacy Policy
This policy describes the request form on Saint Augustine Radon Pros, an independent informational and lead-introduction website.
Information the form collects
The owner-review form requires a name, email address, request type, project description and explicit contact consent. A phone number, project ZIP and existing radon result are optional. Do not submit medical history, smoking status, payment information or another person’s contact details.
Security verification
The form uses a property-specific Cloudflare Turnstile Managed widget. When the form is used, Cloudflare’s browser script and challenge frame process network and device signals such as the IP address, user agent, timing and interaction information under Cloudflare’s own privacy terms. The Worker sends the short-lived token and, when Cloudflare supplies it, the client IP directly to Cloudflare Siteverify. The Worker requires this site’s exact hostname and action. It does not store, log or email the Turnstile token or secret.
How a request is handled
After verification, the Worker writes one immutable private R2 receipt containing the lead, exact consent text and version, consent timestamp, verification metadata and request metadata before attempting email. It then sends a plain-text notification from this property’s fixed sender to contact@staugustineradon.com in Microsoft 365. The request is not automatically routed to contractors. Cloudflare’s acceptance of that notification does not prove inbox delivery, and a submission does not guarantee a response, provider introduction, quote, test or appointment.
The consent and delivery record
The combined receipt records the exact checkbox text, consent version, affirmation and timestamp. The current consent version is st-augustine-radon-owner-review-v3-2026-08-23. A separate immutable delivery or delivery-failure marker may record the notification outcome. The exact consent text appears beside the unticked checkbox before submission.
IP hashing and abuse prevention
The application never stores or emails a raw IP address. When Cloudflare provides a client IP, the Worker combines it with this property’s private salt and stores only a one-way hash in the receipt while using the same property-prefixed hash for two short rate-limit stages. When the IP is unavailable, the Worker skips the shared limiter buckets rather than grouping unrelated visitors together. The hash follows the receipt’s retention period and changes when the property salt is rotated.
Analytics and platform telemetry
The public site has no marketing analytics, advertising pixels, session recording, chat widget or Cloudflare Web Analytics beacon and sets no site analytics cookies. Automatic invocation logs and traces are disabled. The Worker’s application-emitted log fields are limited to event type plus the applicable operational stage and, after assignment, request ID. They exclude visitor fields, raw IP addresses, IP hashes, Turnstile tokens and secrets and follow the Cloudflare account’s Workers Logs retention setting. Cloudflare may add timestamp, script and request metadata or retain runtime errors and still processes ordinary edge, security, DNS and service metadata under its platform practices; those platform records are separate from this application’s R2 receipt.
Service providers and disclosure
Cloudflare hosts the site, provides Turnstile and rate limiting, privately stores the R2 records and accepts the notification for delivery. Microsoft 365 receives the notification in the property mailbox. Request information may therefore appear in that mailbox. Information may be disclosed when legally required or to protect the site from abuse. It is not automatically distributed to providers or published.
Retention and deletion
Private lead, consent, hashed-IP, delivery and delivery-failure records follow this property’s documented operating and evidence-retention policy and are scheduled to expire after five years (1,825 days). This period is an operating policy, not a claim that one period satisfies every law. Microsoft 365 mailbox copies require separate handling. To request access or deletion, email contact@staugustineradon.com or choose “Make a privacy or deletion request” on the form and describe what should be located. Identity may need to be verified; legal or security obligations may require limited retention.
Children and policy changes
This site is for adults making property decisions and is not directed to children. This policy may be updated when practices change; the effective date will be revised.
Privacy contact
Email contact@staugustineradon.com or use the same owner-review form and select the privacy request type.