1. Who we are
House of Icon ("House of Icon," "we," "us," or "our") is a Creative House founded and operated by Brea Ballard in the United States. This policy explains how we handle personal information collected through this website.
House of Icon is the controller of the personal information described here. If you have questions about anything in this policy, reach us using the details in Section 14.
2. What we collect
We only collect information you choose to give us. We do not buy personal information, scrape it, or build profiles about you.
Information you submit
When you fill out a contact or inquiry form, request information about Brand Camp, or email us directly, you may provide:
- Your name
- Your email address
- Your phone number, if you choose to include it
- Your business or brand name
- Whatever you write in the message field
- Your consent to be contacted about your inquiry
Information collected automatically
Like nearly every website, our web host records basic technical data when a page loads. This typically includes IP address, browser type, device type, referring page, and the date and time of the visit. This is generated by the hosting infrastructure for security and reliability, and we do not use it to identify you.
What we do not collect: we do not knowingly collect Social Security numbers, government ID numbers, financial account numbers, precise geolocation, biometric data, health information, or any other sensitive category of personal information through this website.
3. Why we collect it
We use the information you provide only for the purposes you'd reasonably expect:
- To respond to you. Answering your question, scheduling a call, or sending a proposal.
- To provide our services. Delivering brand, identity, packaging, and Brand Camp work you've engaged us for.
- To keep records. Maintaining basic business records of who we've worked with and what we agreed.
- To keep the site running. Diagnosing errors, preventing abuse, and maintaining security.
- To meet legal obligations. Where a law, subpoena, or regulator requires it.
We do not sell your personal information. We do not share it for cross-context behavioral advertising. We never have, and we have no plans to.
4. Consent to be contacted
When you submit a form and indicate that you consent to be contacted, you're agreeing that we may reach you at the email address or phone number you provided, about the inquiry you made.
That consent is entirely yours to withdraw. You can do so at any time by replying to any message from us with a request to stop, using the unsubscribe link in any marketing email, or emailing us at the address in Section 14. We'll action it promptly.
Withdrawing consent doesn't affect anything we did lawfully before you withdrew it, and we may still need to contact you about an active project or contractual matter.
5. Who we share it with
We keep the circle small. Your information may be handled by:
- Service providers. Companies that host our website, deliver our email, or process form submissions. They may only process data on our instructions and may not use it for their own purposes.
- Professional advisors. Accountants or lawyers, where genuinely necessary.
- Legal authorities. Where required by valid legal process, or where necessary to protect our rights, safety, or property.
- A successor entity. If House of Icon is ever sold or merged, information may transfer as part of that transaction. We'd notify you.
That's the full list. We do not share your information with advertisers, data brokers, or marketing networks.
6. How long we keep it
We keep personal information only as long as we need it:
- Inquiries that don't become projects: up to 24 months, then deleted.
- Client records: for the length of our engagement plus up to 7 years, to meet tax, accounting, and contractual record-keeping requirements.
- Marketing contacts: until you unsubscribe or ask us to remove you.
- Server logs: typically 30 to 90 days, depending on our host's retention settings.
You can ask us to delete your information sooner. See Section 8.
7. How we protect it
We use reasonable administrative, technical, and physical safeguards appropriate to the small amount of data we hold. This includes encrypted connections (HTTPS) across the site, access limited to people who need it, reputable service providers with their own security programs, and multi-factor authentication on our business accounts.
That said, no method of transmission or storage over the internet is completely secure. We can't guarantee absolute security, and we'd rather say so plainly than imply otherwise.
8. Your rights
Wherever you live, you can ask us to:
- Access the personal information we hold about you
- Correct anything inaccurate or incomplete
- Delete your information
- Stop contacting you, or limit how we use your information
- Receive a copy of information you gave us, in a portable format
- Withdraw consent you previously gave
To exercise any of these, email us using the details in Section 14. We'll respond within 45 days (or sooner where the law requires it), and we may need to verify your identity first so we don't hand your data to someone else.
We will never discriminate against you for exercising a privacy right. Your pricing, service, and treatment stay exactly the same.
9. California residents (CCPA/CPRA)
If you're a California resident, the California Consumer Privacy Act as amended by the CPRA gives you specific rights. Here's how they map to what we do.
| Category | Do we collect it? | Source |
|---|---|---|
| Identifiers (name, email, phone, IP address) | Yes | Directly from you; server logs |
| Commercial information (services inquired about or purchased) | Yes | Directly from you |
| Internet activity (pages visited) | Limited, via server logs | Automatically |
| Sensitive personal information | No | Not applicable |
| Biometric, geolocation, health, or financial account data | No | Not applicable |
Your California rights include the right to know, the right to delete, the right to correct, the right to opt out of sale or sharing, and the right to limit use of sensitive personal information.
We have not sold or shared personal information in the preceding 12 months, as those terms are defined by the CCPA/CPRA, and we do not collect sensitive personal information. There is nothing to opt out of, but the right remains yours if that ever changes.
You may use an authorized agent to submit a request on your behalf, with written proof of authorization.
10. UK, EU, Canada & Australia
We're based in the United States, and our website is hosted on servers in the United States. If you contact us from outside the US, your information will be transferred to and processed in the US.
UK and EU visitors (UK GDPR / GDPR)
Where the UK GDPR or EU GDPR applies, our legal bases for processing are:
- Consent — where you've submitted a form and agreed to be contacted. You may withdraw it at any time.
- Contract — where processing is necessary to deliver services you've engaged us for.
- Legitimate interests — for site security and basic business records, balanced against your rights.
- Legal obligation — where the law requires us to retain or disclose information.
You also have the right to object to processing, the right to restrict processing, and the right to lodge a complaint with your local supervisory authority — the Information Commissioner's Office (ICO) in the UK, or your national data protection authority in the EU. Transfers out of the UK/EU are made on the basis of your consent or as necessary for a contract with you.
Canadian visitors (PIPEDA)
We collect, use, and disclose personal information only with your knowledge and consent, for the purposes identified in this policy. You may access your information and challenge its accuracy, and you may complain to the Office of the Privacy Commissioner of Canada.
Australian visitors (Privacy Act 1988)
We handle personal information in a manner consistent with the Australian Privacy Principles. You may request access to and correction of your information, and complain to the Office of the Australian Information Commissioner if you believe we've mishandled it.
11. Children's privacy
This website is intended for business audiences and is not directed to children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us information, contact us and we will delete it promptly.
12. Cookies & tracking
This website does not use advertising cookies, analytics cookies, tracking pixels, or third-party marketing trackers. We do not track you across other websites, and we do not build advertising profiles.
Your browser may send a Global Privacy Control (GPC) or "Do Not Track" signal. Since we don't sell or share personal information or run cross-site tracking, there is nothing for these signals to switch off — but we honor GPC signals as a valid opt-out request regardless.
If we add analytics in the future, we'll update this policy and add a consent banner before any non-essential cookies are set.
13. Changes to this policy
We may update this policy as our services or the law change. When we do, we'll revise the "last updated" date at the top of this page. If the changes are significant, we'll make that clear on the site and, where required, notify you directly. Continuing to use the site after an update means you accept the revised policy.
14. Contact us
Questions, requests, or complaints about privacy — we want to hear them.
House of Icon
Attn: Brea Ballard, Founder & Iconist
Email: hello@houseoficon.co
United States
We aim to respond to every privacy request within 45 days.
If you're unhappy with our response, you may contact your local data protection or consumer protection authority.