Privacy Policy
Last updated: August 21, 2026
This policy explains what personal information Simple Cipher collects, why, how it is protected, and how to have it deleted. It covers both this website and the consulting, integration, and software services Simple Cipher provides.
1. Who we are
Simple Cipher is a technology consulting practice operated by Simple Cipher Corp ("Simple Cipher", "we", "us"), based in Denver, Colorado.
- Email: john@toprockco.com
- Mailing address: 1900 N Grant Street, Suite 510, Denver, CO 80203
- Data controller contact: John Galloway
2. Information collected through this website
This website is a static informational site. It does not use cookies, advertising trackers, analytics scripts, or third-party embeds, and it has no forms, logins, or accounts.
Our hosting provider (Amazon Web Services) records standard server logs when a page is requested, which may include IP address, timestamp, requested URL, referring page, and browser user agent. These logs are used solely for security monitoring and diagnosing service problems. We do not use them to build profiles of visitors.
If you email us, we receive the contents of your message along with your email address and any information you choose to include.
3. Information collected in the course of providing services
When you engage Simple Cipher as a client, we collect the information needed to perform the work: your name, business contact details, the identity of the systems we are asked to work with, and any material you send us.
4. Data accessed through third-party integrations
Part of our work involves connecting systems that our clients already use โ customer relationship management (CRM) platforms, transaction management software, accounting systems, business planning tools, and real estate listing data services.
When we access such a system on a client's behalf, the following apply without exception:
- Authorization first. We access an account only after the account holder has explicitly authorized it, through that platform's own authentication flow or an equivalent documented grant. We do not use scraping or credential sharing to obtain data that an API is intended to gate.
- Least privilege. We request the narrowest permission scopes that will accomplish the agreed task, and no others.
- Purpose limitation. Data retrieved through an integration is used only to deliver the service the client asked for. It is never repurposed.
- No sale of data. We do not sell, rent, license, or trade client data or data obtained through any integration, to anyone, for any purpose.
- No use in model training. We do not use client data or integration data to train, fine-tune, or otherwise improve machine learning models, whether our own or a third party's.
- Respect for upstream terms. Data obtained from a third-party platform is handled in accordance with that platform's developer terms and any applicable licensing agreement, including the participation and display rules that govern multiple listing service (MLS) data.
- Revocable at any time. A client may revoke our access at any moment through the platform's own settings, or by asking us to do so. Revocation is honored immediately.
5. How information is used
We use the information described above only to deliver and support the services requested, to communicate with you about that work, to invoice and maintain business records, and to meet legal and tax obligations.
We do not use personal information for advertising, and we do not engage in automated decision-making that produces legal or similarly significant effects.
6. Sharing and service providers
We do not sell personal information. We share it only in these situations:
- Service providers that operate our infrastructure, strictly as needed to run it โ currently our web host and email provider. They are bound to confidentiality and may not use the data for their own purposes.
- At your direction, such as when you ask us to deliver a result to a colleague or another system.
- Legal requirement, where disclosure is compelled by law, subpoena, or valid legal process.
7. Retention and deletion
We retain client information for the duration of the engagement and afterwards only as long as needed for legitimate business and legal purposes, such as tax and accounting records.
Data obtained through an integration is retained only as long as the service requires. On request, or on the conclusion of an engagement, we delete it. Server logs are retained for a limited operational period and then discarded.
To request deletion, email john@toprockco.com. We will confirm completion in writing.
8. Security
Credentials and access tokens are stored encrypted, never committed to source control, and never transmitted over unencrypted channels. Access is limited to those performing the work. This site is served exclusively over HTTPS. No system is perfectly secure, but if a breach affecting your personal information occurs, we will notify you and any required authority without undue delay.
9. Your rights
Depending on where you live, you may have the right to access the personal information we hold about you, correct it, delete it, obtain a portable copy, object to or restrict certain processing, and withdraw consent. Colorado residents have these rights under the Colorado Privacy Act; residents of other jurisdictions may have comparable rights.
Exercise any of them by emailing john@toprockco.com. We respond within 45 days and will not discriminate against you for making a request.
10. Children
Our services are intended for businesses and professionals. We do not knowingly collect personal information from anyone under 18. If we learn that we have, we will delete it.
11. International visitors
Simple Cipher operates in the United States, and information is processed there. If you contact us from outside the United States, you are sending your information to the United States, where privacy laws may differ from those in your country.
12. Changes to this policy
If this policy changes, the revised version will be posted here with an updated date. Material changes affecting existing clients will be communicated directly.
13. Contact
Questions or complaints about privacy: john@toprockco.com, or by mail at the address in Section 1.