Ocotillo IT LLC
Last updated: August 18, 2026
1. INTRODUCTION
Ocotillo IT LLC (“Ocotillo IT,” “we,” “us,” “our“) is an Arizona limited liability company providing managed IT services, help desk support, network and infrastructure management, cloud and Microsoft 365 services, cybersecurity and endpoint protection, backup and business continuity, and IT consulting to businesses in Arizona.
This Privacy Policy explains what personal information we collect, how we use it, who we share it with, and what choices you have.
Two different roles. It matters which one applies to you:
| Information we collect for ourselves | Information about visitors to ocotilloit.com, prospective customers, and our own customers — used to run our business. This Policy governs it. |
| Information we handle for a client | Data inside a business client’s systems that we access while delivering IT services, which may include information about that client’s own employees and customers. We handle it on the client’s instructions, and the client’s own privacy policy governs it — not this one. |
If you are an employee or customer of one of our business clients and have a question about your data, contact that business. We will support them in responding to you.
This Policy replaces our earlier website privacy policy dated July 22, 2026. That version covered the website only. This one also covers the information we handle while delivering IT services, which is the larger and more important part of what we do with data.
2. INFORMATION WE COLLECT
2.1 Information you give us through the website
Our website has one form — the contact form at ocotilloit.com/contact. It collects exactly three things:
| Field | Required |
|---|---|
| Name (first and last) | Yes |
| Email address | Yes |
| Your comment or message | Yes |
That is all the website collects from you directly. There is no account registration, no newsletter signup, no quote calculator, and no payment or checkout on the website. The form does not ask for your phone number, company name, or address.
2.2 Information you give us through other channels
If you contact us by phone or email, or become a customer, we collect what you tell us and what we need to serve and bill you:
| What | When |
|---|---|
| Phone number, company name, job title | Phone calls and email correspondence |
| Service address | Scheduling on-site work |
| Description of your IT environment or the problem you’re having | Inquiries and support requests |
| Billing name, billing address, and payment details | Becoming a customer |
| Content of your communications with us | Email, phone, support tickets |
Payment details. We do not accept payments through the website, and we do not store full credit card or bank account numbers on our own systems. Payments are processed by a third-party payment processor that maintains its own security and compliance obligations. We receive only a token, the last four digits, and the transaction result.
2.3 Information collected automatically when you visit the website
Our web host records standard server logs, as essentially every web host does:
| What | Purpose |
|---|---|
| IP address | Security, abuse prevention |
| Browser type, device type, operating system | Compatibility and troubleshooting |
| Pages requested and referring URL | Basic server operation |
| Date and time of access | Security logging |
Our website also runs login-protection software on its administrative sign-in page. When someone attempts to sign in, it records the IP address the attempt came from, the username submitted, and the date and time. This applies only to sign-in attempts, not to ordinary browsing of the website. It runs entirely on our own hosting, no third party receives this data, and we use it solely to detect and block automated attacks. We do not use it for marketing, analytics, or profiling.
We do not run website analytics. We do not use Google Analytics, Meta Pixel, LinkedIn Insight Tag, Microsoft Clarity, Hotjar, or any comparable measurement or advertising tool. We do not embed third-party fonts, chat widgets, video players, social media widgets, or advertising scripts. As of the last updated date above, our website loads no third-party scripts at all — every file it serves comes from our own domain.
We do not know who you are when you browse our website, and we do not attempt to find out.
2.4 Information we collect while delivering services
While providing IT services to a customer, we necessarily access systems that contain information. This includes device and system telemetry, event and security logs, asset inventories, user account names and email addresses, network configuration, support ticket contents, and — incidentally — files and data stored on the systems we support.
Our commitments about this information:
- We access it only as needed to deliver the services requested.
- We do not browse, review, copy, or retain customer files out of curiosity or for any purpose other than the service being performed.
- We do not use it to train artificial intelligence or machine learning models.
- We do not sell it. Ever.
- We limit access to personnel who need it, and our personnel are bound by confidentiality obligations.
2.5 Information we do not want
Please do not send us sensitive information through website forms or unencrypted email — passwords, credentials, network diagrams, security findings, Social Security numbers, protected health information, or cardholder data. If you need to share something sensitive, contact us and we’ll give you a secure method.
We do not knowingly collect information from anyone under 18. If we learn we have, we will delete it.
3. COOKIES AND SIMILAR TECHNOLOGIES
We do not use analytics cookies, advertising cookies, or tracking pixels on our website.
Our website runs on WordPress. WordPress and our caching software may set a small number of strictly functional cookies — for example, to serve the correct cached version of a page, or to keep one of our own site administrators signed in. These are necessary for the site to work, are not used to profile you, and are not shared with anyone.
| Category | Do we use it? |
|---|---|
| Strictly necessary / functional | Yes — WordPress and page caching only |
| Analytics or measurement | No |
| Advertising, retargeting, or tracking pixels | No |
| Third-party embedded content (fonts, video, chat, social widgets) | No |
No cookie banner. Because we set no analytics or advertising cookies, there is nothing to consent to or opt out of, and we do not display a cookie banner. If that ever changes, we will add a consent mechanism and update this Policy before turning anything on.
Your choices. Most browsers let you block or delete cookies through their settings. Blocking strictly necessary cookies may cause parts of the site to display incorrectly.
Do Not Track. Because we do not track you across websites, browser “Do Not Track” signals do not change anything about how we handle your visit.
4. HOW WE USE INFORMATION
We use personal information to:
- respond to your inquiries and provide quotes;
- provide, maintain, monitor, and support the IT services you’ve engaged us for;
- schedule and perform on-site and remote work;
- bill you and collect payment;
- communicate about your account, service changes, outages, security matters, and renewals;
- detect, investigate, and respond to security incidents and fraud;
- maintain records of the work we’ve performed;
- improve our services and our Site;
- comply with legal obligations and enforce our agreements; and
- send you marketing about our services, which you can opt out of at any time (see Section 7).
We do not sell personal information, and we do not share it for cross-context behavioral advertising.
5. HOW WE SHARE INFORMATION
We share personal information only as described below.
5.1 Service providers and vendors
We use third-party tools to run our business, and information passes through them.
Website vendors — named, because there are only three:
| Vendor | What it does | What it touches |
|---|---|---|
| Hostinger | Hosts ocotilloit.com | Server logs (IP address, browser, pages requested) |
| WPForms | Powers the contact form | The name, email, and message you submit |
| Brevo (via the WP Mail SMTP plugin) | Delivers form submissions to our inbox | The contents of your form submission — including your name, email address, and message — in transit |
Each is bound by its own privacy policy and processes this information only to operate the site and deliver your message to us.
Service delivery vendors. Delivering managed IT services requires tooling that necessarily touches customer systems. Categories include:
| Category | What it does |
|---|---|
| Remote monitoring and management (RMM) | Monitor and manage customer devices |
| Professional services automation / ticketing | Track support requests and time |
| Endpoint security and EDR | Antivirus and threat detection |
| Backup and disaster recovery | Store and restore customer data |
| Cloud productivity | Microsoft 365 administration |
| Payment processing | Process payments |
| Email and communications | Send email, host our mailboxes |
| Accounting | Bookkeeping and invoicing |
These vendors are permitted to use the information only to provide services to us and are bound by contractual confidentiality and security obligations.
Named list on request. We will provide the specific vendors in each category above to any customer or prospective customer who asks.
5.2 Subcontractors
We may engage subcontractors to perform portions of our services. They are bound by confidentiality obligations at least as protective as our own, and we remain responsible for their handling of your information.
5.3 At your direction
We share information with third parties when you ask us to — for example, when coordinating with your internet carrier, software vendor, landlord, or another IT provider on your behalf.
5.4 Legal and safety
We may disclose information when we believe in good faith it is necessary to (a) comply with a law, regulation, subpoena, or court order; (b) enforce our agreements; (c) protect the rights, property, or safety of Ocotillo IT, our customers, or others; or (d) investigate suspected fraud or a security incident.
Where legally permitted, we will notify a customer before disclosing their information in response to legal process, so the customer has an opportunity to object.
5.5 Business transfer
If Ocotillo IT is involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction. We will notify affected customers, and any acquirer will remain bound by this Policy or provide notice before materially changing it.
5.6 What we never do
We do not sell personal information. We do not rent or trade customer lists. We do not share your information with advertisers or data brokers. We do not use customer data to train AI models.
6. HOW WE PROTECT INFORMATION
We maintain administrative, physical, and technical safeguards designed to protect personal information, including:
- multi-factor authentication on our administrative systems;
- encryption of data in transit and, where supported, at rest;
- role-based access controls limiting access to personnel who need it;
- credential management through a dedicated secured system;
- logging and monitoring of administrative access; and
- two-factor authentication and automated brute-force protection on our website’s administrative sign-in page
- confidentiality obligations binding our personnel and subcontractors.
No system is perfectly secure. We cannot guarantee that information will never be accessed without authorization, and we do not warrant absolute security. If we experience a security incident affecting your personal information, we will notify you as required by applicable law, and — for business clients — as required by our services agreement with you.
7. YOUR CHOICES
Marketing email. Every marketing email includes an unsubscribe link. You can also email us at privacy@ocotilloit.com. Note: you cannot opt out of transactional and service messages — invoices, outage notices, security alerts, renewal notices, and account communications — while you are a customer.
Access, correction, and deletion. You may ask us for a copy of the personal information we hold about you, ask us to correct inaccurate information, or ask us to delete it. Email privacy@ocotilloit.com. We will respond within thirty (30) days. We may need to verify your identity first.
Limits on deletion. We may need to retain some information despite a deletion request — to comply with legal or tax obligations, to maintain records of services performed, to resolve disputes, to enforce our agreements, or where it exists in routine backups that are not readily accessible. We will tell you if this applies.
Requests about a business client’s data. If you are an employee or customer of one of our business clients and your request concerns data in that client’s systems, we will refer you to that client, who controls the data and decides how to respond.
Payment method. You can update or remove the payment method on file by contacting us, subject to your obligation to maintain a valid method while under an active plan.
8. STATE PRIVACY RIGHTS
Arizona. Arizona has not enacted a comprehensive consumer privacy statute as of the last updated date above. We extend the access, correction, and deletion rights described in Section 7 to all our customers regardless of where they live.
Other states. If you are a resident of a state with a comprehensive privacy law — such as California, Colorado, Connecticut, Virginia, Utah, Texas, or Oregon — you may have additional rights, including the right to know what we collect, to access, correct, and delete, to opt out of sale or targeted advertising, and not to be discriminated against for exercising those rights. We do not sell personal information or use it for targeted advertising, so there is nothing to opt out of on those points. To exercise any right, email privacy@ocotilloit.com.
Authorized agents. You may use an authorized agent to make a request. We will require proof of authorization and may require you to verify your own identity directly.
Appeals. If we deny a request, you may appeal by replying to our response with the word “Appeal.” We will respond within forty-five (45) days with our decision and the reasons for it.
9. HOW LONG WE KEEP INFORMATION
| Type | Retention |
|---|---|
| Website inquiry that doesn’t become a customer | 24 months, then deleted |
| Customer account and contact records | Duration of the relationship plus 7 years |
| Billing and tax records | 7 years, as required by tax law |
| Support tickets and service records | Duration of the relationship plus 3 years |
| System and security logs | 12 months |
| Customer backup data | Per the retention period in the customer’s service plan; deleted on schedule after termination |
| Credentials for a former customer | Destroyed within 30 days of the transition being complete |
Backups may retain information for a period after deletion from primary systems, following normal backup rotation. Information in backups remains protected under this Policy for as long as it is retained.
10. DATA LOCATION
We operate in the United States, and information is stored and processed in the United States. Some vendors we use may process information in other countries. If you access the Site from outside the United States, you understand that your information will be transferred to and processed in the United States.
11. CHANGES TO THIS POLICY
We may update this Policy from time to time. We will post the updated version here with a new “Last updated” date. If we make a material change to how we handle personal information, we will notify customers by email at least thirty (30) days before it takes effect. Continued use of our Site or services after a change takes effect constitutes acceptance.
12. CONTACT US
Questions, requests, or complaints about privacy:
Ocotillo IT LLC
Chandler, Arizona
Email: privacy@ocotilloit.com
General: info@ocotilloit.com
Phone: 480-535-8800
We take privacy complaints seriously and will respond within thirty (30) days.