GUARDISTRY & CO. LLC — CONSUMER PRIVACY NOTICE
Version 1.1 · DRAFT — NOT FOR PUBLICATION · Prepared 2026-08-06
🔴 READ BEFORE PUBLISHING
This is a draft, not legal work product, and has not been reviewed by counsel. No attorney is on record for this entity (verified against the full brain, 2026-08-06). Per
G_CO_SYSTEMS/LEGAL_SCOPE_HARD_BLOCKS.md§2, frameworks are named, not certified — no statute text is warranted as current.Scope decision of 2026-08-06 (John): this version deliberately covers only what GD3 does today. It contains no Plaid, no bank-account data, and no GLBA/Regulation P framing. Those sections (the original outline’s §§2.2, 4, 5, 6-GLBA) are held until counsel’s written opinion on CRA and financial-institution status is in the file. See
COUNSEL_OPINION_REQUEST_2026-08-06.md.A privacy notice is a binding public representation. Every
[BRACKET]below is a fact this document would assert on GD3’s behalf that is not yet verified. Publishing with a bracket unresolved asserts something unverified. Resolve or delete each one.
1. Who We Are
GUARDISTRY & CO. LLC, a Nevada single-member limited liability company, doing business as GD3 (“GD3”, “we”, “us”). Principal address: 713 E Sahara Ave Ste 325, Las Vegas, NV 89104.
This Notice explains how we handle personal information for our consumer-facing services: junk removal and hauling in the Las Vegas metropolitan area, related scheduling and customer support, our websites at gd3co.net, and our rental-application intake service.
This Notice does not cover employment or job-applicant data, or business-to-business contacts.
2. Information We Collect
2.1 Information You Provide
- Contact and service details — name, email address, telephone number, service address, and the description of the job or request you submit through a quote form, our website, or by phone.
- Scheduling information — appointment times, access instructions, and job notes.
- Rental-application information — where you use our rental-application intake service, the
identifying and application details you submit, and the fact and amount of the
$50 non-refundable Rental Application Processing fee.
[CONFIRM]The exact application fields collected must be enumerated here before publication. A privacy notice that under-describes a rental-application intake is a compliance gap. - Payment information — processed by our payment processor.
[CONFIRM: processor identity]We do not store full card numbers on our systems.[CONFIRM this is true of the chosen processor integration — if any card data touches GD3 systems, this sentence must change.]
🔴
[HELD]Financial account information. GD3 does not currently collect bank account numbers, routing numbers, balances, or transaction history, and does not operate a Plaid integration. Do not add this section until counsel’s opinion is in the file.
2.2 Information Collected Automatically
IP address, device and browser identifiers, pages viewed, referring URLs, approximate location derived from IP, and application telemetry, collected through cookies and similar technologies on gd3co.net.
2.3 Telephone Communications
We operate telephone-based customer intake and support.
🟡
[DECISION REQUIRED — do not publish this section unresolved]Are calls recorded, monitored, or transcribed (including by any AI receptionist or answering service)? If yes, this Notice must say so, and Nevada’s call-recording consent requirement (NRS ch. 200 — framework named, not certified; confirm the current rule and whether all-party consent applies) governs how and when consent must be captured. Recording without the required disclosure is a distinct legal exposure from anything else in this document.
3. How We Use Information
To schedule, perform, and invoice services; to respond to quote and service requests; to process the rental-application intake and its fee; to operate customer support; to secure our systems and prevent fraud; to measure and improve our websites and advertising; and to comply with legal obligations.
We do not sell personal information for money.
We use strictly necessary cookies for authentication and session management. We also load Google Ads conversion tracking (tag AW-18082736069) for measurement of our own advertising campaigns. We do not share personal information with advertising networks for their independent use, do not permit cross-context behavioral advertising by third parties on this site, and do not sell personal information. You may opt out of measurement via the mechanism at /privacy/requests.
4. How We Share Information
We share personal information with:
- Service providers engaged to operate our business, under written contracts limiting their use of the information to performing services for us — including website hosting and content delivery, application data storage, scheduling and CRM, telephony, payment processing, and analytics and advertising measurement.
- Stripe, Inc. — payment processing under written DPA.
- Resend — transactional email delivery.
- Legal and safety — where required by law or legal process, or to protect rights, property, or safety.
- Business transfer — in connection with a merger, acquisition, financing, or sale of assets.
[CONFIRM — named sub-processors]The original outline listed Supabase and Railway. Those are G_CO trading infrastructure, not GD3’s, and naming them here would be inaccurate (and crosses the venture-separation rule inCLAUDE.mdGuardrail #6). Evidence on disk points to GD3 running on Cloudflare (Workers/Pages/CDN), Convex, Airtable, and Google Ads/Analytics. Confirm the actual list before publication. Naming a processor you do not use, or omitting one you do, are both defects.
5. Your Privacy Rights
Depending on your state of residence, you may have the right to:
- Know / access the personal information we hold about you;
- Delete it, subject to legal exceptions;
- Correct inaccurate information;
- Obtain a portable copy;
- Opt out of sale or of sharing for cross-context behavioral advertising, and of certain profiling; and
- Limit the use of sensitive personal information (California), where applicable.
You will not be discriminated against for exercising these rights.
California (CCPA/CPRA) · Texas (TDPSA) · Virginia (VCDPA) · Colorado (CPA) · Connecticut (CTDPA) · Oregon (OCPA) — residents of these states have rights along the lines described above; the precise scope, exceptions, and response deadlines differ by state.
[COUNSEL]Confirm which state statutes GD3 is actually in scope for — most have revenue or volume thresholds a Las Vegas junk-removal operation may not meet. Claiming to honor a regime you are not subject to still creates an enforceable public promise. Confirm the response deadlines and any authorized-agent and appeal requirements before publishing timelines.
How to exercise your rights
To exercise rights, submit a request at https://gd3co.net/privacy/requests or email privacy@gd3co.net.
Mail: Privacy Request, Guardistry & Co. LLC, 713 E Sahara Ave Ste 325, Las Vegas, NV 89104.
We will verify your identity before acting on a request.
6. Data Retention
🟡
[PROVISIONAL — no Data Retention & Disposal Policy exists.]Verified 2026-08-06: no DRDP is present in either repository, so the periods below are not yet backed by an operative policy. The original outline cited a 7-year default drawn from BSA/AML — that rationale does not apply to this version, which covers no financial-institution activity. Publish retention periods only once the DRDP exists and the systems actually enforce them; a stated period you do not honor is the representation that gets enforced against you.
| Category | Provisional period | Basis |
|---|---|---|
| Customer and job records | Relationship + [N] years | Tax/accounting and warranty [CONFIRM] |
| Rental-application records | [N] | Counsel — depends on the CRA question |
| Website/app telemetry | 13 months | Common analytics default [CONFIRM against config] |
| Call recordings (if any) | [N] | See §2.3 |
7. Security
We maintain administrative, technical, and physical safeguards appropriate to the sensitivity of the information, including encryption of data in transit, access controls, and multi-factor authentication for administrative access.
[CONFIRM each control is actually implemented before asserting it.]The original outline framed this as a GLBA §314.4 Safeguards Rule program summary. That framing is held with the rest of the GLBA content. Describe only controls that exist. No method of transmission or storage is completely secure, and we do not guarantee absolute security.
8. Children
Our services are directed to adults and are not directed to children. We do not knowingly collect personal information from children under 13 (COPPA), and we do not knowingly sell or share the personal information of consumers under 16. If you believe a child has provided us information, contact us and we will delete it.
9. Changes to This Notice
We will post any updated Notice at this address with a new effective date. Material changes will be
identified. [If GLBA content is ever added, an annual-notice obligation may attach — counsel.]
10. Contact
Guardistry & Co. LLC (d/b/a GD3) · 713 E Sahara Ave Ste 325, Las Vegas, NV 89104
Email: privacy@gd3co.net [confirm]
Effective date: [NOT SET — do not publish without a real date. "[Launch Date]" is a placeholder, and an undated privacy notice cannot establish what was disclosed when.]
Appendix — what was deliberately omitted, and why
| Outline section | Status | Reason |
|---|---|---|
| §2.2 Plaid / financial account data | HELD | Not built; zero Plaid code in either repo. Plaid production access not approved |
| §4 Plaid as recipient | HELD | Same |
| §5 GLBA / Regulation P notice | HELD | Financial-institution status unresolved — counsel opinion pending |
| §6 GLBA data-level exemptions | HELD | Depends on the same opinion |
| §7 BSA/AML 7-year rationale | REMOVED | No financial-institution activity in this version |
| FCRA disclosures | NOT DRAFTED | Not in the original outline. If counsel finds GD3 is a CRA, this document needs a substantially larger FCRA architecture — permissible purpose, adverse action, file disclosure, dispute and reinvestigation rights |