Privacy
A security company that is vague about its own data handling has answered the question. So: here is everything this website stores, why, and for how long.
Last updated September 19, 2026
The short version
- The shop takes no payment. There is no checkout, no card field and no payment processor anywhere on this site.
- Your quote list is stored in your own browser. It is not sent anywhere until you press the button that opens your email program, and you can see exactly what it says before you send it.
- No analytics, no advertising pixels, no third-party trackers.
- The only cookie is the one remembering your answer to the cookie question.
Who is who
Layer8Secure is the business. It sells networking, premises security and cybersecurity services, and it decides what happens to information you send it.
HatchTag designed, built and operates this website on Layer8Secure's behalf. It is the technical operator, acting on Layer8Secure's instructions, and it does not use anything from this site for its own purposes. HatchTag's own notice is at hatchtag.dev/privacy.php, and it governs the wider domain this site is served from.
For anything about your information, write to DigitalChocolate@layer8secure.com or call +1 (772) 978-6185.
The shop and your list
The shop looks like an online store and behaves like one, up to a point. That point is worth being exact about.
Adding something puts a line in a list held in your browser's local
storage, under the name l8.cart.v1. That list stays on
your device. It is not sent to a server when you add to it, it is not
visible to us, and closing the tab does not send it either.
When you are ready, "Request a quote" fills in a message and opens your email program with it. You can read it, change it, or close it without sending. Nothing is transmitted until you press send in your own email client — at which point it is an ordinary email from you to us.
The prices shown are indicative. Nothing is charged here, because nothing can be: there is no payment field on this site, and we will never ask for card or bank details by email. If you ever receive a message that appears to be from us asking for payment details, treat it as a phishing attempt and call the number above.
What this site collects
Anything you type: nothing
The inquiry form on this site does not post to a server. It assembles a message and hands it to your email program — the same as the quote list. Your name, your email address and your message go from your account to ours without passing through this website.
What your browser sends by itself
The web server records requests: page, time, IP address, user-agent and referring page. That happens at the hosting level, before our code runs. It keeps the site working and helps investigate abuse. It is not used to profile visitors.
Your cookie choice
Answering the cookie banner writes a record: a random identifier not linked to you, the categories chosen, how they were chosen, the time, the page, the user-agent, and your IP address as a one-way hash — scrambled with a secret key, so it can link two records to the same origin but cannot be reversed into an address.
It is the thinnest record that can show consent was obtained. No name, no email, no page content.
Cookies and local storage
The complete list. Not a sample.
| Name | Type | What it does | How long |
|---|---|---|---|
ht_consent |
Cookie | Remembers the cookie choice you made, so you are not asked on every page. | 180 days |
l8.cart.v1 |
Local storage | Holds the list you build on the Layer8Secure shop so it survives changing page. It never leaves your browser on its own. | Until you clear the list or your browser data |
Both are strictly necessary. One remembers your answer to the cookie question; the other holds a list you built deliberately. Switching the list off would just throw away your own work, which is why it is not offered as a choice.
The categories in the cookie panel
Analytics and Marketing appear in the panel and neither runs. They are there so that consent is already handled correctly if either is ever switched on, rather than being retrofitted afterwards.
- Analytics. Counts of visits and page views. If this is ever switched on it will be named here, with the provider, before it runs.
- Marketing. Measuring whether an advert led to an inquiry. Nothing of this kind runs today.
If you become a client
Security work involves being told things most suppliers never hear: network diagrams, device inventories, staff names for a phishing exercise, findings from a penetration test. That information is used for the engagement it was given for, and for nothing else.
It is never sold. It is not used as a case study or a reference without written permission. Test findings are treated as confidential to you — we will not name you as a client, publish a redacted report, or use your results in marketing unless you agree in writing first.
Staff details supplied for phishing simulations are used to run the simulation and to deliver training, and the results are reported as aggregates. Nobody is named to their employer for clicking a test email; that is not what the exercise is for.
Your choices
- Change your cookie choice at any time. . It is also in the footer of every page.
- Global Privacy Control. If your browser sends the GPC signal we treat it as an instruction to keep everything optional off. It is honoured automatically with no extra click, and we record that we honoured it. Switching something on by hand afterwards overrides the signal, because a deliberate choice beats a default.
- Empty your list. "Clear list" in the list drawer removes it from your browser immediately.
- Clear everything. Clearing site data for this domain removes the consent record and the list. You will be asked about cookies again next visit.
Your rights
Florida's Digital Bill of Rights and similar state laws apply above revenue and volume thresholds this business does not meet. Rather than claim an obligation we do not have, here is the commitment we will keep: ask, and we will do it.
- Ask what we hold about you, and we will tell you.
- Ask for a copy, and we will send it.
- Ask us to correct something, and we will correct it.
- Ask us to delete it, and we will delete what we are not legally or contractually required to keep.
- You will not be treated differently for asking.
Email DigitalChocolate@layer8secure.com and expect a reply within 30 days. No form, no fee.
We do not sell personal information and we do not share it for cross-context behavioural advertising.
How long anything is kept
- Your cookie choice: 180 days in your browser, then you are asked again.
- Your quote list: in your browser until you clear it. We never have a copy.
- The consent record: kept as proof for as long as the choice could be questioned, reviewed yearly.
- Server request logs: kept by the web host on their schedule, typically a few weeks.
- Email you send us: kept while the conversation is live and for the life of any resulting engagement.
- Engagement material — reports, findings, inventories: kept for the term agreed in that engagement, then destroyed. If nothing was agreed, ask and we will delete it.
Children
This is a service for businesses and property owners. It is not directed at children and we do not knowingly collect information from anyone under 13.
Security
The site is served over HTTPS. It stores no payment data because it accepts none. The consent log sits outside the part of the server that answers web requests, and addresses in it are hashed rather than recorded. Accounts used to run the site carry multi-factor authentication where the provider supports it.
If you find a flaw in this site or in anything we have built for you, report it to DigitalChocolate@layer8secure.com. Reports made in good faith are welcome and will not be met with a lawyer.
Changes
The date at the top changes whenever this notice does. A substantive change — new data, new recipient, a tracker where there was none — re-opens the cookie banner, so any choice is made against the current facts.