LEGAL

Privacy policy

How Thing Company collects, uses, discloses, and safeguards your information.

Effective October 6, 2026

Thing Company, LLC ("Thing Company", "we", "us") runs this website, thing.company, and sends the emails described below. This policy explains what we collect, why, who else handles it, how long we keep it, and what you can ask us to do.

Our Terms of Use are on their own page. Two community sites, IoT Hub Meetup and the Homebrew A.I. Coders Club, are run by Thing Company and each has its own privacy page. Where a community page says something different for that site, the community page applies there.

1. The short version

  • We collect what you type into a form or send us, plus the technical data needed to run the site and block abuse.
  • On the website we use no advertising, analytics or tracking cookies and no tracking pixels. The HTML version of our automatic emails tracks whether the email was opened and which links are clicked, except for people in the European Economic Area, the United Kingdom and Switzerland, who get a plain-text version with no tracking (section 3).
  • We do not sell personal information, and we do not share it for advertising.
  • When you send a form, we email you one automatic note to confirm it arrived. Section 3 covers every kind of email we send.
  • A short list of service providers hosts the site, stores the data and delivers the email. Section 6 names them.
  • To see, correct or delete what we hold about you, write to privacy@thing.company.

2. What we collect

Details you give us

  • A Sprint Assessment request (the contact form): your name, company, work email, role, the situation you choose from the list, and any note you add about your initiative. If a link brought you to the form from a particular page, we record which one.
  • The free toolkit: your name, work email, company, role, the moment your decision is in, when it has to be made, and whether you agree to follow-up email. We record that choice and when you made it.
  • A resource download or a newsletter sign-up: the details the form asks for, which is at least your email address.
  • Anything you send us directly: an email, a reply to one of ours, or a message from a call.

Please do not send us sensitive personal information, such as health, financial account or government identity details. We do not need it, and a form is not the place for it.

Business contacts we find ourselves

We sometimes write to people we have not heard from, because their role suggests our work may help. For that we use a person's name, work email address, company and job title from public sources and business contact data providers. Section 3 explains how those messages work and how to stop them.

Technical data

  • Hosting logs. Our host records each request: IP address, browser type, the page asked for, the time and the result. It keeps these for a short period, set by the host, so we can run and secure the site.
  • Form security records. To block abuse, each time a form is sent we store a scrambled (keyed hash) version of your IP address and of your email address, if you gave one, with the time. The scramble cannot be read back into the original. We delete these records after a few days. For the community sites and the CMS forms we also store your IP address and browser type with the submission itself.
  • A bot check. Some forms use Cloudflare Turnstile to tell people from scripts. It runs in your browser and shares signals such as your IP address and browser characteristics with Cloudflare, under Cloudflare's own privacy policy. For nearly everyone it is invisible.
  • Fonts. The site's typefaces are served from our own domain. Your browser does not contact a font provider.

We do not collect your precise location. We do not build profiles, and no decision about you is made by automated means.

3. Emails we send and receive

All of these come from Thing Company, LLC. Mail to you is delivered through our email provider (section 6).

  • An acknowledgement of your form. After you send a contact request, a toolkit request or a community form, you receive one automatic email to the address you gave. On the Thing Company site it comes from Hans at Thing Company and confirms the request arrived, says what happens next, and links to a paper or two and the toolkit that fit the situation you chose. On the community sites it comes from the organizers and confirms the form. The text is fixed: it does not repeat what you typed. We send at most one to the same address in 24 hours. It is a service message, so it carries no unsubscribe link. If you do not want it, tell us and we will stop.
  • A notice to us. Each form you send also creates an email to our team inbox with the details you entered, so we can answer you.
  • The toolkit. If you ask for the toolkit, we email the download links. They expire after 24 hours. We write to you about the toolkit or new papers afterward only if you agreed on the form.
  • Updates and newsletters. We send these only if you ask for them or agree to them. Each one has an unsubscribe link or tells you how to stop, and carries our mailing address.
  • Business outreach. When we write to someone we have not heard from, the message says who we are and why we wrote, and offers a way to opt out. We keep a list of people who have opted out and do not write to them again. Where the law of your country requires your consent before we write, we ask for it first.
  • Our conversations. Replies and the emails we exchange with you sit in our mailboxes, which our email provider hosts (section 6).
  • Account emails. If you have a staff account on our admin tools, we send verification and password-reset emails.

Tracking in our emails. The HTML version of our automatic emails, the acknowledgements, contains a small image, and its links pass through our email provider. When your email program loads the image, or you click a link, our email provider records whether and when the email was opened and which links are clicked, with technical details such as your IP address and email program. We use this to see whether our messages arrive and are read, and to fix delivery problems. We do not use it to build a profile of you or for advertising.

If you are in the European Economic Area, the United Kingdom or Switzerland, the law generally requires your consent before we track you this way, so we do not. We judge where you are from your connection and from the country in your email address, and when we cannot tell, we treat you as if you were there. You receive the plain-text version only, which has no tracking image. The toolkit email is plain text for everyone. The plain-text version of each email has no image, so reading it, or blocking remote images in your email program, stops the open being recorded.

You can end any of this at any time by replying "stop" to any email from us or writing to privacy@thing.company.

4. Why we use your information

  • To answer you and run an engagement you ask about: your requests, our replies, the acknowledgement. Legal basis, where the law asks for one: taking steps at your request before a contract, or our legitimate interest in answering the people who write to us.
  • To send what you asked for: the toolkit links, papers, updates. Basis: your request, or your consent where you gave it.
  • To keep the site working and safe: logs, the form security records, the bot check. Basis: our legitimate interest in security and in stopping abuse.
  • To see whether our emails arrive and are read: the tracking in section 3, used only for people outside the European Economic Area, the United Kingdom and Switzerland. Basis: our legitimate interest in knowing that our messages are delivered. You can avoid it by reading the plain-text version or blocking remote images.
  • To write to business contacts about relevant work. Basis: our legitimate interest, with an opt-out in every message, or your consent where the law requires it.
  • To meet legal duties and to establish or defend legal claims.

We do not use your information for advertising, and we do not sell it.

5. How long we keep it

  • Requests, toolkit sign-ups and form submissions: until you ask us to delete them, or until we no longer need them for the reason you sent them. We do not delete them automatically today.
  • Form security records: a few days.
  • Hosting logs: the short period set by our host.
  • Emails in our mailboxes: until they are deleted.
  • Opt-out records: for as long as we need them to honor your choice.

If you ask us to delete your information, we do, except for what the law requires us to keep.

6. Who handles your information

These providers process information for us, to provide the service named, and under their own terms.

  • Vercel hosts the website and records the hosting logs.
  • Neon hosts our database, where requests and sign-ups are stored, in the United States.
  • Resend delivers the emails we send, keeps delivery records for them, and records when the HTML ones are opened and their links clicked.
  • Google Workspace hosts our mailboxes and the messages in them.
  • Cloudflare provides our domain's DNS and, on forms that use it, the Turnstile bot check.

We also share information when the law requires it or to protect our rights, with an adviser bound by confidentiality, and, if we are ever bought or merged, with the other party, who would have to honor this policy. We do not pass your details to sponsors, partners or speakers.

7. Cookies and similar technologies

  • One security cookie. When you send a form, the site sets a cookie named _csrf. It proves the form came from this site, holds no personal details, and ends when you close your browser.
  • One saved preference. The site stores your light or dark theme choice in your browser's local storage. It never leaves your device.
  • Staff only. People who sign in to our admin tools get a session cookie to stay signed in.
  • A tracking image and tracked links in our HTML emails, not on the website, and not for people in the European Economic Area, the United Kingdom or Switzerland. Section 3 explains it.

On the website we use no advertising or analytics cookies and no tracking pixels today. If that changes, we will update this page first and ask for your consent where the law requires it.

8. Your rights and choices

Depending on where you live, you may have the right to:

  • see the personal information we hold about you and get a copy;
  • have it corrected or deleted;
  • object to, or ask us to restrict, how we use it;
  • take it with you in a common format;
  • withdraw consent you gave, at any time;
  • opt out of the sale or sharing of personal information. We do neither, so there is nothing to opt out of.

In California and several other US states these are rights under state privacy law. In the European Economic Area, the United Kingdom and some other countries they are rights under data protection law. We will honor a request from anywhere, within the limits of the law.

To make a request, write to privacy@thing.company from the address we hold, or tell us which address to search. We may ask you to confirm it is you, because we will not give your information to someone else. We reply within 30 days, or tell you why we need longer. You may ask someone to act for you; we will ask for proof they may. If we refuse a request, we say why, and you can ask us to look again. We do not treat you differently for making a request.

If you are in the European Economic Area or the United Kingdom, you may also complain to your data protection authority. If you are in California, you may contact the California Attorney General.

9. Transfers outside your country

We are based in the United States and our providers process information mainly there. If you are in the European Economic Area, the United Kingdom or elsewhere, your information is sent to and handled in the United States. Where the law requires a safeguard for that transfer, we rely on our providers' standard contractual terms.

10. Security

We use encrypted connections to the site, restrict who can sign in to our systems, store security records only as scrambled hashes, and limit how fast anyone can send a form. No system is completely secure, and email in particular is not end-to-end encrypted. If a breach affects your information, we will tell you and the authorities as the law requires.

11. Children

Our site and our work are for businesses. We do not direct either to children under 16, and we do not knowingly collect their information. If you think a child has sent us some, write to privacy@thing.company and we will delete it.

12. Do Not Track and Global Privacy Control

We do not track you across sites, so we have nothing to change when your browser sends a Do Not Track or Global Privacy Control signal.

13. Links to other sites

Our pages link to other sites, such as Meetup, YouTube, LinkedIn and Discord. They run those sites under their own privacy policies, and we are not responsible for them.

14. Changes to this policy

When we change this policy, we post the new version here with a new date. If a change would use your information in a way you did not expect, we will tell you before it takes effect. The version in force before this one was dated February 15, 2025.

15. Contact us

Thing Company, LLC Email: privacy@thing.company

Last updated: October 6, 2026