Privacy Policy
What this website collects, why, who else sees it, and how to ask us to change or delete it.
- Effective date
- August 5, 2026
- Last updated
- August 5, 2026
1. Who operates this website
Molded By Grace Business Group LLC is a Texas single-member limited liability company based in Williamson County, Texas. It operates this website and is responsible for the information described in this policy.
Throughout this policy, “we”, “us” and “our” mean Molded By Grace Business Group LLC. “You” means anyone who visits this website or sends us a message through it.
You can reach us at admin@mbgbusinessgroup.com.
2. What this policy covers
This policy covers this website only: the pages published at mbgbusinessgroup.com, including the contact form on it.
It does not cover the separate websites operated by the businesses within the group, which are described in section 26. It does not cover email you choose to send us directly, phone conversations, or anything that happens away from this website, although we handle information from those channels with the same care.
3. Our privacy commitments
These are the commitments this company makes about personal information, and they apply whichever privacy law happens to reach us:
- We maintain an accurate privacy notice. This page describes what this website actually does, verified against the site itself, rather than what a template says a website usually does.
- We collect only the information reasonably needed for the purpose at hand, and no more.
- We accept reasonable requests to access, correct or delete personal information, as described in sections 23 and 24.
- We protect the information in an inquiry, and keep the number of places it is stored as small as we can.
- We do not sell personal information.
- We do not use personal information for targeted advertising.
- We reevaluate our privacy obligations at least once a year.
- We reevaluate them again, before the change is made, if we add ecommerce, analytics, advertising, a newsletter, visitor accounts, AI processing, or a materially different business or data practice.
Texas has a comprehensive privacy law, the Texas Data Privacy and Security Act. Whether, and to what extent, its obligations reach a business of this size and activity is something we keep under review with counsel rather than a claim we make on this page. We do not tell you that every provision of it applies to us, we do not tell you that we are exempt from it, and we do not claim to comply with every privacy law everywhere. The commitments above are what we will do regardless of the answer.
4. Information you give us directly
The only way this website invites you to give us information is the contact form. Nothing else on the site asks you for anything. There are no accounts, no logins for visitors, no subscriptions, no newsletter, no comments, no reviews, no downloads that ask who you are, and no payments.
5. Information from the contact form
When you send us an inquiry, the form collects:
- Your name. Required.
- Your email address. Required. It is the address we reply to.
- Your company or organization. Optional.
- Your website. Optional.
- Your reason for contacting us, chosen from a short list. Required.
- Your message. Required, and entirely up to you what it contains.
- Your two confirmations: that the inquiry is genuine, and that we may use what you have provided to reply to it.
Alongside those answers, the inquiry that reaches our mailbox carries:
- a submission reference, generated at random for that message so it can be found and discussed without quoting its contents;
- the date and time of the submission, in UTC;
- the address of the page the form was sent from;
- the exact consent wording you agreed to and the version of that wording, so what you agreed to is preserved with the message rather than assumed afterwards.
Your IP address is not included in that email. It is not in the body, the subject, the headers, the consent record or the confirmation shown to you. The submission reference is generated at random and is not derived from your name, your email address, your IP address, your message, or any database record. Section 7 describes the two places an IP address is still involved, and what form it takes there.
The form asks you not to send passwords, financial information, government identification numbers, medical information, or other highly sensitive information, and says so on the page. See section 18.
6. Information collected automatically
This website does not use analytics software, advertising pixels, conversion trackers, session recording, heat mapping, social media embeds, embedded video, or remotely hosted fonts. Our typefaces are served from our own server rather than from a font service, so loading a page on this site does not tell any third party that you did.
What is collected automatically is what any web server records in order to serve a page, described in the next section.
7. IP addresses and server logs
Our hosting provider’s web server records requests made to this website. Records of this kind ordinarily include the IP address the request came from, the date and time, the page or file requested, the response given, the referring page where one is sent, and the browser’s user-agent string. These records are created and controlled by the hosting provider as part of running the server, and are used for delivering pages, diagnosing faults, and investigating abuse.
The hosting environment also runs a web application firewall that inspects incoming requests and refuses ones matching known attack patterns. Refused requests are logged in the same way.
Separately from those provider logs, the website itself uses your IP address in exactly one way, and never in a form that can be read back:
- A one-way hash, for ten minutes. To apply a submission rate limit, the site stores a one-way cryptographic hash of the submitting IP address. The hash cannot be reversed to recover the address, it is never sent anywhere, and it is discarded automatically after ten minutes.
The site also stores a one-way hash of a submitted message for thirty minutes, to recognise a message that has just been sent twice. That hash contains no IP address.
8. Cookies and similar technologies
We tested this. Loading the public pages of this website does not set any cookie, and does not write to your browser’s local storage or session storage. There is no analytics, no advertising, no tracking pixel, no social embed, no video embed, no remote font and no third-party script on any public page.
WordPress, which this site is built on, sets cookies when someone signs in to administer the site. Those are functional cookies for our own administrators. They are not set for visitors, and there is no visitor account to sign in to.
Because nothing on the public site is stored on your device, there is no consent banner. We would rather remove the tracking than ask you to dismiss a notice about it. If we ever add technology that changes this configuration, we will reconsider both this section and whether a banner is required before that technology goes live, not afterwards. Section 27 lists what would trigger that review.
9. How we use information
We use the information described above to:
- read and reply to the inquiry you sent us;
- keep a record of the inquiry and the permission you gave us to answer it;
- protect the website and the inbox from automated abuse; and
- keep the website working, secure, and accessible.
We do not use it to build a profile of you, to score you, to train a model, or to decide anything about you automatically.
10. Responding to your inquiry
The permission you give on the form is permission to reply to that inquiry, and to whatever follows naturally from it in the same conversation.
It is not permission to send you a newsletter, a promotional email campaign, automated marketing, text messages, or automated telephone calls, and it is not permission to contact you later about something unrelated. We do not run any of those, and if we ever do, we will ask separately rather than treating your inquiry as consent for it.
11. Spam, fraud and security prevention
The contact form applies several checks to each submission before it is accepted. Between them they use a hidden field that a person never sees, a signed token proving the form was loaded from this website, how long the form was open before it was submitted, the number of links in the message, the length of each field, whether an email address is readable, whether any field contains an attempt to inject an email header, whether the same message has just been sent, and how many submissions have come from the same IP address recently.
All of these run on our server, not in your browser, so none of them depends on JavaScript. None of them uses a third-party service, and no information about you is sent anywhere in order to perform them. We do not use an image CAPTCHA.
A submission that is refused by any of these checks is not emailed to us. Nothing about a refused submission is kept beyond the short-lived hashes described in section 7.
12. Email delivery through SMTP2GO
Inquiries reach us as email, and that email is delivered by SMTP2GO, an email delivery service. To send the message, SMTP2GO receives its contents: your name, your email address, your company and website if you gave them, your reason for writing, your message, the consent record, and the submission details described in section 5.
SMTP2GO processes that information in order to deliver the message on our behalf and keeps its own records of delivery activity under its own terms and privacy policy. We have not enabled the local logging option in the SMTP2GO software on this website, so no second copy of your message is stored in this website’s database by it.
13. WordPress and Elementor
This website runs on WordPress with the Elementor and Elementor Pro page builder, which provides the contact form.
Elementor can store form submissions in the website’s own database. We have deliberately turned that off. Your inquiry is sent as email and is not saved into the website database as a second copy. Keeping one copy in one place, in a mailbox, is a smaller footprint than keeping two, and it means there is no growing store of messages sitting inside the website.
The website does briefly store the two short-lived hashes described in section 7. Neither is readable as the original value, and both expire on their own.
14. Hosting and technical providers
This website is hosted by a third-party hosting provider, which operates the servers, the network and the backups for the environment the site runs in. In the course of doing that, the provider necessarily processes the requests made to the site, including the log information described in section 7.
Our domain name and its DNS records are managed through a domain registrar and DNS provider, which sees requests to resolve our domain name.
15. Who can receive information
Information you send through this website can reach:
- Us. Inquiries go to a company mailbox read by the owner.
- Service providers acting on our behalf, which today are the email delivery service, the hosting provider, and the domain and DNS provider. They may use the information only to provide their service to us.
- Anyone you direct us to. If your message asks us to pass something to someone, doing so is at your direction.
- Authorities or advisers, where the law requires it, or where it is necessary to establish or defend a legal claim, or to protect someone’s safety.
- A successor, if the business or part of it were ever sold, merged or reorganised, in which case information would transfer as part of the business.
Sharing information with a service provider so that it can do a job for us is not the same as selling it, and neither is a disclosure the law requires of us. Section 16 addresses selling directly.
16. We do not sell personal information
We do not sell personal information, and we do not exchange it for anything of value. We have never done so.
17. We do not use targeted advertising
We do not use personal information for targeted advertising, and we do not share it with anyone else for that purpose. This website carries no advertising and no advertising technology.
18. Sensitive information
We do not ask for sensitive personal information and we do not want it. The contact form asks you not to send passwords, financial account or card numbers, government identification numbers, health or medical information, or comparable information, and it says so directly above the message box.
A message box will accept whatever is typed into it, so we cannot prevent it being sent. If you send sensitive information anyway, we will not use it for anything beyond replying to you, and we will delete it once the conversation no longer needs it. If you realise afterwards that you sent something you should not have, write to us and we will remove it.
19. How long information is kept
This is our retention schedule for information that comes through this website. Periods run from the last contact about the matter unless stated otherwise.
| Record | Retention |
|---|---|
| Blocked spam or rejected submission | No inquiry retained |
| Rate-limit IP hash | 10 minutes |
| Duplicate-detection hash | 30 minutes |
| Routine inquiry that does not proceed | 12 months after last contact |
| Active preliminary discussion | While active, then 12 months |
| Consent evidence | Same period as the related inquiry |
| Inquiry becoming a business relationship | Transferred to the applicable contract or business-record schedule |
| SMTP2GO delivery activity | Shortest practical available period, preferably 30–90 days |
| Hosting and firewall logs | Provider-controlled; target 30–90 days unless needed for security |
| Legal hold, dispute, audit, or investigation | Ordinary deletion suspended until released |
What is automatic and what is not. The two hashes in the table expire on their own; nobody has to act for that to happen. Everything else on this list is deleted by a person working to this schedule. We are telling you that plainly rather than describing manual housekeeping as though it were an automated process.
Two of the rows are not ours to enforce. SMTP2GO’s delivery records and the hosting provider’s server and firewall logs are held by those providers under their own arrangements; the periods shown are what we ask for and aim at, not a guarantee we can make on their behalf.
20. Records that follow separate schedules
Some records are not website records at all, and this schedule does not govern them. Contractual records, invoices, tax records, intellectual-property records and formal business correspondence follow separate retention schedules established with our counsel and our accountant, because the periods for those are set by law and by the needs of the business rather than by this website.
If an inquiry that started here becomes a business relationship, the record moves onto whichever of those schedules applies to it, as shown in the table above.
21. Security practices
We use reasonable administrative, technical, and organizational safeguards appropriate to the information processed through this website. In practice that includes serving the entire site over an encrypted connection, sending inquiries through an authenticated email delivery service, keeping the number of places your information is stored as small as we can, not putting your IP address into the inquiry email at all, and applying the submission checks described in section 11.
No website, service or method of transmission is completely secure, and we do not claim otherwise. We cannot guarantee the security of information sent to us over the internet.
22. Your privacy choices
The most direct choice is not to use the contact form. Nothing else on this website asks for information about you, and you can read every page without giving us anything.
If you have sent us an inquiry, you can ask us at any time to stop using your information and to delete it. You do not need to give a reason, and asking will not change how we treat any inquiry you send later.
23. Access, correction and deletion
You can ask us to:
- tell you what information about you we hold, if any;
- give you a copy of it;
- correct it if it is wrong; or
- delete it.
We will do these things unless the law requires us to keep something, in which case we will tell you what we are keeping and why. We may need to ask you a question to confirm that the request is really from you, and we will not treat you differently for making one.
Rights of this kind are given by different laws in different places and are not identical everywhere. Whichever rights apply to you, the list above is what we will do on request.
24. How to make a privacy request
Email admin@mbgbusinessgroup.com and tell us what you would like us to do. Sending your request from the same email address you used to write to us is the quickest way for us to find the right information. If you have a submission reference from a previous inquiry, including it helps us find the right message immediately.
We will acknowledge your request and tell you what we have done. If we cannot do what you asked, we will explain why.
25. Children’s privacy
This website is a corporate information site intended for adults doing business. It is not directed to children, we do not knowingly collect information from children, and nothing on it is designed to appeal to them.
If we learn that a child has sent us information through this website, we will delete it. If you believe that has happened, please write to us.
26. Our other business websites
The businesses operating under Molded By Grace Business Group run their own separate websites, including OnTrack Web Solutions, Bob Backwards, and Molded X God.
This policy does not automatically govern those websites. Each of them maintains, or will maintain, its own site-specific privacy policy, website terms, cookie practices and contact arrangements, appropriate to what that business actually does — which for some of them includes ecommerce, shipping and returns, or the collection of testimony. When you follow a link from this website to one of them, you are on a different website, and the policy published there is the one that applies.
Links to any other website, including a business we have no connection to, are outside our control, and we are not responsible for how those sites handle information.
27. When we reevaluate this policy
We review this policy, and our privacy obligations generally, at least once a year.
We also review it before making any of the following changes, rather than after:
- adding ecommerce or taking payments;
- adding analytics or any measurement tool;
- adding advertising or advertising technology;
- adding a newsletter or any marketing list;
- adding visitor accounts or logins;
- adding AI processing of anything a visitor submits;
- adding an embedded video, map, live chat, third-party font or third-party bot-protection service;
- starting a materially different business, or changing our data practices materially.
None of these is present today. Each of them would change what this page has to say, and in several cases would change whether a cookie notice is required at all.
28. Changes to this policy
If we change what this website does with information, we will change this policy to match before or when the change takes effect, and we will update the dates below. Material changes will be identified on this page rather than made quietly.
29. Effective date and last updated
This policy is in effect.
Effective date: August 5, 2026
Last updated: August 5, 2026
30. How to contact us
Molded By Grace Business Group LLC
A Texas single-member limited liability company based in Williamson County, Texas
Email: admin@mbgbusinessgroup.com
Please put “Privacy” in the subject line so your message reaches the right place quickly.
- Effective date
- August 5, 2026
- Last updated
- August 5, 2026