This Privacy Policy explains how The Spider Services collects, uses, shares, and protects information when you visit our website, contact us, or use services provided by any of our subsidiaries. It applies to our website and to all of our subsidiaries, with service-specific sections where practices differ.
Our goal has not changed: we provide security-focused services while minimizing the personally identifiable information we collect and store. When possible, we anonymize information and combine it with information from other clients so it cannot reasonably be used to identify an individual client or user.
1. Who we are
1.1 The companies. The Web Holding Services, LLC d/b/a "The Spider Services" (the "Holding Company") and its wholly owned subsidiaries, Spider Computing Services, LLC; Spider Consulting Services, LLC; and Spider Security Services, LLC (together, "our subsidiaries") are all Missouri limited liability companies. In this policy, "The Spider Services," "we," "us," and "our" mean the Holding Company and our subsidiaries collectively, unless we say otherwise. Our subsidiaries provide, respectively, our Managed Computing and Hosting services, our Consulting services, and our Managed Security services. All hardware and equipment used to provide our Services, including equipment at client sites and the servers in our hosting and security cloud, is owned by Spider Leasing Services, LLC (the "Equipment Lessor"), a separate company under common ownership with the Holding Company, and leased to our subsidiaries. The Equipment Lessor is not one of our subsidiaries and is not included in "The Spider Services" or "we" in this policy. It only owns the equipment and does not access, process, or receive client data or the personal information described in this policy.
1.2 Who is responsible for your information.
- Website, inquiries, and marketing. The Holding Company is responsible for information collected through our website, contact form, and marketing activities.
- Client relationships. The subsidiary named in a client's order or statement of work is responsible for the business contact, account, contract, and billing information of that client, including the invoices it issues and the payments it collects. A client that works with more than one of our subsidiaries has a separate order and receives separate invoices from each, and each subsidiary is responsible for the information it holds for its own orders.
- Data we handle for clients. When we host, manage, monitor, or access systems and data on a client's behalf, the client decides what data is involved and why. For that data, we act as the client's service provider or processor and handle it only to provide the services and as the client instructs in its agreement with us. If your information is in a client's systems (for example, you are an employee or customer of one of our clients), please contact that client first. We will assist them in responding.
1.3 Contact. The Web Holding Services, LLC, 120B E 1st Street, Mountain Grove, MO 65711; (888) 271-8668; support@spiderservices.net.
2. Scope
2.1 This policy covers:
- our website at spiderservices.net, its subdomains, and our service status page at status.spider.services, together with any page that links to this policy (together, the "Site");
- communications with us by phone, email, the contact form, or in person;
- the services provided by our subsidiaries (the "Services"); and
- the Wi-Fi hotspot and advertising programs we are building (planned, not yet live), where described below.
2.2 This policy does not cover third-party websites, platforms, or products, even if we link to them or use them (for example, our social media pages, Palo Alto Networks products, or our payment providers). Their own privacy policies apply.
2.3 Our Services are designed for businesses. Where a client agreement includes specific data protection terms (such as a data processing addendum), those terms control for the data they cover.
3. Information we collect
We collect only what we need for the purposes described in Section 4. The specific information depends on how you interact with us.
3.1 Website visitors
- Server logs. Like most websites, our web servers automatically record basic technical information when a page is requested: IP address, date and time, page requested, referring page, browser type, and device/operating system information. The Site is hosted on servers operated by The Spider Services, either on infrastructure that we manage or on cloud infrastructure provided by Akamai Technologies, Inc. (Akamai Cloud), which acts solely as an infrastructure and hosting provider to us. We use these logs to operate and secure the Site.
- No cookies, analytics, or advertising trackers. The Site does not currently use cookies, analytics tools, advertising pixels, or third-party tracking scripts. See Section 8.
- Status page. Our service status page at status.spider.services is hosted on servers operated by The Spider Services on cloud infrastructure provided by Akamai Technologies, Inc. (Akamai Cloud, formerly Linode). Akamai acts solely as an infrastructure and hosting provider to us. When the status page is requested, our server automatically records standard server log data: IP address, browser type and user agent, the URL requested, and the date and time of the request. We use this information to operate and secure the status page. The status page does not use cookies and does not require or offer user accounts.
3.2 Contact form and inquiries
When you use our contact form or otherwise contact us, we collect the information you provide: your name, organization, email address, the company you want to talk to, and your message, along with anything else you choose to share (such as a phone number). Contact form submissions are delivered to us through [CRM/EMAIL PROVIDER]. [CONFIRM: CONTACT FORM BACKEND]
Please do not include passwords, confidential data, or sensitive personal information in the contact form.
3.3 Clients: account, contract, and billing information
- Business contact information: names, job titles, business email addresses, phone numbers, and business addresses of client personnel.
- Contract and account information: orders, statements of work, service configuration, support tickets, scheduling, and correspondence.
- Billing information: invoices, payment history, and payment reference numbers.
Payments. Each of our subsidiaries issues its own invoices and collects its own payments. We accept online payments, but we do not collect or store credit card or bank account numbers. The invoicing and payment portal our subsidiaries use is provided by Invoice Ninja, and payments are processed by Stripe. We receive only a payment confirmation and reference number, not your full financial information. Invoice Ninja and Stripe handle payment data under their own privacy policies and security standards.
3.4 Managed Computing and Hosting services – hosted data
Our Managed Computing and Hosting services provide managed computing and hosting, either on hardware at the client's site ("local") or in our hosting environment ("remote"). In doing so, we store and back up whatever data the client chooses to place on its systems ("Hosted Data"), which may include personal information about the client's employees, customers, or others.
- The client controls Hosted Data. We act as the client's service provider/processor.
- Each client's environment is kept separate from every other client's, and data is encrypted at multiple levels.
- Remote backups are always included and always encrypted.
- We do not access the contents of Hosted Data except as needed to provide, maintain, secure, or restore the Services, at the client's request, or as required by law.
- We also collect technical information needed to operate the platform, such as system logs, resource usage, IP addresses, and application usage.
3.5 Consulting services – client firewall and security environments
Our Consulting services provide ongoing cybersecurity and firewall management, specializing in Palo Alto Networks environments. To do this, we access the client's firewall and security management systems, which may contain:
- device configurations, security policies, and rule sets;
- administrator account information and credentials provided to us;
- traffic, threat, URL, and system logs, which can include IP addresses, usernames, device names, and websites visited by the client's users; and
- reports, assessments, and notes we create during the engagement.
We access this information only as needed to perform the engagement. For this information, we act as the client's service provider/processor.
3.6 Managed Security services – network and endpoint data
Our Managed Security services provide a fully managed security infrastructure from our own cloud, using equipment at client sites that we supply (leased from the Equipment Lessor; see Section 1.1). Because client network traffic passes through our managed environment, we collect:
- Network traffic metadata and logs: source and destination IP addresses, ports, domains requested (including the server name, or SNI, in encrypted connections), URLs for unencrypted traffic, timestamps, connection durations, traffic volumes and bandwidth, and security events (for example, blocked sites, threat-signature matches, or detected intrusion attempts).
- Endpoint telemetry: information from endpoint protection software on client devices, such as device names, logged-in usernames, running processes and applications, files flagged as malicious, and security alerts.
- Equipment data: health, configuration, and performance information from the equipment we place at client sites.
Encrypted traffic. By default, we do not decrypt encrypted (TLS/HTTPS) traffic; for that traffic we see only the metadata listed above, not its content. A client may add TLS inspection only by specifically requesting it and agreeing in writing (for example, in its order or statement of work). When a client enables it, our systems decrypt and automatically inspect covered traffic to apply security controls, the client is responsible for any notices and consents its users require, and sensitive categories such as health and banking sites are excluded by default.
Our Managed Security services do not include security camera or video surveillance services.
The client decides which networks, devices, and locations are covered, and is responsible for giving any notices to its employees, guests, and others that the law requires. For this information we act as the client's service provider/processor, except that we may use de-identified security information (for example, indicators of malicious sites or attack patterns) to improve protection for all clients (see Section 4.2).
3.7 Marketing, featured clients, and gift boxes
We feature client businesses in our marketing and promotional materials, and we include and advertise client businesses in the gift boxes we send. For these programs we may collect:
- client business names, logos, descriptions, photos, and testimonials (with the client's permission, as described in our client agreements);
- names and shipping addresses of gift box recipients; and
- information about client products included in gift boxes.
Clients can opt out of being featured at any time by contacting support@spiderservices.net. If you receive a gift box and do not want future ones, let us know at the same address.
3.8 Advertising network (planned)
We are building a local advertising network to give participating clients free advertisements in their area. It is not live yet. If and when it launches, we expect to collect only the advertising content participating clients provide (such as business name, logo, offers, and contact details) and aggregate counts of how many times each ad was displayed at each location. We do not expect to track, profile, or target individual viewers, and we will not use the network to follow individuals across websites. See Section 7.
3.9 Wi-Fi hotspot users (planned)
We are building a network of public or guest Wi-Fi hotspots, including at client locations that host equipment we operate. The hotspots are not live yet. There will be no sign-up, account, or email requirement, and we will not collect information about hotspot users other than the standard network management data needed to operate and secure the network:
- device identifiers such as the device's MAC address and the IP address assigned to it;
- connection information such as access point, connection times, and duration;
- bandwidth and usage metadata, such as the amount of data transferred; and
- security filtering data, such as domains requested, which our security controls check automatically to block malicious or prohibited content.
We do not use this data to identify, profile, or advertise to individual hotspot users. The hotspot connection page may display advertisements for local businesses (see Section 7). A short Hotspot Privacy Notice will appear on the connection page and link back to this policy. If and when the hotspots launch, we will update this policy if our practices differ from what is described here.
3.10 Information from other sources
We may receive business contact information from referral partners, clients who introduce colleagues, vendors such as Palo Alto Networks (for example, license or support information for a client's products), and public sources such as business websites.
4. How we use information
4.1 We use information to:
- respond to inquiries and route you to the right subsidiary;
- provide, operate, maintain, secure, and support the Services, including monitoring, backups, restores, troubleshooting, and incident response;
- schedule work, track reserved and flex hours, and manage client accounts;
- invoice and collect payment;
- protect our clients, our systems, and the Site, including detecting, investigating, and preventing security incidents, fraud, and abuse;
- improve our Services using sanitized and de-identified information;
- run our marketing and gift box programs, and (once launched) our planned advertising network and hotspot programs, as described in Section 3;
- send business communications to clients and prospects, such as service notices and, where permitted, information about our services (you can opt out of marketing emails at any time); and
- comply with law, enforce our agreements, and protect our rights and the rights of others.
4.2 Sanitized and de-identified information. Where practical, for our Managed Security services we sanitize and correlate logs so identifying details are removed or replaced, and we combine information across clients so it cannot reasonably be linked to a specific client or individual. We may use and keep de-identified information to improve our Services. We will not attempt to re-identify it, except to test our de-identification methods, and we require the same of anyone we share it with.
4.3 Data we handle for clients. We use Hosted Data, client firewall data, and client security data (Sections 3.4–3.6) only to provide the Services to that client, as the client instructs, to secure our Services, or as required by law. We do not use it for our own marketing or advertising.
4.4 No automated decisions with legal effects. We do not use personal information to make automated decisions that produce legal or similarly significant effects about individuals. Our security tools do automatically block traffic, sites, and files that appear malicious, according to the client's configured policies.
5. How we share information
We minimize the information we share outside The Spider Services. We do not share specific network activity or application usage that can be attributed to a specific individual or client, except with that client or when required by law. We share information only as follows:
- Within The Spider Services. The Holding Company and our subsidiaries share information as needed for shared support, administration, and the website, and to coordinate services for a client that works with more than one of our subsidiaries. Each subsidiary issues its own invoices. We do not share client data or personal information with the Equipment Lessor, which only owns the equipment we use.
- With the client. Information we collect while providing Services to a client (including logs, alerts, and reports) is shared with that client.
- Service providers. We use vendors that help us operate, under contracts that limit their use of information to providing services to us. Where possible we sanitize information before sharing it. Our service providers include:
- Invoice Ninja – invoicing and payment portal;
- Stripe – payment processing;
- [CRM/EMAIL PROVIDER] – contact form delivery, email, and customer relationship management [CONFIRM: CONTACT FORM BACKEND];
- Akamai Technologies, Inc. (Akamai Cloud) – cloud infrastructure hosting for portions of the Site, including our status page;
- [DATA CENTER / CLOUD PROVIDER] – infrastructure for our hosting and security cloud, where applicable [CONFIRM: INFRASTRUCTURE PROVIDERS];
- [SHIPPING CARRIER] – gift box delivery; and
- security, threat intelligence, and software vendors whose products are part of the Services, which may receive security events, malicious file samples, or indicators of compromise needed to identify threats.
- Technology vendors at the client's direction. For example, Palo Alto Networks or other vendors when we open support cases on a client's behalf.
- Legal and safety. When we believe in good faith that disclosure is required by law, subpoena, or court order, or is necessary to protect the rights, property, or safety of The Spider Services, our clients, or others. Where legally permitted, we will notify the affected client before disclosing its data.
- Business transfers. In connection with a merger, acquisition, financing, reorganization, or sale of all or part of our business, subject to this policy.
- With your consent or at your direction.
6. No sale of personal information
We do not sell personal information, and we do not "share" personal information for cross-context behavioral advertising (as those terms are defined under California and other state privacy laws). We have not done so in the past 12 months. We do not knowingly sell or share the personal information of anyone under 16.
7. Advertising network (planned)
Our planned local advertising network is expected to display client advertisements in places such as hotspot connection pages (once hotspots launch), gift box materials, and other locations we choose. Ads would be placed by location and context, not on profiles of individual viewers. We expect reporting to advertisers to be limited to the number of ad displays per location (aggregate counts only), and we will not give advertisers personal information about people who see their ads. If and when the network launches, we will update this policy to describe how it works. If our practices ever change in a way that involves personal information, we will update this policy first and provide any opt-out or consent required by law.
8. Cookies and similar technologies
8.1 Currently none. The Site does not currently use cookies, web beacons, analytics tools, or third-party scripts. The contact form sends only the information you enter.
8.2 Embedded content and links. If the Site later includes embedded content from other websites (for example, videos or a news feed), that content behaves as if you visited the other website, which may collect data about you, use cookies, and track your interaction with the content.
8.3 Social media. If you interact with our pages on social media (for example, Facebook), the platform's privacy policy applies to that interaction.
8.4 Changes. If we add cookies, analytics, or similar tools, we will update this section before doing so, describe what they do, and provide any choices required by law.
8.5 Browser signals. Because we do not sell or share personal information or track you across sites, there is nothing for a "Do Not Track" or Global Privacy Control signal to turn off today. If that changes, we will treat a Global Privacy Control signal as a valid request to opt out of sale or sharing.
9. How long we keep information
We keep information only as long as needed for the purposes in this policy, our client agreements, and our legal obligations.
| Information | How long we keep it |
|---|---|
| Contact form submissions and inquiries that do not become clients | [INQUIRY RETENTION PERIOD] after our last communication |
| Website server logs | [SERVER LOG RETENTION PERIOD] |
| Client account, contract, and billing records | For the relationship plus [RECORDS RETENTION PERIOD] for tax, accounting, and legal purposes |
| Hosted Data (Managed Computing and Hosting services) | For the term of the Services, then returned or deleted as described in the Computing Service Terms |
| Unsanitized security logs (Managed Security services) | Deleted within 24 hours of being sanitized and correlated |
| Sanitized / de-identified information | As long as needed to improve our Services |
| Hotspot connection logs (planned program) | [HOTSPOT LOG RETENTION PERIOD] |
| Gift box recipient details | Until the recipient or client opts out or the relationship ends |
Encrypted backups. Sanitized and unsanitized information, including client data, may continue to exist in encrypted backups beyond the periods above until those backups are replaced. Encrypted backups are replaced and deleted on a regular cycle of approximately [BACKUP ROTATION PERIOD]. We do not restore or use information from backups except to restore services, recover from incidents, or meet legal obligations.
We may keep information longer when required by law or to resolve disputes, enforce agreements, or preserve evidence of a security incident.
10. How we protect information
Each of our Services depends on some level of access to private or confidential client data. While client data is in our possession, we commit to the following.
All Services:
- restricting access to client data to personnel with a business need;
- using SSL/TLS encryption to access any website or portal containing client data;
- using full-disk or file-level encryption anywhere client data is stored;
- restricting file transfers to approved services that encrypt data in transit and at rest; and
- requiring non-disclosure agreements from every employee and contractor who may have access to client data or environments.
Managed Computing and Hosting services:
- keeping each client's environment separate from every other client's;
- encrypting client data at multiple levels, and enabling encryption any time client data leaves a managed server; and
- always encrypting remote backups.
Consulting services:
- using client-approved accounts and credentials only for the engagement, storing credentials in an encrypted credential manager, and returning or deleting access at the end of the engagement. [CONFIRM: CREDENTIAL HANDLING PRACTICE]
Managed Security services:
- sanitizing and correlating logs containing identifiable information;
- expiring and removing unsanitized logs within 24 hours of correlation (some unsanitized logs may continue to exist in encrypted backups until the backup is replaced); and
- not decrypting encrypted traffic unless the client has specifically requested TLS inspection and agreed to it in writing.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we learn of a security incident affecting personal information we are responsible for, we will notify affected clients and individuals as required by our agreements and applicable law, including Missouri's breach notification law (RSMo § 407.1500) and the laws of the states where affected individuals live. Where Missouri law requires, we will also notify the Missouri Attorney General and the nationwide consumer reporting agencies.
11. Your privacy rights
11.1 Information we control. Depending on where you live, you may have the right to:
- know and access the personal information we hold about you and how we use it;
- correct inaccurate personal information;
- delete personal information;
- receive a copy of your personal information in a portable format;
- opt out of the sale or sharing of personal information, targeted advertising, or certain profiling (we do not do these things);
- limit the use of sensitive personal information (we use it only as permitted to provide the Services and keep them secure); and
- not be discriminated against for exercising any of these rights.
Residents of California, Colorado, Connecticut, Virginia, Texas, Oregon, and other states with comprehensive privacy laws have some or all of these rights, subject to exceptions in those laws. Missouri, where we are based, does not currently have a comprehensive consumer privacy law, but we extend these rights to all U.S. individuals where practical.
11.2 Data we handle for clients. For Hosted Data, client firewall data, client security data, and other information we process on a client's behalf, the client controls the data and should handle your request. If you send us a request about that data, we will forward it to the client or tell you which client to contact, and we will help the client respond.
11.3 Limits based on how our services work. Because we sanitize and de-identify much of what we collect and delete raw security logs quickly, we often cannot connect that information back to a specific person, and we are not required to re-identify information to respond to a request. The information we are generally able to provide access to includes:
- your contact, account, and billing information; and
- Managed Computing and Hosting services: managed server backups containing encrypted and unencrypted data (to the client, under its agreement).
11.4 California notice at collection. In the past 12 months we have collected these categories of personal information: identifiers (such as name, email, IP address); commercial information (such as orders and payment history); internet or network activity (such as server logs, network traffic metadata, and application usage); professional information (such as job title and employer); and inferences only to the extent needed to detect security threats. We collect them from the sources and for the purposes described in Sections 3 and 4, disclose them only as described in Section 5, keep them as described in Section 9, and do not sell or share them. We may collect "sensitive personal information" such as account login credentials when clients provide them to us for the Services; we use it only to provide the Services and not to infer characteristics about anyone.
12. How to exercise your rights
- Email: support@spiderservices.net with the subject "Privacy Request"
- Phone: (888) 271-8668
- Mail: The Web Holding Services, LLC, Attn: Privacy, 120B E 1st Street, Mountain Grove, MO 65711
We will confirm receipt within 10 business days and respond within 45 days (or the period required by applicable law), and tell you if we need more time. We will verify your identity by matching information you provide with information we already have; we may ask for more information when needed. You may use an authorized agent, but we may ask the agent for proof of authority and ask you to verify your identity.
Appeals. If we deny your request, you may appeal by replying to our decision or emailing support@spiderservices.net with the subject "Privacy Appeal." We will respond within the time required by law. If you are not satisfied, you may contact your state attorney general.
13. Visitors outside the United States
The Spider Services is based in the United States and serves U.S. businesses. The Site is not directed to individuals outside the United States. If you visit from elsewhere, your information will be processed in the United States, where data protection laws may differ from those in your country. If you have a question about your information, contact us using Section 12.
14. Children
Our Site and Services are intended for businesses and are not directed to children. We do not knowingly collect personal information from children under 13 (or under 16 where state law sets a higher age). If you believe a child has provided us personal information, contact us and we will delete it. Our planned hotspots will be offered to the general public; a minor should use them only with a parent or guardian's permission.
15. Changes to this policy
We will update this policy when our services or practices change, including before we add cookies, analytics, or new data uses. The "Last updated" date at the top shows when it was last revised. If we make material changes, we will post a notice on the Site and, for clients, notify the primary contact on the account before the change takes effect.
16. Contact us
The Web Holding Services, LLC d/b/a The Spider Services
Attn: Privacy
120B E 1st Street, Mountain Grove, MO 65711
(888) 271-8668
support@spiderservices.net
Appendix A: Hotspot Privacy Notice (planned program)
The hotspot network is still being built. When it launches, display this short notice on the hotspot connection (captive portal) page.
Free Wi-Fi provided by The Spider Services. No sign-up is required, and we do not ask for your name, email address, or other personal details. When you connect, we collect only the standard network management data needed to operate and secure the network: your device's MAC and IP addresses, connection times, and bandwidth and usage metadata. Our security filtering automatically checks the domains your device requests to block malicious or prohibited content. This page may show ads for local businesses; ads are based on location, not on you or your browsing. We do not sell your personal information. Connection logs are kept for [HOTSPOT LOG RETENTION PERIOD]. By connecting, you agree to the hotspot rules in our Website Terms of Use. Learn more in our Privacy Policy or contact support@spiderservices.net.