Your data, your choice.
AmbiSecure does not require analytics to use the site. We use privacy-conscious, aggregate analytics — opt-in by default, no advertising cookies, no PII collection, no profiling. Adjust your preference below or reset it via the consent banner.
Need to revisit the consent banner? .
What we collect
- Server-side request logs. Standard web-server logs (IP, user agent, request path, HTTP status, byte count) kept by Hostinger LiteSpeed. Used for operational troubleshooting; not joined with any other data.
- Aggregate analytics (only if enabled): privacy-conscious page-view counts via Plausible, or page-view + interaction counts via GA4. Configuration:
/assets/js/analytics-config.js?v=32. - Web Vitals telemetry (only if enabled): LCP, CLS, INP, TTFB. Reported through the same analytics provider; no separate beacon endpoint.
- Contact-form enquiries. If you submit the form at /contact/, we receive the name, business email, and message you enter, plus company, phone, country and enquiry topic if you choose to provide them. This is the one place on the site where we do collect personal data, and it is collected only so we can reply to you.
What we do not collect: we do not set advertising cookies, we do not load third-party advertising tags, we do not embed social-sharing pixels, and we do not cross-link visitors across sessions. Analytics never receives your name, email, phone, company or message — enquiry content is handled only by the contact path described below.
Contact-form enquiries
Where it goes. The form posts to AmbiSecure’s own endpoint on this domain (/contact/submit.php) over HTTPS. It is not routed through a third-party form service, CRM, marketing platform, or analytics provider. There is no external processor involved.
What happens to it. Your enquiry is written to a private store on the web host that is not reachable over the web, and a copy is emailed to the AmbiSecure team so we can reply. Each submission gets a random reference (for example AS-20260101-A1B2C3D4) that is not derived from anything you entered.
What we use it for. Replying to you, and nothing else. We do not add you to a mailing list, we do not profile you, we do not sell or share your details, and submitting the form does not subscribe you to anything.
Retention. Enquiries are kept while we are in contact with you and for a reasonable period afterwards so we can pick up an earlier conversation.
Analytics is separate. A successful submission may record an anonymous conversion event, but only if you allowed analytics, and it carries no personal data — only the enquiry topic you selected and which form it came from.
Abuse controls. To limit spam we apply rate limiting based on a salted, daily-rotating hash of your IP address. The raw IP is not stored by the form, and the hash cannot be reversed to identify you.
WhatsApp. The WhatsApp links on this site open a conversation with our business number in WhatsApp. That conversation happens on WhatsApp’s service, not on this website — messages you send there are processed by WhatsApp/Meta under their own terms and privacy policy, and we receive them in the WhatsApp Business app. We do not pass anything from this website into that chat; clicking the link sends no form content, name, email, or tracking identifier. If you prefer your enquiry to stay entirely within AmbiSecure’s own systems, use the contact form or email instead.
To ask what we hold about you, or to have an enquiry deleted, email support@ambimat.com.
Do-Not-Track
AmbiSecure honours the DNT: 1 browser signal by default. If your browser sends Do-Not-Track, the analytics + Web Vitals scripts will not load even if the site operator has the provider enabled. The opt-out toggle above is independent of the DNT signal — you can opt out without DNT, or DNT without opting out.
Vulnerability disclosure & security contact
Security reports go to security@ambimat.com — the vulnerability-disclosure channel is documented at /trust/.