terms · billing, retainers, deposits
What you are agreeing to
Everything here applies to every engagement unless a signed scope says otherwise. It is written down so that neither of us has to reconstruct it later from memory, and so that the answer to an awkward question is the same whether it gets asked before the work or after it.
Payment
Payment
when it is due
Net 14
Invoices are due fourteen days from the date they are issued. That is short enough that a missed invoice surfaces while everyone still remembers the work, and long enough to clear an ordinary accounts payable cycle. If your payables run on a different schedule, say so before the first invoice rather than after it.
if it is late
A reminder, not a penalty
A late invoice gets an email. There is no automatic late fee and no interest, because chasing small penalties costs more goodwill than it recovers. What does happen is that new work pauses while an invoice is materially overdue, and that pause is the whole consequence.
how it arrives
A real Stripe invoice
Every invoice is issued through Stripe, itemized, with the work period on each line. It is payable by ACH Direct Debit or card from the invoice itself. Nothing is ever collected by wire, and nobody will ever email you asking to change payment details.
Processing fees
Processing fees
The invoice total is what you pay. Card and ACH processing fees come out of my side, they are not added to your bill, and payment processing is not marked up. An invoice for a thousand dollars costs you a thousand dollars whichever way you pay it.
That is worth stating plainly because it changes how you should read the ACH request on the payment page. I prefer ACH Direct Debit because a card fee is a percentage of the total and grows every time the invoice does, while ACH does not. Choosing ACH saves money I would otherwise absorb, not money you would otherwise be charged. It is a favor, and it is fine to decline it when clearing today matters more.
source: Stripe's published processing fees, which price cards as a percentage of the total and ACH Direct Debit separately. No figure is quoted here because Stripe changes them and a stale number on this page would be a lie about my costs rather than yours.
Deposits
Deposits
New work starts with a deposit against a scope you have already approved. The deposit is credited against the first invoice; it is not an extra charge and not a booking fee.
If the work is cancelled before it starts, the deposit is returned in full. If it is cancelled partway, the deposit is applied to the hours already worked and anything left over is returned. What I do not do is keep a deposit against work that never happened, on either side of the decision to stop.
Your data and AI
Your data and AI
These are commitments rather than intentions, which is why they are here and not only on the questions page. If any of them is broken, it is a breach of these terms and not a judgment call I got wrong.
- Your data is not put into AI prompts. Assistants used while building see code and structure. They do not see your records, your customers, or anything identifying. Where realistic data is needed, it is synthetic.
- If real data is ever required, you are asked first. It is minimized before it moves: direct identifiers removed, quasi-identifiers generalized, the smallest sample that answers the question rather than a full export. You approve that before it happens, and you can decline it.
- Nothing of yours is submitted to a service that trains on its inputs.This constrains which tools I use, not how carefully I use them.
- Your systems run on your accounts. Not mine, not a reseller account, from the first day rather than migrated at the end.
- My access ends at handoff. You change the credentials and I am out. I keep no standing access to a delivered system, and nothing continues to depend on me.
- Credentials are never committed to a repository. Configuration lives outside the code, and unfinished configuration announces itself rather than failing silently in production.
What these do not include is a certification. I am not SOC 2 audited and not CMMC assessed, and I will not imply otherwise. Both are formal processes with reports behind them rather than postures a solo practice can adopt. If your procurement needs specific controls evidenced, raise it before we start and I will tell you plainly whether I meet them.
If something goes wrong
If something goes wrong
If your data is exposed, or I have reason to believe it may have been, you hear it from me within 24 hours of my becoming aware. Not after I have finished investigating, and not after I have worked out whether it was my fault.
That deadline is deliberate and it is not about my convenience. If your business has its own notification obligations, and most do, the clock on them starts when the breach happens rather than when I get around to mentioning it. A vendor who takes two weeks to tell you has already made it impossible for you to meet your own deadline. Telling you inside a day is what keeps that decision yours.
The first message will be short, because a fast partial account is worth more than a slow complete one. It will say what I know, what data is involved, when it happened, what I have already done, and what I need from you. A fuller written account follows within 72 hours, including how it happened and what changes so it cannot happen the same way twice.
Three things I commit to alongside the timing. I will tell you on suspicion rather than waiting for certainty, accepting that some of those calls will turn out to be nothing. I will not quietly fix something and decide afterward that you did not need to know. And I will preserve the logs and evidence rather than cleaning up first, because your own investigation may need them and a tidied system cannot be examined.
This applies to anything I hold or have access to. Where a system runs on your own accounts, which is the normal arrangement here, an incident inside your account is yours to handle, and I will help. What I am promising is that nothing reaches you late because it came through me.
What a retainer covers
What a retainer covers
A retainer buys support for a system that exists. The line between support and new work is the one thing on this page most likely to be argued about, so it is drawn here rather than in an email during a disagreement.
The test
If it worked before and does not now, that is support and it is covered. If it has never existed, that is new work and it is quoted. When a request genuinely sits on the line, it is treated as covered. That default is deliberate: the cost of occasionally absorbing a small piece of new work is much lower than the cost of a monthly argument about which side of the line something falls on.
Covered
- Fixing something that used to work and now does not, whatever the cause.
- Dependency and security updates, and the breakage that sometimes follows them.
- Content and copy changes to pages that already exist.
- Answering questions about how the system works, including from your own staff.
- Monitoring, and telling you about a problem before you notice it.
Quoted separately
- A capability the system has never had.
- A new page, a new integration, or a new data source.
- A redesign of something that works as specified.
- Work on a system I did not build, unless we have agreed to that separately.
Retainers bill monthly and can be stopped before any renewal. There is no minimum term and no cancellation fee. Stopping a retainer does not affect anything already built and handed over, which remains yours regardless.
Something here does not fit
These are defaults, not conditions of doing business. If your organization needs different payment terms, a purchase order referenced on the invoice, or a scope boundary drawn somewhere else, that is a conversation rather than a problem. Raise it before the first invoice.
Ask about terms