Privacy Policy
Effective 27 July 2026 · Last updated 27 July 2026
This is the full account of what Spider Digital Group collects through this website, why, who else sees it, how long it stays, and what you can do about any of it. It was written from what the site actually does — every statement below is something the code does or does not do, and when the site changes, this page changes in the same release.
1. Who we are, and how to reach us
Spider Digital Group is a web design and build studio founded and run by Ian Ciamarra. It is the trading name of Ian Ciamarra, LLC, a North Carolina limited liability company, which is the legal entity behind this site and behind everything described in this policy. We work remotely with companies across the United States and we are based in North Carolina. For everything in this policy — questions, requests, complaints — we are the people responsible for the information described here. European and UK law calls that the controller; US state privacy laws call it the business, or the controller.
- Email — hello@spiderdigitalgroup.com. This inbox is monitored, and it is the fastest route for a privacy request.
- Phone — 202-318-5500.
- In writing — ask by email for a postal address and we will give you one.
You need no account, no reference number and no reason to contact us about your information. Asking costs nothing and changes nothing about how we deal with you.
2. What this policy covers
This website, and everything you can do on it: the forms, the design center, the accessibility toolbar and the privacy controls. It also covers the email that reaches us when you use a form.
It does not cover the websites we have built for clients — those are theirs, under their own policies — and it does not cover anywhere else you might find us. If a page here ever links out, the site on the other end has its own rules.
3. The short version
The detail is below and none of it contradicts this. If you read one section, read this one.
- Almost everything we hold, you typed in. Four forms, and all of them exist so we can reply to you.
- Two measurement tools can run here, and by default they do not. Microsoft Clarity and idpixel, both described in full below. Where the law requires permission first, nothing is loaded until you give it — not loaded-and-disabled; not present at all.
- We do not sell your information for money, and we never upload what you send through a form to an advertising platform. Section 12 says more, including the one place a US state law might still call what happens a “share”.
- Your browser can answer for you. If it sends a Global Privacy Control signal we treat that as an opt-out everywhere, before anything loads, and we tell you we saw it.
- You can change your mind at any moment, from the button in the corner of every page — one click, the same as it was to agree.
4. What we collect
Grouped the way the privacy statutes group it, so you can match this against the categories they name.
a. What you type into a form
There are four places on this site where you can send us something. All four deliver to the same inbox and nowhere else.
- Project brief. The “Start your project” form asks for your first and last name, company, email and phone, optionally your website address, anything you write in the notes, how you found us, and the goals and services you select along the way. It is the only form that also records a consent decision — section 5.
- Design center preview. Unblurring an imported preview asks for your first and last name, company, email and — optionally — phone. It sends those with the domain you asked us to import and the design settings your preview was built with.
- Design center quote. Asking for a quote sends your first and last name, company, email, optional phone, anything you write in the notes box, and the theme, colours, fonts and logo settings on screen at the time.
- Article notifications. The band on the writing page asks for an email address and nothing else.
Alongside a submission we record which of the four sent it, the page you were on, how long the form was open, and an event id for that one message. The endpoint keeps a fixed list of fields and discards anything not on it, so nothing extra can ride along into our inbox.
b. Records made by serving you the page
Delivering a website involves a server, and that server keeps ordinary request records — the page requested, the time, your IP address and your browser’s user-agent string — as part of sending you the page and protecting the site. That is our hosting provider’s infrastructure logging. It happens for every visitor, including one who refuses everything, because without it the page cannot reach you at all.
Our own form endpoint also reads your IP address, to enforce a limit of five submissions an hour from one connection. It is held in memory for that comparison and is never written to a log, an email or a file.
c. The two measurement tools, if they are running
Microsoft Clarity records how pages are used — clicks, scrolling, mouse movement, the pages you view, your browser and screen setup — and replays those sessions so we can see where a page is confusing. Microsoft sets its own identifiers when it runs, including one on bing.com that lasts about thirteen months and that Microsoft also uses for advertising.
idpixel gives your browser an identifier so a returning visit can be recognised as a returning visit, and sends visit activity to its own collector.
Neither runs unless the rules where you are permit it or you switched it on — section 9 sets out exactly which applies to you. There is a third switch, for advertising and data sharing. Nothing runs under it today: no advertising or remarketing tag is installed on this site. The switch exists ahead of any tag on purpose, so that permission can never be collected after the fact.
d. The design center’s import step
The design center has an optional step where you type a domain and we build a preview from it. When you do, our server — not your browser — requests that site’s public homepage and up to three of its stylesheets, and reads four things: the brand colours, a logo, the site name and tagline, and the first headline. The request identifies itself as SDG-DesignImport. It only reads pages that are already publicly available, and it refuses loopback, private, carrier-internal and link-local addresses — on the address you typed, on every redirect it is sent to, and on every stylesheet and logo it goes on to fetch.
Please use it on a site you own or are entitled to preview.
e. The website audit
The homepage has a tool where you type a web address and we report back on that site. When you use it, our server — not your browser — requests that address’s public homepage, and then /robots.txt, /sitemap.xml and /llms.txt on the same domain. It reads what is already in those public files: the page title and description, the headings, the links, whether images carry alt text, any structured data, and the response headers. The request identifies itself as SDG-SiteAudit. It only reads pages that are already publicly available, and it refuses loopback, private, carrier-internal and link-local addresses — on the address you typed and on every redirect it is sent to.
The address you type is also sent to Google. The speed half of the audit is Google PageSpeed Insights, which is a third-party service: we pass it the address and it returns the performance measurements. Google’s handling of that request is governed by their terms, not ours. Everything else in the audit is measured by us directly.
We do not store the report. If you ask us to email it to you, the address you give is a form submission and is handled under section 4a like any other enquiry.
Please use it on a site you own or are entitled to audit.
f. What we do not collect
We do not collect, and this site has no means of collecting, sensitive personal information as the US state laws define it: government identifiers, financial account or card details, precise geolocation, racial or ethnic origin, religious or philosophical beliefs, union membership, genetic, biometric or health data, or information about sex life or sexual orientation. We take no payments here. We do not buy, rent, trade or enrich your contact details, and we do not append data about you from an outside source.
Two clarifications, because both are commonly misread. First, a message you write to us in a form is addressed to us — that is not the interception of your correspondence those statutes have in mind. Second, to decide which privacy rules apply to your visit, our edge reads the country — and for the US and Canada, the state or province — that our platform attaches to your connection. It is used for one comparison and then discarded: no IP address, no city, no coordinates, no precise location is stored, and what is written down is a single word naming which rulebook you got.
5. The consent record the form keeps
The project brief form ends with two tick boxes. Both start unticked and neither is filled in for you.
- Permission to reply — required. It says that we may call, text and email you about your enquiry and a possible working relationship, that message and data rates may apply, that message frequency varies, and that you can stop at any time by replying STOP. It covers that enquiry, and it is required because without it we have no way to answer you.
- Marketing — optional, and it stays optional. It says that we may send you marketing emails and texts, that you can unsubscribe at any time, and that message and data rates may apply. Leaving it unticked does not stop your enquiry going through and does not change the reply you get. The form submits without it; it does not submit without the box above.
When you submit, we record which boxes you ticked, the exact sentence that was on screen beside each one word for word, the moment you agreed as a UTC timestamp, and a version number for that wording. We keep the sentence rather than a yes or no, because a yes or no cannot show what you were agreeing to. If we ever change the wording, the version number changes with it, so an older record stays readable as what it actually said. A declined marketing box is recorded as declined, in words, so it can never be mistaken for a question nobody asked.
The other three forms do not carry these boxes. When you use one of them you are asking us for something specific, and we treat it that way — a reply, or the notification you signed up for. Not a marketing list.
6. Where it comes from
- From you — when you fill in a form, type a domain into the design center, or set your privacy choices.
- From your device automatically — the request records above, and, where a measurement tool is running, what that tool observes about your visit.
- From the website you asked us to import — which is a public page, not a person.
There is no fourth source. We receive no lists from data brokers, we do not enrich a submission against a third-party database, and we do not buy contact details.
7. Why we use it
- To reply to you, and to work out, scope and price the thing you asked about.
- To build the preview or the quote you requested in the design center.
- To send what you asked for — article notifications, and, only if you ticked the optional box, marketing you agreed to.
- To keep the site working and safe — serving pages, blocking automated abuse, rate-limiting the form, and refusing requests the import step should not make.
- To understand how the site is used, where that is permitted — which pages are read, where people get stuck, whether a visit is a first or a return.
- To record and honour your privacy choice, and to be able to show that we honoured it.
- To meet a legal obligation, or to establish, exercise or defend a legal claim if it ever comes to that.
That is the whole list. We do not build a profile of you, we do not score you against a model, and filling in one form does not put you on a list for something else.
8. Our legal bases
This section is written for the GDPR and the UK GDPR, which require a named basis for each purpose. It is also the honest account of why we think each use is lawful anywhere else.
- Steps taken at your request before a contract — Article 6(1)(b). Handling your enquiry, preparing a preview, quoting, replying. Without this information we cannot do the thing you asked for.
- Consent — Article 6(1)(a). The measurement tools, and any marketing you opted into. Consent is the basis wherever the rules where you are require permission before something runs on your device. You can withdraw it at any time and withdrawing is as easy as giving it — one click in the same panel. Withdrawal does not make what happened beforehand unlawful, and it does not affect anything we hold on another basis.
- Legitimate interests — Article 6(1)(f). Three uses only: keeping the site available and secure, including the request records and the rate limit; answering an enquiry from someone plainly writing on behalf of a business; and keeping a record that a privacy choice was made and honoured. In each case the interest is our ability to run and defend a small studio’s website, the data is the minimum that does the job, and none of it is used to build a profile, to make a decision about you, or for anything you would not expect from having written to us. Where a jurisdiction treats one of these as needing consent instead, consent is what we ask for. You can object to any of it — section 18.
- Legal obligation — Article 6(1)(c) — and legal claims, only if we are required to produce something or have to defend ourselves.
We rely on no basis for special-category data, because we collect none.
9. How the choice works where you are
Privacy law does not ask the same question everywhere, so this site does not either. Before a page is built, our edge works out which of three rulebooks applies to you, from the country — and for the US and Canada, the state or province — that your connection arrives with. Nothing about that is kept beyond which rulebook you got.
- Permission first. The European Economic Area, the United Kingdom, Switzerland, Brazil and Quebec — and anyone we cannot place. Nothing optional is put into the page at all until you say yes: not loaded and switched off, not there. Accept all and Reject all are the same size in the same box, there is no pre-ticked switch, and closing the banner with the X or the Escape key refuses rather than dodges the question.
- Notice, and a one-click stop. US states with a comprehensive privacy law, which use an opt-out model. The tools start when the page loads; the notice says so in those words rather than asking for a permission we did not wait for; and its main button turns the sharing off. Closing that notice is neither agreement nor opt-out and changes nothing about what is collected — it only stops us repeating ourselves for a month. Every right in section 18 is yours whether you click anything or not.
- Canada, outside Quebec. Analytics runs with this notice; anything that identifies you or feeds advertising stays off until you switch it on.
If we cannot tell where you are — no signal, a VPN, a corporate proxy, anything ambiguous — you get the strictest of the three. A US visitor whose state we cannot read gets the strictest one too. There is no branch in this site that guesses in our favour.
Global Privacy Control
If your browser sends a GPC signal — Firefox and Brave do by default, and several extensions add it — every optional category is switched off before anything can load, in every country, whether or not the law where you are compels it. You are shown no banner, because your browser has already answered. We read the signal three ways: the request header our edge sees before the page is built, the property your browser exposes to the page, and the older Do Not Track header. We treat GPC as a valid opt-out of sale and sharing, and both the privacy panel and the Do Not Sell or Share page show you that it was detected and honoured. It is an opt-out, not a lock — you can still switch something on afterwards if you want to.
Changing your mind
The button in the corner of every page opens your privacy choices, with a separate switch for analytics and session recording, for visitor identification, and for advertising and data sharing. The footer link opens the same panel. Turning something off clears what it stored on this device where we can reach it, and reloads the page without it — because a script already running in an open page cannot be recalled, only stopped from loading again.
10. Cookies and what is stored on your device
With every optional category off, a visit here leaves you with two small cookies and, if you have used the toolbar or made a choice, two entries in your browser’s local storage. None of them identifies you.
sdg_regionandsdg_gpc— set by us for thirty minutes, holding which of the three rulebooks applies to you and whether your browser sent a GPC signal. They exist so a page can honour your rules before it renders. Between them they contain one word and a 0 or a 1.sdg:consentin local storage — your own privacy decision, kept on your device: what you chose, when, which rulebook you were shown, which wording you saw, and whether the decision came from you or from your browser’s GPC signal.sdg:a11yin local storage — only if you change something in the accessibility toolbar. It never leaves your device.
If the measurement tools run, they set their own. Clarity sets two cookies on this site’s own domain and several on Microsoft’s, including the roughly thirteen-month one Microsoft also uses for advertising; idpixel writes its identifiers into local storage. The cookie policy is the itemised list, with names and lifetimes. Everything else here is first-party: the typefaces, the images and the video on the home page are served from this site, so with those switches off, loading a page here hands a request to nobody but us.
11. Who else sees it
This is all of them. If another is ever added, it is named here in the same release that adds it.
- Our hosting and content-delivery provider. It serves every page, and necessarily handles the traffic and the request records described in section 4b.
- Resend, an email-delivery provider in the United States. What you send through any of the four forms reaches us as email, and Resend delivers it. It receives the contents of your submission and your email address — which is set as the reply-to, so a reply goes straight back to you — and handles that only to deliver the message. It is not used for marketing and it sets nothing on your device.
- Microsoft, through Clarity — only while that category is running. It sees your visit, not your form submission, and it sets its own identifiers including an advertising one.
- idpixel — only while that category is running. It sees your visit and gives your browser an identifier.
- LeadConnector, our scheduling provider — only if you open “Book a call”. Nothing is requested from them until you do. When you do, the calendar is loaded from their servers, so they see that request and whatever you then enter to book a time. They are not involved in anything else on this site.
- Anyone the law requires — a lawful request, a court order, or where we must act to establish or defend a legal claim or to protect someone’s safety. We would tell you unless we were forbidden to.
- A buyer, if the business ever changed hands. Enquiry records could pass to a successor as part of the business. Whoever received them would be bound by this policy for what they received, and we would post the change here first.
There is no advertising network, no data broker, no CRM, no chat widget, no embedded video, map or social button, and no analytics product other than the two named above.
12. Sale, sharing and targeted advertising
We do not sell personal information for money. We have never uploaded what you send through a form to an advertising platform, and there is no advertising or remarketing tag on this site.
We will not claim more than that, because US state laws define “sale” and “sharing” more broadly than an exchange of money — passing identifiers to an advertising company can count on its own. Microsoft Clarity sets a Microsoft advertising identifier when it runs. So while the analytics category is running, a visit here can involve the kind of disclosure those laws call a share for cross-context behavioural advertising. We would rather write that down than lean on an exemption we have not tested.
We do not knowingly sell or share the personal information of anyone under 16, and we offer no financial incentive or price difference in exchange for your information.
Three ways to stop it, each of which works on its own:
- the Do Not Sell or Share My Personal Information page — one button, no account, no email address, no identity check, because the law forbids making you prove who you are to stop a sale;
- the privacy panel in the corner of any page, where each category has its own switch;
- a browser that sends Global Privacy Control, which we honour automatically and everywhere.
The third switch, for advertising and data sharing, is a permission in advance. Turning it on means agreeing that what is collected may be used for advertising and shared or sold as those laws use the words. Nothing is installed under it today, it is off unless you switch it on, and you can withdraw it in the same panel.
13. How long we keep it
This website has no database of enquiries. What you send arrives as email and lives in our mail system, which is where the retention question actually applies.
- Enquiries and their consent records — for as long as we are in conversation with you about the work, and afterwards for as long as there is a business or legal reason to keep the record. A record of when and to what you agreed is one of those reasons, and it is kept for as long as a claim about that contact could still be brought. When neither applies, we delete it. If you want your enquiry deleted sooner, ask and we will do it.
- Your privacy decision — stays in your browser until you clear this site’s data or change it. A copy carrying no identifier is sent to our own server, where it appears in a short-lived runtime log. To be straight with you: that is enough to see the system working, it is not a durable archive, and we are not claiming to keep one.
- Server request records — kept by our hosting provider for its own short operational window.
- What the measurement tools collect — Microsoft and idpixel hold it under their own retention rules. The cookie lifetimes we can see are in the cookie policy.
14. How it is protected
The most effective thing we do is keep the number of places your details live as small as possible. This site stores no leads, holds no accounts, has no login and takes no payments, so there is very little here to lose in the first place.
- Every page and every form is served over an encrypted connection.
- The form endpoint accepts a fixed list of fields, caps the size of a submission, limits how many can arrive from one connection in an hour, and drops automated fillers using a hidden field no person can see, focus or tab to.
- It refuses to report success for a message it did not deliver, so an enquiry cannot be silently lost.
- Nothing about you enters our own logs from that endpoint — it records an event id, which form it came from, and whether delivery worked.
- The import step will not fetch an address on a private or internal network, and re-checks that on every redirect it is sent to.
- The record of your privacy decision is rebuilt field by field from a fixed schema, so nothing extra can be attached to it, and the page it was made on is truncated and stripped of its query string.
No transmission over the internet is completely secure, and we will not pretend otherwise. We hold no security certification and we do not claim one.
15. Where it goes
We are in the United States and so is our infrastructure. If you are outside the United States, what you send us is transferred there, and the country you are in may treat that as a transfer to a place without an equivalent data-protection regime.
For visitors in the European Economic Area, the UK or Switzerland, two things carry that transfer. Anything you send through a form travels because it has to — it is necessary to take the steps you asked us to take, which is the contract-necessity route in Article 49(1)(b). Anything the measurement tools collect travels because you allowed them, having first been told what they are and where they are: the explicit-consent route in Article 49(1)(a). You can withdraw that in a click, at which point they stop.
We do not claim a certification we do not hold, and we will not name a safeguard we have not executed. If you would rather your information did not leave your own region, do not use the forms — call us instead.
16. Automated decisions and profiling
There is no automated decision-making here, and there is no scoring. Nothing on this site produces a decision about you with legal or similarly significant effects, automatically or otherwise. No model ranks you, prices you, filters you out or decides whether you get a reply. A person reads every enquiry.
The measurement tools do observe behaviour, and while they are running that observation is what some laws call profiling in the broad sense — recognising a returning browser, replaying how a page was used. Nothing is decided from it. If that ever changes it will be described here before it happens, with the right to object and the right to human review spelled out.
17. Children
This site is for businesses. It is not directed at children, we do not knowingly collect personal information from anyone under 13, and we do not knowingly sell or share the personal information of anyone under 16. We do not ask your age, so we have no way to know it — which is exactly why we do nothing with what we collect that would need to know it.
If you are a parent or guardian and believe a child has sent us something, email hello@spiderdigitalgroup.com and we will delete it.
18. Your rights, in full
Which of these you can enforce depends on where you live, and we do not intend to argue that with you. Whoever you are and wherever you are, you can ask us for any of the following and we will do it unless a law stops us. If we ever refuse, we will tell you why and what you can do about it.
- Know and access. What we hold about you, where it came from, why we have it, and who else has seen it.
- A copy you can take elsewhere. In a common, machine-readable format.
- Correction. Tell us what is wrong and what it should say.
- Deletion. Ask, and we delete it — unless we are required to keep something, in which case we tell you what and why.
- Opt out of sale, sharing and targeted advertising. The Do Not Sell or Share page, a GPC signal, or an email — any one of the three.
- Limit how sensitive information is used. We collect none, so there is nothing to limit. If that ever changes, the control ships with the change.
- Withdraw consent, and object. Withdraw any permission from the corner button. Object to anything we do on legitimate interests, including the request records, by emailing us — say what you object to and we stop, unless we have a compelling reason we can explain to you.
- Restrict processing while a dispute about accuracy or a legitimate interest is being worked out.
- No retaliation. Exercising any of this changes nothing about the service you get, the price we quote, or how we deal with you. It never will.
- Appeal. Several US states give you the right to appeal a refusal. If we turn a request down, reply to our answer and say you are appealing — a person looks at it again and writes back, and we tell you how to contact your state Attorney General if you are still not satisfied.
- Complain.To your data-protection authority: your supervisory authority in the EEA, the Information Commissioner’s Office in the UK, the FDPIC in Switzerland, the ANPD in Brazil, the Office of the Privacy Commissioner in Canada, or your Attorney General in the US. You do not have to come to us first — but we would rather you did, because usually we can just fix it.
19. How to make a request
Email hello@spiderdigitalgroup.com or call 202-318-5500 and say what you want. There is no form to fill in and no portal to register with. It helps to say which right you are exercising, and enough about your enquiry — the email address you used, roughly when — for us to find it, but we will work with whatever you can give us.
- How we check it is you. For access, copies, correction and deletion we match what you tell us against what we hold, usually by replying to the email address in the record. We ask for the least we can, we never ask for a government ID, and anything you do send to prove identity is used for that and then deleted.
- Opting out needs no proof at all. The Do Not Sell or Share button and the privacy panel work on the spot, for that browser, with no identity check.
- Someone acting for you. Where the law lets you use an authorised agent, we will deal with them: send us written permission signed by you, and we may check with you directly before acting. We have no dedicated agent portal, so email is the route — and we will not use the absence of a portal as a reason to say no.
- What it costs. Nothing. Some laws let us charge for, or refuse, a repetitive or excessive request; we would tell you before doing either, and we would rather just answer.
- How fast. As fast as we can, and within any deadline the law that applies to you sets. We are not going to invent a number here that a studio this size cannot guarantee on a bad week — but where a statutory clock applies to your request, that clock is the promise.
20. US state addendum
This section restates what is already above, in the form the US state privacy statutes ask for. Where a state gives you something section 18 does not, this is where it is written down.
Notice at collection
We collect identifiers (name, email, phone), commercial information (what you are asking us to build), internet activity (pages viewed, how the page was used, and the identifiers the measurement tools set), and inferences only in the loose sense that a returning browser can be recognised as returning. We collect no sensitive personal information, no biometric information, no precise geolocation and no financial account information. Purposes are in section 7, recipients in section 11, retention in section 13. We do not sell personal information for money; “sharing” is addressed squarely in section 12.
California
If you are a California resident, the CCPA as amended by the CPRA gives you the right to know, access, delete, correct, obtain a portable copy, opt out of sale and sharing, limit the use of sensitive personal information — moot here, since we collect none — and not to be discriminated against for exercising any of them. We honour Global Privacy Control as a valid opt-out signal and show you that we did. We offer no financial incentives. Under California’s “Shine the Light” law you may ask whether we disclosed personal information to third parties for their own direct marketing: we do not, and we will confirm that in writing if you ask.
Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky and Rhode Island
Each of these states gives residents a version of the same set: confirm and access, correct, delete, take a portable copy, and opt out of targeted advertising, of sale, and of profiling that produces legal or similarly significant effects — the last of which does not happen here at all. Most also give you an appeal, which is in section 18. Most require us to honour an opt-out preference signal such as GPC, which we honour everywhere rather than only where we must. Minnesota residents may additionally ask about the profile used in a profiling decision; there is none. Maryland’s tighter limits on sensitive data and on data from minors bite on information this site does not collect.
Other states
Nevada residents may tell us not to sell covered information; we do not sell it, and the same email address handles the request. Washington and Nevada consumer-health laws apply to consumer health data, which this site does not collect. Illinois biometric law applies to biometric identifiers, which this site does not collect and has no means of collecting.
If your state is not listed
You get the strictest of our three rulebooks, which means nothing optional runs until you say yes — we would rather over-protect a visitor than guess in our own favour. And section 18 still stands: ask us, and we will do it.
21. EEA, UK, Switzerland and Brazil addendum
Our services are offered to businesses in the United States. The site is reachable from anywhere, so we apply the permission-first rulebook to visitors in the EEA, the UK, Switzerland, Brazil and Quebec regardless of whether we are required to.
- Controller. Spider Digital Group, contactable at hello@spiderdigitalgroup.com. We have not appointed a data protection officer and are not required to: we carry out no large-scale monitoring and no large-scale processing of special categories. Ian Ciamarra handles privacy questions personally.
- Legal bases — section 8. Transfers — section 15. Your rights — section 18, including the right to complain to your supervisory authority.
- Nothing here is required of you by statute or contract. Every field on this site is voluntary. The only consequence of leaving one blank is that we cannot reply about the thing it was for.
- Quebec.Law 25 requires express consent for profiling and tracking technology, so Quebec gets the permission-first rulebook rather than the rest of Canada’s.
- Brazil. The LGPD offers several legal bases; for third-party session recording and cross-site identifiers we ask for consent, which is the honest one.
22. What this policy does not cover
Sites we have built for clients, which are theirs and carry their own policies. Any site you reach by following a link from here. What a measurement tool’s own provider does with what it collects, which is governed by their terms as well as ours. And anything you choose to send us outside this site — an email you write directly, a call you make — which we handle just as carefully but which did not come through the machinery described above.
23. Changes to this policy
This version is effective 27 July 2026 and replaces every earlier one. When it changes, the date at the top changes with it, in the same release as the change it describes. That is the rule we hold ourselves to, and it is the reason this page can be read as a statement of fact rather than an aspiration. If a change materially affects how we use information we already hold, we will not apply it to that information without asking you first.
This policy describes what this website does. It is not legal advice, and it creates no rights beyond the ones the law already gives you — but nothing in it takes any of those away either.
Also on this site: Terms of Use · Cookie policy · Do Not Sell or Share My Personal Information · Accessibility statement
