
Privacy and Data Protection
Privacy and Data Protection
Everything we hold and why, split by who you are: a visitor, an inquiry, a client, or somebody we contacted first. Including where we got it and how to make us delete it.
On this page · 12 sections
The two roles we play
Which one applies decides whose policy governs the data, and who has to answer the person it belongs to.
| Role | When | What it means |
|---|---|---|
| We decideController | Our own website, our own marketing, our own sales outreach, and our relationship with you as a client | We decide why and how the data is used, and this policy governs it. |
| You decideProcessor | Data belonging to your customers, held in systems we built or manage for you. Form submissions, call records, CRM contacts, SMS lists | You decide why and how it is used. We act on your instructions. Your privacy policy governs it, not ours. |
We only ever act in the second role for your customer data, and we never step outside your instructions with it. If you are a client and you need a written data processing agreement, ask and we will provide one.
If you are subject to HIPAA, read this before you go further. We do not sign business associate agreements and we do not accept protected health information in any system we build or manage. That is a fixed limit rather than a negotiating position. It does not mean we cannot work with you, and what we can still build a practice sets out exactly what a healthcare engagement looks like. The full list of data we decline, and the laws behind each one, is in Compliance Responsibilities.
What we collect, and why
Grouped by how you came into contact with us, because the answer is different in each case.
If you visit our website
- Pages viewed, time on page, referring source, approximate location from IP, device and browser
- Cookie and similar identifiers, the full list is in the Cookie and Tracking Policy
Why: to understand which pages work and to improve them.
If you contact us or book a call
- Name, email, phone, business name and website
- What you told us about your business, what you sell, roughly what a customer is worth, how you get customers now, your timeline and budget range
- Call recordings or transcripts, where a call is recorded and you have been told so at the time
Why: to answer you, to work out whether we are a fit, and to quote accurately.
If you become a client
- Everything above, plus billing details held by our payment processor
- Business details required for third-party registrations, legal name, EIN, registered address
- Access credentials or delegated permissions to systems you have asked us to work on
- Project communications, approvals and support history
Why: to deliver the work, to invoice, and to keep a record of what was agreed.
We do not ask for and do not want your passwords. Where a credential is unavoidable it is transmitted by an expiring secure link, never by email.
If we contact you first
We do outbound sales, so here it is plainly. If you heard from us without having contacted us, we found you through research and networking, searching for businesses in our area and industries, looking at your website, meeting people, and following up on referrals and introductions.
What we hold in that case is business information: your company name, website, industry, location, a publicly listed phone number or a business email address, and notes from looking at your site, how fast it loads, whether the contact form works, whether the Google profile is complete. We may confirm that an email address accepts mail or that a phone number is a working line before using it, so we are not calling dead numbers.
We do not buy lists. Any lists.
Not consumer lists, not business lists, not appended data, not a “verified B2B database” from anyone. Every contact we hold, we found ourselves, from a company’s own website, a public directory, a conversation, an introduction, or someone getting in touch with us.
We do not compile information about you as a private individual. What we hold is the kind of business contact information a company publishes in order to be contacted, and it is held for the same reason it was published.
If you would rather not hear from us, say so once and that is the end of it. You go on a do-not-contact list that every stage of our process checks against, and we delete what we hold if you ask. One email or one sentence on a call is enough, and you do not have to explain why.
Direct mail
Where we send physical mail, we use Every Door Direct Mail, the USPS service that delivers to every address on a chosen postal carrier route.
It is worth being precise about what that means: EDDM involves no personal data at all. There is no list. We do not know who lives or works at any address, we do not hold names, and nothing is addressed to an individual. We choose a geographic route and the Postal Service delivers to every address on it. The mail is addressed to “Postal Customer”.
Direct mail is the channel people assume is the least privacy-respecting. Done this way it is the only one we run that touches no personal information whatsoever.
Verification and enrichment
This is the part worth understanding properly, because it applies to information you gave us rather than information we went and found.
When someone fills in a form, on our website, or on a website we built for a client. They typically give a name, a phone number and an email address. Before that inquiry reaches a person, it is checked and, in some cases, added to.
What actually happens
| Step | What it does | Why |
|---|---|---|
| Spam filtering | Checks the submission itself, timing, patterns, bot signals | So real inquiries are not buried under junk |
| Email verification | Confirms the address exists and accepts mail | So a reply does not vanish, and so sending reputation is not damaged by bad addresses |
| Phone validation | Confirms the number is a working line and what type it is, mobile, landline, or internet | So a text is not sent to a landline, and so a call is not wasted |
| Business enrichment | Adds publicly available business information, company, industry, approximate size, role | So the person calling back knows who they are talking to |
| Scoring and routing | Ranks the inquiry against the criteria the business set | So the most urgent inquiry is called first rather than the earliest one |
All of it happens in seconds, and none of it decides whether anyone is offered a service. It decides what order a callback queue runs in. A person makes every decision after that.
Whose data this is
When it happens on our website, we are the controller and this policy governs it.
When it happens on a client’s website, that business is the controller and we are the processor. Their privacy policy governs it, they are responsible for telling people it happens, and a request to see or delete that data goes to them. We will help them action it, and we will tell you who they are if you are not sure.
Mobile and text messaging
Where you have given consent to receive text messages from us:
- We collect your mobile number, the consent record itself, when, how, and the exact wording you saw, and the delivery status of messages sent to you
- We use it only to send the messages you agreed to receive
- Mobile information and consent are never sold, rented or shared with third parties or affiliates for their own marketing or promotional purposes. No mobile opt-in data is shared with anyone except the service providers who deliver the messages on our behalf, and they may not use it for anything else
- You can stop at any time by replying STOP. Opt-outs are honored immediately and permanently, and we do not re-add a number from a later import
Full program details, frequency, rates, help, are in our SMS Terms.
How long we keep it
| What we hold | Kept for |
|---|---|
| Website analytics | [CONFIRM] |
| Inquiries that do not become clients | [CONFIRM] |
| Prospect records we sourced ourselves | [CONFIRM] |
| Client records and project files | Duration of the engagement plus [CONFIRM] |
| Invoices and financial records | As required by tax law, [CONFIRM, typically 7 years] |
| SMS consent records | [CONFIRM, keep at least as long as you message them, and afterwards as evidence] |
| Do-not-contact list | Indefinitely, because that is the point of it |
Security
We run our own infrastructure rather than reselling a third-party marketing platform, which means fewer parties hold your data and we control how it is protected.
- Encryption in transit across all services
- Access limited to people who need it for the work, using individual accounts
- Multi-factor authentication on administrative access
- Firewall, malware monitoring and intrusion detection
- Daily backups with 90-day retention
- Credentials handled through a password manager and expiring secure links, never by email
No system is perfectly secure and anyone who tells you otherwise is selling something. If a breach affects your personal information we will notify you and any regulator required, within the timeframes the law sets.
Your rights
Whatever jurisdiction you are in, you can ask us to:
- Tell you what we hold about you, and where we got it
- Correct it if it is wrong
- Delete it
- Send it to you in a portable format
- Stop contacting you, which we will do immediately and permanently, no reason required
- Object to how we are using it, or ask us to restrict it
How to ask
Email [email protected] or call +1-248-205-6977. Say what you want and give us enough to find you, usually the email address or phone number you were contacted on.
We respond within 30 days, and usually much faster. We may need to verify who you are before acting on a request, which is a protection for you rather than an obstacle. There is no charge, and we will not treat you differently for having asked.
You may use an authorized agent. If you do, we will need proof of their authority.
If we act as processor
If your data sits in a system we built for one of our clients, send your request to that business. They are the controller. If you are not sure who that is, ask us and we will tell you.
If you are not satisfied
Tell us first, most of these are misunderstandings and we would rather fix it directly. You also have the right to complain to your regulator: your state attorney general in the US, the ICO in the UK, your data protection authority in the EU, or the Office of the Privacy Commissioner in Canada.
Regional specifics
California
California residents have the rights above, plus the right to know what categories of information we collect and disclose, the right to opt out of any sale or sharing, the right to limit the use of sensitive personal information, and the right not to be discriminated against for exercising them.
We do not sell personal information for money. Whether certain advertising technologies constitute “sharing” is addressed below.
Canada
Commercial electronic messages to Canadian recipients are sent only with consent as required under CASL, with sender identification and a working unsubscribe in every message, honored within the required period.
United Kingdom and European Union
Where UK or EU data protection law applies, our lawful basis is: contract for work we do for clients, consent for marketing messages where consent is required, legitimate interests for business-to-business outreach and for keeping our own systems secure, and legal obligation for financial records.
You have the additional rights that law provides, including the absolute right to object to direct marketing.
Other US states
Several states now provide similar rights. We apply the rights listed above to everyone who asks, regardless of where they live, because maintaining different standards by state is how mistakes happen.
Children
Our services are for businesses and are not directed at children. We do not knowingly collect information from anyone under 16. If you believe a child has given us information, tell us and we will delete it.
Our SMS program is limited to people aged 18 or over.
Changes to this policy
We update this policy when what we do changes. The effective date at the top tells you when it last changed. Where a change is significant we will say so rather than quietly reposting it.
Ask what we hold about you
Client, inquiry, or somebody we emailed first, it makes no difference. Ask and we will tell you. Ask us to delete it and we do, with confirmation in writing.
Related documents
Black Tiger Digital · Waterford, Michigan · Mon to Sun, 9am to 9pm ET