We Do Not Sell Your DataNot yours, and not your customers. No list, no broker, not once, and every tool that touches it is named on this page.
Never Sold Deleted On Request

The two roles we play

Which one applies decides whose policy governs the data, and who has to answer the person it belongs to.

We only ever act in the second role for your customer data, and we never step outside your instructions with it. If you are a client and you need a written data processing agreement, ask and we will provide one.

If you are subject to HIPAA, read this before you go further. We do not sign business associate agreements and we do not accept protected health information in any system we build or manage. That is a fixed limit rather than a negotiating position. It does not mean we cannot work with you, and what we can still build a practice sets out exactly what a healthcare engagement looks like. The full list of data we decline, and the laws behind each one, is in Compliance Responsibilities.

What we collect, and why

Grouped by how you came into contact with us, because the answer is different in each case.

If you visit our website

  • Pages viewed, time on page, referring source, approximate location from IP, device and browser
  • Cookie and similar identifiers, the full list is in the Cookie and Tracking Policy

Why: to understand which pages work and to improve them.

If you contact us or book a call

  • Name, email, phone, business name and website
  • What you told us about your business, what you sell, roughly what a customer is worth, how you get customers now, your timeline and budget range
  • Call recordings or transcripts, where a call is recorded and you have been told so at the time

Why: to answer you, to work out whether we are a fit, and to quote accurately.

If you become a client

  • Everything above, plus billing details held by our payment processor
  • Business details required for third-party registrations, legal name, EIN, registered address
  • Access credentials or delegated permissions to systems you have asked us to work on
  • Project communications, approvals and support history

Why: to deliver the work, to invoice, and to keep a record of what was agreed.

We do not ask for and do not want your passwords. Where a credential is unavoidable it is transmitted by an expiring secure link, never by email.

If we contact you first

We do outbound sales, so here it is plainly. If you heard from us without having contacted us, we found you through research and networking, searching for businesses in our area and industries, looking at your website, meeting people, and following up on referrals and introductions.

What we hold in that case is business information: your company name, website, industry, location, a publicly listed phone number or a business email address, and notes from looking at your site, how fast it loads, whether the contact form works, whether the Google profile is complete. We may confirm that an email address accepts mail or that a phone number is a working line before using it, so we are not calling dead numbers.

We do not buy lists. Any lists.

Not consumer lists, not business lists, not appended data, not a “verified B2B database” from anyone. Every contact we hold, we found ourselves, from a company’s own website, a public directory, a conversation, an introduction, or someone getting in touch with us.

We do not compile information about you as a private individual. What we hold is the kind of business contact information a company publishes in order to be contacted, and it is held for the same reason it was published.

If you would rather not hear from us, say so once and that is the end of it. You go on a do-not-contact list that every stage of our process checks against, and we delete what we hold if you ask. One email or one sentence on a call is enough, and you do not have to explain why.

Direct mail

Where we send physical mail, we use Every Door Direct Mail, the USPS service that delivers to every address on a chosen postal carrier route.

It is worth being precise about what that means: EDDM involves no personal data at all. There is no list. We do not know who lives or works at any address, we do not hold names, and nothing is addressed to an individual. We choose a geographic route and the Postal Service delivers to every address on it. The mail is addressed to “Postal Customer”.

Direct mail is the channel people assume is the least privacy-respecting. Done this way it is the only one we run that touches no personal information whatsoever.

Verification and enrichment

This is the part worth understanding properly, because it applies to information you gave us rather than information we went and found.

When someone fills in a form, on our website, or on a website we built for a client. They typically give a name, a phone number and an email address. Before that inquiry reaches a person, it is checked and, in some cases, added to.

What actually happens

Verification and enrichment
StepWhat it doesWhy
Spam filteringChecks the submission itself, timing, patterns, bot signalsSo real inquiries are not buried under junk
Email verificationConfirms the address exists and accepts mailSo a reply does not vanish, and so sending reputation is not damaged by bad addresses
Phone validationConfirms the number is a working line and what type it is, mobile, landline, or internetSo a text is not sent to a landline, and so a call is not wasted
Business enrichmentAdds publicly available business information, company, industry, approximate size, roleSo the person calling back knows who they are talking to
Scoring and routingRanks the inquiry against the criteria the business setSo the most urgent inquiry is called first rather than the earliest one

All of it happens in seconds, and none of it decides whether anyone is offered a service. It decides what order a callback queue runs in. A person makes every decision after that.

Whose data this is

When it happens on our website, we are the controller and this policy governs it.

When it happens on a client’s website, that business is the controller and we are the processor. Their privacy policy governs it, they are responsible for telling people it happens, and a request to see or delete that data goes to them. We will help them action it, and we will tell you who they are if you are not sure.

Mobile and text messaging

Where you have given consent to receive text messages from us:

  • We collect your mobile number, the consent record itself, when, how, and the exact wording you saw, and the delivery status of messages sent to you
  • We use it only to send the messages you agreed to receive
  • Mobile information and consent are never sold, rented or shared with third parties or affiliates for their own marketing or promotional purposes. No mobile opt-in data is shared with anyone except the service providers who deliver the messages on our behalf, and they may not use it for anything else
  • You can stop at any time by replying STOP. Opt-outs are honored immediately and permanently, and we do not re-add a number from a later import

Full program details, frequency, rates, help, are in our SMS Terms.

Cookies

We use necessary, performance, functional and marketing cookies. Every individual cookie, what it does, how long it lasts, and which third parties are involved is listed in the Cookie and Tracking Policy, along with how to control them.

Who we share it with

We do not sell personal information, and we do not rent or trade lists.

We share data with service providers who process it on our behalf, under contract, and only for the purpose we engage them for:

Most of our stack runs on infrastructure we operate ourselves rather than on a third-party marketing platform. That is unusual at our size and it matters here: fewer outside companies hold your data, and the ones that do are named below.

Systems we run ourselves

These hold data on servers we control. No third-party platform vendor has access to it.

Who we share it with
SystemWhat it holds
Website and forms
WordPress, Gravity Forms
What you type into a form, plus the technical details that come with any web request
CRM
EspoCRM
Contact details, inquiry history, notes, deal records
Marketing automation and email lists
Mautic, Listmonk
Contact details, subscription and consent status, opens and clicks
Website analytics
Matomo
Page views and behavior, configured to minimize what is collected
Live chat
Chatwoot
Chat transcripts and anything you type into them
Workflow automation
n8n, Activepieces
Moves data between the systems above. Holds it only in transit.
Reporting
Metabase
Reads from the systems above to build reports
Documents and signatures
Documenso
Agreements and the signature record

Third-party services we use

These are outside companies. Each is used for one purpose, under their terms, and may not use your data for their own.

Who we share it with
WhoWhat forWhat they see
StripePaymentsCard and billing details. These never touch our systems.
TwilioText messages and phone numbersPhone number, message content, delivery status
Amazon SES, Postmark or MailgunEmail deliveryEmail address and message content
Cal.comBooking callsName, email, and what you enter when booking
ZoomVideo callsName, email, and the call itself where recorded with notice
CallRail or WhatConvertsCall trackingCaller number, call time and duration, and recordings where used and disclosed
BouncerEmail verificationAn email address, to check it accepts mail
Twilio LookupPhone validationA phone number, to check the line type
TrestlePhone identity checkingA phone number and name, to check they match
ClayCoordinates the enrichment stepsThe contact record being enriched
Hunter, DropContact, People Data Labs, ApolloBusiness enrichmentA name, business email or company domain, returning business information
Google Analytics and Search ConsoleWebsite measurementSite usage. See the Cookie Policy.
Google Ads and MetaAdvertising, where runningSee the Cookie Policy and the California section below.
Vultr, Netcup and our hosting providersServersThey host the systems; they do not use the data.

We may also disclose information where the law requires it, or to establish or defend a legal claim. If the business is ever sold, client and contact data may transfer as part of it, and we would tell you.

How long we keep it

How long we keep it
What we holdKept for
Website analytics[CONFIRM]
Inquiries that do not become clients[CONFIRM]
Prospect records we sourced ourselves[CONFIRM]
Client records and project filesDuration of the engagement plus [CONFIRM]
Invoices and financial recordsAs required by tax law, [CONFIRM, typically 7 years]
SMS consent records[CONFIRM, keep at least as long as you message them, and afterwards as evidence]
Do-not-contact listIndefinitely, because that is the point of it

Security

We run our own infrastructure rather than reselling a third-party marketing platform, which means fewer parties hold your data and we control how it is protected.

  • Encryption in transit across all services
  • Access limited to people who need it for the work, using individual accounts
  • Multi-factor authentication on administrative access
  • Firewall, malware monitoring and intrusion detection
  • Daily backups with 90-day retention
  • Credentials handled through a password manager and expiring secure links, never by email

No system is perfectly secure and anyone who tells you otherwise is selling something. If a breach affects your personal information we will notify you and any regulator required, within the timeframes the law sets.

Your rights

Whatever jurisdiction you are in, you can ask us to:

  • Tell you what we hold about you, and where we got it
  • Correct it if it is wrong
  • Delete it
  • Send it to you in a portable format
  • Stop contacting you, which we will do immediately and permanently, no reason required
  • Object to how we are using it, or ask us to restrict it

How to ask

Email [email protected] or call +1-248-205-6977. Say what you want and give us enough to find you, usually the email address or phone number you were contacted on.

We respond within 30 days, and usually much faster. We may need to verify who you are before acting on a request, which is a protection for you rather than an obstacle. There is no charge, and we will not treat you differently for having asked.

You may use an authorized agent. If you do, we will need proof of their authority.

If we act as processor

If your data sits in a system we built for one of our clients, send your request to that business. They are the controller. If you are not sure who that is, ask us and we will tell you.

If you are not satisfied

Tell us first, most of these are misunderstandings and we would rather fix it directly. You also have the right to complain to your regulator: your state attorney general in the US, the ICO in the UK, your data protection authority in the EU, or the Office of the Privacy Commissioner in Canada.

Regional specifics

California

California residents have the rights above, plus the right to know what categories of information we collect and disclose, the right to opt out of any sale or sharing, the right to limit the use of sensitive personal information, and the right not to be discriminated against for exercising them.

We do not sell personal information for money. Whether certain advertising technologies constitute “sharing” is addressed below.

Canada

Commercial electronic messages to Canadian recipients are sent only with consent as required under CASL, with sender identification and a working unsubscribe in every message, honored within the required period.

United Kingdom and European Union

Where UK or EU data protection law applies, our lawful basis is: contract for work we do for clients, consent for marketing messages where consent is required, legitimate interests for business-to-business outreach and for keeping our own systems secure, and legal obligation for financial records.

You have the additional rights that law provides, including the absolute right to object to direct marketing.

Other US states

Several states now provide similar rights. We apply the rights listed above to everyone who asks, regardless of where they live, because maintaining different standards by state is how mistakes happen.

Children

Our services are for businesses and are not directed at children. We do not knowingly collect information from anyone under 16. If you believe a child has given us information, tell us and we will delete it.

Our SMS program is limited to people aged 18 or over.

Changes to this policy

We update this policy when what we do changes. The effective date at the top tells you when it last changed. Where a change is significant we will say so rather than quietly reposting it.

Ask what we hold about you

Client, inquiry, or somebody we emailed first, it makes no difference. Ask and we will tell you. Ask us to delete it and we do, with confirmation in writing.

Related documents

Black Tiger Digital · Waterford, Michigan · Mon to Sun, 9am to 9pm ET

CallBook a Free Call