Skip to content
Services Case Studies About Us Blog
Book a call
Choose your seat
The GTM Engineering Company Podcasts and Appearances Team and Culture Manifesto
30-60-90 Day Plan For New Managers: The Ultimate Guide Relationship Intelligence: Turning Your Network Into a Profitable Pipeline CRM Data Hygiene: Build Cleanup Flows That Run Themselves Read all articles

100% CRM cleanup, automated account intelligence

Read the case study

Legal

Privacy Policy

Effective 27 August 2026 · replaces the August 2026 policy

This is the privacy policy of GTM Engineering LLC (“we”, “us”) for gtm-engineering.io, including the blog. It says what we collect, why, who receives it, how long we keep it, and how to say no. It is written to meet the California Consumer Privacy Act, the other U.S. state privacy laws, the EU and UK GDPR and the ePrivacy rules, whether or not any of them strictly applies to a business our size — the promises hold either way.

What we collect · Cookies & third parties · Session replay · Visitor identification · Advertising · Selling & sharing · Your privacy choices · Your rights · EEA, UK & Switzerland · Retention · Contact

What we collect, and where it comes from

What you give us. When you book a meeting through the calendar on this site: your name, work email, phone number, LinkedIn profile URL, company, the time you chose and your time zone, and anything you type in the notes. When you use the chat widget: whatever you write. When you email us: the email.

What your browser sends. IP address, country (from the IP), browser and device type, the page you came from, the pages you visit and how long you stay, what you click, how far you scroll, and — if you arrived from an ad — the ad-click identifiers in the address (gclid, li_fat_id, UTM tags). Some of this is stored in cookies and browser storage; the table below lists every one.

What partners add. Our visitor-identification provider (Warmly) may match your IP address and session to business records held by its data partners and tell us the company visiting and, where those partners hold it, a work email, name and job title. LinkedIn may tell us that a visit came from one of our ads. Nothing we collect is “sensitive” personal information (no health, financial, precise-location, biometric or government-id data).

What we do with it. Reply to you and run the meeting; understand which pages and campaigns lead to booked meetings; fix errors and slow pages; follow up with business-to-business outreach to companies that visited; measure and target our advertising on LinkedIn (and, soon, Google); keep the site secure; and meet legal obligations. We do not use personal information to make decisions with legal or similarly significant effects about you, and we do not use it to train AI models.

Cookies, trackers and every third party

We do not run a tag we cannot describe. The table is generated from the same list our code loads from and is checked against the live site, so it cannot silently fall behind.

Every third party this site talks to, measured from a real browser. “Only after you accept” means the tag is never even downloaded until you choose Accept in the EEA, UK or Switzerland; elsewhere it loads unless your browser sends Global Privacy Control or you opt out below.
ServiceWhat it does hereData it receivesWhen it loadsRetentionLinks
Google Tag Manager
Google LLC · Hosting & delivery
Loads the measurement tags below. Sets no cookies of its own. page URL, the consent decision after you accept (EEA, UK, CH); by default elsewhere unless you opt out n/a Privacy policy
Google Analytics 4
Google LLC · Analytics
Counts visits and what pages and actions lead to a booked meeting. Google Signals (cross-device / demographic reporting) is off. pseudonymous client id (cookie _ga, 2 years), pages, events, referrer, approximate location from IP, device/browser; a hashed (SHA-256) email as a user id after you book after you accept (EEA, UK, CH); by default elsewhere unless you opt out 14 months (event and user data) Privacy policy
Opt out
PostHog
PostHog, Inc. · Analytics
Product analytics, session replay, error and performance monitoring. Served first-party from gtm-engineering.io/ingest. Replay is masked: everything you type is hidden and the booking form is never recorded. If you reject, PostHog counts the visit without a cookie or identifier. pseudonymous id (cookie ph_*, 1 year), pages, clicks, scroll, recordings of page interactions, browser errors, page speed; after you book, your email and company become the profile after you accept (EEA, UK, CH); by default elsewhere unless you opt out replay 30 days; events 7 years (PostHog default), person profile until you ask Privacy policy
Use “Your privacy choices” below
Warmly
Warmly, Inc. · Visitor identification
Visitor identification and the chat widget. Warmly matches your IP address and session against business records held by its data partners to tell us which company — and sometimes which person — is visiting, so we can follow up with business-to-business outreach. Under California law this is 'sharing' of personal information. IP address, session id, user agent, pages visited, time on page, UTM parameters; matched company and, where its partners hold it, work email, name and title after you accept (EEA, UK, CH); by default elsewhere unless you opt out as long as needed for the purpose (Warmly policy); we delete the record on request Privacy policy
Opt out
LinkedIn Insight Tag & Ads
LinkedIn Corporation · Advertising
Measures whether our LinkedIn ads led to a booked meeting and lets us show ads to people who visited (retargeting). cookies (li_fat_id first-party, 30 days; LinkedIn's own bcookie/lidc/UserMatchHistory), page URL, IP, device, LinkedIn profile data if you are signed in after you accept (EEA, UK, CH); by default elsewhere unless you opt out up to 180 days on LinkedIn's side Privacy policy
Opt out
Calendly
Calendly LLC · Booking & contact
Runs the meeting calendar. The booking form on this site sends your details to Calendly through our own server; Calendly's page is never embedded. name, work email, phone, LinkedIn URL, company, chosen time and time zone, answers you type only when you use the booking form as long as the meeting record exists Privacy policy
Slack
Salesforce, Inc. · Booking & contact
Our internal notification when a meeting is booked, cancelled or missed. name, email, chosen time, how you found us server-side only, when you book internal channel history Privacy policy
Cloudflare
Cloudflare, Inc. · Hosting & delivery
Hosts and secures the site. Your country (from IP) decides whether you see the consent banner; it is not stored. Cloudflare Web Analytics measures page performance without cookies or identifiers. IP address and request logs (security), country, page performance timings always — no cookies, no identifiers logs: short-term; Web Analytics: aggregate only Privacy policy
Framer
Framer B.V. · Hosting & delivery
Hosts the blog's content and images, which we serve through gtm-engineering.io. Framer's own analytics beacon is removed before the page reaches you. image and asset requests (IP, user agent) always — no cookies, no identifiers n/a Privacy policy
Loom, YouTube, Spotify
Loom (Atlassian), Google, Spotify · Embedded media
Case-study walkthroughs and podcast appearances. Only a thumbnail loads from their servers until you press play; playing a video is governed by that provider's own policy. thumbnail requests (IP, user agent); on play, the provider's own cookies thumbnail always; the player only when you press play n/a Privacy policy

Coming soon: Google Ads (conversion measurement and remarketing for google search ads, including sending a hashed email after you book so the conversion can be matched to an ad click (enhanced conversions)); HubSpot (our crm). This table is updated the day they go live.

Session replay

PostHog records how the page is used — mouse movement, scrolling, clicks, and which elements are on screen — so we can see where the site confuses people. Everything you type is masked before it leaves your browser, the booking form is never recorded, and recording stops the moment you focus a booking field. Recordings run only on the live site (never previews), only after you accept in the EEA/UK/Switzerland, and are deleted after 30 days. If you reject, or your browser sends Global Privacy Control, no recording is made. You can withdraw at any time under Your privacy choices.

Visitor identification (Warmly)

When the Warmly script runs, it and its data partners may use your IP address, a session cookie and similar technologies to associate your visit with other business information they hold about you, potentially including your work email and job title. We use that to decide which companies to contact and may send business-to-business outreach to that address. Warmly is only loaded after you accept our banner in the EEA, UK and Switzerland, and never when your browser sends Global Privacy Control. To opt out: use Your privacy choices, or go to Warmly directly at warmly.ai/p/do-not-sell-share-my-data. To stop outreach that already started, reply to the email or write to us — we remove you the same day.

Advertising measurement

We advertise on LinkedIn. The LinkedIn Insight Tag on this site sets cookies (including a first-party li_fat_id that lives 30 days) so LinkedIn can tell us that a click on our ad led to a booked meeting, and so we can show ads again to people who visited. When we run Google Ads, Google's conversion tag will do the same, and after you book we will send Google a hashed (SHA-256) version of your email so the conversion can be matched to the ad click (“enhanced conversions”); this policy and the table will be updated the day that goes live. Both platforms only run after you accept in the EEA/UK/Switzerland. Opt out at any time below, or at LinkedIn's guest controls and Google Ads Settings.

Selling and sharing

We do not sell personal information for money. Under California's definitions we do “share” it for cross-context behavioural advertising (the LinkedIn cookies) and the visitor-identification flow can count as a sale or share (Warmly's partners exchange identifiers with each other). Both are covered by the opt-out below and by Global Privacy Control. Everyone else in the table is a service provider that processes data only on our instructions — hosting, analytics, scheduling, notifications, our CRM — under contracts that forbid any other use. We have not sold or shared sensitive personal information, and we do not sell or share the personal information of anyone we know to be under 16.

Your privacy choices

One control, honoured everywhere on this site and on the blog:

Current setting for this browser: …

Opting out here removes the analytics identifier, stops session replay, and keeps the LinkedIn, Warmly and (later) Google tags from loading. Your visit is still counted, anonymously and without cookies. The choice is stored in this browser only; repeat it on other browsers and devices.

  • Global Privacy Control. If your browser sends the GPC signal we treat it as an opt-out from sale, sharing and targeted advertising — on every page, without a banner. We do not respond to the older “Do Not Track” header.
  • The banner. Visitors in the EEA, UK and Switzerland see a banner before any of the “only after you accept” services load. Reject is one click and does exactly what it says.
  • The footer. “Your privacy choices” in the footer of every page reopens the banner.
  • Vendor opt-outs. Listed in the table's last column for the services that offer one.
  • Cookies. You can clear or block them in your browser; the booking form works without them.

Your rights, and how we handle a request

Wherever you live, you can ask us to tell you what personal information we hold about you and where it came from, correct it, delete it, give you a copy in a portable format, opt out of sale, sharing, targeted advertising and profiling, and stop marketing email (every message has an unsubscribe link). We will not treat you differently for exercising a right.

Send the request to [email protected] from the email address on file, or tell us that address; that is how we verify it is you. An agent may act for you with your written permission. We answer within 45 days (we will tell you if we need 45 more). If we decline, we say why, and you can appeal by replying “appeal” to that decision — a different person reviews it and answers within 45 days, and if we still decline we tell you how to complain to your state Attorney General or, in the EEA/UK, your data protection authority.

If you are in the EEA, UK or Switzerland

GTM Engineering LLC is the controller. Our legal bases: performing the contract you ask for when you book (the booking data); your consent for the analytics, session replay, visitor identification and advertising services in the table — which is why none of them load until you accept, and why withdrawing is as easy as accepting; legitimate interests for security, hosting, aggregate cookieless performance measurement and replying to you; and legal obligation where we must keep records.

Your data is processed in the United States. Google, LinkedIn, PostHog, Cloudflare, Calendly, Slack (Salesforce) and HubSpot are certified under the EU-U.S. Data Privacy Framework, its UK extension and the Swiss-U.S. DPF, which the EU General Court upheld in September 2025; standard contractual clauses are the fallback. Warmly is not on the DPF list. It receives data only from visitors who accept the banner (in the EEA, the UK and Switzerland it does not load until you do), and Warmly states that it applies the safeguards required by data-protection law to any transfer outside Europe; its transfer terms are available from [email protected], and we have asked it for a data processing addendum that incorporates the standard contractual clauses. You have all the rights above plus the right to withdraw consent, to object to processing based on legitimate interests, and to complain to your supervisory authority (in the UK, the ICO). UK visitors: the cookie exemption introduced in 2026 for purely statistical cookies does not cover replay or advertising, so we ask for consent for all of them rather than split hairs.

How long we keep things

  • Booking and contact details: for as long as we work with you or your company, then up to five years after our last contact, unless you ask sooner.
  • Analytics: Google Analytics 14 months; PostHog session replays 30 days; PostHog events per its default retention, with your profile deleted on request.
  • Advertising cookies: 30 days (LinkedIn first-party) to 2 years (see the table); LinkedIn keeps its side up to 180 days.
  • Server and security logs: short-term, at Cloudflare.
  • Your consent choice: in your own browser only, until you change it.

Children

This site is for businesses. We do not knowingly collect information from anyone under 16; if you think we have, write to us and we delete it.

Security

Encryption in transit everywhere, the booking form talking only to our own server, access limited to the people who need it, secrets kept out of the browser. No system is perfectly secure; if something goes wrong that affects you, we tell you.

Changes

We change this page when what we do changes — the vendor table is regenerated from our code, so a new service cannot appear on the site without appearing here. The effective date at the top moves, and if a change reduces your rights we say so on this page for at least 30 days.

Contact

GTM Engineering LLC
Email: [email protected]
GTM Engineering

Durable pipeline infrastructure, engineered into your CRM — signal-based outbound, enrichment, scoring, and attribution that compound.

Services

FoundersOperationsSalesMarketing

Company

Case StudiesTestimonialsAbout UsBlog

Blog

Clay Automation: The Ultimate Guide Best B2B Revenue Operations Agencies 30-60-90 Day Plan for New Managers Go-to-Market Strategy Examples
Only when we publish · no other mail
© 2026 The GTM Engineering Company · Privacy Policy · Terms