Legal
Privacy Policy
Effective 27 August 2026 · replaces the August 2026 policy
This is the privacy policy of GTM Engineering LLC (“we”, “us”) for gtm-engineering.io, including the blog. It says what we collect, why, who receives it, how long we keep it, and how to say no. It is written to meet the California Consumer Privacy Act, the other U.S. state privacy laws, the EU and UK GDPR and the ePrivacy rules, whether or not any of them strictly applies to a business our size — the promises hold either way.
What we collect, and where it comes from
What you give us. When you book a meeting through the calendar on this site: your name, work email, phone number, LinkedIn profile URL, company, the time you chose and your time zone, and anything you type in the notes. When you use the chat widget: whatever you write. When you email us: the email.
What your browser sends. IP address, country (from the IP), browser and device type, the page you came from, the pages you visit and how long you stay, what you click, how far you scroll, and — if you arrived from an ad — the ad-click identifiers in the address (gclid, li_fat_id, UTM tags). Some of this is stored in cookies and browser storage; the table below lists every one.
What partners add. Our visitor-identification provider (Warmly) may match your IP address and session to business records held by its data partners and tell us the company visiting and, where those partners hold it, a work email, name and job title. LinkedIn may tell us that a visit came from one of our ads. Nothing we collect is “sensitive” personal information (no health, financial, precise-location, biometric or government-id data).
What we do with it. Reply to you and run the meeting; understand which pages and campaigns lead to booked meetings; fix errors and slow pages; follow up with business-to-business outreach to companies that visited; measure and target our advertising on LinkedIn (and, soon, Google); keep the site secure; and meet legal obligations. We do not use personal information to make decisions with legal or similarly significant effects about you, and we do not use it to train AI models.
Cookies, trackers and every third party
We do not run a tag we cannot describe. The table is generated from the same list our code loads from and is checked against the live site, so it cannot silently fall behind.
| Service | What it does here | Data it receives | When it loads | Retention | Links |
|---|---|---|---|---|---|
| Google Tag Manager Google LLC · Hosting & delivery |
Loads the measurement tags below. Sets no cookies of its own. | page URL, the consent decision | after you accept (EEA, UK, CH); by default elsewhere unless you opt out | n/a | Privacy policy |
| Google Analytics 4 Google LLC · Analytics |
Counts visits and what pages and actions lead to a booked meeting. Google Signals (cross-device / demographic reporting) is off. | pseudonymous client id (cookie _ga, 2 years), pages, events, referrer, approximate location from IP, device/browser; a hashed (SHA-256) email as a user id after you book | after you accept (EEA, UK, CH); by default elsewhere unless you opt out | 14 months (event and user data) | Privacy policy Opt out |
| PostHog PostHog, Inc. · Analytics |
Product analytics, session replay, error and performance monitoring. Served first-party from gtm-engineering.io/ingest. Replay is masked: everything you type is hidden and the booking form is never recorded. If you reject, PostHog counts the visit without a cookie or identifier. | pseudonymous id (cookie ph_*, 1 year), pages, clicks, scroll, recordings of page interactions, browser errors, page speed; after you book, your email and company become the profile | after you accept (EEA, UK, CH); by default elsewhere unless you opt out | replay 30 days; events 7 years (PostHog default), person profile until you ask | Privacy policy Use “Your privacy choices” below |
| Warmly Warmly, Inc. · Visitor identification |
Visitor identification and the chat widget. Warmly matches your IP address and session against business records held by its data partners to tell us which company — and sometimes which person — is visiting, so we can follow up with business-to-business outreach. Under California law this is 'sharing' of personal information. | IP address, session id, user agent, pages visited, time on page, UTM parameters; matched company and, where its partners hold it, work email, name and title | after you accept (EEA, UK, CH); by default elsewhere unless you opt out | as long as needed for the purpose (Warmly policy); we delete the record on request | Privacy policy Opt out |
| LinkedIn Insight Tag & Ads LinkedIn Corporation · Advertising |
Measures whether our LinkedIn ads led to a booked meeting and lets us show ads to people who visited (retargeting). | cookies (li_fat_id first-party, 30 days; LinkedIn's own bcookie/lidc/UserMatchHistory), page URL, IP, device, LinkedIn profile data if you are signed in | after you accept (EEA, UK, CH); by default elsewhere unless you opt out | up to 180 days on LinkedIn's side | Privacy policy Opt out |
| Calendly Calendly LLC · Booking & contact |
Runs the meeting calendar. The booking form on this site sends your details to Calendly through our own server; Calendly's page is never embedded. | name, work email, phone, LinkedIn URL, company, chosen time and time zone, answers you type | only when you use the booking form | as long as the meeting record exists | Privacy policy |
| Slack Salesforce, Inc. · Booking & contact |
Our internal notification when a meeting is booked, cancelled or missed. | name, email, chosen time, how you found us | server-side only, when you book | internal channel history | Privacy policy |
| Cloudflare Cloudflare, Inc. · Hosting & delivery |
Hosts and secures the site. Your country (from IP) decides whether you see the consent banner; it is not stored. Cloudflare Web Analytics measures page performance without cookies or identifiers. | IP address and request logs (security), country, page performance timings | always — no cookies, no identifiers | logs: short-term; Web Analytics: aggregate only | Privacy policy |
| Framer Framer B.V. · Hosting & delivery |
Hosts the blog's content and images, which we serve through gtm-engineering.io. Framer's own analytics beacon is removed before the page reaches you. | image and asset requests (IP, user agent) | always — no cookies, no identifiers | n/a | Privacy policy |
| Loom, YouTube, Spotify Loom (Atlassian), Google, Spotify · Embedded media |
Case-study walkthroughs and podcast appearances. Only a thumbnail loads from their servers until you press play; playing a video is governed by that provider's own policy. | thumbnail requests (IP, user agent); on play, the provider's own cookies | thumbnail always; the player only when you press play | n/a | Privacy policy |
Coming soon: Google Ads (conversion measurement and remarketing for google search ads, including sending a hashed email after you book so the conversion can be matched to an ad click (enhanced conversions)); HubSpot (our crm). This table is updated the day they go live.
Session replay
PostHog records how the page is used — mouse movement, scrolling, clicks, and which elements are on screen — so we can see where the site confuses people. Everything you type is masked before it leaves your browser, the booking form is never recorded, and recording stops the moment you focus a booking field. Recordings run only on the live site (never previews), only after you accept in the EEA/UK/Switzerland, and are deleted after 30 days. If you reject, or your browser sends Global Privacy Control, no recording is made. You can withdraw at any time under Your privacy choices.
Visitor identification (Warmly)
When the Warmly script runs, it and its data partners may use your IP address, a session cookie and similar technologies to associate your visit with other business information they hold about you, potentially including your work email and job title. We use that to decide which companies to contact and may send business-to-business outreach to that address. Warmly is only loaded after you accept our banner in the EEA, UK and Switzerland, and never when your browser sends Global Privacy Control. To opt out: use Your privacy choices, or go to Warmly directly at warmly.ai/p/do-not-sell-share-my-data. To stop outreach that already started, reply to the email or write to us — we remove you the same day.
Advertising measurement
We advertise on LinkedIn. The LinkedIn Insight Tag on this site sets cookies (including a first-party li_fat_id that lives 30 days) so LinkedIn can tell us that a click on our ad led to a booked meeting, and so we can show ads again to people who visited. When we run Google Ads, Google's conversion tag will do the same, and after you book we will send Google a hashed (SHA-256) version of your email so the conversion can be matched to the ad click (“enhanced conversions”); this policy and the table will be updated the day that goes live. Both platforms only run after you accept in the EEA/UK/Switzerland. Opt out at any time below, or at LinkedIn's guest controls and Google Ads Settings.
Selling and sharing
We do not sell personal information for money. Under California's definitions we do “share” it for cross-context behavioural advertising (the LinkedIn cookies) and the visitor-identification flow can count as a sale or share (Warmly's partners exchange identifiers with each other). Both are covered by the opt-out below and by Global Privacy Control. Everyone else in the table is a service provider that processes data only on our instructions — hosting, analytics, scheduling, notifications, our CRM — under contracts that forbid any other use. We have not sold or shared sensitive personal information, and we do not sell or share the personal information of anyone we know to be under 16.
Your privacy choices
One control, honoured everywhere on this site and on the blog:
Current setting for this browser: …
Opting out here removes the analytics identifier, stops session replay, and keeps the LinkedIn, Warmly and (later) Google tags from loading. Your visit is still counted, anonymously and without cookies. The choice is stored in this browser only; repeat it on other browsers and devices.
- Global Privacy Control. If your browser sends the GPC signal we treat it as an opt-out from sale, sharing and targeted advertising — on every page, without a banner. We do not respond to the older “Do Not Track” header.
- The banner. Visitors in the EEA, UK and Switzerland see a banner before any of the “only after you accept” services load. Reject is one click and does exactly what it says.
- The footer. “Your privacy choices” in the footer of every page reopens the banner.
- Vendor opt-outs. Listed in the table's last column for the services that offer one.
- Cookies. You can clear or block them in your browser; the booking form works without them.
Your rights, and how we handle a request
Wherever you live, you can ask us to tell you what personal information we hold about you and where it came from, correct it, delete it, give you a copy in a portable format, opt out of sale, sharing, targeted advertising and profiling, and stop marketing email (every message has an unsubscribe link). We will not treat you differently for exercising a right.
Send the request to [email protected] from the email address on file, or tell us that address; that is how we verify it is you. An agent may act for you with your written permission. We answer within 45 days (we will tell you if we need 45 more). If we decline, we say why, and you can appeal by replying “appeal” to that decision — a different person reviews it and answers within 45 days, and if we still decline we tell you how to complain to your state Attorney General or, in the EEA/UK, your data protection authority.
If you are in the EEA, UK or Switzerland
GTM Engineering LLC is the controller. Our legal bases: performing the contract you ask for when you book (the booking data); your consent for the analytics, session replay, visitor identification and advertising services in the table — which is why none of them load until you accept, and why withdrawing is as easy as accepting; legitimate interests for security, hosting, aggregate cookieless performance measurement and replying to you; and legal obligation where we must keep records.
Your data is processed in the United States. Google, LinkedIn, PostHog, Cloudflare, Calendly, Slack (Salesforce) and HubSpot are certified under the EU-U.S. Data Privacy Framework, its UK extension and the Swiss-U.S. DPF, which the EU General Court upheld in September 2025; standard contractual clauses are the fallback. Warmly is not on the DPF list. It receives data only from visitors who accept the banner (in the EEA, the UK and Switzerland it does not load until you do), and Warmly states that it applies the safeguards required by data-protection law to any transfer outside Europe; its transfer terms are available from [email protected], and we have asked it for a data processing addendum that incorporates the standard contractual clauses. You have all the rights above plus the right to withdraw consent, to object to processing based on legitimate interests, and to complain to your supervisory authority (in the UK, the ICO). UK visitors: the cookie exemption introduced in 2026 for purely statistical cookies does not cover replay or advertising, so we ask for consent for all of them rather than split hairs.
How long we keep things
- Booking and contact details: for as long as we work with you or your company, then up to five years after our last contact, unless you ask sooner.
- Analytics: Google Analytics 14 months; PostHog session replays 30 days; PostHog events per its default retention, with your profile deleted on request.
- Advertising cookies: 30 days (LinkedIn first-party) to 2 years (see the table); LinkedIn keeps its side up to 180 days.
- Server and security logs: short-term, at Cloudflare.
- Your consent choice: in your own browser only, until you change it.
Children
This site is for businesses. We do not knowingly collect information from anyone under 16; if you think we have, write to us and we delete it.
Security
Encryption in transit everywhere, the booking form talking only to our own server, access limited to the people who need it, secrets kept out of the browser. No system is perfectly secure; if something goes wrong that affects you, we tell you.
Changes
We change this page when what we do changes — the vendor table is regenerated from our code, so a new service cannot appear on the site without appearing here. The effective date at the top moves, and if a change reduces your rights we say so on this page for at least 30 days.
Contact
GTM Engineering LLCEmail: [email protected]