Skip to main content

Privacy

Privacy policy.

What this website collects, how it's used, and how data from a client engagement is handled separately.

What this covers

This policy covers two different things, and they are governed differently. The first is this website: the form you can fill out and the analytics that run while you browse. The second is the data we handle on a client’s behalf once an engagement starts — a client’s CRM records, ad accounts, or call logs. That second category belongs to the client, is governed by the signed statement of work described in our terms of service, and is covered separately in the “Client data” section below.

What we collect on this site

If you submit the contact form: your name, work email, company, role, number of locations, marketing spend band, current stack, and what you told us you’re trying to measure.

Through analytics — Google Analytics 4 and Google Tag Manager: pages viewed, referring source, approximate location from IP address, and device and browser type.

Cookies

This site sets one kind of cookie, and no others. Analytics cookies, set by GA4 and Google Tag Manager, so we can see aggregate traffic and behavior. This is not an advertising cookie — this site does not run retargeting pixels, and we do not sell or share this data with advertisers. You can refuse it through your browser’s cookie controls; refusing it does not affect your ability to browse the site or submit the contact form.

Retention

A contact form submission that does not turn into a client or an active opportunity is deleted after 30 days. Once a submission becomes a client or opportunity record, we keep it for the life of the relationship plus 10 years. Analytics data is kept according to Google’s retention setting for this property, not a period we set ourselves.

Who processes data on our behalf

Google — analytics (GA4) and tag management (Google Tag Manager) for this site.
GoHighLevel — receives contact form submissions and stores them as leads.
Vercel — hosts this website.

We do not use a processor beyond the three listed here.

Client data

When an engagement gives us access to a client’s systems — a CRM, an EMR, a call tracking platform, an ad account — that access is granted by the client, scoped to what the engagement requires, and used only for that engagement. It is handled by the same senior team described on our about SiteOptz page, not a rotating pool of contractors.

Where a client is a covered entity, we sign a Business Associate Agreement before any work touching protected health information begins. Our team has completed HIPAA training, and we operate under written policies and safeguards governing how that data is stored, handled, and who can access it. We make no certification claim beyond this — no HIPAA certification exists, and no government body issues one.

We work to keep patient and customer identifiers out of the advertising platforms and analytics tools we configure, using de-identified or hashed values wherever a platform requires an identifier at all. Client data is never used to train any model, and it is never shared between clients — what we learn on one engagement stays with that engagement.

Your choices

To request access to, a correction of, or deletion of the information we hold about you, email info@siteoptz.com. We respond within one business day, the same commitment we make for every inquiry through this site.

Changes to this policy

We update this policy when what we collect or how we handle it changes. This version was last updated September 11, 2026.

How to reach us

Vortex Demand, LLC, doing business as SiteOptz
9595 Six Pines Dr., Ste 8210, The Woodlands, TX 77380
info@siteoptz.com

Questions about a specific engagement are best asked directly — see our four-stage engagement process for how one runs, or book a call to talk to someone about it.