Privacy · plain language
What happens to what you send us.
Short version: your website, phone, and email personalize your fix plan and send your confirmation email. That’s the whole business model — there’s nothing else to do with them.
What we collect
What you put in the form: your business website URL, your business phone, and your email. If you filled in the leak calculator or the scorecard on the same page, those answers travel with your request too — they’re your own estimates, and they make the fix plan sharper. Submitting also records a request ID, the page you sent it from, your browser’s user-agent, and the country Cloudflare reports for your connection — routine details that help a person find your request and spot spam. That’s the whole list for the form.
The med spa quiz runs entirely on your screen and asks for no email — your result appears without anything being sent. If you choose “Email me my Fix Plan,” we receive the email address you enter and the quiz answers behind your result, used once to render and send that one report. The same delete-on-request promise below applies.
Next to that email field sits one optional checkbox, off by default: a 4-part follow-up series — one short email a week about fixing your leak, then it ends on its own. We send it only if you tick the box, every email carries an unsubscribe link that stops it instantly, and leaving the box unticked keeps the one-email promise exactly as written. Addresses collected before this checkbox existed are never enrolled in anything.
What it’s used for
Personalizing your free fix plan — it generates in your browser from your own answers, with your website and phone printed in the test kit as the contact points you’ll test — and sending your confirmation email. The after-hours response test itself is yours to run: one realistic inquiry you send to your own public contact points, never a held appointment; nothing from us contacts your business. If you don’t become a client, that’s where it ends — we don’t add you to a list, and there is no newsletter to be added to.
What we don’t do
We don’t sell your details, and what you put in the form is never handed to anyone else. We don’t send marketing sequences unless you explicitly ask for the one described above — and even that one ends by itself. And we don’t test any business uninvited — the kit has you run your own test; if you ever want one run for you, you ask us first, always. One nuance: if you switch on the optional advertising pixel described below, Meta receives standard pixel signals from your visit — some privacy laws call that “sharing” — and it stays off unless you allow it.
Site analytics and cookies
The site is static and runs no advertising of its own. Type is self-hosted, so no font service sees your visit. Cloudflare provides hosting. Form submissions travel over HTTPS to our intake and arrive as email. Four measurement tools can be involved — two always on and cookieless, two only if you allow them:
- Cloudflare Web Analytics — always on, cookieless. Counts page visits without cookies, fingerprinting, or personal identifiers. We see totals, not people. Its beacon also reports standard reliability data for each pageload — an anonymous pageload id, load timing, device and network performance details, the page address, and the referring page — used to keep the site fast, not to identify anyone.
- Our own quiz step counter — always on, cookieless. The med spa quiz counts which step is reached — landing, start, midpoint, result, a booking-button tap, or a report email being sent — with no cookies and no identifiers. Each count carries only the step, the page-variant label, and the ad-campaign labels already in the page address. Totals per step, not people.
- Google Analytics — off until you allow it. If you allow “Analytics” in the cookie banner, Google Analytics loads and sets
_ga-family cookies (kept up to 90 days) so we can see which pages are useful. We send it no names, emails, or form contents; query strings are stripped; ad features and Google Signals are turned off; reports are kept two months. Google LLC processes this in the United States (their policy). - Meta (Facebook) pixel — off until you allow it. If you allow “Advertising,” Meta’s pixel loads, sets the
_fbpcookie, and reports your visit and any test request (as an opaque request ID, never your contact details) so our ads can reach relevant business owners instead of blanketing everyone. Meta Platforms, Inc. processes this in the United States (their policy).
How the choice works. Your decision is stored in your browser (not a cookie) for up to 180 days, or until this policy changes — then we ask again. The “Cookie settings” button in the corner reopens the choice any time; withdrawing consent removes the tool and deletes its cookies. If your browser sends Global Privacy Control, we treat it as a “no” and the optional tools stay off.
Booking a call
The “book a call” buttons leave this site and go to Cal.com, the outside scheduling service that runs our calendar. Its booking form asks for your name, your email, and — depending on the call type — your phone, business name, what prompted the call, and any notes you add. Those details are used to put the call on both calendars and send you the meeting invitation — nothing else; they live in our Cal.com account and in the calendar entries the booking creates. Cal.com processes them under its own privacy policy.
One transparency note: if you arrive at the booking page from our scorecard, readiness check, or med spa quiz, your result travels with the booking link so the call starts from your result. On the med spa review it arrives as the booking subject — visible on the form and yours to edit or delete before you book (verified 2026-08-24). On the discovery call it prefills the “what prompted the call” box; wherever the form shows that field, it is equally yours to edit or delete. A med spa quiz booking carries nothing else: no answer codes and no advertising identifiers ride along.
Rather not use Cal.com? Email [email protected] or call (616) 320-1277 and a person will set the time with you directly.
Want it gone?
Email [email protected] and a person will delete your request details. Include the request ID if you have it; the email address alone is enough.