Privacy

Last updated 30 August 2026

What this site collects

This site uses Google Analytics 4 to count page views, see which referrers send traffic, and understand which content readers find useful. It also uses Google Ads conversion measurement to tell whether an ad click led to a booking (see Advertising measurement below). No cross-site tracking, no remarketing, no personalized-ads tags.

GA4 collects: the page path (the query string is stripped before GA sees it, so campaign tags and other URL parameters are not sent — the one exception is a Google Ads click identifier, gclid, which, with your consent, is kept for conversion measurement when you arrive from an ad), referrer, approximate location (country / region, derived from IP and then discarded), browser and OS class, and a device-scoped identifier stored in a first-party cookie. With Google's Consent Mode v2 the cookie is only set when consent is granted; declined visitors are counted via cookieless pings with no identifier.

Session attribution

To understand which channels bring people here, this site records a small first-touch record on your first page view of a visit. It holds at most four things, and each is restricted to a fixed vocabulary rather than copied from the address bar:

  • The channel that referred you, mapped to a fixed list of labels — linkedin, x, google, github, hackernews, reddit, bluesky, and a handful more, or other for anything unrecognized. The referring URL and even its hostname are reduced to one of these labels and then discarded; the raw referrer is never stored or forwarded.
  • The section you landed in, reduced to a fixed list of route families (/, /integrations, /migrations, /app-production, /ai-production-readiness, /proof, /build, /call, /controls-call, /resources, /evidence-kit, /sample-report, /partners, /search, /security-review-remediation, /privacy, /checklists, /due-diligence, /ews-migration, /services). Not the exact page, and never an arbitrary address. Any other path is discarded.
  • A few campaign fields from the link you followed. utm_source and utm_medium are each matched against a fixed list of channels and media (linkedin, email, social, and so on); a value not on the list becomes other. utm_campaign is kept only when it exactly matches one of the specific, named campaigns we run (used to measure a particular ad or outreach test); any other campaign value is discarded. utm_content and utm_term — the free-form fields that most often carry per-recipient or personalized values — are not collected at all. In every case the raw value is never kept.
  • A timestamp.

The record lives in sessionStorageon your device and is deleted when you close the tab. It is not a cookie, it is not used to build a profile, and it is not used to track you across sites or sessions. Every field is reduced to one of these fixed lists — a channel, a route section, a known source, a known medium, a named campaign — so the record cannot contain a value we didn't define, and it does not identify you. That is why it is not gated behind the consent banner. Anything forwarded to Google Analytics still respects your consent choice.

Advertising measurement (Google Ads)

When a paid Google ad brings you here, the ad link carries a Google click identifier (gclid). With your consent, Google Ads conversion measurement is enabled and Google stores that click identifier in a first-party cookie on this domain. If you then book a call, that lets Google attribute the booking to the ad — so I can tell which campaigns are worth running. It is conversion counting only.

What this specifically does not do: no personalized or targeted advertising, no remarketing / retargeting audiences, no Google Signals, and no building a cross-site profile of you. In Consent Mode terms, ad-storage and ad-user-data are granted only after consent; ad-personalization stays denied at all times. EU/EEA/UK/Switzerland visitors: none of this runs until you accept the banner, and declining keeps every advertising cookie off (analytics falls back to cookieless pings).

Advertising measurement (Reddit)

The Product build pages (/build and /build/call) can be advertised on Reddit. To measure whether those ads lead to a booking, those pages load Reddit's conversion pixel — but only after you allow measurement, and only within that route family. It records a page visit on /build and /build/call, and a single Lead event when a Product build fit call is booked. It is conversion counting for campaign attribution and aggregate performance, nothing more.

Reddit's advanced matching is disabled: the site never passes Reddit your name, email, phone number, booking answers, or prototype URL. Like any conversion pixel, Reddit's script does itself process technical data when it fires, under Reddit's privacy policy: the page address and referrer, its own ad-click identifier when you arrive from a Reddit ad, a first-party cookie it sets on this domain, and standard device and browser information. Because the page address is part of that, this site removes every utm_ campaign parameter from the address bar before each Reddit event — campaign links are free-form and could carry per-recipient values, and Reddit's attribution doesn't need them — so those values never reach Reddit. If the address cannot be cleaned, the event is not sent at all.

The pixel never loads before your consent decision permits it, stays off entirely if you decline, and its script is only ever fetched when you reach a Product build page. Reddit events are sent only on those two pages; once fetched, the script (like any script) remains part of the current browser tab until you leave or close it, but it receives no events from the rest of the site. You can reopen Cookie preferences in the footer to change your decision at any time.

Consent and EU visitors

Visitors with a device timezone in the EU, EEA, UK, or Switzerland see a small consent banner on first visit and can accept or decline. Visitors elsewhere are opted in by default; they can opt out at any time using the Cookie preferences link in the site footer.

Choice is stored in localStorageon the visitor's device, not on any server. Clearing browser storage resets it and re-shows the banner for EU visitors.

What this site does NOT do

  • No personalized or targeted ads, no remarketing / retargeting audiences, no Google Signals, no Reddit advanced matching, and no cross-site tracking. (Google and Reddit conversion measurement is used, with consent — see the two Advertising measurement sections above — but only to count whether an ad led to a booking.)
  • No selling or sharing of personal data, and no transfer of it to third parties for their own purposes. The only processors that receive anything are Google (Analytics and Ads conversion measurement, subject to your consent choice), Reddit (conversion measurement on the /build pages, subject to your consent choice — see Advertising measurement (Reddit) above), Cal.com (contacted as soon as the /call, /controls-call, or /build/call page loads, not only when you book — see Booking and calls below).
  • No tracking pixels from other services beyond the consent-gated Google and Reddit measurement described above.
  • No server-side logging that ties requests to identified individuals.

Data retention

GA4 event data is retained for 14 months and then automatically deleted. Aggregate reports (page views per month, country mix) persist longer.

Booking and calls

The /call, /controls-call, and /build/call pages embed Cal.com's scheduler in an iframe. When you book a call, Cal.com collects the data you submit (name, email, qualification answers) under their privacy policy. That data is shared with me so I can prepare for and attend the call.

Two things to be explicit about. First, loading any of those pages contacts Cal.com and passes the session attribution described above (referral channel, landing section — including the /build route family — and campaign labels) plus fixed labels for the offer, as booking metadata — so that if you do book, I can see which channel the booking came from. This happens when the booker loads, before and regardless of whether you submit anything. Second, if you would rather not load Cal.com at all, you can reach me by email instead — the address is below and on every booking page.

Your rights

Under the EU/UK GDPR you can request access to, correction of, or deletion of any personal data this site holds about you. For GA4 data, the device-scoped identifier is not linked to a name or email so there is typically nothing personally identifiable to retrieve. For booking data, email me using the contact below.

Contact

For privacy questions or data requests: hello@musabdulai.com.