Skip to main content
Outcomes By Page
How It Works Measurement Model GA4 Integration Pricing Insights FAQ Sign in Join Early Access

Privacy Policy

Controller/operator: Outcomes By Page, operated by Britton Kimler as a sole proprietorship · Privacy contact: [email protected]

This Privacy Policy explains how Outcomes By Page, operated by Britton Kimler as a sole proprietorship (“Provider,” “we,” “us,” or “our”) collects, uses, discloses, retains, and protects personal information in connection with our websites, hosted analytics platform, scripts, scanners, dashboards, APIs, AI-assisted features, support, and related services (collectively, the “Service”). It also explains privacy choices and rights.

This Policy distinguishes between information we process for our own business purposes and Customer Site information we process on behalf of business customers. If you visit a website operated by one of our customers, that customer’s privacy notice also applies and generally controls the purposes for which your information is processed.

1. Scope and Roles

This Policy applies to visitors to our website, prospective and current customers, authorized users, support contacts, and—where described—visitors to Customer Sites using the Service. It does not apply to third-party websites, products, or services that we do not control.

For account administration, billing, security, fraud prevention, marketing our own Service, and legal compliance, Provider generally acts as a controller or business. For event, page, device, visitor, and connected analytics information processed according to a customer’s instructions, the customer generally acts as controller or business and Provider acts as processor or service provider. The applicable Data Processing Addendum (“DPA”) governs that processing.

2. Information We Collect

A. Information you provide directly

  • Account and identity information, such as name, email address, organization, role, username, authentication data, and communication preferences.
  • Customer configuration, including connected domains, pages, sites, analytics properties, streams, event definitions, outcomes, consent settings, data-retention choices, and Authorized Users.
  • Billing and transaction information. Our payment processor may collect card and bank details; we generally receive payment status, product, amount, billing contact, and limited transaction identifiers rather than full card numbers. Resolved: as of this writing, paid billing has not yet launched — no live payment processor connection exists, and no card or bank data has been collected. This section describes how payment information will be handled once billing is enabled.
  • Support, sales, survey, and correspondence content, including files, screenshots, issue details, and feedback you choose to provide.
  • Instructions, prompts, configuration choices, and content submitted to AI-assisted features.

B. Information collected automatically from our Service

  • Network and device information, including IP address, user agent, browser, operating system, language, approximate location derived from IP, device type, timestamps, and diagnostic identifiers.
  • Usage and interaction information, including pages viewed, clicks, navigation, referring and destination URLs, campaign parameters, feature use, login events, errors, performance, session events, and support interactions.
  • Cookie, local-storage, tag, pixel, SDK, and consent-signal information, subject to configuration and applicable consent requirements.
  • Security and audit information, including authentication events, source IP, administrator changes, consent-tool elections, acknowledgement text and version, timestamps, suspicious activity, and rate-limit events.

C. Information collected from Customer Sites

Depending on the customer’s instructions, enabled features, visitor choices, device settings, and law, the Service may process:

  • page views, clicks, scrolls, outbound links, navigation, form interactions, conversion events, element visibility, timing, errors, session events, and customer-defined events;
  • page URL, title, headings, link text and destinations, forms, metadata, structured data, DOM-derived content, accessibility information, and other publicly accessible or customer-authorized site content;
  • referrer, campaign and UTM parameters, browser and device characteristics, IP address, user agent, language, approximate location, and pseudonymous or customer-supplied identifiers where enabled and lawful; and
  • consent status, privacy preferences, Global Privacy Control or similar signals, and configuration used to determine whether particular technologies or events activate.

Collection may be limited by consent choices, browser settings, ad blockers, network conditions, platform thresholds, and law. “Cookieless,” “anonymous,” “modeled,” or “privacy-enhanced” does not necessarily mean that information falls outside privacy law.

Layer A baseline measurement. We may provide a limited first-party analytics mode (“Layer A”) that does not use cookies, local storage, fingerprinting, persistent visitor identifiers, cross-site identity, or session reconstruction. Layer A is intended to record coarse page and event information for aggregate reporting. Under the current design, a full IP address is not persisted for Layer A and is discarded before event storage; a full user-agent string is not stored in Layer A event records. We do not use Layer A for sale, sharing, targeted advertising, or cross-site profiling.

Layer A and Google Analytics are separate. Google Analytics and other third-party tags may collect different information, use different identifiers, and operate under their own consent settings and privacy terms. A site operator must configure Google Consent Mode or another applicable control independently; eligibility for Layer A does not grant consent for Google Analytics.

D. Information from integrations and other sources

  • Connected analytics and platform information, such as Google account, property, stream, report, audience, event, and measurement metadata and results, subject to the scopes the user authorizes.
  • OAuth authorization records and tokens needed to maintain a connection. We do not intentionally expose tokens to other customers.
  • Information from hosting, payment, fraud-prevention, communications, authentication, and support providers.
  • Publicly accessible business, domain, and website information used to provide scanning, verification, or analysis.

E. AI and model-operation information

  • Prompts, extracted site content, structured inputs and outputs, classifications, recommendations, confidence scores, model/provider/version, validation results, token counts, latency, and estimated cost.

Resolved: we do not use customer prompts, site content, or model outputs to train our own models — we operate no model-training pipeline. Our AI features call third-party model providers (currently OpenAI) through their standard API, which is governed by that provider’s API data-usage terms rather than their consumer-product terms; those terms should be confirmed by counsel against our current agreement before publication, as provider terms can change.

3. How We Use Information

  • Provide, configure, operate, authenticate, support, and improve the Service.
  • Collect, classify, reconcile, measure, analyze, and report Customer Site activity according to customer instructions.
  • Generate AI-assisted analyses, recommendations, measurement plans, summaries, estimates, and other requested outputs.
  • Process payments, enforce subscriptions and usage limits, estimate and allocate infrastructure or model costs, and maintain transaction records.
  • Secure the Service; prevent fraud, abuse, unauthorized access, and technical failures; debug and audit changes.
  • Communicate about accounts, incidents, support, product changes, and—where permitted—features or offers.
  • Comply with law, legal process, contracts, and enforceable requests; establish, exercise, or defend legal claims.
  • Create aggregated or de-identified statistics for benchmarking, reliability, capacity planning, product development, security, and research, subject to commitments not to reidentify the data.

We will not materially expand use of personal information in a manner incompatible with this Policy without providing any notice or choice required by law.

4. Legal Bases for EEA, UK, and Similar Jurisdictions

Where required, we rely on one or more of the following legal bases: performance of a contract; legitimate interests in operating, securing, supporting, and improving a business Service; consent, including for non-essential cookies or similar device access where required; and compliance with legal obligations.

When we rely on legitimate interests, we consider the nature of the information, reasonable expectations, safeguards, and impact on individuals. Where consent is the basis, it may be withdrawn at any time without affecting earlier lawful processing. Customer Site operators are responsible for selecting and documenting the appropriate legal basis for processing they direct.

Regional operation of Layer A. In the EU, EEA, United Kingdom, Switzerland, and any location classified as unknown, failed, unreviewed, or requiring prior consent, Layer A remains off until affirmative analytics consent. We may permit the constrained baseline in specifically reviewed jurisdictions, currently including the United States, Australia, and New Zealand, subject to the safeguards in this Policy and any overriding state, sector, child, sensitive-data, or other applicable rule. Canada, Brazil, Japan, Singapore, and every unlisted country currently receive the strict prior-consent fallback pending further review. We determine country from supported country-level geolocation or another appropriate signal, not from browser language. Regional classifications may change after legal and product review; a change never retroactively alters an earlier visitor choice.

5. Cookies, Similar Technologies, and Consent Signals

Our website and the Service may use cookies, local storage, pixels, tags, SDKs, and similar technologies for authentication, security, preferences, measurement, support, and—if enabled—advertising. Essential technologies operate because they are necessary to provide requested functionality or security. Non-essential technologies will be conditioned on consent where required.

Customers choose whether and how to deploy our scripts and Consent Tools on Customer Sites. A customer may decline or disable our Consent Tools, but doing so does not remove the customer’s duty to provide lawful notices, choices, opt-outs, records, or signal handling. Our Terms allocate responsibility for that customer election; they do not waive visitor rights or duties imposed directly on Provider.

Layer A choices. Before a visitor answers a consent prompt, and after the visitor rejects optional cookies, Layer A may operate only where our reviewed regional policy permits the constrained baseline and the site provides the required disclosure. In prior-consent and strict-fallback regions it remains off. Selecting “Do Not Measure My Visit” disables Layer A in every region. Withdrawing analytics consent disables consent-dependent measurement prospectively.

Global Privacy Control. When a supported browser sends Global Privacy Control or another legally recognized universal opt-out signal, sale, sharing, targeted advertising, and qualifying profiling are disabled. Because Layer A is not used for those purposes, the signal does not automatically disable Layer A in a baseline-permitted region unless applicable law, the site operator’s promise, or another binding requirement says otherwise. Visitors may always use the separate Do Not Measure control to disable Layer A.

Third-party consent. Rejecting optional cookies does not authorize Google Analytics or another third-party analytics tag. Those technologies remain governed by their separate consent configuration, including Google Consent Mode where used.

You may change choices through the Cookie Notice and preference control where available. We also honor legally recognized browser-based opt-out preference signals, including Global Privacy Control, when applicable to our role and processing.

6. How We Disclose Information

We may disclose personal information only as reasonably necessary for the purposes described above:

  • to the customer that controls the applicable Customer Site and its Authorized Users;
  • to hosting, database, observability, authentication, payment, email, customer-support, security, analytics, and AI/model service providers acting under contract (a current list is available on request);
  • to third-party integrations selected or authorized by the customer;
  • to professional advisers, auditors, insurers, financing sources, and transaction counterparties subject to appropriate confidentiality;
  • to governmental authorities or other parties when required by law or reasonably necessary to protect rights, safety, security, or the Service; and
  • as part of a merger, financing, reorganization, bankruptcy, acquisition, or sale of all or part of the business, subject to appropriate protections.

We may disclose aggregated or de-identified information that does not reasonably identify an individual, subject to our commitment not to reidentify it.

7. Sale, Sharing, Targeted Advertising, and Profiling

Resolved: We do not sell personal information for money. We do not sell or share personal information for cross-context behavioral advertising, and we do not process personal information for targeted advertising. As of this writing, no advertising, ad-tech, or data-broker integration exists anywhere in the Service.

We do not knowingly sell or share personal information of people under 16.

We do not use the Service to make decisions producing legal or similarly significant effects about individuals. Customers may not use the Service for high-impact decisions except under a separately approved agreement and lawful safeguards.

8. Data Retention and Deletion

We retain personal information only as long as reasonably necessary for the purposes described in this Policy, including providing the Service, meeting contractual commitments, resolving disputes, maintaining security and audit records, enforcing agreements, and complying with law. Retention depends on data type, sensitivity, configuration, customer instructions, legal requirements, and backup cycles.

DataRetention
Layer A hourly aggregates (object_metrics_hourly)100 days, then automatically purged
Diagnostic events90 days, then automatically purged
Layer B session events (consent-gated)Purged on the same rolling schedule as diagnostic events
Retired measurement manifests90 days after retirement, kept for audit
Cached GA4 report dataRefreshed hourly; cache purged on expiry
Cancelled accountRecoverable for 30 days, then deleted or anonymized
Audit logRetained separately for security and legal purposes, not deleted with account data

Deletion runs as a scheduled job that records how many rows it removed, so retention is verifiable rather than assumed. When deletion is required, information may persist temporarily in restricted backups until overwritten through normal cycles, or longer if subject to a legal hold. Aggregated or de-identified information may be retained where it cannot reasonably identify an individual.

9. Security

We use reasonable administrative, technical, and organizational safeguards designed for the nature of the Service and information, which may include access controls, encryption in transit, credential and token protections, logging, environment separation, vendor review, rate limits, backups, and incident response. See our security summary for specifics. No system is completely secure, and we cannot guarantee that unauthorized access, loss, or interruption will never occur.

Customers are responsible for their accounts, endpoints, administrator access, scripts, configurations, lawful data minimization, and credentials. Please report suspected security issues to [email protected].

10. International Transfers

We and our service providers may process information in the United States and other countries that may have different data-protection laws. Where required, we use recognized safeguards for restricted transfers, such as applicable standard contractual clauses, the UK addendum, adequacy decisions, or another lawful mechanism.

11. Privacy Rights and Requests

Depending on location and subject to exceptions, individuals may have rights to know or access personal information; correct inaccuracies; delete information; obtain a portable copy; restrict or object to processing; withdraw consent; opt out of sale, sharing, targeted advertising, or qualifying profiling; limit certain uses of sensitive information; and appeal a denied request.

Submit a request at [email protected]. We may verify identity and authority, request information needed to locate records, and use an authorized-agent process where required. We will not unlawfully discriminate for exercising privacy rights. We will respond within the period required by applicable law.

If your request concerns a Customer Site, contact that site’s operator first. When we act as its processor or service provider, we will assist the customer as required by our contract and law but may not be authorized to respond directly.

EEA and UK individuals may also lodge a complaint with their local supervisory authority. U.S. residents may have a right to appeal a denial by replying to our decision.

12. U.S. State Privacy Disclosures

Subject to statutory thresholds and exceptions, the categories of personal information described in Section 2 may correspond to identifiers; customer records; commercial information; internet or other electronic-network activity; geolocation at an approximate level; professional information; inferences; and account credentials or other sensitive information when provided or enabled.

We collect these categories from individuals, customers, Customer Sites, devices and browsers, integrations, service providers, and public sources. We use and disclose them for the business and commercial purposes described in Sections 3 and 6. We do not use or disclose sensitive personal information for purposes that require a right to limit under California law, consistent with Section 7 above. We do not offer financial incentives for personal information.

13. Children

The Service is designed for business users and is not directed to children under 13 or any higher age requiring parental consent under applicable law. We do not knowingly collect personal information directly from children for our own purposes. Customers must not configure the Service for a child-directed site or knowingly submit children’s personal information without Provider’s written approval and all legally required notices, consents, contracts, and safeguards. Contact us if you believe a child’s information was collected improperly.

14. Third-Party Services

Links and integrations may lead to third-party services governed by their own terms and privacy policies. We are not responsible for their independent practices. Connecting an integration authorizes the exchange of information needed to provide the requested function. Revoking access may stop future collection but may not delete information previously processed under an applicable retention period.

15. Automated Analysis and Accuracy

AI and automated systems may derive classifications, recommendations, confidence scores, or other inferences from Customer Data and public site content. Outputs may vary or be inaccurate. We use them to provide and improve business analytics features, not to make legal or similarly significant decisions about individuals. Customers must review outputs before relying on them.

16. Changes to This Policy

We may update this Policy to reflect changes in the Service, law, or our practices. We will post the updated version and revise the effective date. If changes are material, we will provide additional notice or obtain consent when required. Prior versions will be retained or made available where required.

17. Contact

Outcomes By Page, operated by Britton Kimler as a sole proprietorship · [email protected]

© Outcomes By Page. All rights reserved.

Privacy Terms Cookies Security Contact