Terms of Service
Operator: Outcomes By Page, operated by Britton Kimler as a sole proprietorship · Contact: [email protected]
PLEASE READ THESE TERMS CAREFULLY. BY CLICKING “ACCEPT,” CREATING AN ACCOUNT, CONNECTING A SITE OR INTEGRATION, INSTALLING A SCRIPT, OR USING THE SERVICE, CUSTOMER AGREES TO THESE TERMS. IF AN INDIVIDUAL ACCEPTS FOR AN ENTITY, THAT INDIVIDUAL REPRESENTS THAT THEY HAVE AUTHORITY TO BIND THE ENTITY.
1. Agreement; Business Use
These Terms of Service (the “Terms”) form a binding agreement between Outcomes By Page, operated by Britton Kimler as a sole proprietorship (“Provider,” “we,” “us,” or “our”) and the person or entity using the Service (“Customer,” “you,” or “your”). The Terms incorporate any order form, pricing page, Data Processing Addendum (“DPA”), Privacy Notice, and product-specific terms expressly referenced by Provider.
The Service is offered for business and professional use, not personal, family, or household use. Customer represents that it is legally capable of contracting, has authority over each Customer Site it connects, and will ensure that its Authorized Users comply with these Terms.
2. Definitions
“Authorized User” means an individual Customer permits to access the Service. “Customer Data” means data, content, configurations, event information, website content, and instructions submitted to, collected through, or processed by the Service for Customer. “Customer Site” means a website, application, or digital property that Customer connects to the Service. “Consent Tools” means any feature supplied by Provider to display notices, collect choices, transmit consent signals, or condition tags or collection. “Service” means Provider’s hosted analytics, scanning, measurement, reporting, AI-assisted analysis, integrations, scripts, APIs, dashboards, and related services.
“Layer A Baseline” means Provider’s limited first-party measurement mode designed to operate without cookies, local storage, fingerprinting, persistent visitor identifiers, cross-site identity, or session reconstruction. “Do Not Measure” means an explicit visitor instruction to stop Layer A collection. “Region Policy” means Provider’s then-current operational rules for determining whether Layer A remains off pending consent or may operate in a constrained baseline mode. The Region Policy is a product safeguard and not a legal opinion or guarantee of compliance.
3. Accounts, Access, and Security
Customer must provide accurate account information and maintain the confidentiality of credentials, API keys, tokens, and administrator access. Customer is responsible for activity under its accounts and must promptly notify Provider of suspected unauthorized access. Customer will use reasonable security controls, including unique credentials and multi-factor authentication where available.
Provider may rely on instructions from an Authorized User. Customer is responsible for assigning appropriate permissions, removing former users, and ensuring that any person connecting a third-party account is authorized to do so.
4. License and Acceptable Use
Subject to payment and compliance with these Terms, Provider grants Customer a limited, non-exclusive, non-transferable, revocable right during the subscription term to access and use the Service for Customer’s internal business purposes.
Customer will not reverse engineer, bypass usage controls, probe or disrupt the Service, introduce malware, scrape the Service except through authorized APIs, resell the Service unless authorized in writing, or use the Service to violate law or another person’s rights.
Customer will not use the Service to make high-impact decisions about employment, housing, credit, insurance, health care, education, or legal services without Provider’s prior written approval and appropriate human review.
Customer will not submit payment-card data, authentication secrets, government identification numbers, precise health information, biometric identifiers, data concerning children, or other sensitive or regulated data unless Provider expressly agrees in writing and the parties implement required safeguards.
5. Customer Sites; Installation and Configuration
Customer authorizes Provider to access, scan, retrieve, and analyze Customer Sites and connected sources as configured by Customer. Customer is solely responsible for installing scripts correctly, identifying the proper domain, property, stream, pages, events, and conversion outcomes, and testing each configuration before relying on results.
Customer represents that it owns or has sufficient rights to each Customer Site and to all data made available to the Service. Customer will not use the Service on a site or account without the site owner’s authorization.
Provider may apply regional defaults using a visitor’s country-level location or another supported signal. An invalid, unavailable, failed, unreviewed, or unknown location defaults to prior-consent treatment. Customer will not use browser language as a substitute for country and will not alter or circumvent Provider’s strict fallback. Provider may revise regional classifications prospectively as law, regulator guidance, product design, or risk assessments change.
6. Data the Service May Process
Depending on Customer’s configuration, enabled features, integrations, device settings, consent choices, and applicable law, the Service may process the following categories:
- account, contact, authentication, organization, subscription, billing-status, and support information;
- site, domain, URL, page, content, title, heading, link, form, metadata, structured-data, accessibility, and technical configuration information;
- page views, clicks, scrolls, navigation, referrers, campaign parameters, form interactions, conversions, element visibility, timing, errors, and custom events;
- device, browser, operating-system, language, approximate location derived from network information, IP address, user agent, identifiers, and similar technical information where enabled and lawful;
- analytics account, property, stream, report, audience, event, and measurement information obtained from connected services such as Google Analytics;
- prompts, extracted site content, model inputs and outputs, classifications, recommendations, confidence scores, token usage, and estimated AI cost; and
- consent signals, privacy preferences, configuration changes, acknowledgements, timestamps, terms versions, audit records, fraud-prevention data, and security logs.
Provider does not promise to collect every category in every deployment. Customer must review the actual configuration and disclosures. Where collection is blocked or limited by consent choices, browsers, ad blockers, platform thresholds, network conditions, or law, reports may be incomplete or modeled.
7. Privacy Roles and Data Processing
As between the parties, Customer determines the purposes and essential means of processing Customer Site visitor data and is the controller or business; Provider generally acts as Customer’s processor or service provider for that data. Provider may act as an independent controller for account administration, billing, fraud prevention, security, service improvement, and legal compliance as described in Provider’s Privacy Notice.
If applicable privacy law requires a DPA, the parties will enter Provider’s then-current DPA before regulated personal data is processed. In a conflict concerning personal-data processing, the DPA controls. Customer is responsible for determining whether the Service is appropriate for its data and regulatory obligations.
8. Customer Privacy and Consent Obligations
Customer—not Provider—controls the content, audience, purpose, geography, and configuration of each Customer Site. Customer is solely responsible for identifying applicable privacy, communications, advertising, consumer-protection, accessibility, and sector-specific laws and for establishing a lawful basis for every collection and use.
Without limiting the foregoing, Customer must: (a) provide clear, accurate, and complete notices; (b) obtain prior opt-in consent when required; (c) provide legally sufficient opt-out mechanisms where required; (d) honor withdrawal, Global Privacy Control and other legally recognized universal opt-out signals where applicable; (e) maintain required records; (f) respond to data-subject requests; (g) configure retention and deletion; (h) avoid dark patterns; and (i) ensure that downstream advertising, analytics, and AI providers receive and honor required signals.
Provider does not determine whether consent is legally required for Customer’s implementation and does not provide legal advice. A feature described as “cookieless,” “anonymous,” “aggregated,” “modeled,” or “privacy-enhanced” is not a legal conclusion and does not eliminate Customer’s obligations.
Layer A and third-party analytics are separate systems. Where the Region Policy permits, Layer A may continue after a visitor rejects optional cookies because the constrained baseline does not use those storage technologies. In prior-consent, unknown, failed-location, and unreviewed regions, Layer A remains off until affirmative analytics consent. Google Analytics and other third-party tags must be gated and configured independently, including through an applicable consent-mode implementation.
Customer must accurately disclose Layer A wherever deployed and provide an accessible Do Not Measure control. An explicit Do Not Measure instruction disables Layer A regardless of region. Global Privacy Control or another legally recognized universal opt-out signal must disable sale, sharing, targeted advertising, and qualifying profiling; it disables Layer A as well where required by law or Customer’s disclosed policy. Child-directed, sensitive, regulated, or high-risk contexts remain off unless Provider approves them in writing after appropriate review.
9. Consent Tools; Customer Election to Disable or Bypass
Provider may offer Consent Tools as a configurable convenience. Customer understands that no consent tool is universally compliant without correct configuration, accurate disclosures, appropriate geolocation and signal handling, and alignment with Customer’s actual technologies. Customer remains responsible for testing and legal review.
If Customer disables, declines, removes, bypasses, misconfigures, or fails to deploy Consent Tools, or instructs Provider to collect or activate technologies before a required choice, Customer knowingly assumes responsibility for that election and for all resulting notices, legal bases, consents, opt-outs, records, requests, configurations, and claims. Provider may require a separate affirmative acknowledgement, suspend collection, limit features, or refuse a configuration that Provider reasonably believes creates legal, security, or platform risk.
Rejecting optional cookies is not the same instruction as selecting Do Not Measure. Customer may not label, describe, or configure these controls in a misleading manner. If Customer elects to use Layer A after optional cookies are rejected, Customer is responsible for ensuring that its notice describes the continuing baseline accurately and that the implementation stays within Provider’s published technical constraints.
Customer’s election does not authorize Provider to violate law, does not waive obligations that applicable law imposes directly on Provider, and does not release Provider from liability that cannot lawfully be waived.
10. Artificial Intelligence and Automated Analysis
The Service may use machine-learning or generative-AI systems to classify site elements, propose measurement plans, summarize content, estimate effort or cost, or generate recommendations. Outputs are probabilistic, may vary between runs, and may be incomplete, inaccurate, or unsuitable. Customer must independently review outputs before acting on them.
AI outputs are not legal, accounting, security, medical, or professional advice. Provider may record model, version, token, cost, validation, and structured output metadata for reliability, billing, security, and audit purposes as described in the Privacy Notice and DPA.
11. Third-Party Services and Integrations
The Service may interoperate with third parties such as hosting providers, payment processors, Google services, analytics platforms, and AI model providers (a current list is available on request). Customer authorizes Provider to exchange Customer Data with each integration selected by Customer. Third-party terms, privacy practices, availability, quotas, and charges apply independently.
Provider is not responsible for third-party services, changes, suspensions, data accuracy, account access, or Customer’s violation of third-party terms. Customer must maintain required accounts and permissions. Revoking an integration may interrupt features but may not delete data previously processed under the applicable retention schedule.
12. Ownership; Customer Data; Feedback
Customer retains its rights in Customer Data. Customer grants Provider a worldwide, non-exclusive license during the term to host, copy, transmit, transform, analyze, and otherwise process Customer Data only as necessary to provide, secure, support, and improve the Service and as otherwise permitted by the DPA and Privacy Notice.
Provider and its licensors own the Service, software, models, workflows, documentation, de-identified service statistics, and all related intellectual property. Customer may provide feedback; Provider may use it without restriction or compensation, provided Provider does not identify Customer publicly without permission.
13. Aggregated and De-identified Data
Provider may create and use aggregated or de-identified data for security, benchmarking, analytics, service improvement, pricing, and research, provided Provider does not attempt to reidentify it and does not disclose it in a manner reasonably capable of identifying Customer or an individual. This clause does not permit a use prohibited by the DPA or applicable law.
14. Confidentiality and Security
Each party will protect the other party’s nonpublic information using reasonable care and use it only to perform or exercise rights under the agreement. Confidentiality obligations do not apply to information that is public without breach, already known without restriction, independently developed, or lawfully received from another source.
Provider will maintain reasonable administrative, technical, and organizational safeguards appropriate to the Service (see our security summary). No service is completely secure, and Provider does not guarantee that unauthorized access, loss, or interruption will never occur. Customer is responsible for secure endpoints, access controls, backups, and configuration within Customer’s control.
15. Fees, Taxes, Usage, and Changes
Customer will pay fees shown at purchase or in an order form. Resolved: as of this writing, the only metered dimension is the number of active pages included in a plan tier; no usage-based charge exists for events, storage, AI tokens, files, or users. Provider may introduce additional metered dimensions in the future; any change to what is metered will be described in the order form or plan description before it takes effect, not applied retroactively. Estimates are not guarantees. Unless otherwise stated, fees are non-refundable and exclusive of taxes; Customer is responsible for applicable taxes other than taxes on Provider’s net income.
Resolved: paid billing has not yet launched as of this writing; no live payment processor connection exists and no card has been charged. This section describes how fees will be handled once billing is enabled, and will be updated when it is.
Provider may change fees or plan limits prospectively by giving notice required by law or the order form. Failure of a payment method may result in suspension. Customer must review usage meters and promptly report a good-faith billing dispute.
16. Availability, Changes, Beta Features, and Support
Provider may modify, replace, or discontinue Service features. Unless an order form states a service level, the Service is provided without an uptime commitment. Beta, preview, trial, or free features may be changed or withdrawn at any time and are provided without warranty or support commitment.
17. Suspension and Termination
Provider may suspend or restrict access if Customer fails to pay, creates security or legal risk, violates these Terms, exceeds limits, or threatens the Service or another user. Where practicable, Provider will provide notice and an opportunity to cure.
Either party may terminate as provided in the applicable plan or order form. Upon termination, Customer’s right to use the Service ends. Provider may delete Customer Data after the stated export or retention period, subject to the DPA, backups, legal holds, and law. Sections that by nature should survive—including payment, ownership, disclaimers, indemnity, limitations, and dispute provisions—survive.
18. Disclaimers
TO THE MAXIMUM EXTENT PERMITTED BY LAW, THE SERVICE, CONSENT TOOLS, REPORTS, OUTPUTS, INTEGRATIONS, AND DOCUMENTATION ARE PROVIDED “AS IS” AND “AS AVAILABLE.” PROVIDER DISCLAIMS ALL EXPRESS, IMPLIED, AND STATUTORY WARRANTIES, INCLUDING MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, NON-INFRINGEMENT, ACCURACY, COMPLETENESS, RESULTS, AND COMPLIANCE WITH LAW.
PROVIDER DOES NOT WARRANT THAT THE SERVICE WILL BE UNINTERRUPTED, ERROR-FREE, SECURE, OR SUITABLE AS CUSTOMER’S SOLE RECORD; THAT DATA WILL BE COLLECTED OR ATTRIBUTED COMPLETELY; OR THAT ANY CONSENT CONFIGURATION, NOTICE, ANALYTICS METHOD, OR AI OUTPUT WILL SATISFY CUSTOMER’S LEGAL OR BUSINESS REQUIREMENTS.
19. Customer Indemnification
TO THE MAXIMUM EXTENT PERMITTED BY LAW, CUSTOMER WILL DEFEND, INDEMNIFY, AND HOLD HARMLESS PROVIDER, ITS AFFILIATES, AND THEIR OWNERS, OFFICERS, DIRECTORS, EMPLOYEES, CONTRACTORS, AND AGENTS FROM AND AGAINST ALL THIRD-PARTY CLAIMS, INVESTIGATIONS, DEMANDS, ACTIONS, FINES, PENALTIES, SETTLEMENTS, DAMAGES, JUDGMENTS, LOSSES, LIABILITIES, COSTS, AND REASONABLE ATTORNEYS’ FEES ARISING OUT OF OR RELATING TO: (A) CUSTOMER SITES OR CUSTOMER DATA; (B) CUSTOMER’S COLLECTION, USE, SHARING, SALE, RETENTION, DELETION, OR OTHER PROCESSING OF DATA; (C) CUSTOMER’S NOTICES, CONSENTS, OPT-OUTS, PRIVACY REQUESTS, OR FAILURE TO HONOR SIGNALS; (D) CUSTOMER’S ELECTION TO DISABLE, DECLINE, REMOVE, BYPASS, OR MISCONFIGURE CONSENT TOOLS; (E) CUSTOMER’S INSTRUCTIONS OR CONFIGURATION; (F) CUSTOMER’S PRODUCTS, SERVICES, CONTENT, ADVERTISING, OR CLAIMS; (G) CUSTOMER’S VIOLATION OF LAW, THIRD-PARTY TERMS, OR ANOTHER PERSON’S RIGHTS; OR (H) CUSTOMER’S BREACH OF THESE TERMS.
Provider will promptly notify Customer of an indemnified claim, permit Customer to control the defense with qualified counsel, and reasonably cooperate at Customer’s expense. Customer may not settle a claim in a manner that admits fault by, imposes obligations on, or fails to fully release Provider without Provider’s written consent. Customer’s obligations are reduced only to the extent a final judgment determines the claim resulted from Provider’s gross negligence, willful misconduct, or breach of an obligation that applicable law places directly and non-delegably on Provider.
20. Limitation of Liability
TO THE MAXIMUM EXTENT PERMITTED BY LAW, NEITHER PARTY WILL BE LIABLE FOR INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, PUNITIVE, OR CONSEQUENTIAL DAMAGES, OR FOR LOST PROFITS, REVENUE, GOODWILL, DATA, OR BUSINESS INTERRUPTION, EVEN IF ADVISED OF THE POSSIBILITY.
TO THE MAXIMUM EXTENT PERMITTED BY LAW, PROVIDER’S TOTAL AGGREGATE LIABILITY ARISING OUT OF OR RELATING TO THE SERVICE OR AGREEMENT WILL NOT EXCEED THE AMOUNTS CUSTOMER PAID PROVIDER FOR THE SERVICE DURING THE TWELVE MONTHS BEFORE THE EVENT GIVING RISE TO LIABILITY. THE LIMITATIONS APPLY REGARDLESS OF THEORY AND EVEN IF A REMEDY FAILS OF ITS ESSENTIAL PURPOSE.
Nothing in these Terms limits liability that cannot lawfully be limited. Customer’s payment obligations, misuse of Provider intellectual property, breach of confidentiality, and indemnification obligations are not subject to the foregoing cap.
21. Governing Law and Disputes
These Terms are governed by the laws of the State of Kansas, without regard to conflict-of-law rules. The state and federal courts located in Johnson County, Kansas will have exclusive jurisdiction, and each party consents to personal jurisdiction and venue there.
TO THE EXTENT PERMITTED BY LAW, EACH PARTY WAIVES TRIAL BY JURY AND AGREES TO BRING CLAIMS ONLY IN ITS INDIVIDUAL CAPACITY, NOT AS A PLAINTIFF OR CLASS MEMBER IN A CLASS, COLLECTIVE, CONSOLIDATED, OR REPRESENTATIVE ACTION. Either party may seek temporary or injunctive relief to protect security, confidentiality, or intellectual property.
22. General
Provider may update these Terms prospectively. Material changes will be notified as required by law, and continued use after the effective date constitutes acceptance. If Customer does not agree, it must stop using the Service before the change takes effect.
Neither party is liable for delay caused by events beyond its reasonable control. Customer may not assign the agreement without Provider’s consent; Provider may assign it in connection with a merger, reorganization, financing, or sale of assets. The parties are independent contractors. No waiver is continuing. If a provision is unenforceable, it will be modified to the minimum extent necessary and the remainder will remain effective. These Terms and incorporated documents are the entire agreement and supersede prior discussions concerning the Service. Order-form terms control only if they expressly identify the provision being overridden.
23. Notices and Contact
Legal notices to Provider must be sent to [email protected]. Provider may send notices to the email associated with Customer’s account or through the Service. Notices are effective when received, except that electronic notices are deemed received when sent absent a delivery failure.
Schedule A — Required Consent Opt-Out Acknowledgement
This Schedule is part of the Terms. The following acknowledgement should appear as a separate, unticked checkbox or equivalent affirmative control when a Customer disables or declines Provider’s Consent Tools. Do not treat continued browsing, silence, or a pre-checked box as acceptance.
“I elect not to use the consent-management feature. I understand that analytics and similar technologies may require notice, prior consent, opt-out mechanisms, signal handling, records, or other safeguards depending on applicable law and my implementation. I accept responsibility for configuring and operating each connected site lawfully, and I agree to the Customer Privacy and Consent Obligations and Customer Indemnification provisions in the Terms of Service.”