Skip to content
ClelandCo

Privacy notice

Effective 15 August 2026

What this site processes, and why.

ClelandCo is a sole-operator practice. This notice describes the data paths in the current site code and names the places where an outside provider—not this repository—controls additional logging or retention.

Plain-language notice

Information you choose to send

The contact form asks for your name, email address, an optional company name, and your message. Netlify Forms processes the submission so Jeremy Cleland can read and answer it. Do not send passwords, health records, government identifiers, payment-card data, or other information that is unnecessary for a first conversation.

Scheduling, LinkedIn, GitHub, and other external links take you to a separate provider. Their notices and account settings govern what happens there.

The visibility scanner

When you submit a URL, the ClelandCo server fetches that public page and limited companion files such as robots.txt, llms.txt, and sitemap.xml. The submitted URL and scan findings are processed to return the result; application code does not intentionally write them to a ClelandCo results database. The site being scanned receives requests from the scanner infrastructure, and hosting logs may still contain ordinary request metadata.

The scan endpoint rate-limits repeated requests. Application code reads the best available client-address header, immediately converts it to a SHA-256 key, and stores only that pseudonymous key with request timestamps in Netlify Blobs. Only timestamps from the prior 60 seconds affect the limit. Blob or infrastructure retention can last longer than that active window; the repository does not prove the provider-side deletion date. The raw address is not written to Blobs by ClelandCo application code, but Netlify and network providers can process it in their own logs.

Analytics and browser storage

The repository’s Netlify configuration records an expectation that the deployed build has a Google Analytics 4 measurement ID, but this worktree cannot verify the current external environment. When that ID is present, the site loads Google's tag. It sends page path, page location, page title, and limited events such as scan started, completed, failed, score band, score, elapsed time, or CTA selection. The event helpers do not intentionally send the scanned URL, contact-form text, name, email, or company. Google may receive standard device, network, cookie, and identifier information under its own policies and the GA property configuration.

The site also keeps your light/dark/system theme preference in browser storage. This site does not currently expose its own analytics-consent control. Browser privacy settings or blockers can restrict Google requests, cookies, and local storage; clearing local storage may reset the theme. A direct email does not require site analytics.

Purposes and service providers

Data is used to deliver the page or scan you requested, limit abuse, respond to messages, understand aggregate site use, maintain security, and keep necessary business records. Current service paths include Netlify for hosting, functions, forms, and Blobs; Google when an analytics build ID is present; Cal.com when you choose the scheduling link; the public site you ask the scanner to fetch; and ordinary email providers when a conversation continues.

Retention and requests

The repository does not enforce a deletion schedule for contact messages or correspondence. Retention depends on the conversation, business-record and legal needs, and the configured Netlify/email systems; those settings require external review. Analytics retention follows the configured Google property and Google's policy. Hosting, form, function, Blob, and network logs likewise follow provider configuration and policy, which this source tree cannot prove.

To ask what ClelandCo holds about you, request correction or deletion, or raise a privacy question, email jeremy@clelandco.com. A request may be limited where retention is required for security, contracts, accounting, disputes, or applicable law. Identity may need to be verified before a record is disclosed or changed.

Security, scope, and changes

Reasonable technical controls reduce risk but do not make internet transmission or third-party processing risk-free. This notice covers the public ClelandCo site; a consulting engagement may require a separate agreement, security schedule, or data-processing terms before client data is handled.

Material changes will update the effective date above. This notice explains the current implementation and is not legal advice.