Privacy notice
Effective 15 August 2026
What this site processes, and why.
ClelandCo is a sole-operator practice. This notice describes what the public site processes when you browse, send a message, or run a scan, and which providers handle part of that work. Those providers may process data in the United States.
Plain-language notice
Information you choose to send
The contact form asks for your name, email address, an optional company name, and your message. Netlify Forms processes the submission so Jeremy Cleland can read and answer it. Netlify also records the submitting IP address and time. Form posts are rate-limited at the edge. Do not send passwords, health records, government identifiers, payment-card data, or other information that is unnecessary for a first conversation.
Scheduling, LinkedIn, GitHub, and other external links take you to a separate provider. Their notices and account settings govern what happens there.
The visibility scanner
When you submit a URL, ClelandCo servers resolve the host and fetch that public page plus robots.txt, llms.txt, and sitemap.xml at the site root. Requests identify as ClelandCoScanner. The scan returns a result for this visit; ClelandCo does not keep a scan-results database. The scanned site, its DNS, and its hosting still see the request, and their logs may retain ordinary request metadata.
Repeated scans are rate-limited. The application limit stores a hashed key and recent timestamps in Netlify Blobs. The edge also limits requests by IP. Hosting, Blob, and network logs can retain request metadata longer than the active limit window.
Analytics, error reporting, and browser storage
This site loads Google Analytics 4. It sends page path, page location, page title, and events such as scan started, completed, or failed; score band, score, and elapsed time; CTA selection; and contact-form submit. Visiting this privacy notice is measured the same way as any other page. The event helpers do not intentionally send the scanned URL, contact-form text, name, email, or company. Google may receive standard device, network, cookie, and identifier information under its own policies. First-party cookies exist. This site does not currently expose its own analytics-consent control.
The site sends error reports and a sample of performance traces to Sentry. Reports can include the page URL, browser or runtime details, and a stack trace. Form bodies and scan URLs are not attached as dedicated fields; error text can still contain a URL. Sentry processes that telemetry under its own policy and retention settings.
The site stores a light or dark theme choice in localStorage. If no choice is stored, the site follows the browser color-scheme preference. Browser privacy settings or blockers can restrict Google or Sentry requests, cookies, and local storage; clearing local storage may reset the theme. A direct email does not require site analytics.
Purposes and service providers
Data is used to deliver the page or scan you requested, limit abuse, respond to messages, understand aggregate site use, maintain security, diagnose failures, and keep necessary business records. Current service paths include Netlify for hosting, functions, forms, Blobs, and edge rate limiting; Google Analytics 4; Sentry; Cal.com when you choose the scheduling link; the public site you ask the scanner to fetch; and ordinary email providers when a conversation continues. Those providers may process data in the United States.
Retention and requests
Contact messages and correspondence are retained according to the conversation and ordinary business-record and legal needs, under the configured Netlify and email systems. Analytics retention follows the configured Google property and Google's policy. Hosting, form, function, Blob, and network logs follow provider configuration and policy. Error-report retention follows the configured Sentry project.
To ask what ClelandCo holds about you, request correction or deletion, or raise a privacy question, email jeremy@clelandco.com. A request may be limited where retention is required for security, contracts, accounting, disputes, or applicable law. Identity may need to be verified before a record is disclosed or changed.
Security, scope, and changes
Reasonable technical controls reduce risk but do not make internet transmission or third-party processing risk-free. This notice covers the public ClelandCo site; a consulting engagement may require a separate agreement, security schedule, or data-processing terms before client data is handled.
Material changes will update the effective date above. This notice explains the current implementation and is not legal advice.