Skip to content
Cleland & Co.

Privacy notice

Effective 15 August 2026

What this site processes, and why.

Cleland & Co. is a sole-operator practice. This notice describes what the public site processes when you browse, send a message, or run a scan, and which providers handle part of that work. Those providers may process data in the United States.

Plain-language notice

Information you choose to send

The contact form asks for your name, email address, an optional company name, and your message. Netlify Forms processes the submission so Jeremy Cleland can read and answer it. Netlify also records the submitting IP address and time. Form posts are rate-limited at the edge. Do not send passwords, health records, government identifiers, payment-card data, or other information that is unnecessary for a first conversation.

Scheduling, LinkedIn, GitHub, and other external links take you to a separate provider. Their notices and account settings govern what happens there.

The visibility scanner

When you submit a URL, Cleland & Co. servers resolve the host and fetch that public page plus robots.txt, llms.txt, and sitemap.xml at the site root. Requests identify as ClelandCoScanner. When the optional speed-data check is turned on, the site origin (scheme and host, not the full path) is sent to Google's Chrome UX Report so the result can show origin-level field Core Web Vitals. That is not a Lighthouse or PageSpeed Insights lab test. The submitted URL is not sent to PageSpeed Insights, a listing API, a crawl index, or an answer-engine API. The scan returns a result for this visit; Cleland & Co. does not keep a scan-results database. The scanned site, its DNS, and its hosting still see the request, and their logs may retain ordinary request metadata.

Repeated scans are rate-limited. The application limit stores a hashed key and recent timestamps in Netlify Blobs. The edge also limits requests by IP. Hosting, Blob, and network logs can retain request metadata longer than the active limit window.

Analytics, error reporting, and browser storage

This site loads Google Analytics 4. It sends page path, page location, page title, and events such as scan started, completed, or failed; score band, score, and elapsed time; CTA selection; and contact-form submit. Visiting this privacy notice is measured the same way as any other page. The event helpers do not intentionally send the scanned URL, contact-form text, name, email, or company. Google may receive standard device, network, cookie, and identifier information under its own policies. Google Analytics sets first-party cookies. This site does not currently expose its own analytics-consent control.

The site sends error reports and a sample of performance traces to Sentry. Reports can include the page URL, browser or runtime details, and a stack trace. Form bodies and scan URLs are not attached as dedicated fields; error text can still contain a URL. Sentry processes that telemetry under its own policy and retention settings.

The site stores a light or dark theme choice in localStorage. If no choice is stored, the site follows the browser color-scheme preference. Browser privacy settings or blockers can restrict Google or Sentry requests, cookies, and local storage; clearing local storage may reset the theme. A direct email does not require site analytics.

Purposes and service providers

Data is used to deliver the page or scan you requested, limit abuse, respond to messages, understand aggregate site use, maintain security, diagnose failures, and keep necessary business records. Current service paths include Netlify for hosting, functions, forms, Blobs, and edge rate limiting; Google Analytics 4; Google Chrome UX Report when a scan key is configured; Sentry; Cal.com when you choose the scheduling link; the public site you ask the scanner to fetch; and ordinary email providers when a conversation continues. Those providers may process data in the United States.

Retention and requests

Contact messages and correspondence are retained according to the conversation and ordinary business-record and legal needs, under the configured Netlify and email systems. Analytics retention follows the configured Google property and Google's policy. Hosting, form, function, Blob, and network logs follow provider configuration and policy. Error-report retention follows the configured Sentry project.

To ask what Cleland & Co. holds about you, request correction or deletion, or raise a privacy question, email jeremy@clelandco.com. A request may be limited where retention is required for security, contracts, accounting, disputes, or applicable law. Identity may need to be verified before a record is disclosed or changed.

Security, scope, and changes

Reasonable technical controls reduce risk but do not make internet transmission or third-party processing risk-free. This notice covers the public Cleland & Co. site; a consulting engagement may require a separate agreement, security schedule, or data-processing terms before client data is handled.

Material changes will update the effective date above. This notice describes how the site works today and is not legal advice.