Privacy policy
What I collect, why, who it goes to, and the control you have over it.
This policy covers philmeyfarth.com, operated by Phil Meyfarth in connection with Orevida LLC ("I", "me", "we"). It explains what personal data the site collects, how it is used, who processes it, and the choices you have. Questions or requests go to support@philmeyfarth.com.
What I collect
Information you give me
When you subscribe to the newsletter, submit an inquiry, apply, or book a call, you provide details such as your name, email address, phone number, company or website, and anything you write in a message or application. The application forms also ask business questions: a revenue band, a size band, how dependent the business is on its owner, a timeline, how much capital you have to put in, and what you are trying to buy or fix. Booking a call adds the slot you picked. You choose what to send, though some fields are required for me to respond, and the business questions are answered as ranges rather than exact figures.
Information collected automatically
When you use the site, standard technical and usage data is recorded: pages viewed, the referring page, approximate location from your IP address (not precise location), device and browser type, and how you interact with the site. This is collected through cookies and similar technologies, described below, and non-essential collection happens only after you consent. Two things run whatever you choose, because they are part of keeping the site up: my server sees your IP address on every request, and a form submission is checked against a rate limit and two silent spam traps before anything is stored.
Information from the emails I send
Emails I send can record whether you opened them and which links you clicked. That is how I know whether an issue was worth writing. If you would rather not send that back, set your email client to block remote images, and use the unsubscribe link in any message to stop the emails entirely.
Cookies and tracking
The site uses cookies and similar technologies (pixels, tags, and local storage). What happens before you choose depends on where you are, because the law does:
- In the EU, EEA, UK, Switzerland or Brazil
- Nothing non-essential runs until you choose. You are shown the banner first, and you can accept everything, decline everything, or press "Choose" and pick analytics and marketing separately.
- Everywhere else
- Analytics and marketing run by default, without a banner, because prior opt-in is not required there. You can switch them off at any time through the "Privacy choices" link in the footer, and that choice is remembered.
Two things apply everywhere, regardless of location. If your browser sends a Do Not Track or Global Privacy Control signal, nothing non-essential runs at all and you are never shown a banner. And if your location cannot be determined, you are treated as though you were in the EU, which is the more protective of the two.
You can change your choice at any time through the "Privacy choices" link in the footer. Withdrawing it is not just a setting: advertising and analytics consent is signalled as withdrawn to Google and Meta, and Microsoft Clarity's cookies are erased from your browser.
- Strictly necessary
- Remember your consent choice, keep the forms working, remember preferences you set yourself, and protect the site through Cloudflare. These are always on, because they only ever do what you asked for.
- Analytics
- Understand how the site is used so I can improve it: my own first-party pixel and Google Analytics, which count visits, pages and where people arrived from. Set only after consent.
- Session recording and heatmaps
- Microsoft Clarity records how pages are used: mouse movement, clicks, scrolling and the pages visited, replayed as an anonymous session. It is more detailed than the counting above, which is why it is listed separately rather than folded into "analytics". Clarity masks form fields by default, so what you type into a form is not part of a recording. It runs only after consent, and if you withdraw consent the recording stops and its cookies are erased. Microsoft is the data controller for what Clarity collects, and its terms are on the Clarity site.
- Marketing
- Measure and improve advertising, primarily Meta (Facebook and Instagram) through its pixel and Conversions API. Set only after consent.
- Embedded video
- Videos load from YouTube in privacy-enhanced, no-cookie mode. YouTube may still set cookies once you press play.
Some of these tools are served through this domain so they load reliably, but the data still goes to the provider named above. You can also block or delete cookies in your browser settings, though parts of the site may then stop working. Each provider has its own controls: Google's analytics opt-out is at tools.google.com, Meta's ad settings sit in your Facebook or Instagram account, and Microsoft's privacy dashboard is at account.microsoft.com. In Europe, youronlinechoices.eu switches off interest-based advertising across a list of companies in one go.
Those five purposes map onto two switches, because two of them are not yours to switch. Strictly necessary is always on and cannot be turned off: the panel behind "Choose" lists it first, ticked and locked, so you can see what runs whatever you decide. Analytics and session recording move together on the Analytics toggle. Advertising moves on the Marketing toggle. Embedded video has no toggle because the player sets nothing until you press play, and pressing play is the choice.
Exactly what gets stored
This is the full list, taken from the site itself rather than from a template. "Until cleared" means it stays until you clear your browser storage or withdraw consent.
Strictly necessary, always on
| Name | Set by | What it does | Kept for |
|---|---|---|---|
| pm_consent (browser storage) | This site | Stores your cookie choice so you are not asked again. Without it the banner would return on every page. | Until cleared |
| pm_timefmt (browser storage) | This site | Remembers whether you chose 12 hour or 24 hour times on the booking page. Written only when you press that toggle. | Until cleared |
Analytics, only after consent
| Name | Set by | What it does | Kept for |
|---|---|---|---|
| _ga | Google Analytics | Tells one visitor apart from another. | 400 days |
| _ga_KBJF03YMZ5 | Google Analytics | Keeps the state of your current visit. | 400 days |
| _clck | Microsoft Clarity | Links your sessions to one anonymous visitor id. | 365 days |
| _clsk | Microsoft Clarity | Joins the pages of one visit into a single recording. | 1 day |
| _cltk (browser storage) | Microsoft Clarity | Session key for the recording in progress. | Until the tab closes |
| _pm_vi (browser storage) | This site | Counts your visits and page views, and how long you have been coming back. | Until cleared |
| _pm_vis (browser storage) | This site | Marks this visit as already counted, so one visit is not counted twice. | Until the tab closes |
| _attr_first (browser storage) | This site | Remembers the first campaign or link that ever brought you here, including the tracking parameter an advert adds to the link. | Until cleared |
| _attr (browser storage) | This site | The campaign or link that brought you here this time, including the tracking parameter an advert adds to the link. | Until the tab closes |
| lc_session_tk_… | My CRM provider | Ties your enquiry to the pages you looked at before sending it. | 1 day |
| lastExternalReferrer lastExternalReferrerTime (browser storage) | My CRM provider | Records which site you arrived from, and when. | Until cleared |
Marketing, only after consent
| Name | Set by | What it does | Kept for |
|---|---|---|---|
| _fbp | Meta | Identifies your browser so Meta can tell whether an advert led to an enquiry. | 90 days |
| _fbc | Meta | Stores the click identifier from a Meta advert so a later enquiry can be matched to the advert that produced it. Set only if you arrive from one. | 90 days |
| MUID | Microsoft, on bing.com and clarity.ms | A Microsoft identifier that works across Microsoft sites, not only this one. | 390 days |
| MR, SRM_B, SM, ANONCHK | Microsoft, on c.bing.com and c.clarity.ms | Microsoft's advertising and measurement infrastructure. | Session to 390 days |
The last two rows are worth being explicit about, because they are the least obvious thing on this page. Microsoft Clarity is a session-recording tool, but it also sets identifiers that reach across Microsoft's own network, including Bing. Those are advertising cookies rather than analytics ones, so they are listed under Marketing and they are governed by the Marketing toggle: decline marketing and none of them are set at all, while Clarity itself keeps working through the first-party entries above. That behaviour was tested, not assumed.
How it is used
To respond to you, deliver the newsletter and anything else you sign up for, route applications and inquiries, run and secure the site, understand and improve how it performs, and, where you have consented, measure advertising. I also use it to keep the records I am required to keep, to enforce the terms of this site, and to establish or defend a legal claim if one ever arises. I do not sell your personal data, and I do not use it to train AI models.
Inquiries are sorted. Each one is tagged by which door it came through and by the answers you gave, so it reaches the right place and I can see what kind of conversation it is. That is sorting, not deciding: nothing about you is settled by a machine in a way that has a legal or similarly significant effect, and I read every submission myself.
Legal bases
Where the GDPR applies, I rely on: your consent (analytics, marketing, and the newsletter); the steps needed to respond to a request or perform an agreement (inquiries, applications, and engagements); a legal obligation, where one applies, for records I have to keep; and legitimate interests in running, securing, and improving the site, balanced against your rights. You may withdraw consent at any time, and withdrawing it does not undo what was already done while it was in force.
Two consequences of that split are worth stating, because they are the parts people ask about. Sending an inquiry does not put you on a mailing list: replying to you is a step toward doing business, so it needs no permission box, and being added to a sequence is a separate purpose with its own optional checkbox on the form. It ships unticked, and whichever way you answer is recorded along with the date and the exact wording you were shown.
When an inquiry reaches my CRM it also carries context: which page you sent it from, which campaign or link first brought you to the site, how many times you had visited before, and how long you had been reading. That is how I know what someone was looking at before they wrote. It is covered by the analytics choice above, so if you decline analytics none of it is collected and an inquiry arrives with your message and nothing attached.
Who it is shared with
Most of this is providers who process data on my behalf, under their own terms, to run the business. A few entries are not that, and they are listed anyway:
- My CRM and email delivery provider, for contact management, forms, and sending what you sign up for
- Meta, for advertising measurement through its pixel and Conversions API. If you consented to marketing, a form submission also sends Meta a hashed (one way scrambled) version of your email address and phone number from my server, so it can match the enquiry to the advert without receiving either in the clear. If you did not consent, nothing is sent
- Google and Microsoft, for website analytics and session recording
- PostHog and Ahrefs, for privacy-first website analytics
- Cloudflare, for hosting, delivery, and security
- YouTube, for embedded video
- Professional advisers, such as my accountant and my lawyers, when they need it to do their work
- A buyer or successor, if the business behind this site is ever sold or merged, in which case your data moves with it and stays under terms no weaker than these
I may also disclose data where the law requires it. I do not sell or rent your personal data to anyone.
International transfers
The business behind this site is established in the United Arab Emirates, so what you send me reaches me there. It also passes through my CRM and email provider, which is named by category above. Several of the providers above are in the United States. Neither the UAE nor the United States as a whole holds an adequacy decision from the European Commission, so these transfers do not rest on adequacy.
What they rest on instead: for the US providers, the standard contractual clauses in their data processing terms, and for those certified under it, the EU to US Data Privacy Framework. For an enquiry, an application or a booking, the transfer is a step in responding to the request you made. If you want to know which mechanism covers a particular transfer, or a copy of the safeguards, ask and I will tell you.
How long it is kept
Contact and application data is kept for as long as needed to operate the relationship, and for a reasonable period afterward for legal and record-keeping reasons, then deleted or anonymized. The working rule: if you enquire and nothing comes of it, the record goes after three years. If we work together, records tied to that work are kept for as long as the law requires me to keep them, which is longer. Newsletter subscribers stay until you unsubscribe, plus a small record of the unsubscribe itself so you are not added back by mistake. You can ask me to delete anything sooner.
One caveat worth stating: deleting something from the live systems does not instantly remove it from backups. Where a copy survives in a backup it is walled off from any further use, and it goes when that backup rotates out.
Your rights
Depending on where you live, you may have the right to access, correct, delete, restrict, or object to the processing of your data, to receive a copy of it, and to withdraw consent. If you are in California, you may request to know or delete your information and to opt out of any "sale" or "sharing" (I do not sell or share it in that sense), without being treated differently for exercising these rights. To exercise any right, email support@philmeyfarth.com. You can unsubscribe from email using the link in any message.
How that works in practice: email me and say what you want. I may have to ask you something to be sure it is really you, because handing your data to the wrong person would be the worse failure. I answer within one month. If a request is complicated I will tell you inside that month and take up to two more. There is no charge unless a request is clearly excessive or repetitive, and if I ever refuse one I will say why.
If you are in the EEA, the UK or Switzerland you can also complain to the data protection authority where you live or work. The EEA list is at edpb.europa.eu. You can object to direct marketing at any time and I have to stop, with no balancing and no questions asked.
Sensitive information
Please do not send me special category data: health, religion, politics, trade union membership, sexual life, biometric or genetic data, or anything about a criminal matter. I do not ask for it and I have no use for it. The message fields on this site are free text, so if you write it anyway it is stored with the rest of your message, and you can ask me to delete it.
Children
The site is not directed to anyone under 16, and I do not knowingly collect data from children.
Links to other sites
This site links out: to Orevida, to my profiles on other platforms, and to videos on YouTube. Once you follow a link you are on someone else's site under their policy, not mine. I do not control what they collect and I am not answerable for it.
Security
The site runs behind Cloudflare with encryption in transit and reasonable safeguards. No method of transmission is perfectly secure, but I take protecting your data seriously.
Changes
I may update this policy as the site or the law changes. The date above shows the current version.
Who is responsible, and how to reach me
The controller for everything described here, in the sense the GDPR uses that word, is Phil Meyfarth, operating through Orevida LLC, which is established in the United Arab Emirates. There is no office or branch in the EU. Privacy questions and data requests go to support@philmeyfarth.com and reach me directly.