Skip to main content

Privacy Policy

Last updated

1The short version

We use Google Analytics to count visits and see which pages people read. That sets cookies on your device and sends data to Google, for every visitor, from the first page you open. Section 4 explains what it collects and how to opt out.

Beyond that we do not track you. No advertising pixel, no retargeting tag, no heatmap, no session recorder, no profiling, and nothing sold to anybody.

One more thing worth knowing before you read further. Our contact page and the foot of our home page embed Calendly's scheduler, and when it loads it brings a set of Calendly's own third party services with it, including Stripe, Meta, and Segment. That happens inside Calendly's frame rather than on our pages, and section 6 names every one of them.

Everything below is the same story with the detail attached.

2Who we are

RunSimpler is a brand of Moonbound Consulting, LLC, an Illinois limited liability company. The website is runsimpler.com. The company responsible for your personal data is Moonbound Consulting, LLC, registered at 333 West Wacker Drive, Suite 2600, Chicago, IL 60606. One business, two names, and you should not have to guess which one is accountable to you.

For personal data we handle about website visitors and our own clients, we are the controller. That means we decide why and how it is used, and we are the one you hold to account.

Privacy questions and requests go to tony@runsimpler.com, marked for the attention of Anthony Drummond, President.

3What this policy covers

This policy covers this website and the personal data we handle in the course of running our business and serving clients.

It does not cover client data we process on a client's behalf as part of delivering their work. When we run a workflow that touches a client's customer data, the client is the controller and we are the processor, and the terms are in that client's signed agreement or data processing agreement rather than here.

It does not cover websites we link to. When you follow a link away from here, you are on somebody else's terms.

4What the website collects by itself

Google Analytics. We use Google Analytics 4, a service from Google LLC, to understand how people find and use this site. It tells us which pages get read, roughly where visitors come from, and which links work. We use it to make the site better, and for nothing else.

It runs for every visitor, from the first page load. There is no panel asking permission and no setting to answer first. Google Analytics loads as soon as the page does and sets its cookie then, the same way for everyone. The paragraph below, on legal basis, names the two ways to stop it on your own device; neither one requires us to agree first.

Google Analytics collects your approximate location derived from your IP address, your device and browser type, the pages you view and how long you spend on them, how you arrived here, and a randomly generated identifier stored in a cookie so repeat visits can be recognized as the same browser. It does not collect your name or your email address, and we have not configured it to receive either.

Google acts as our processor for this, and processes the data under its own terms. IP addresses are truncated by Google Analytics 4 before storage, so we never see your full IP address in it. We do not enable Google Signals, we do not link the property to Google Ads, and we do not use it to build advertising audiences.

Legal basis, and how to opt out. Our legal basis under GDPR is legitimate interests: understanding how people use this site so we can make it better. You have the right to object to that at any time by emailing us at tony@runsimpler.com. You can also opt out anywhere, regardless of legal basis, by installing Google's browser add-on at tools.google.com/dlpage/gaoptout, or by blocking cookies as described in our Cookie Policy. Nothing on this site stops working if you do.

What we do not do.

No advertising or social pixels. No Meta pixel, no LinkedIn Insight Tag, no Google Ads tag, no TikTok pixel, no retargeting of any kind. We are not following you around the internet.

No heatmaps, session recording, or profiling. We do not record your mouse movements, replay your session, or build a profile about you. We do not use your data for automated decision making.

No Google Tag Manager, and no other analytics. Google Analytics is the only measurement tool on this site.

No selling or sharing. We do not sell your personal data and we do not share it for advertising. Section 12 says this again in the words California law uses.

Cookies, honestly. Google Analytics sets two cookies on our domain, for every visitor. Apart from those two we set none: no preference cookies, no advertising cookies, nothing else. Our Cookie Policy names every cookie individually.

Self hosted fonts. Our typefaces are served from our own domain. We do not use Google Fonts, so Google does not receive your IP address because you looked at our typography.

No account, no login, no newsletter, no comments. There is nothing on this site to sign up for.

No contact form. Our contact page offers a booking calendar, and there is no form of ours anywhere on this site. The only fields you can type into are Calendly's own, inside the scheduler.

One item of local browser storage. Some animations on the site remember, within a single browsing session, that they have already played, so they do not replay every time you navigate. This is stored by your browser under a key beginning rs-arrival-fired and its value is the character 1. It contains no personal data, it is not a cookie, it is never sent to our servers, and it disappears when you close the tab. It did not write during our test run, so on many visits it does not appear at all.

5Server logs and hosting

Serving a web page requires receiving a request, and a request carries information about the device that made it.

Our hosting provider, Vercel Inc., processes standard server log data on our behalf. That typically includes your IP address, the page requested, the time of the request, your browser and operating system as reported by your browser, and the page you came from if your browser sent one.

We use this only to serve the site, keep it running, and investigate abuse or faults. We do not use it to build a profile of you, and we do not combine it with anything else.

Our legal basis under GDPR is legitimate interest, specifically our interest in operating a functioning and secure website.

6The booking scheduler, and what it brings with it

What it is. This is the significant disclosure in this policy, so it gets its own section and plain description. Our contact page embeds a scheduler provided by Calendly LLC, so you can book a call without emailing back and forth. It runs inside a frame on our page. When you use it, you are giving your information to Calendly as well as to us.

Calendly receives the name, email address, and any answers you type into the booking form, plus your time zone and the technical data any web service receives. Calendly then sends us the booking. Calendly handles that data under its own privacy policy and as a processor for us in respect of the booking itself.

When it loads. This distinction matters, so here it is precisely.

On our home page, the scheduler does not load when the page loads. It shows a still placeholder, and it loads when you scroll the booking section into view, or sooner if you click the placeholder to open it. That section is at the foot of a long page, so a reader who does not scroll that far never loads it, nothing described below reaches their browser, and no third party learns they were there.

On our contact page, the same thing happens, but the booking section is near the top of a short page, so the first time you scroll it loads. Everything below loads at that point, without you clicking anything. If you open that page and neither scroll nor touch it, nothing loads at all.

On every other page, including our work, team, finance, operations, and sales and marketing pages, the scheduler does not load at all and no third party is contacted.

Who else loads inside it. Calendly's scheduler loads its own third party services. We do not choose these and we do not receive data from them, but they run in your browser as a result of a choice we made to embed Calendly, so we name them.

Observed loading inside the Calendly frame:

  1. Calendly (calendly.com, assets.calendly.com, dfp.calendly.com), the scheduler itself
  2. Google (www.googletagmanager.com, www.google-analytics.com, www.gstatic.com, fonts.gstatic.com, accounts.google.com, www.recaptcha.net), analytics, fonts, sign in, and bot protection
  3. Stripe (js.stripe.com, m.stripe.com, m.stripe.network), payment and fraud detection, present because Calendly supports paid bookings
  4. OneTrust (cdn.cookielaw.org, geolocation.onetrust.com), Calendly's own cookie consent tool
  5. Meta (connect.facebook.net), Facebook's advertising and analytics library
  6. Twilio Segment (cdn.segment.io), event data routing
  7. Sprig (cdn.sprig.com, api.sprig.com), in product surveys
  8. Braze (js.appboycdn.com), customer messaging
  9. Airbrake (notifier-configs.airbrake.io), error reporting
  10. Two hosts we have not been able to attribute (featureassets.org, prodregistryv2.org), contacted from inside Calendly's frame using a Calendly key. We do not know which company runs them, and we are not willing to guess in a privacy policy, so we name what loads and tell you plainly that we could not identify who receives it.

What this means for you. Because the scheduler runs inside a frame, these services see your interaction with Calendly rather than with our site, and the cookies they set belong to their own domains rather than ours. Our Cookie Policy names each cookie and its lifetime.

If you would rather none of this loaded, do not open our contact page and do not click the booking button. Email us instead at tony@runsimpler.com and we will arrange a call by hand. That option is real, and we would rather tell you about it than bury it.

7What we collect when you contact us or become a client

If you email us or book a call, we hold what you send, which is usually your name, email address, company, and whatever you tell us about your situation. We use it to reply and to work out whether we can help. Legal basis: legitimate interest in responding to a business enquiry, or steps at your request before entering a contract.

If you become a client, we hold what running the engagement requires. Contact details for you and your team, billing and payment details, the contents of our correspondence, access credentials and account permissions for systems we operate on your behalf, and the materials you give us to work with. Legal basis: performance of our contract with you, and compliance with our legal obligations for tax and accounting records.

If you attend a workshop or download something we publish, we hold the details you gave us to attend or download, and we may follow up about related work. You can tell us to stop at any time and we will.

We do not buy personal data from data brokers, and we do not sell yours.

8Who we share it with

We share personal data with service providers who help us run the business, and only as far as they need it to do their job for us. They are: Vercel for hosting and infrastructure; Microsoft 365 for email and calendar, with Proofpoint filtering the mail before it reaches us; Calendly for scheduling and Zoom for the calls it books; Google Analytics for measurement, and only for the readers who agreed to it; QuickBooks for accounting and for payments; and Adobe for document signing.

We also share where the law requires it, where we need to establish or defend a legal claim, and, if the business is ever sold or reorganized, with the party acquiring it. If that last one happens, this policy travels with the data.

We do not sell personal data and we do not share it for cross context behavioral advertising, as those terms are used in California law. We have never done this and have no plans to.

9International transfers

We are based in the United States and our service providers are mostly based there. Some of our clients are outside the United States.

If you are in the European Economic Area, the United Kingdom, or Switzerland and you give us personal data, it will be transferred to and stored in the United States. Transfers are made under the EU-US Data Privacy Framework certification where the vendor holds it, and under the European Commission's Standard Contractual Clauses with the UK Addendum where it does not, together with the supplementary measures our service providers apply.

10How long we keep it

WhatHow long
Enquiries that do not become clients24 months from last contact
Client records and correspondenceThe engagement, plus 3 years after it ends
Invoices, tax, and accounting records7 years
Server logs30 days
Marketing list, where you subscribedUntil you unsubscribe, plus a short record of the unsubscribe so we honor it

When a period ends we delete the data or anonymize it so it can no longer identify you.

11Your rights if GDPR or UK GDPR applies to you

If you are in the EEA or the UK, you have the right to ask us for a copy of your personal data, to correct it, to delete it, to restrict how we use it, to object to our using it under legitimate interests, and to receive it in a portable format.

You can also complain to your data protection authority. In the UK that is the Information Commissioner's Office. In the EEA it is the supervisory authority for your country. We would rather you came to us first, but the right is yours either way.

12Your rights if California law applies to you

If you are a California resident, the CCPA as amended by the CPRA gives you the right to know what personal information we have collected about you, the sources, the purpose, and the categories of third party we disclosed it to; the right to delete it; the right to correct it; the right to opt out of sale or sharing for cross context behavioral advertising; the right to limit use of sensitive personal information; and the right not to be discriminated against for exercising any of these.

Two of those need a direct answer rather than a recital. We do not sell your personal information and we do not share it for cross context behavioral advertising. We do not collect sensitive personal information for the purpose of inferring characteristics about you, so the right to limit does not currently have anything to bite on.

We honor these rights as a voluntary commitment rather than as a statutory obligation, and we extend them to every US resident rather than only to residents of the states whose legislatures have passed a law. The rights are the same wherever you live.

13How to make a request

Email tony@runsimpler.com and tell us what you want us to do.

We will need to be reasonably confident you are who you say you are before we hand over or delete anything, so we may ask you to confirm something only you would know. We will not ask you for more information than the request needs.

We respond within 30 days for GDPR requests and 45 days for CCPA requests, and we will tell you if we need an extension the law allows. There is no charge unless a request is manifestly unfounded or excessive, and we will tell you before charging anything.

An authorized agent may make a request for you. We will ask for proof that you authorized them.

14Security

We use access controls, encryption in transit, multi factor authentication on business systems, and least privilege access to client systems.

No system is perfectly secure and anyone who tells you otherwise is selling something. If a breach affects your personal data and the law requires us to tell you, we will tell you, and we will tell you what happened rather than issue a statement that says nothing.

15Children

This site and our services are for businesses. We do not direct them at children, and we do not knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, email tony@runsimpler.com and we will delete it.

16Changes to this policy

When we change this policy we update the date at the top. If a change materially affects how we handle your personal data, we will do more than change a date. We will say what changed.

Because this policy describes specific third parties observed loading on this site, any change to what the site loads requires a change here as well. That is a maintenance obligation we are taking on deliberately, and a vague policy would have avoided it. We think the specificity is worth the upkeep.

Contact
tony@runsimpler.com, for the attention of Anthony Drummond, President
Responsible entity
RunSimpler is a brand of Moonbound Consulting, LLC, an Illinois limited liability company.
Moonbound Consulting, LLC333 West Wacker Drive, Suite 2600, Chicago, IL 60606