# Data Protection | Winston Digital Marketing

The operational companion to the privacy policy. What we hold, which system it sits in, who can open it, how long it stays, and what to do if you want it gone.

**Last reviewed:** September 19, 2026

> General information, not legal advice. This page describes how winstondigitalmarketing.com handles data as of the review date above. It is not a legal opinion and it does not replace advice from your own counsel. Items marked TO CONFIRM are open questions. A visible gap is better than a number that is not true.

## What this page is for.

The [privacy policy](/privacy/) tells you what gets collected and why. This page is the layer underneath: the systems, the vendors, the retention settings, and the security measures that exist today. If you are a client doing vendor due diligence on us, this is the page to send to your reviewer.

Winston Digital Marketing, LLC is a small operation based in Brooklyn, New York. That shapes everything below. There is no security team and no SOC 2 report. What we do have is listed below.

## The systems, one by one.

### Website and hosting

**What:** Static HTML served by a Cloudflare Worker. Request logs hold IP address, user agent, URL, and timestamp.

**Where it lives:** Cloudflare, United States and its global edge network.

**Who can open it:** John Morabito. Any additional named accounts are TO CONFIRM.

**Retention:** Cloudflare's log retention on our plan is TO CONFIRM.

### The live audit tool

**What:** The URL you submit. Our worker fetches that page and sends an extract (title, meta description, headings, structured data types, and roughly the first 4,000 characters of text) to a language model provider for scoring. Your IP address is read to rate limit the tool.

**Where it lives:** Nowhere, on our side. The audit is computed and returned in the response. The rate-limit IP sits in the worker's memory for about a minute and is written to no database. We keep no audit history.

**Model provider:** Anthropic by default, NVIDIA as fallback. What each provider retains from an API call is governed by their terms, linked below.

**Retention:** None held by us.

### Session recording and heatmaps

**What:** Microsoft Clarity, project ID yjzr7kp3aw, on every page. Mouse movement, clicks, taps, scroll behavior, navigation, device and browser, approximate location from IP, and enough page content to replay the visit.

**Where it lives:** Microsoft's Clarity service.

**Masking configuration:** Form fields are masked. Microsoft applies this at the product level, not as a setting we chose: "Content in the input boxes is masked in all modes and can't be customized," and drop-down menus are masked in all modes too. That holds even on Clarity's most permissive Relaxed mode. A replay of this site cannot show what you typed into a form, and we could not switch that off if we wanted to. Microsoft documents it in [Masking content](https://learn.microsoft.com/en-us/clarity/setup-and-installation/clarity-masking). Separately, general page text is being recorded: this project is not in Strict mode, which we verified by reading the configuration Clarity serves for project yjzr7kp3aw, where content capture is switched on. Whether it runs Balanced or Relaxed is TO CONFIRM, and the only difference that makes is whether numbers and email addresses printed in ordinary page text get masked. No page on this site prints yours.

**Who can open it:** Anyone with access to the Clarity project. The current user list is TO CONFIRM.

**Retention:** TO CONFIRM. Microsoft publishes retention periods for recordings and for aggregate metrics, and they should be verified against current Microsoft documentation rather than quoted from memory.

### Analytics

**What:** Google Tag Manager (container GTM-N36WKNH) on every page, loading Google Analytics 4. Page views, CTA clicks, outbound link clicks, scroll depth, form submissions, device, and approximate location. Plausible Analytics on roughly a quarter of pages, cookie-free, holding page views, referrer, country, and device only. Conscriba on most pages, tracking visitor and AI agent traffic and running A/B tests.

**Where it lives:** Google, Plausible, and Conscriba respectively.

**Tag Manager container inventory:** TO CONFIRM. Tags can be added to a GTM container without any change to this site's code, so the source files cannot prove what is firing. The container needs to be exported and its full tag list recorded here. As of this review, no Meta pixel, LinkedIn Insight Tag, or TikTok pixel appears in the site's source.

**Retention:** The GA4 data retention setting on our property is TO CONFIRM. Plausible and Conscriba retention are TO CONFIRM.

### CRM and forms

**What:** HubSpot, portal 7293353. The contact form on /contact/ and the meeting scheduler. Name, email, site URL, message, meeting time, and HubSpot's own visitor tracking that links a form fill to the pages that visitor read.

**Where it lives:** HubSpot, North America region.

**Who can open it:** John Morabito. Additional seats are TO CONFIRM.

**Retention:** Records stay until deleted. A defined deletion schedule is TO CONFIRM.

### Email list

**What:** Intuit Mailchimp, audience on the us2 data center. Email address, plus for audit report requests the audited URL, the score, and the weakest signal, stored as merge fields.

**Where it lives:** Mailchimp, United States.

**Who can open it:** John Morabito. Additional seats are TO CONFIRM.

**Retention:** Until you unsubscribe or ask for deletion. Unsubscribing leaves an archived record in Mailchimp so we do not email you again by accident. Ask for deletion and we delete outright.

### Product buyers

**What:** For anyone who buys the GEO Skill Pack or the Compliance Kit, we hold the email address used, so updates can be sent. There is no checkout on the site and no card data touches it.

**Where it lives:** Email and TO CONFIRM (whichever payment or invoicing system is used to take payment directly).

**Retention:** Tax and accounting records are kept as long as the law requires.

## Sub-processors.

Every company that processes data from this site, what they do, and whether a data processing agreement is in place.

- **Cloudflare**. Hosting, CDN, request logs. US. [Policy](https://www.cloudflare.com/privacypolicy/). DPA signed: TO CONFIRM.
- **Microsoft**. Clarity session recording and heatmaps. US. [Policy](https://privacy.microsoft.com/privacystatement), [Clarity terms](https://clarity.microsoft.com/terms). DPA signed: TO CONFIRM.
- **Google**. Tag Manager and Analytics 4. US. [Policy](https://business.safety.google/privacy/). Data processing terms accepted in the GA4 admin: TO CONFIRM.
- **Conscriba**. Visitor and AI agent analytics, A/B testing. [Policy](https://conscriba.com/privacy). Entity location, data location, and DPA: all TO CONFIRM.
- **Plausible**. Cookie-free page analytics. EU-hosted. [Data policy](https://plausible.io/data-policy). DPA signed: TO CONFIRM.
- **HubSpot**. CRM, forms, meeting scheduler. US. [Policy](https://legal.hubspot.com/privacy-policy). DPA signed: TO CONFIRM.
- **Intuit Mailchimp**. Email list and sending. US. [Policy](https://mailchimp.com/legal/privacy/). DPA signed: TO CONFIRM.
- **Anthropic**. Scores the extract from the live audit tool. US. [Commercial terms](https://www.anthropic.com/legal/commercial-terms), [data retention](https://privacy.anthropic.com/en/articles/10023548-how-long-do-you-store-my-data).
- **NVIDIA**. Fallback model provider for the same extract. US. [Policy](https://www.nvidia.com/en-us/about-nvidia/privacy-policy/).

We add a sub-processor when we add a tool. When one is added or removed, it changes here and the review date at the top moves.

## Security measures in place.

These are verifiable from the site's own code and configuration:

- TLS on every page and every form submission. The apex domain redirects to www with a Strict-Transport-Security header, one year, including subdomains. Whether HSTS is also enforced at the Cloudflare zone level is TO CONFIRM.
- Clickjacking protection on every HTML response: X-Frame-Options set to DENY, plus a Content-Security-Policy of frame-ancestors none.
- X-Content-Type-Options set to nosniff, so a browser will not reinterpret a file type.
- Referrer-Policy set to strict-origin-when-cross-origin, so full URLs do not leak to third parties.
- Permissions-Policy switching off camera, microphone, geolocation, and interest-cohort by default. A marketing site has no business asking for any of them.
- No user accounts, no passwords, and no customer database on the public site. There is nothing to breach here that is not already public.
- API keys for the audit tool are held as Cloudflare Worker environment secrets. They are not in the page source and not in the repository.
- The audit endpoint is rate limited to five runs per minute per IP address.

Things a reviewer will ask about that are not settled yet:

- Multi-factor authentication on every vendor account listed above: TO CONFIRM.
- A named list of who has access to which system: TO CONFIRM.
- A written incident response plan: TO CONFIRM. One does not exist in writing today.
- A documented backup and restore procedure for HubSpot and Mailchimp exports: TO CONFIRM.
- Encryption at rest is handled by each vendor on their own infrastructure. We hold no separate database of our own.

## If there is a breach.

No written procedure exists today, so this is the commitment we hold ourselves to in the meantime. If we learn that personal data we hold has been exposed, we will find out what happened and what was affected, email everyone whose data was involved at the address we hold, tell them what was taken and what to do about it, notify the vendor and any regulator where notification is required, and write up what changed so it does not happen twice. The deadline we hold ourselves to, and the written plan behind it, are TO CONFIRM.

If you think you have found a security problem on this site, email [john@winstondigitalmarketing.com](mailto:john@winstondigitalmarketing.com) with the detail and we will answer.

## Making a request.

Whether you are a client, a visitor, or someone who filled in a form once and forgot, the route is the same. Email [john@winstondigitalmarketing.com](mailto:john@winstondigitalmarketing.com) and say which of these you want:

- **A copy** of what we hold about you, listed by system.
- **A correction** to something that is wrong.
- **Deletion** of everything we hold, apart from records kept for tax, accounting, or a live legal claim.
- **An opt-out** from analytics, from marketing email, or both.

Include the email address you used with us. If the request concerns a session recording, include the page and roughly when you visited, because Clarity recordings are not filed under your name and we may not find it otherwise. We will confirm receipt and tell you what we did. Our target turnaround is TO CONFIRM.

Client data held under a signed engagement is governed by that contract. If you are a client and your reviewer needs something this page does not cover, ask and we will answer directly.

## Related.

[Privacy policy](/privacy/), for what the site collects and why. [Terms of service](/terms/), for the site, the free audits, and the paid products.
