All Trades Digital

All Trades Digital

Privacy policy

What we collect, who receives it, how long we keep it — and that we hold records about businesses that never contacted us.

In effect 30 September 2026

Who this is

All Trades Digital is a one-person digital agency in Austin, Texas. We sell local search visibility, websites and quoting tools to service and trade businesses, and we run a free audit on this site that anyone can use.

This policy covers this website and that audit. It is written to be read rather than to be survived, and if something in it is unclear the address at the bottom is a person.

What we collect when you use this site

Four things, and the first three happen whether or not you ever type an address:

  • A session — A cookie that keeps this browser recognisable from one page to the next, so a scan can find its own results. With it we record the pages opened, the scans run, the page you arrived on, the site that sent you and any campaign tags in the link.
  • A connection, reduced — Your IP address is hashed with a secret we hold on the server the moment it arrives and the original is never written down. The hash is what enforces the rate limits that stop a script spending our scanning budget. We also record the browser string and the country and region our host reports.
  • What you typed into the audit — A website address, or a business name and a town, and — where we had to ask which business you meant — which one you picked.
  • An email address, if you give one — The full report is unlocked by an email address, and we send a copy of the report to it — or, where we could not load your website, we write to it once, the morning it loads. That address becomes a record of a person, separate from the record of a business, and we keep it.

We do not ask for a name, a phone number, or anything about you personally to run an audit. There is no account to create and no password to set.

We scan businesses that never asked us to

The audit runs against whatever is typed into the box on the homepage, and often that is not the person’s own business. A competitor can audit a rival. We can audit a business to decide whether it is worth approaching. So we hold records about businesses that never contacted us, and rather than leave that to be discovered, here it is.

What we read is public. The Google Business Profile Google already publishes — name, category, rating, review count, hours, photo count — the map-pack position for a handful of search terms, what a phone would see loading the website, and Google’s own PageSpeed score for it, with the picture of the page its test took. Nothing behind a login, nothing confidential, nothing that twenty minutes and a browser would not find.

What we store is that public data, the findings our own checks produced from it, and our internal score for how well the business fits what we sell. Raw copies are kept for twelve months; the summarised columns outlive them. A business shown a homepage mockup also has the logo its site names and the typefaces it asks Google Fonts for fetched once and kept with the mockup, in private storage, beside that picture of its site — so the mockup is shown from our site and never loaded from theirs.

What we do not store, deliberately: reviewer names, reviewer profiles, or a word of review text. A review is kept as a date, a rating, and whether the owner replied.

The one exception is a business that pays us to answer its reviews. For those we keep each reviewer’s public name and what they wrote, because that is what a reply is written from — and a model drafts the reply, which the AI disclosure describes.

What we do with it: decide who to approach, and build the audit for whoever ran it. We do not sell it and we do not share it.

If it is your business and you would rather we did not hold it, write to privacy@alltradesdigital.com and we will remove it.

We respect a site’s robots.txt and we stop reading after three seconds. A site that refuses us is recorded as having refused us, which is itself a finding, and we do not go round it.

If your business pays us

A business that buys from us gives us more than an audit ever reads, and here is all of it:

  • Who you are, and how you paid — The email address you bought with, which is also how you sign in to your portal — by a link we email you, never a password. Your business’s legal name if you give it. Stripe takes the payment on its own page; we never see a card number, and what we keep is what you bought, what you paid and when.
  • What you tell us when you start — Your services, service area, hours and phone number as you confirm them, your three most profitable services, a competitor if you name one, how you want reviews answered and posts handled — and the name and role of whoever answers your phone, so asking customers for reviews goes through the right person. That last one is about somebody other than you, so tell them.
  • The photos and logo you upload — Kept exactly as your phone or computer sent them. We do not resize them, convert them or strip anything out — which means a photo can still carry what your phone wrote into it, often including where and when it was taken. We also keep each file’s name, so you can tell your uploads apart. They sit in private storage that only we can open, each is reached by a link that stops working after ten minutes, and we use them for your Google profile or your website and nothing else. For a website we also keep two smaller copies of each photo and one of your logo, made for the site itself — turned upright, cropped or fitted, and without anything your phone wrote into it; your own file stays as it was, and removing it removes its copies too. You can remove any of them yourself, from the same page you uploaded them on, and a removed file is deleted from storage, not hidden.
  • Your Google profile, as a Manager — You add us as a Manager on your Google Business Profile, and we use that access to do the work you bought. We never ask for your Google password. When you leave, we remove our access the same day.
  • Buying a website: two answers and a box — Before you pay for a website we ask whether you sell products online and whether you can log in to where your domain is registered, and you tick that you own the business or may buy for it — and, where it applies, that you have read why a website will not fix your reviews. We keep your answers and each box you ticked, with the exact words you were shown and when, as we keep your acceptance of the agreement.
  • Your domain, for a website — To tell you on the order page what a new website changes and what it leaves alone, we read your domain’s public records — who runs your email, where the records are kept, and who registered the domain — and keep what we read for a week. At setup we give you one record to add to your domain, and we look it up each morning until it is there. We never ask for a password, and the record lets us change nothing.
  • Your website, while we build it — When you buy a website we read your current site once — the addresses of its pages, and its first headline and paragraph — so your old links can lead to your new pages and you can keep your own words if you prefer them. We keep what you choose for it: a design, your words or ours, what its buttons do, and anything you ask us to avoid or change. Its preview has an address of its own that opens for whoever holds the link, is kept out of search engines, and sets no cookie; approving it happens only in your portal.
  • Messages from your website’s contact form — A message someone sends through your website’s contact form is emailed to you, and we keep no copy of it — only a count of how many were sent, so the form cannot be used to flood you. On the preview, a message goes only to you, marked as a test. Our email provider keeps its own copy for 30 days, below.
  • What we write for you — Replies to your reviews and posts on your profile, which the AI disclosure describes, and what you approved or declined — and a report each month on how your profile did, which we keep, and whether you opened it.
  • Asking your customers for reviews — We give you a short link, a page for your technicians and a card to print. When someone presses Text it on that page, or opens the link, we count it — the business, which of the two it was, and the time. Nothing about the customer: no phone number, no name, no address, no cookie and nothing about their device. Your technician picks who to text in their own phone, and we never see it.
  • When you leave — We email you one page with your final report and everything we made for you, and the files you gave us. The page works for ninety days, for whoever has its link.

We keep all of it while you are a client, and until you ask us to delete it. Write to privacy@alltradesdigital.com and we will send you what we hold, or delete it — except the record of what you paid, which we keep.

Who else receives any of this

Running an audit means asking other companies questions, and those questions carry what you typed. Every one of them is a supplier working on our instructions, not a partner we trade data with:

  • Google — The Places API identifies the business and returns its public profile; the PageSpeed Insights API scores the website; and, when we make a homepage mockup, Google Fonts serves the typefaces the business’s site names. All three receive the business being audited, never your email address.
  • DataForSEO — Measures where a business ranks in the map pack and reads the public reviews on its profile. Receives the business, never your email address.
  • Anthropic — Runs the model. It classifies what a website says and writes the 90-day plan and the words of the homepage mockup some businesses are shown, and receives the public text of the business being audited — never your email address, and nothing about you. For a business that pays us to answer its Google reviews it also drafts the replies, so it receives those reviews and the reviewers’ public names. For a business that pays us it writes the monthly posts too, from the same public facts a plan is written from, and a second, smaller model reads each post before anybody else does. For a business that buys a website it writes the site’s pages, from the details and services you confirm, your current site’s headline, and anything you ask us to avoid or change. It never receives a photo you upload, or the name of whoever answers your phone.
  • Stripe — Takes payment from a business that buys from us, on its own page, and receives what you enter there. We receive the result, never the card.
  • Public DNS, and the registry that holds a domain — When a business is offered a website, we ask Cloudflare’s and Google’s public DNS services about its domain’s email and records, and the registry for its ending — found through IANA’s public directory — who registered it; and we ask the same DNS services each morning for the record a website client adds. They receive the domain name, never your email address.
  • Cloudflare — The bot check in front of the audit. It is the privacy-preserving one of the available choices by design, and it runs for everybody.
  • Resend — Sends the report email, and the few emails described below, and tells us whether each arrived. Receives your email address and what each email says — and, for a website client, the messages their contact form sends them. It keeps a copy of every email it sends for 30 days, then deletes it. Nothing in them tracks whether you opened it.
  • Vercel, Supabase, Upstash and Inngest — Respectively the host, the database, the cache and the queue that runs the slow steps of a scan. They hold what this site holds because they are where it lives — and Supabase also stores the photos and logos clients upload, and what a homepage mockup is made from, in private storage.

None of them is paid in data and none of them is an advertiser. We do not sell personal information, we do not share it for cross-context behavioural advertising, and there is no advertising pixel on this site.

The two things that are optional, and off until you say otherwise

Everything above happens because the audit cannot run otherwise. Two things are not like that, and neither loads until you accept them:

  • Product analytics — A third-party analytics service, run by somebody other than us. When it is on it is configured to keep nothing in your browser and no identifier that follows you to another site.
  • A booking calendar — A third-party embed, which loads when you open it rather than when a page loads.

Our own record of what happens here is not one of them. It sits in our database, it is never sold and never shared, and there is no switch for it on this site. Calling it strictly necessary would not be true, so we are telling you about it instead.

Session recording is off across this entire site, and there is no setting anywhere that turns it on. Nothing records your mouse, your keystrokes or your screen.

We also do not fingerprint devices. A session cookie, a hashed IP and what you actually did are enough.

Cookies, and the choice you get about them

This site sets two cookies. The session cookie described above, and a second one holding the answer you give the banner so you are not asked on every page. Neither can be switched off, and neither is used to advertise to you. The banner lists both, alongside the bot check, with the reason each exists.

Your answer is remembered for 180 days, and a decline is remembered exactly as long as an accept. You can change it whenever you like from Privacy choices in the footer of every page.

We honour Global Privacy Control. If your browser sends that signal we treat it as a standing opt-out, nothing optional loads, the banner does not appear, and we will not ask you to turn it off. A stored acceptance is ignored while the signal is set.

When this policy changes, the recorded answer is treated as no answer and you are asked again — rather than inheriting your consent to a document that no longer exists. The date at the top of this page is the version your answer is recorded against.

Email, and what we will and will not send

Unlocking a report sends you that report, once. It carries the report and the link to it and nothing that sells. That is deliberate: the day such a message gains an offer it becomes marketing, and marketing is a different thing with different rules.

If we could not load your website, there is no report to send, and the field offers something else: leave your address and we try the website again each morning for two weeks, and write to you once, the morning it loads. That email says so and gives you the way back to the check, and nothing that sells. If the site never loads, you hear nothing about it.

If your business looks like one we can help, we may send up to four more. We say so beside the field where you type your address, before you give it. They arrive over about three weeks, each about one thing your audit found and how to fix it yourself, and the last offers a 15-minute call. They come from a different address from the report, they carry our postal address, and every one has an unsubscribe link that works on one click — no sign-in and nothing to confirm. We send them only to businesses in the United States.

An address given before we said this is never sent them. This paragraph replaced one promising no list at all, and we record which version of the notice beside the field each address was given under.

A permanently bounced address stops us mailing it. A spam complaint stops us mailing it permanently.

How long we keep things

  • Raw scan data — Twelve months, after which the full copy is dropped and only the summarised columns survive.
  • Your consent answer — 180 days in the cookie. The record that you answered is kept, because a record of consent that expires cannot evidence the consent.
  • Email addresses and the reports behind them — Until you ask us to delete them. A report link stops working after 30 days either way.
  • Rate-limit counters — Hours or days. They exist to count the last hour and the last day, and they expire on their own. The hashed IP stored against a session lives as long as the session record does.

Your options, stated plainly

We are a very small business and the state privacy statutes that grant formal access and deletion rights apply to companies far larger than this one. We are not going to pretend otherwise by publishing a rights section that quotes a law we are not subject to.

What you get instead is simpler and is not conditional: write to privacy@alltradesdigital.com and ask us what we hold about you or your business, or ask us to delete it, and we will do it. There is no form and no verification hoop.

We re-check whether those statutes have started to apply to us every year. If they do, this section changes and you will be asked to read the policy again.

Children

This site sells business services to business owners. It is not directed at children and we do not knowingly collect anything from one.

Where the rest of it is

The notice at collection is the one-screen version of this page, and it is the one worth reading if you are about to type something in. The AI disclosure covers what a model does in an audit, the plan it writes, and the review replies we publish for the businesses that pay us. The acceptable use policy covers what the audit may be used for.

Questions, corrections and deletion requests all go to the same place: privacy@alltradesdigital.com.