Privacy Policy
Last updated: August 22, 2026 · Effective date: August 22, 2026
1. Who We Are
HoloGrowth ("HoloGrowth," "we," "us," or "our") operates the website hologrowth.com and provides growth advisory and growth-infrastructure services to direct-to-consumer e-commerce brands. HoloGrowth is registered in the United States, with a fully international team. For any privacy question or request, contact privacy@hologrowth.com.
2. What We Collect
Information you give us
- Application and booking details: when you apply for a Profit Clarity Strategy Call, we collect your name, email, phone number, brand name and URL, and business information you provide (such as revenue range and monthly ad spend) so we can assess fit and schedule the call.
- Correspondence: emails and messages you send us.
- Engagement data: if you become a HoloGrowth partner, we access the business data you grant us (for example ad accounts, analytics, and store data) strictly to deliver the services under our agreement with you.
Information collected automatically
- Basic technical data: our hosting provider (Netlify) logs standard technical information (IP address, browser type, pages visited) to serve and secure the site, and counts page views from those logs. Netlify also injects a small measurement script of its own into every page (its "Real User Metrics" feature), which reports page-speed timings from your browser back to Netlify. It measures performance, not identity, and sets no cookie.
- Analytics and advertising measurement: we use Google Analytics 4, Google Ads conversion tracking, the Meta (Facebook) Pixel, and Microsoft Clarity. These services set cookies and similar identifiers to measure how visitors use the site, attribute visits to campaigns (including via URL parameters such as gclid and fbclid), and measure conversions. Microsoft Clarity additionally records session replays and heatmaps (scrolls, clicks, mouse movement). We may add further measurement tools (for example Hyros) and will keep this list current.
- An advertising cookie we set ourselves: our own code creates
_fbp, a random browser identifier in Meta's format, valid for 90 days. We create it rather than waiting for Meta's script, and later send it to Meta and to our scheduling tool so a booking can be matched to an ad click. - Sharing hashed personal data with Google and Meta: when you book a call, and also when you opt in to a free resource and answer the follow-up question, we share your email address with Google and Meta so they can match the action to the click that led to it. For a booking we also share your first and last name and phone number. This is more than a cookie, so we want to be specific:
- Who does the hashing. For the copy sent from our own server, we apply SHA-256 ourselves before sending, so no readable value leaves our systems. For the copy sent from your browser, the readable values are handed to Google's and Meta's own scripts running in the page, and those scripts hash them before transmitting. Either way no readable value crosses the network, but in the browser case the hashing is performed by their code, not ours.
- What a hash does and does not do. It lets Google or Meta recognize a record they already hold, and does not disclose your details to anyone who does not already have them. It is not anonymization and we do not claim it is.
- Not everything is hashed. The server copy of an opt-in event also carries your IP address, your browser's user-agent string, and Meta's own browser and click identifiers (
_fbpand_fbc). Meta requires those in their original form, so they are not hashed. - How it reaches each platform. Meta receives it from your browser (the Pixel's Advanced Matching) and from our server (Meta's Conversions API), because ad blockers and tracking protection frequently stop the browser copy arriving. Both carry the same event identifier so a booking is counted once. Google receives it from your browser through Google Ads Enhanced Conversions and, where that setting is enabled, Google Analytics' user-provided data collection. Each acts as an independent controller of what it receives.
- Personal details are removed from the page address: our scheduling tool redirects you back to our site after you book, and its redirect link contains your name, email address and phone number. Before any analytics or advertising script runs, we rewrite that address to strip those details out, so they are never recorded in the page address stored by Google Analytics, the Meta Pixel or Microsoft Clarity. Campaign parameters (such as utm_source and gclid) are kept, because those identify the ad, not you. This applies to the address only. On our post-booking and application-outcome pages we greet you by your first name on the page itself, and Microsoft Clarity's session replay records the page as rendered, so your first name appears in that recording.
- What we keep in your browser, and for how long: we store the campaign parameters you arrived with, a random identifier, the answers you gave to our qualifying questions, a reference for any call you booked, which version of a page or video you were shown, and when you last completed one of these actions. Once you have given them to us, we also hold your email address, first and last name and phone number. Lifetimes differ, so we will not quote one number for all of it. The
_fbpcookie expires after 90 days. Your email, name and phone sit in session storage and are erased when you close the tab. Everything else sits in local storage with no automatic expiry, so it stays until you clear your site data. The 90-day figure that appears in our code governs when a newer campaign source replaces an older one, not when anything is deleted. - A signal when you reach the booking step: this one fires without a click. If we already know your email address in the browser tab you are using - because you submitted one of our sign-up forms, or because you arrived from our scheduling tool after applying or booking - then scrolling to the booking section is enough. We send that address to our own server. If you are on our email list we tag your record to note that you reached the calendar; if you are not, nothing is stored. We use it to tell who got that far without booking, so we can decide whether to follow up.
- Third parties your browser contacts, and when: some tools are contacted as soon as a page loads, before you have done anything. Being specific, because "we use third-party tools" is not a useful disclosure:
- On page load, without any action from you: Netlify (hosting). Google Analytics, Google Ads, the Meta Pixel and Microsoft Clarity - these load 3.5 seconds after the page opens even if you do nothing, and immediately if you arrived from one of our ads or a tracked link. Our email platform Kit, on any page carrying a sign-up form, to render that form - so Kit sees your IP address and browser on those pages whether or not you ever subscribe. On pages with a sales video, Vidalytics: that player loads with the page rather than waiting for a click, so Vidalytics receives your IP address, browser and the page you are on as soon as you open it.
- On page load or as you approach it: the booking widget (iClosed). Your browser opens a connection to iClosed as soon as a page carrying the scheduler loads, and the widget itself loads once it is within about 600 pixels of the screen - which on some pages is immediately. Either way iClosed receives your IP address and browser before you type anything.
- Only when you choose: client-interview videos load from YouTube in its no-cookie mode, and nothing reaches YouTube until you press play.
- Our free calculators do not collect what you type. The numbers you enter into the calculators and the Scaling Scorecard are processed entirely inside your browser. They are never sent to us or to anyone else, and they are not stored. Microsoft Clarity's session recording is switched off on every one of those pages specifically so that your figures cannot be captured in a replay. The only thing we record is that a calculator was used and which result band it produced - never the inputs themselves.
- Opting out: you can block these tools with browser settings or extensions, opt out of Google Analytics via Google's opt-out add-on, and manage ad personalization at adssettings.google.com and facebook.com/adpreferences. You can also ask us directly to delete what we hold - see "Your Rights" below.
3. How We Use Your Data
- To evaluate your application and run your Profit Clarity Strategy Call
- To deliver the services you engage us for
- To send you a resource you asked for, and the newsletter if you subscribed
- To respond to your questions
- To measure which ads and pages actually produce booked calls, so we do not keep paying for advertising that does not work. This is the purpose the hashed sharing in section 2 exists for.
- To meet legal and accounting obligations
We do not sell your personal data. Ever.
4. Who We Share It With
We share your data only with the providers we use to run the business, and only as far as each one needs to do its job. Each processes data under its own terms.
- iClosed - scheduling and the application form. Your browser contacts iClosed as soon as a page carrying the scheduler loads, and the scheduler itself loads once it is near the screen, so iClosed receives your IP address and browser before you enter anything, along with the campaign parameters and advertising identifiers we attach to the scheduler link so a booking can be attributed to the right ad. It then receives everything you enter when you apply and book.
- Kit - our email platform. Receives your email address and first name; the answers you gave about your role and monthly ad spend; the campaign, ad set, ad and landing page you arrived through; the status of any call you book (booked, rescheduled, cancelled, or finished - whether or not you attended); and a tag noting that you reached the booking step. If you book a call without ever having subscribed, booking creates a subscriber record for you and enrols you in the short email series we send before a call. Kit also renders the sign-up forms themselves, so it is contacted by your browser on any page carrying one, even if you never subscribe.
- Google (Analytics 4, Ads) and Meta - measurement and advertising. Receive site usage data including the role and ad-spend answers you gave us, and the hashed email described in section 2 when you book or opt in, plus your hashed name and phone number when you book. Meta additionally receives your IP address and user-agent string, unhashed, on the server copy of an opt-in event.
- Microsoft (Clarity) - session replays and heatmaps, switched off on our calculator pages.
- Netlify - hosting. Standard server logs, server-side page-view counting from those logs, and a page-speed measurement script Netlify injects into pages (no cookie, no identity - performance timings only).
- YouTube - client-interview video, contacted only if you press play, in no-cookie mode. Vidalytics - sales-video hosting, contacted automatically when you open a page carrying a sales video.
- Plus the ordinary back office: video conferencing, payment processing, cloud email and documents, and internal messaging.
Several of these providers are based in the United States and process data there. Where we transfer personal data out of the UK or EEA, we rely on the transfer mechanisms in each provider's own data-processing terms.
5. Legal Bases (GDPR)
Where the GDPR applies, we process your data on the basis of: performance of a contract or pre-contractual steps (applications, calls, engagements); legitimate interests (site security, responding to inquiries, and measuring which advertising produces booked calls); and legal obligations (accounting records).
We want to be straight with you about one point rather than bury it. This site currently loads its analytics and advertising tools without first asking you to accept them, and relies on legitimate interests for that measurement. If you would rather we did not hold or share your data, tell us at privacy@hologrowth.com and we will delete it and stop - see "Your Rights" below. You can also block these tools yourself using the options listed in section 2.
6. Retention
We keep application and correspondence data for as long as reasonably needed to evaluate and maintain our relationship, and engagement records for as long as required by law. What we hold in your browser is described in section 2 - most of it has no automatic expiry and clears when you clear your site data. Our server keeps short diagnostic logs of the booking and application messages we receive; email addresses, names and phone numbers are masked in those logs, but other details you supplied in the application may appear, and Netlify retains them under its own policy. Data held by the providers in section 4 is retained under each provider's own policy. You can request deletion at any time (see below).
7. Your Rights
Depending on where you live, you may have the right to access, correct, export, restrict, object to the processing of, or delete your personal data, and to lodge a complaint with a supervisory authority. To exercise any of these rights, email privacy@hologrowth.com - we respond to all legitimate requests within 30 days.
8. Security
We use access controls, encryption in transit, and least-privilege access to partner data. No method of transmission or storage is 100% secure, but we treat your business data with the same care we ask partners to grant it with: view-access only where possible, revokable at any time.
9. Children
Our site and services are for businesses and are not directed at anyone under 18. We do not knowingly collect data from children.
10. Changes
If we change this policy, we will update the date at the top of this page. Material changes will be highlighted on this page.
11. Contact
HoloGrowth · privacy@hologrowth.com