Privacy

Your choice. A clear boundary.

Optional measurement is off by default. Contact works with or without it.

Your analytics choice

Optional first-party usage analytics are off until you explicitly allow them. Global Privacy Control and Do Not Track keep them off. Refusing or withdrawing consent never blocks contact or site content. There are no advertising pixels, third-party analytics SDKs, session recordings, fingerprints, keystroke capture or analytics containing your form text.

Optional analytics off. Contact works either way.

How measurement works

When enabled, a small deferred JavaScript file records page views and consulting, contract, email-draft, successful email-copy, capabilities-print and inquiry-form-start actions. An email click, copied address or printed page is not a received inquiry or booked meeting.

Consented browser storage retains a random visitor identifier and first/last registered source, campaign and landing-page attribution for at most 30 days. Sessions expire after 30 minutes of inactivity. Your yes/no choice is stored for 180 days. Turning analytics off removes local attribution and stops queued/new events; it does not retrospectively delete events already received. Browser or network restrictions can make measurement incomplete.

Only registered page paths and campaign codes are accepted, not full query strings or referrer URLs. Raw usage events and visitor/session identifiers are removed after 90 days. Consented source, campaign and landing-page details attached to an inquiry remain with that inquiry until its record is deleted. Search Console data is separate aggregate search-performance information, never a visitor-to-search-query identity map.

When you contact Zac

The inquiry form sends the name, email, company, work type, focus and message you deliberately submit to a PostgreSQL-backed private lead system on Zac’s Kubernetes cluster. With analytics consent, it also attaches the bounded attribution described above. Without consent or JavaScript, the form still works and the inquiry is unattributed. Receipt is confirmed only after storage succeeds. No message is sent to an external person automatically.

Zac uses submitted details to respond and discuss potential work. Qualification, meetings, proposals, signed contract value and received payments are recorded separately; none are inferred from clicks. Contact details are not copied into analytics, logs, metrics or traces. Unqualified, lost and spam inquiries are removed after one year without activity. Active engagements and financial records may need longer retention. You can request access, correction or deletion at zac@zacp.xyz.

Database backups follow the cluster’s 14-day backup-retention policy; deletion can take that additional period to leave retained backups. Access is private and restricted to the owner. Backup configuration is not a claim that a particular restore has been verified.

Email links instead open a draft in your own email app. Nothing is sent until you send it there; your email provider and receiving service then handle the message.

Delivery and technical examples

Google Cloud hosts static pages. A separate HTTPS intake service on the local cluster receives submitted inquiries and opted-in analytics. Hosting and network providers may process IP addresses and request metadata to deliver and secure requests. The application does not persist IP addresses or browser fingerprints in analytics.

JavaScript and WebAssembly animations run locally, last under five seconds, do not loop and stop offscreen or in print. Reduced-motion and data-saving preferences preserve static explanations. Native scrolling is not intercepted. External references and profiles have their own privacy practices.

Optional analytics off. Contact works either way.

How measurement works