Privacy Policy
Never Behind — Privacy Policy
Last updated: July 22, 2026
This policy explains what Business Geeks, Inc., doing business as Never Behind (“we,” “us,” “our”), collects when you use neverbehind.com, why we collect it, who we share it with, and what you can do about it.
We sell to businesses in the United States, and this policy is written to U.S. standards. Plain English, no hedging.
The short version:
- We collect your business name, website, email, and whatever you type in the optional notes box. That’s it.
- We use your email to send you what you asked for and to market to you. You can opt out of the marketing anytime.
- We use Google Analytics and Google Ads on the Site. When you submit a form, a scrambled (hashed) version of your email is sent to Google so it can match up ad conversions.
- Stripe handles payment. We never see your card number.
- We don’t sell your personal information for money. Because sending that
hashed email to Google for ad measurement counts as “sharing” under California
law, we treat it that way: we honor Global Privacy Control signals automatically,
and we give you a “Do Not Sell or Share My Personal Information” toggle at
/privacy-choices(linked in our footer) that stops the sharing for your browser in real time (§5.2). - Want your data deleted? Email hello@neverbehind.com and we’ll do it — with a couple of narrow exceptions (like data already sent to Google), spelled out in §5.5.
1. What we collect
1.1 Information you give us
| Where | What we collect | Required? |
|---|---|---|
| Free Snapshot form | Business name, website URL, work email | All required |
| Sample audit form | Work email | Required |
| Paid intake form ($30 / $500) | Business name, website URL, work email, and an optional free-text “Anything else?” note | Note is optional |
Please don’t over-share in the notes field. It’s for context like competitors, questions, or target cities. Do not put confidential information, passwords, personal data about other people, or regulated data (health, financial) in it.
1.2 Payment information
When you buy, you’re sent to Stripe to pay. We never receive, see, or store your card number, CVC, or full payment credentials. Stripe handles that directly and processes your payment under its own privacy policy (https://stripe.com/privacy).
From Stripe we receive the fact of payment, the amount, your email address, and a reference that lets us match the payment to your intake submission.
1.3 Information collected automatically
When you visit the Site, we and our analytics/advertising providers automatically collect:
- IP address and rough location derived from it (typically city/region level)
- Browser and device type, operating system, screen size
- Pages viewed, links clicked, time on page, and how you arrived (referrer)
- Google click identifier (
gclid) if you arrived from one of our ads - Signals Google’s reCAPTCHA collects to tell humans from bots (see §3.1)
1.4 What we do not collect
We do not collect government IDs, financial account numbers, health information, biometric or genetic data, precise geolocation, or the contents of your website beyond what is publicly available. We never ask for and never want your website login credentials — see the Terms of Service, §2.4.
We do not knowingly collect information from anyone under 18. The Site is for business use. If you believe a minor has given us information, email us and we’ll delete it.
2. Why we use it — and our legal basis
| Category collected | Why we use it |
|---|---|
| Business name, website URL | To perform the scan/audit you requested, on the right site |
| Email address | (a) To deliver your report and receipt (transactional) · (b) To send you marketing about our services · (c) To reply when you contact us |
| Optional notes | To tailor the audit to what you told us you care about |
| Payment/order data | To take payment, provide receipts, handle refunds, and keep required financial records |
| Automatic/usage data | To keep the Site working and secure, block bots and abuse, and measure whether our advertising works |
gclid / ad click data | To attribute a purchase back to the ad that produced it, so we know what to spend on |
2.1 Email: transactional AND marketing — plainly stated
We’re being direct about this because it’s the thing people care about most.
We use your email address for two distinct purposes:
- Transactional — sending your Snapshot, your audit, your Roadmap, your receipt, and answers to questions you ask us. This is what you signed up for.
- Marketing — sending you information about our services, new offerings, research, and reasons to buy from us.
This applies to every tier, including the free ones. If you submit the free Snapshot form or the sample-audit form, you go on our marketing list too.
You can opt out of marketing at any time — click the unsubscribe link in any marketing email, or email hello@neverbehind.com. We honor it promptly.
Opting out of marketing does not stop transactional email. If you have an open order, we will still send you your report and your receipt. You cannot unsubscribe from the thing you paid for.
We do not need your prior consent to send marketing email to a business address under U.S. law (CAN-SPAM), which is an opt-out regime — but we tell you plainly at the point of collection anyway, because burying it would be a lousy way to start a business relationship. If you’re in the EU/UK, see §9.
3. Cookies, analytics, and advertising
3.1 Google reCAPTCHA v3
The forms on our Site are protected by Google reCAPTCHA v3, which distinguishes real people from bots. To do this, reCAPTCHA collects hardware and software information (including device and application data) and sends it to Google for analysis.
The reCAPTCHA script and its invisible badge load when a page with a form loads and
contact Google (sharing basic technical details like your IP address, browser, and the
page you’re on). However, on our Site the actual bot-check runs when you
submit a form — that’s when reCAPTCHA sends its results to Google and the
_GRECAPTCHA cookie gets set. Just loading the page does not set that cookie, and we
don’t score visitors who never fill out a form.
The reCAPTCHA badge is displayed on pages with protected forms, and the standard reCAPTCHA disclosure — “This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.” — appears next to each protected submit button.
Your use of reCAPTCHA is subject to Google’s Privacy Policy and Terms of Service.
(Note: those Google links appear on our forms because Google’s terms require
them. They are Google’s terms, not ours. Our terms are at /terms.)
3.2 Google Analytics 4
We use Google Analytics 4 (measurement ID G-E32PEDYG9E) to understand how
people find and use the Site — which pages get read, where visitors come from,
where they drop off. GA4 sets cookies and collects the usage data in §1.3.
Google processes this data under its own terms. Google’s own description of how
it handles this data:
https://policies.google.com/technologies/partner-sites
3.3 Google Ads conversion tracking
We advertise on Google. We use Google Ads conversion tracking (conversion ID
AW-18326157968) to learn which ads actually produce customers.
- When you click one of our ads, you arrive with a
gclid(Google click ID) in the URL. - Google’s Conversion Linker stores this in a cookie on neverbehind.com. We also keep a backup copy of it in our own systems (see the cookie table in §3.6).
- When you submit a form or complete a purchase, we tell Google a conversion happened, and the cookie lets Google attribute it back to the original ad click.
3.4 Enhanced Conversions — we send Google a hashed version of your email
We want to be explicit about this one, because it involves your email address.
We have Enhanced Conversions enabled. When you submit a form on our Site, your browser turns your email address into a scrambled, one-way version and sends that scrambled version, not your email itself, to Google along with the conversion event. Google compares it against its own scrambled records to improve the accuracy of ad attribution.
This is a standard, widely-used ad-measurement technique (Google calls it Enhanced Conversions). Here is exactly what it does, and doesn’t do:
- We do not send Google your readable email address.
- We do send Google a fingerprint derived from it, which Google can use to match you to a Google account it already has. If Google already knows your email address, this hash can identify you to Google. It is not anonymous, and we won’t pretend it is.
- This scrambling happens in your browser, before anything is sent.
Google’s handling of this data is governed by its own policies and its customer data terms.
3.5 Your choices about tracking
- Browser controls. Most browsers let you block or delete cookies. Our forms and checkout will still work; our attribution won’t.
- Google Analytics opt-out. Google offers a browser add-on: https://tools.google.com/dlpage/gaoptout
- Google Ads personalization. Manage at https://adssettings.google.com
- “Do Not Sell or Share My Personal Information” toggle. We provide a persistent
opt-out control at
/privacy-choices, linked from our site footer on every page. Setting it records a preference (a cookie plus local storage, kept one year) that, in real time and on every page, stops the Enhanced-Conversions transmission and denies the ad-cookie / DoubleClick sharing described in §5.2. It is a preference you set yourself — not an email request — and it takes effect immediately for that browser. - Global Privacy Control. We honor Global Privacy Control (GPC) signals automatically. If your browser or a browser extension sends a GPC signal, we treat it as a valid opt-out of the “sharing” of your personal information for cross-context advertising (§5.2) and suppress that sharing for your browser; a GPC signal cannot be overridden.
- What opting out actually changes. When you opt out, we tell Google to stop using your data for ads — no ad-tracking cookies, no sending your data along for ad matching, no personalized ads. Basic analytics on our own site (which pages get visited, in general) keeps running, because that alone isn’t “sharing” under California law.
- Scope of the opt-out. The toggle is stored per browser (cookie + local storage), so it is not synced across your devices. If you would rather we handle it, email hello@neverbehind.com and we will opt your record out — email is a fallback, not the primary path.
3.6 Cookie table
Built from observation of the live Site in a real browser, not from documentation
about what these tools are supposed to do. First-party cookies are set on
neverbehind.com; third-party cookies are set by Google from Google’s own domains
when our ad and analytics tags load.
In plain terms, three kinds of cookies run on our Site — all tied to the tools described above:
| Kind | What it’s for | Roughly how long |
|---|---|---|
| Analytics (Google Analytics) | See how the Site is used — which pages get read, where visitors come from | Up to ~13 months |
| Ad-attribution (Google Ads) | Connect a purchase back to the ad you clicked — set only if you arrive from one of our ads | ~90 days |
| Bot-protection (Google reCAPTCHA) | Tell real people from bots apart — set only when you submit a form | ~6 months |
We also keep a first-party backup of the ad-click identifier in our own database, which we do not share with Stripe.
The full detail:
First-party (neverbehind.com):
| Cookie / storage | Set by | Purpose | Rough lifetime |
|---|---|---|---|
_ga | Google Analytics | Distinguish visitors | Up to ~13 months. GA4 requests 2 years, but browsers cap script-set cookies at 400 days, so the real lifetime is shorter than “2 years” |
_ga_E32PEDYG9E | Google Analytics | Maintain session state for our GA4 property | Up to ~13 months (400-day cap, as above) |
_gcl_au | Google Ads (Conversion Linker) | Attribute a conversion to an ad click | ~90 days |
_gcl_aw / _gcl_ls | Google Ads (Conversion Linker) | Store the ad-click identifier when you arrive from one of our ads | ~90 days; set on ad-click arrivals only |
nb_gclid | Never Behind | Backup copy of the ad-click ID, stored in our database. Not shared with Stripe — the reference we send Stripe is a separate random ID, not this one | 90 days; set on ad-click arrivals only |
Third-party (set by Google, not by us):
| Cookie / storage | Set by (domain) | Purpose | Rough lifetime |
|---|---|---|---|
test_cookie | doubleclick.net | Checks whether your browser accepts cookies | ~15 minutes — set on page load |
GCL_AW_P (and related conversion-linker cookies) | Google Ads / doubleclick.net | Cross-domain ad-click attribution | ~90 days — set when you arrive from one of our ads (a gclid is present), not on a plain organic visit |
_GRECAPTCHA | Google reCAPTCHA / google.com | Bot detection | ~6 months (Google-set) — set when you submit a protected form, not on page load |
4. Who we share it with
We do not sell your personal information. We share it only as follows.
4.1 Service providers
| Provider | What they get | Why |
|---|---|---|
| Amazon Web Services (AWS), our hosting provider | Everything you submit | Hosting and storage, in the United States. Your submissions are stored in our database. We also use AWS to notify our team and to send you email. |
| Stripe | Your email, order amount, card/payment details you enter with them, and a reference number that lets us match the payment to your submission — no Google identifier and no other advertising data | Payment processing. Stripe is the controller of your card data, not us. |
| Google (Analytics, Ads, reCAPTCHA) | Usage data, cookie IDs, gclid, hashed email (§3.4), reCAPTCHA device signals | Analytics, ad measurement, bot protection. |
| AI answer engines (currently OpenAI/ChatGPT, Anthropic/Claude, Google/Gemini, Perplexity, xAI/Grok) | The scan questions we run, which include your business name and website | To observe what these engines say about you — that observation is the product. We do not send them your email address or your notes. |
4.2 Other disclosures
- Legal. If required by law, subpoena, or valid legal process, or to protect our rights, safety, or property, or investigate fraud.
- Business transfer. If we’re acquired or merge, your information may transfer as part of the business. Any acquirer remains bound by this policy or gives notice of a change.
- With your permission. For anything else — including naming you publicly as a customer, which we will not do without your prior written permission (see Terms, §5.4).
4.3 Aggregated and anonymized data
We may publish aggregated, anonymized findings from our research — for example, “X% of sites we audited had no schema markup.” This never identifies you, your business, or your website.
5. Your California privacy rights (CCPA/CPRA)
If you’re a California resident, you have specific rights. We extend these to everyone who asks, regardless of where they live, because operating two systems is a waste of our time and yours.
5.1 Categories of personal information we collect
Using the CCPA’s own categories, in the last 12 months we have collected:
| CCPA category | Do we collect it? | What, specifically |
|---|---|---|
| Identifiers | Yes | Name (business), email address, website URL, IP address, cookie/device IDs, gclid |
| Commercial information | Yes | Products purchased, order history |
| Internet/network activity | Yes | Pages viewed, clicks, referrer, session data |
| Geolocation data | Yes, coarse only | City/region inferred from IP. Not precise location |
| Professional/employment info | Yes, incidentally | Your business name and anything you volunteer in the notes field |
| Protected classifications | No | — |
| Biometric information | No | — |
| Sensory data (audio/video) | No | — |
| Education information | No | — |
| Inferences / profiling | No | We do not build behavioral profiles |
| Sensitive personal information | No | We do not collect SSNs, precise geolocation, financial account numbers, health data, or the contents of your communications |
Sources: you (directly, through our forms); your device (automatically); Stripe (payment confirmation); Google (ad attribution).
Purposes: as set out in §2.
5.2 Selling and sharing
-
We do not sell your personal information for money, and have not in the preceding 12 months. We have not sold or shared the personal information of anyone under 16.
-
“Sharing” for cross-context behavioral advertising. Our Google Ads + Enhanced Conversions setup transmits a hashed version of your email (§3.4) and cookie identifiers to Google for cross-context ad measurement, and loading our ad tag causes your browser to contact Google’s ad-serving domains (
googleadservices.com,ad.doubleclick.net) and set a third-party ad cookie ondoubleclick.net. Under the CPRA, that conduct is “sharing” — disclosure of personal information to a third party for cross-context behavioral advertising, even though no money changes hands. We treat it as sharing and give you the corresponding controls. Specifically:- We provide a “Do Not Sell or Share My Personal Information” control — a
persistent toggle at
/privacy-choices, linked from our site footer on every page. Setting it records a preference (cookie + local storage, kept one year) that, in real time and on every page, stops the Enhanced-Conversions transmission and denies the ad-cookie / DoubleClick sharing described above. You set it yourself; it is not an email request and takes effect immediately for that browser (§3.5). - We honor Global Privacy Control (GPC) signals automatically as an opt-out of this sharing; a browser sending GPC is treated as opted out and the signal cannot be overridden (§3.5).
- When you opt out, we tell Google to stop using your data for ads — no ad-tracking cookies, no sending your data along for ad matching, no personalized ads. Basic analytics on our own site keeps running, because that alone isn’t “sharing” under California law.
- We give notice at collection — a short notice when each form is submitted, linking to this policy and to the opt-out.
- Email is a fallback, not the primary path. If you would rather we handle it, email hello@neverbehind.com and we will opt your record out.
We do this regardless of whether we currently meet the CCPA’s applicability thresholds — we chose to comply now rather than gate it on size.
- We provide a “Do Not Sell or Share My Personal Information” control — a
persistent toggle at
5.3 Your rights
You have the right to:
- Know what we’ve collected about you, where we got it, why, and who we shared it with
- Access a copy of it
- Delete it (subject to exceptions — see below)
- Correct inaccurate information
- Opt out of sale/sharing, if applicable
- Non-discrimination — we will not charge you more, give you less, or degrade your service for exercising any of these rights. Ever.
5.4 How to exercise them
Email hello@neverbehind.com with what you want. That’s the whole process. There is no form and no portal.
- We’ll confirm within 10 business days and respond substantively within 45 calendar days (extendable by another 45 if it’s complicated — we’ll tell you if so).
- Verification: we’ll ask you to send the request from the email address we have on file, or otherwise confirm you’re you. We won’t hand your data to someone who isn’t you.
- Authorized agents may submit on your behalf with written proof of authorization.
5.5 What deletion actually means
When you ask us to delete, we remove your record from our customer database and our marketing list, and we delete everything within our control. Be aware of what we cannot delete:
- A scrambled version of your email already sent to Google. When you submit a form, your browser sends a scrambled (one-way) version of your email to Google for ad measurement (§3.4). Scrambling it hides your email from casual view, but it is not anonymous — Google can match it back to a person (that is how the measurement works). Once we have sent it, we cannot recall or delete it — it is no longer within our control. What we can do, and will do on request, is delete your email and everything else within our control from our own customer database.
- Transaction records. We must keep records of what you bought and what you paid for tax, accounting, and legal-compliance reasons. Stripe keeps its own records under its own retention obligations, and we cannot delete those for you — contact Stripe.
- A report already delivered to you. It’s in your inbox. That’s yours.
- Backups. Deleted data may persist in routine encrypted backups until they expire on their normal cycle.
- The suppression list. If you unsubscribe, we keep your email on a do-not-contact list precisely so we don’t email you again. Deleting that record would defeat its purpose. If you ask for full deletion, tell us whether you want to stay suppressed — otherwise a future form submission could re-add you.
6. How long we keep it
| Data | Retention |
|---|---|
| Customer/lead records (our database) | 3 years from your last interaction, then deleted |
| Order and payment records | 7 years, to match tax and accounting requirements |
| Delivered reports | 2 years, so we can resend them if you ask |
| Marketing list membership | Until you unsubscribe or ask for deletion |
| Suppression/do-not-contact list | Indefinitely (that’s the point — see §5.5) |
| Analytics/ads data | About 14 months — GA4 event-data retention set to 14 months |
7. Security
Your information is stored with our hosting provider, Amazon Web Services (AWS), in the United States, encrypted in transit (HTTPS across the Site) and at rest. Access is limited to people who need it to run the business. We use reCAPTCHA and honeypot fields to keep bots out of our forms, and we never store card data.
No system is perfectly secure, and we can’t guarantee absolute security. If a breach affects your personal information, we’ll notify you as required by law.
8. Where your data lives
We’re a U.S. business and store data in the United States, with our hosting provider (Amazon Web Services). Our service providers (Google, Stripe) may process data in other countries under their own terms. If you’re outside the U.S., you’re sending your information to the U.S., where privacy law differs from your home jurisdiction.
9. If you’re in the EU, UK, or elsewhere outside the US
We target and market to U.S. businesses. We do not aim our advertising at the EU or UK, and this policy is written to U.S. requirements.
If you’re outside the U.S. and choose to use the Site anyway, you’re doing so on your own initiative and sending your data to the U.S.
10. Changes to this policy
We’ll update this policy as our practices change, and revise the “Last updated” date. Material changes get an email notice to our list. Continuing to use the Site after a change means you accept it.
11. Contact us
Questions, requests, or complaints:
Business Geeks, Inc. (d.b.a. Never Behind), a Utah corporation 4627 W Flintlock Way, Herriman, UT 84096 Email: hello@neverbehind.com
We read every one of these and we answer them.