This policy explains what LFW collects when you visit LFW.com or use our tools, why we collect it, who we share it with, and the choices you have. We keep this deliberately plain.
LFW is operated by LFW.com LLC, a Virginia limited liability company doing business as LFW (“LFW,” “we,” “us”). This policy covers our public website, the free audit, the reports we send, and the client portal (together, the “Services”).
It does not cover the separate written agreement we sign with retainer clients, which governs how we handle a client’s own systems and data.
What we collect
Information you give us
- The free audit. The domain you enter, and, if you ask for the full report, your email address, so we can run the audit and send you the results.
- Contact and booking. Your name, email, and anything you write when you contact us or book a call. We use these to reply to you and arrange the conversation. Separately, analytics can count that a form was started or submitted without collecting its contents. A contact message does not put you on a mailing list.
- Meal invitations. If you respond to a private meal invitation, we store your availability, optional dietary and accessibility needs, and any note you provide so the organizer can confirm the plans.
- The client portal. If you’re a client, your name and email, the requests and messages you submit, and any files you attach.
Public information reviewed by the free audit
The free audit itself looks only at information that is already public about a domain: the same things any visitor or standard tool can see. It does not attempt to access private systems, and it does not require you to give us access to yours.
Information we collect automatically
- Report and invitation visits. When you open a report or an invitation we’ve sent (a link like LFW.com/r/…, LFW.com/i/…, or LFW.com/lunch/…), standard server logs record the time, your IP address, your browser and device type, and the page that referred you. We use this to operate and secure the link.
- Page views. We count visits to our public pages using our own first-party analytics: the page you viewed, the site that referred you, an approximate location (country, and where available region or city, computed by our security provider from your IP address, which we do not store), and a one-way hashed identifier derived from your IP address and browser (used to estimate unique visitors). The raw IP address and browser details are not stored, and the identifier is salted with the date, so it cannot be linked across days or reversed. This is cookieless and stays on our servers; we don’t use Google Analytics, and we don’t track you across other sites.
- Security and delivery logs. Our servers and our security provider record IP addresses and basic request details to keep the Services running, prevent abuse, and rate-limit automated traffic.
- Cookies and preferences. Functional cookies keep you signed in, protect forms, and maintain your assigned homepage experiment. When you save an optional-service preference, we also store a privacy receipt and your choices for up to 90 days. Advertising identifiers are used only when advertising integrations are active and your applicable privacy settings permit them.
One place for your privacy choices
Open privacy choices to see the optional services currently enabled on this website and change your preferences. Advertising, optional analytics, and Replay have separate controls. Required website functions and the first-party page-view measurement described above are separate.
Our Tag Manager supports Meta, LinkedIn, and Google Ads, but an available integration is not automatically active. The preference panel lists active services. When advertising is enabled and permitted, approved page views and accepted conversions may be sent to the selected provider, using browser or server delivery. Matching can include advertising click identifiers and, where specifically enabled and permitted, normalized, hashed email addresses. Hashing is not anonymization. We do not send contact messages or arbitrary form contents through these integrations.
Optional tracking respects Global Privacy Control and Do Not Track. Replay always requires an affirmative choice. Advertising defaults depend on the reviewed regional policy and a trustworthy location signal; when location is unknown, advertising requires an affirmative choice. You can opt out at any time. Changing a choice stops future eligible delivery; it cannot recall information a provider has already received.
We retain minimized conversion-delivery diagnostics for 30 days and privacy receipts for up to 90 days. Consented advertising click identifiers may be stored in a first-party cookie for up to 30 days. Provider retention is governed by the relevant provider's policies. Client installations have their own controller, configuration, and privacy notice.
Optional Replay on our public website
We offer Replay to a random sample of browsers, not on every visit. We use local storage on your device, when available, to remember the sampling decision and avoid repeating an unanswered notice for up to 24 hours. These preferences contain no visitor identifier.
If you enable Replay in privacy choices, we record the layout and interactions during your visit to our public marketing pages. This can include page paths, navigation order, timing, scrolling, pointer movements, clicks, and signals that a form was started, encountered an error, or completed. We use these recordings to find usability problems and improve the website.
Recording starts after you agree. Your recording permission and a random visit identifier are stored in your browser’s session storage for the current tab, allowing recordings from different pages to appear as one journey. We do not join that identifier to your contact details or client account, our page-view analytics, or your activity on other sites.
Recording fragments with private content removed can also be held in that tab’s session storage so a page change does not discard them. They are removed after delivery or when you stop Replay. Undelivered fragments are eligible for retry for up to 15 minutes; expired fragments are removed the next time Replay runs in the tab.
Published text on LFW.com can remain readable when it matches a separately verified public copy of the page. This includes static form labels and buttons. Other text is masked.
Form controls, entered values, editable areas, private results and messages, and elements marked private are excluded. Form milestones contain no field values or error messages.
Approved images and fonts hosted by LFW can appear in playback; other assets, embedded frames, and media are excluded. Replay does not record the client portal, admin, login pages, private reports, or invitations.
Leave Replay off or choose “Reject optional” to decline, or “Stop optional Replay” to stop recording. We remember that preference, when local storage is available, for up to 90 days, including in other tabs on the same browser. Clearing your browser storage removes the preference.
If your browser blocks storage, we cannot reliably remember a preference across tabs or page loads. A diagnostic link can display the notice again for testing, but cannot grant permission to record.
Recording consent expires after 30 minutes without interaction or two hours from the start of the visit. Closing the tab normally clears its session storage; some browsers can restore it when reopening a tab. The same expiry limits still apply.
If you previously agreed to playback with all text masked, we ask you to opt in again before recording with readable public content. Earlier masked recordings stay masked.
Our ordinary analytics counts notice displays, choices to allow or decline, privacy-link clicks, and observed page exits without a notice interaction. These consent event counts are not joined to a visitor identifier or Replay recording. An unanswered notice is not treated as a decline, and diagnostic offers are counted separately.
Replay respects Global Privacy Control and Do Not Track signals. Recordings are stored on LFW’s server and available only through authorized access. LFW.com recordings expire after 14 days.
Stopping recording prevents further collection but does not delete recordings already received. Contact us about deletion using the details below.
Why we use it
- To run the free audit and send you the report you asked for.
- To respond to you, schedule calls, and provide the Services.
- To operate and secure the site: preventing abuse, debugging, and rate-limiting.
- To improve public pages and forms using interaction measurements and optional Replay.
- To understand whether a report or an invitation we sent has been opened.
- To send you service messages and, only if you subscribe to it, the newsletter. You can unsubscribe at any time.
- To meet our legal obligations.
We do not sell your personal information, and we do not use it for targeted advertising or to build profiles about you.
Who we share it with
We share information only with the service providers that help us run LFW, and only as needed. Today those are:
- Hetzner: hosting for our servers and database.
- Cloudflare: content delivery, security, and Web Analytics. It processes IP addresses and request data to protect the site. Its browser beacon also collects page-view and performance measurements; see Cloudflare’s Web Analytics documentation.
- Google Workspace: our email and calendar. Contact messages and booking requests land in our Google mailbox, replies go out through it, and calendar invitations for booked calls are created there.
- Resend: sending some of our email, such as audit reports and receipts; it receives the email address and the contents of messages we send you.
- OpenAI and Anthropic: AI-assisted research, drafting, software development, and administrative work. These tools act as assistants to LFW. Depending on the task, they may process relevant client and prospective-client information, including names, contact details, communications, project requirements, and notes about our working relationship. LFW remains responsible for the work and decisions made with their assistance.
We may also disclose information if the law requires it, to protect our rights or safety, or in connection with a sale or transfer of the business. We’ll update this list as our providers change.
How long we keep it
We keep information for as long as we need it for the purpose it was collected, and then delete or de-identify it.
Scan results and report-visit logs are kept while they’re useful for the outreach or engagement they relate to; contact messages and portal records are kept for the life of the relationship and a reasonable period after.
We keep our own aggregate website analytics (page-view and visitor counts) indefinitely, to understand long-term trends. You can ask us to delete your information sooner (see below).
Replay recordings are unavailable after their 14-day retention period and are removed during collection or review. On an idle system, physical cleanup occurs the next time Replay runs. Encrypted or access-controlled backups may retain earlier copies until those backups expire.
Your choices and rights
If you are a Virginia resident, the Virginia Consumer Data Protection Act gives you the right to confirm whether we process your personal data, to access it, to correct it, to delete it, to obtain a portable copy, and to opt out of the sale of your data or targeted advertising. We do not sell personal information for money. Where advertising integrations are active, use privacy choices to opt out. We extend these same choices to everyone, wherever you live.
To exercise any of these, email hello@lfw.com. We’ll respond within 45 days. If we decline a request, you may appeal by replying to our response, and we’ll reconsider and explain our decision.
To stop non-essential email from us, use the opt-out in the message or email us. We can’t remove the essential cookies without breaking login, but you can clear or block cookies in your browser.
Security
We take reasonable measures to protect the information we hold: encrypted connections, access controls, and login by one-time link rather than stored passwords. No method of transmission or storage is perfectly secure, so we can’t guarantee absolute security.
Children
The Services are for businesses and organizations and are not directed to children. We don’t knowingly collect personal information from anyone under 13. If you believe a child has given us information, email us and we’ll delete it.
Where your information is handled
LFW is based in the United States, and we process information in the United States and in the facilities of the providers listed above. If you contact us from outside the U.S., you’re sending your information to the U.S.
Changes to this policy
We may update this policy as the Services change. When we do, we’ll revise the “last updated” date above, and for significant changes we’ll do more to let you know.
Questions, or want to exercise a right? Email hello@lfw.com. See also our Terms & Conditions.