Privacy Policy
Last updated: September 19, 2026
The short version
- We collect the minimum: what you give us on the form, what we need to do the work, and publicly available business information.
- We don’t sell your data. Not to data brokers, not to anyone, not ever.
- Your audit request goes straight from your browser to a Google Apps Script webhook, and lands in a Google Sheet we control. That’s the whole form pipeline.
- We don’t run tracking scripts, ad pixels, or analytics on this site. Your browser does make two requests to Google we want you to know about — the site’s fonts, and the form itself (§2.3). If tracking is ever added, this page changes first — and we’ll say so.
- We reach out to local businesses using public business contact info — today, US businesses, with CAN-SPAM-compliant emails (which also stay within Canada’s CASL rules) and calls to published business numbers about business services. No cold texts, ever. If you tell us to stop, we stop — we delete what we hold, keeping only your contact info on a do-not-contact list so it never happens again.
- Ask us what we have on you, and we’ll show you. Ask us to fix or delete it, and we will — the one thing we keep is your contact info on the do-not-contact list, because that’s what keeps the outreach stopped.
The short version is a summary. The full policy below is what actually governs.
This Privacy Policy explains what information Page1local (“Page1local,” “we,” “us”) collects when you use page1local.com (the “Site”), request an audit, or become a client, and what we do with it. It’s written to be read, not skimmed past. If a question isn’t answered here, email us — contact details are at the bottom.
1. Who we are
Page1local is a two-person shop based in Ontario, Canada. We audit the web presence of local service businesses, rebuild slow or broken websites, and run ongoing Google-visibility work (Business Profile, local SEO, review management, hosting) under a monthly plan called Full Care.
Because we’re a Canadian business, Canada’s federal private-sector privacy law — PIPEDA (the Personal Information Protection and Electronic Documents Act) — governs how we collect, use, and disclose personal information in the course of commercial activity, and we hold ourselves to it. Some of what we handle sits outside PIPEDA’s scope: public business contact information used only to contact someone in their business capacity. The rest — audit-form submissions, communications, and the customer data clients entrust to us for review requests — sits inside it. We apply the same care to all of it.
Your customers’ contact details are the one thing we handle purely on your instructions — to send review requests on your behalf (Section 3.1).
2. What we collect
2.1 Information you give us directly
- The audit form: your name, business name, website URL, and email address or phone number. Four fields on the form; our host logs the visit as any host does (Section 2.3). When you hit submit, your browser sends those fields straight to a Google Apps Script webhook (script.google.com), which writes them into a Google Sheet on our account — with a timestamp of when your entry lands. Section 2.3 explains exactly what that means.
- Communications: whatever you send us — emails, texts, calls, notes from a meeting. If you email us, we have your email address; that’s how email works.
- If you become a client: the information in your proposal and what we need to do the work — business details, your content (text, photos, logos), and your customers’ reviews (which are public anyway). Where possible, we use delegated access instead of your passwords — a manager role on your Google Business Profile, delegate access at your registrar, a team invite on your hosting — so we can do the work without ever holding them. Where you give us credentials, they’re stored in a password manager. We revoke our access and delete them when the engagement ends. If you’re on Full Care, you may also give us your customers’ contact details — names and email addresses — so we can send review requests on your behalf. Review requests go by email, not text.
2.2 Publicly available business information
We prospect and audit using public business information: business name, address, phone, website, and what’s visible on Google Maps, Google Business Profiles, review sites, and business websites. These come from publicly available sources: Google Maps and Business Profiles, review sites, directories, and the businesses’ own websites. This is how we know who’s invisible on Maps and who to reach out to.
We don’t collect or store anything that isn’t already public business-contact information, and we don’t keep sensitive personal details (driver’s licenses, social security numbers, customer lists of our prospects).
2.3 Information collected automatically
- Hosting logs. Our host (Vercel) keeps standard server logs — IP address, browser type, pages visited, timestamps. Every website host does this. We use it for basic operations and to keep the site working, not to build profiles of visitors.
- Cookies and tracking scripts: none. We don’t run third-party tracking scripts, ad pixels, or analytics cookies on the Site, and we don’t set cookies ourselves. Two things on the Site do talk to Google, and we disclose both here:
- Google Fonts. The Site’s fonts (Inter and Space Grotesk) are loaded from Google’s font servers (fonts.googleapis.com / fonts.gstatic.com). When a page loads, your browser requests those font files from Google, and that request includes your IP address and browser type — as every request to Google’s servers does. It’s not a tracking script and it’s not used to build a profile of you; it’s how the fonts get delivered.
- The audit form posts straight to Google. When you submit the form, your browser sends your name, business name, website URL, and contact info — plus your IP, as every web request does — directly to a Google Apps Script webhook (script.google.com), which writes your entry into a Google Sheet on our account. This fires only when you submit: it’s not passive tracking, and there’s no script following you around the rest of the site. Google may set its own functional cookies on that network call; those make the form work, and we never read them or use them for tracking.
If we add analytics (e.g., Google Analytics) later, we will update this policy first and tell you in it what changed.
2.4 What we do NOT collect
- We don’t collect payment card details — if you pay by card, the payment processor handles the transaction and we never see or store the card number.
- We don’t collect health data, precise location data, or other sensitive personal information.
3. What we do with it
| Purpose | What it covers |
|---|---|
| Answer audit requests | Sending your audit report to the contact you gave us, and following up on it — by email, or by call or text to the number you gave us. We won’t add you to a newsletter or sell your contact info — reply “stop” (or text STOP) and we stop. |
| Provide services | Building your site, managing your Google Business Profile, running review management (including sending review requests to the customers whose contact details you give us), hosting, maintenance. |
| Prospecting and outreach | Contacting local businesses whose public web presence suggests our services are relevant. Emails go to business addresses, about business services, with an opt-out in every message. Calls go to published business numbers, about business services (Section 4). |
| Run the business | Invoicing, records we’re legally required to keep, responding to your questions, defending ourselves if there’s a dispute. |
| Improve the Site and services | Seeing what pages get visited from our host’s server logs. |
We do not sell your personal information. Not to data brokers, not to advertisers, not to anyone. Selling data isn’t our business model.
3.1 Customer data you give us for review requests
If you’re on Full Care, you may hand us your customers’ contact details so we can ask them for reviews on your behalf. Straight answers about that data:
- We use it only to send review requests on your behalf. Nothing else — not our marketing, not anyone else’s.
- Email, not text. Review requests go by email at launch — we don’t text your customers.
- The consent is on you. You collected these contacts, and you know what they agreed to. Our Terms (§6.2) make you responsible for that consent, and we rely on it.
- We keep it only for your engagement. When Full Care ends, it’s deleted or returned with the rest of your data, per Section 7.
- It’s never sold, and never shared beyond the tools that actually send the request (see Section 5). Your customers won’t hear from us about anything but your review request.
4. Our outreach — and how to make it stop
We cold-email and cold-call local businesses using the public business contact info described in 2.2. Here’s how that works under the rules:
- We send from Canada and comply with both Canadian anti-spam law (CASL) and US law (CAN-SPAM). If we ever email Canadian businesses, we’ll follow CASL’s consent rules and update this policy first.
- We email businesses about business services at their business address — not personal accounts.
- Calls to published business numbers. We may call a business’s published phone number about services for that business — business calls about business services, not calls to private lines. That’s permitted under the telemarketing rules that apply, and “don’t call again” ends it immediately.
- Texts: only with a number you gave us — never cold. If you gave us your phone number on the audit form, we may call or text you about your audit; reply STOP to any text and the texts stop. What we will never do is text a number we found on a listing or website — even one labeled “business line.” Many contractors’ published number is a personal cell, and an unsolicited text to a cell phone is a statutory-damages mistake we won’t make. (The same rule governs review requests, §3.1.)
- If you tell us to stop, we stop. Reply “remove me” to any email, say “don’t call again” on a call, or reply STOP to any text — and you’re off the list. No re-adds, no arguments.
- How “no re-adds” actually works: when you opt out, we delete the business-contact information we hold about you — and keep one thing: your email address (and phone number, if we had it) on a do-not-contact list. If we deleted everything, a future prospecting run could re-find your public email or number and contact you again; the do-not-contact list is the mechanism that stops that. Entries don’t expire and we don’t remove them — an expired “stop” would be a broken “stop.”
You can also email us at any time to see what we hold on you, including your do-not-contact entry, and to ask us to fix or delete anything else.
5. Who we share information with
We share only what’s needed to do the work, with these kinds of parties:
| Party | Why | What they get |
|---|---|---|
| Fonts load from Google’s font servers; the form posts directly to a Google Apps Script webhook (script.google.com) that stores leads in a Google Sheet; audits draw on Google’s public Maps and Business Profile listings; Business Profile work happens in your Google account | Font requests (your IP and browser type); form submissions (sent by your browser straight to Google, IP included); audit queries; work done in your own account | |
| Vercel | Hosts the Site | Standard server logs |
| Payment processor (Stripe) | Processing card payments, if you pay by card | Transaction details, never stored by us |
| Email provider (Google Mail, Microsoft 365 email, AWS SES) | Sending and receiving email | Whatever’s in the emails, as all email providers hold |
| Review-request tool (PageSpeed) | Sending review requests to your customers by email (no texts) | The customer names and email addresses you give us for that purpose |
| Domain registrar / DNS (NameCheap, GoDaddy, or AWS) | Registering and pointing your domain | Your domain records |
| Contractors | If we ever bring in help (a designer, a writer) | Only what that person needs for their piece of the work, under the same confidentiality obligations |
We never sell or rent any of it, and we don’t hand it to anyone who isn’t doing a specific job for us. We also disclose if the law requires it — subpoena, court order, or an actual legal obligation, not just because someone asks.
6. Where data lives and how we protect it
- Data lives in the platforms above — Google’s servers, Vercel’s servers, our email provider — mostly in the United States.
- We take reasonable and appropriate safeguards: unique strong passwords, two-factor authentication, access limited to the two people who run this company, and reputable platforms.
- Breach notification: if a security breach affects your information, we’ll notify you as the law requires. That includes New York residents under the SHIELD Act, and — where a breach creates a real risk of significant harm — reporting to the Office of the Privacy Commissioner of Canada and notifying affected individuals, as PIPEDA requires.
- Straight answer: no method of transmission or storage is 100% secure — for anyone, at any size. The safeguards above are proportionate to the data we hold, which per Section 2.4 is deliberately limited.
7. How long we keep it
- Audit requests: as long as useful for following up, then deleted. Ask anytime and we’ll delete yours promptly.
- Prospect/business-contact information: while outreach is relevant, or until you tell us to stop — whichever comes first. After a stop request, we keep only your contact info (email, and phone if we had it) on the do-not-contact list, permanently — it’s what keeps the stop stopped.
- Client data: for the duration of the engagement, then as long as the law requires for records (tax and contract law set the floor, usually a few years), then deleted or returned to you.
- Hosting logs: handled per our host’s retention, which is their policy, not ours — we don’t keep our own copies.
8. Your rights and choices
Whatever privacy law applies to you — these are your PIPEDA rights if you’re in Canada, and we extend them to everyone anyway, because it’s simpler and fairer — you can ask us to:
- Access: tell you what personal information we hold about you.
- Correct: fix information that’s wrong or outdated.
- Delete: remove it, where the law lets us (we may need to keep records the law requires, like invoices). The one exception: do-not-contact entries (your email, and phone if you gave us one) stay, because keeping them is what honors your opt-out.
- Opt out: of outreach — emails, calls, and texts — at any time, permanently. “Remove me” in an email reply, “don’t call again” on a call, or STOP to a text is enough.
- Opt out of marketing use: per our Terms §10.4, you can opt out of us naming you as a client or showing your case study — free.
To exercise any of these: email hello@page1local.com. We’ll respond within 30 days, usually much faster. There’s no charge for asking, and it doesn’t change how we treat you.
One thing we can’t do: remove your business’s public information from Google Maps or the internet. That data belongs to Google and the public web; we can’t delete it, and neither can you, except through those platforms’ own tools.
9. Children
The Site and our services are for business owners and aren’t directed at minors. We don’t knowingly collect information from children under 13, and if we learn we have, we delete it.
10. Changes to this policy
We’ll update this policy as the business changes — new tools, new services, or (eventually) analytics. Material changes get notice: by email to active clients, and by updating this page with a new “Last updated” date for everyone else. The trigger rule stands: real policy text before any tracking, every time. Continued use of the Site after a change means you accept it.
11. Questions and complaints
- Email: hello@page1local.com
- Phone: 716.936.8123
- Mailing address: 4498 Main St Suite 4 # 1247 Buffalo, NY 14226 United States
If you have a complaint about how we handle your data, tell us first — we’ll take it seriously and fix what we can. You also have the right to complain to a regulator, and we won’t hold that against you.
As a Canadian business, our privacy regulator is the Office of the Privacy Commissioner of Canada (OPC). If you’re in Canada and not satisfied with our answer, you can file a complaint with the OPC (priv.gc.ca). If you’re in the US, your state’s attorney general — New York’s enforces the SHIELD Act — and the FTC are the routes open to you.