What we collect
When you fill out a form or send us an email, we collect what you give us — typically your name, email address, phone (if you share it), business name, and whatever you tell us about your project. That’s the whole point; no surprises.
When you start or submit the project form, we also record a small set of technical details to help us route the lead, understand where forms stall, and defend against bots: approximate location (country/region/city from your IP, we don’t store the raw IP — we hash it with a server-side secret), device type, browser, operating system, viewport size, timezone, locale, the page you were on, the referrer host that sent you, any UTM tags or ad click IDs in the URL, the sanitized attribution query, form step timing, field names touched, and value lengths. We don’t store typed form answers unless you submit the form to us.
When you visit the site, we may use cookieless Umami measurement to understand page views, section views, button clicks, form steps and non-sensitive form choices, Web Vitals, browser type, device type, referrers, and approximate country. We may also record diagnostic markers such as whether the page was visible, whether the visitor became inactive, route transition timing, media playback or stalls, font readiness, and long browser tasks. These markers help us tell a real pause from a broken experience. Umami page URLs are sanitized before sending: we keep the page path and analytics-safe campaign parameters such as UTM tags and ad click IDs, but drop arbitrary query parameters and hash fragments. Umami does not use tracking cookies in its tracking code, does not store IP addresses, respects browser Do Not Track signals, and does not identify visitors across websites. Its script starts only after a trusted interaction or a short period of visible page time, which helps exclude automated scans. If you choose optional site-improvement, experience, or marketing settings, we also use Google Analytics, Microsoft Clarity, Meta Pixel, and Meta Conversions API to understand form-step drop-off, Web Vitals, masked session replay, and whether our ads are working. Clarity masks input and dropdown contents; we keep personal text masked even when it appears elsewhere on the page. If you enable Visit context, Meta Pixel and Meta Conversions API record eligible page visits and selected site actions. Meta may use those events to create Website Custom Audiences so we can show you relevant Meridii ads after your visit. For Meta ad measurement and audience matching, consented events may include the page path, campaign context, Meta browser or click IDs, request IP, and browser user agent. Successful lead events may also include hashed contact identifiers. Clarity may receive a client-side hashed contact identifier for a successful inquiry so we can find that consented journey. We don’t send business names, notes, website details, or free-text answers to those analytics tools. Non-sensitive categories such as project type, selected goals, timeline, and budget band may be measured so we can analyze form journeys; Meta may receive those categories and a goal count for consented ad measurement.