Meridii loading
  • Work
  • Tech
  • About
  • Contact
Hello
  • Work
  • Tech
  • About
  • Contact
Hello
Skip to content
MERIDII
Meridii
Let’s talk →hello@meridii.com
Your vision has our attentionBooking Q3 2026
Navigate
WorkTechAboutContactFAQ
Legal
PrivacyTermsAccessibility
Studio
CareersToronto, OntarioCanada

Experiences that turn strangers into regulars

© 2025–2026 Meridii · All rights reserved
Meridii™ · BN 790 776 975
Meridii / Legal

Privacy

The short version: with respect.

We don’t do creepy. Here’s what we collect, why, and how to make us forget you exist — in plain English, because we think legalese is a design problem.

01

What we collect

When you fill out a form or send us an email, we collect what you give us — typically your name, email address, phone (if you share it), business name, and whatever you tell us about your project. That’s the whole point; no surprises.

When you start or submit the project form, we also record a small set of technical details to help us route the lead, understand where forms stall, and defend against bots: approximate location (country/region/city from your IP, we don’t store the raw IP — we hash it with a server-side secret), device type, browser, operating system, viewport size, timezone, locale, the page you were on, the referrer host that sent you, any UTM tags or ad click IDs in the URL, the sanitized attribution query, form step timing, field names touched, and value lengths. We don’t store typed form answers unless you submit the form to us.

When you visit the site, we use cookieless Umami and Vercel Web Analytics measurement to understand page views, section views, button clicks, form steps and non-sensitive form choices, Web Vitals, browser type, device type, referrers, and approximate country. Vercel receives anonymous aggregate page views and a small set of funnel events. When a homepage experiment is active, those events may include only the experiment and variant labels; we do not attach form answers or personal details. Its built-in filtering removes traffic it identifies as automated, and Vercel says the temporary visitor hash used to group a session is discarded within 24 hours. We may also record diagnostic markers such as whether the page was visible, whether the visitor became inactive, route transition timing, media playback or stalls, font readiness, and long browser tasks. These markers help us tell a real pause from a broken experience. Umami and Vercel Analytics page URLs are sanitized before sending: we keep the page path and analytics-safe campaign parameters such as UTM tags and ad click IDs, but drop arbitrary query parameters and hash fragments. Umami does not use tracking cookies in its tracking code, does not store IP addresses, respects browser Do Not Track signals, and does not identify visitors across websites. Its script starts only after a trusted interaction or a short period of visible page time, which helps exclude automated scans. If you choose optional site-improvement, experience, or marketing settings, the same non-identifying experiment labels may also appear in Google Analytics or Microsoft Clarity under the setting you enabled. For homepage visual tests, we create a random first-party browser identifier that expires after 180 days, hash it with a server-side secret, and record the assigned version, repeat exposures, visible time, technical fallbacks, form reach, and whether an inquiry was submitted within the attribution window. The experiment record contains no raw IP, contact details, or form answers.

02

How we use it

03

Third parties

04

Cookies

05

Retention & deletion

06

Your rights

07

Email

08

Changes to this policy

09

Contact

If you choose optional site-improvement, experience, or marketing settings, we also use Google Analytics, Microsoft Clarity, Meta Pixel, and Meta Conversions API to understand form-step drop-off, Web Vitals, masked session replay, and whether our ads are working. Clarity masks input and dropdown contents; we keep personal text masked even when it appears elsewhere on the page. If you enable Visit context, Meta Pixel and Meta Conversions API record eligible page visits and selected site actions. Meta may use those events to create Website Custom Audiences so we can show you relevant Meridii ads after your visit. For Meta ad measurement and audience matching, consented events may include the page path, campaign context, Meta browser or click IDs, request IP, and browser user agent. Successful lead events may also include hashed contact identifiers. Clarity may receive a client-side hashed contact identifier for a successful inquiry so we can find that consented journey. We don’t send business names, notes, website details, or free-text answers to those analytics tools. Non-sensitive categories such as project type, selected goals, timeline, and budget band may be measured so we can analyze form journeys; Meta may receive those categories and a goal count for consented ad measurement.

We use your information to reply to your inquiry, manage our client relationships, and occasionally make the site better. We don’t sell your data. We don’t share it with anyone who isn’t helping us do the work.

A few trusted providers run behind the scenes: hosting, email delivery via Loops.so, cookieless measurement from Umami and Vercel Web Analytics, and optional analytics, performance, and ad measurement from Google Analytics, Microsoft Clarity, Meta Pixel, and Meta Conversions API. Basic Umami and Vercel Web Analytics measurement may run without cookies or optional consent; Google Analytics, Microsoft Clarity, Meta Pixel, and Meta Conversions API run only when you enable their matching optional setting. Email legal@meridii.com any time to ask us to delete everything we have.

Essential storage keeps the site running. Basic measurement is cookieless, except for the anonymous first-party assignment cookie used to keep a visual experiment consistent on repeat visits. That cookie expires after 180 days and is not shared across websites. Optional settings may use a few helpful cookies and quiet signals to show us what people use, where the experience gets rough, which notes bring the right visitors here, and, when you allow it, show you relevant Meridii ads after your visit. You can always adjust the helpful cookie settings .

We keep project inquiries for as long as we might reasonably need them (typically two years after the last contact). Client project records are retained longer for accounting and legal reasons. Email legal@meridii.com any time to request deletion or a copy of what we have on file.

You have the right to ask what personal information we hold about you, to correct it, to request its deletion, and to withdraw consent at any time. Email legal@meridii.com and we’ll respond within 30 days.

If you write to us, we write back — that’s the whole point. If you ticked the opt-in box on the form, we’ll also send the occasional good thing: never filler, never sales, one-click unsubscribe at the bottom of every email.

Our legal name and mailing address sit in the footer of every email we send, because CASL asks us to put them somewhere. We also keep a record of what the checkbox said the day you ticked it, so if you ever ask, we can answer honestly.

When we update this policy, we’ll update the last-updated date at the bottom. Substantive changes will be flagged on the home page for a week.

Questions about privacy? Email legal@meridii.com. We’re the designated privacy contact for Meridii, and we handle access, correction, and deletion requests within 30 days.

This policy is governed by Canadian privacy law, including the Personal Information Protection and Electronic Documents Act (PIPEDA) at the federal level and Quebec’s Law 25 where applicable.

Last updated: August 2, 2026