All Trades Digital

All Trades Digital

Privacy policy

What we collect, who receives it, how long we keep it — and that we hold records about businesses that never contacted us.

In effect 13 September 2026

Who this is

All Trades Digital is a one-person digital agency in Austin, Texas. We sell local search visibility, websites and quoting tools to service and trade businesses, and we run a free audit on this site that anyone can use.

This policy covers this website and that audit. It is written to be read rather than to be survived, and if something in it is unclear the address at the bottom is a person.

What we collect when you use this site

Four things, and the first three happen whether or not you ever type an address:

  • A sessionA cookie that keeps this browser recognisable from one page to the next, so a scan can find its own results. With it we record the pages opened, the scans run, the page you arrived on, the site that sent you and any campaign tags in the link.
  • A connection, reducedYour IP address is hashed with a secret we hold on the server the moment it arrives and the original is never written down. The hash is what enforces the rate limits that stop a script spending our scanning budget. We also record the browser string and the country and region our host reports.
  • What you typed into the auditA website address, or a business name and a town, and — where we had to ask which business you meant — which one you picked.
  • An email address, if you give oneThe full report is unlocked by an email address, and we send a copy of the report to it. That address becomes a record of a person, separate from the record of a business, and we keep it.

We do not ask for a name, a phone number, or anything about you personally to run an audit. There is no account to create and no password to set.

We scan businesses that never asked us to

The audit runs against whatever is typed into the box on the homepage, and often that is not the person’s own business. A competitor can audit a rival. We can audit a business to decide whether it is worth approaching. So we hold records about businesses that never contacted us, and rather than leave that to be discovered, here it is.

What we read is public. The Google Business Profile Google already publishes — name, category, rating, review count, hours, photo count — the map-pack position for a handful of search terms, what a phone would see loading the website, and Google’s own PageSpeed score for it. Nothing behind a login, nothing confidential, nothing that twenty minutes and a browser would not find.

What we store is that public data, the findings our own checks produced from it, and our internal score for how well the business fits what we sell. Raw copies are kept for twelve months; the summarised columns outlive them.

What we do not store, deliberately: reviewer names, reviewer profiles, or a word of review text. A review is kept as a date, a rating, and whether the owner replied.

What we do with it: decide who to approach, and build the audit for whoever ran it. We do not sell it and we do not share it.

If it is your business and you would rather we did not hold it, write to privacy@alltradesdigital.com and we will remove it.

We respect a site’s robots.txt and we stop reading after three seconds. A site that refuses us is recorded as having refused us, which is itself a finding, and we do not go round it.

Who else receives any of this

Running an audit means asking other companies questions, and those questions carry what you typed. Every one of them is a supplier working on our instructions, not a partner we trade data with:

  • GoogleThe Places API identifies the business and returns its public profile; the PageSpeed Insights API scores the website. Both receive the business being audited, never your email address.
  • DataForSEOMeasures where a business ranks in the map pack and reads the public reviews on its profile. Receives the business, never your email address.
  • AnthropicWrites the sentence around a finding and classifies what a website says. Receives the public text of the business being audited — never your email address, and nothing about you.
  • CloudflareThe bot check in front of the audit. It is the privacy-preserving one of the available choices by design, and it runs for everybody.
  • ResendSends the report email, and tells us whether it arrived. Receives your email address and the report link. Nothing in that email tracks whether you opened it.
  • Vercel, Supabase, Upstash and InngestRespectively the host, the database, the cache and the queue that runs the slow steps of a scan. They hold what this site holds because they are where it lives.

None of them is paid in data and none of them is an advertiser. We do not sell personal information, we do not share it for cross-context behavioural advertising, and there is no advertising pixel on this site.

The two things that are optional, and off until you say otherwise

Everything above happens because the audit cannot run otherwise. Two things are not like that, and neither loads until you accept them:

  • Product analyticsA third-party analytics service, run by somebody other than us. When it is on it is configured to keep nothing in your browser and no identifier that follows you to another site.
  • A booking calendarA third-party embed, which loads when you open it rather than when a page loads.

Our own record of what happens here is not one of them. It sits in our database, it is never sold and never shared, and there is no switch for it on this site. Calling it strictly necessary would not be true, so we are telling you about it instead.

Session recording is off across this entire site, and there is no setting anywhere that turns it on. Nothing records your mouse, your keystrokes or your screen.

We also do not fingerprint devices. A session cookie, a hashed IP and what you actually did are enough.

Cookies, and the choice you get about them

This site sets two cookies. The session cookie described above, and a second one holding the answer you give the banner so you are not asked on every page. Neither can be switched off, and neither is used to advertise to you. The banner lists both, alongside the bot check, with the reason each exists.

Your answer is remembered for 180 days, and a decline is remembered exactly as long as an accept. You can change it whenever you like from Privacy choices in the footer of every page.

We honour Global Privacy Control. If your browser sends that signal we treat it as a standing opt-out, nothing optional loads, the banner does not appear, and we will not ask you to turn it off. A stored acceptance is ignored while the signal is set.

When this policy changes, the recorded answer is treated as no answer and you are asked again — rather than inheriting your consent to a document that no longer exists. The date at the top of this page is the version your answer is recorded against.

Email, and what we will and will not send

Unlocking a report sends you that report, once. It carries the report and the link to it and nothing that sells. That is deliberate: the day such a message gains an offer it becomes marketing, and marketing is a different thing with different rules.

We do not add you to a list for running an audit. If we ever do send marketing email it will be because you asked for it, it will say who it is from, and getting off it will be one click.

A permanently bounced address stops us mailing it. A spam complaint stops us mailing it permanently.

How long we keep things

  • Raw scan dataTwelve months, after which the full copy is dropped and only the summarised columns survive.
  • Your consent answer180 days in the cookie. The record that you answered is kept, because a record of consent that expires cannot evidence the consent.
  • Email addresses and the reports behind themUntil you ask us to delete them. A report link stops working after 30 days either way.
  • Rate-limit countersHours or days. They exist to count the last hour and the last day, and they expire on their own. The hashed IP stored against a session lives as long as the session record does.

Your options, stated plainly

We are a very small business and the state privacy statutes that grant formal access and deletion rights apply to companies far larger than this one. We are not going to pretend otherwise by publishing a rights section that quotes a law we are not subject to.

What you get instead is simpler and is not conditional: write to privacy@alltradesdigital.com and ask us what we hold about you or your business, or ask us to delete it, and we will do it. There is no form and no verification hoop.

We re-check whether those statutes have started to apply to us every year. If they do, this section changes and you will be asked to read the policy again.

Children

This site sells business services to business owners. It is not directed at children and we do not knowingly collect anything from one.

Where the rest of it is

The notice at collection is the one-screen version of this page, and it is the one worth reading if you are about to type something in. The AI disclosure covers which parts of a report a model wrote. The acceptable use policy covers what the audit may be used for.

Questions, corrections and deletion requests all go to the same place: privacy@alltradesdigital.com.