Ignite XDS
Privacy Policy
How we collect, use, and protect personal data — and the choices you have over analytics, advertising, and the sale or sharing of your information.
Ignite XDS, Inc. (dba Get2Friday, dba Get2Business) — "Ignite XDS," "we," "us," "our"
Effective date: 2 September 2026 Last updated: 2 September 2026 Supersedes: Privacy Policy dated May 11, 2022
1. What this policy covers
This Privacy Policy explains what personal information Ignite XDS collects when you visit https://ignitexds.com and our related subdomains, campaign sites, and client-facing tools (together, the "Website"), how we use it, who we share it with, how long we keep it, and the choices and rights you have.
"Personal information" (also called "personal data") means information that identifies, relates to, describes, or could reasonably be linked with you — either directly or in combination with other information. Where this policy uses defined terms not explained here, they carry the meaning given in our End User License Agreement (the "User Agreement").
This policy applies to visitors, prospects, clients, and users of our platform and services worldwide. If you are in the European Economic Area ("EEA"), the United Kingdom, or Switzerland, Section 6 explains the legal bases we rely on. If you are a resident of California or another U.S. state with a comprehensive privacy law, Section 11 explains your specific rights.
2. Your privacy choices, in short
- We do not run non-essential tracking on you until we are allowed to. In the EEA, the UK, and Switzerland — and anywhere we cannot determine your location — nothing beyond strictly necessary technology loads until you accept it.
- Everywhere else, you can turn it off. Analytics and advertising technologies load by default, and you can withdraw them at any time.
- The control is always one click away. A "Your Privacy Choices" link appears in the footer of every page. It opens the same preference panel you saw on your first visit and lets you change or withdraw any category at any time. For California residents, that link is also our opt-out mechanism for the sale or sharing of personal information.
- We honor Global Privacy Control. If your browser or extension transmits a GPC signal, we treat it as a valid opt-out of advertising and cross-context behavioral advertising automatically. You do not need to do anything else, and the setting cannot be overridden by us or by the on-page interface.
- Your choice expires. Stored preferences last 12 months, after which we ask again.
3. Information we collect
3.1 Information you give us
| Category | Examples | When |
|---|---|---|
| Identifiers and contact data | Name, business email, phone number, company name, job title, city, state, country, postal code | Forms, Outside-In Analysis requests, Fit Call bookings, newsletter and resource downloads |
| Professional and firmographic data | Industry, employee count, revenue range, role, stated business challenges | Discovery and assessment forms, diagnostic tools |
| Account credentials | Username, confirmed email address, password | Platform registration, where applicable |
| Content you submit | Message contents, uploaded documents, diagnostic answers, support tickets | Contact and inquiry forms, support requests |
| Billing information | Payment card and billing details, processed by PCI-compliant payment providers | Paid engagements |
| Preferences | Communication preferences, consent choices, optional demographic details | Preference center, consent manager |
3.2 Information collected automatically
| Category | Examples |
|---|---|
| Device and connection data | IP address, browser type and version, operating system, device type, screen size, language |
| Usage data | Pages viewed, referring URL, time on page, scroll depth, links and buttons clicked, form interactions, search terms used in on-site tools |
| Approximate location | Country-level location derived from the network-edge geolocation header supplied by our hosting provider (Vercel). We use this solely to decide which consent regime to apply. We do not use it for advertising and we do not store precise GPS location from the Website. |
| Interaction recordings | Where analytics consent is in effect, aggregated session replays and heatmaps of pointer movement, clicks, and scrolling (see Hotjar in Section 4.2) |
| Server logs | Requests to our servers, response codes, security and abuse signals |
Our server logs, security controls, load balancing, and record of your consent choice operate on all visits, including before any consent decision, because the Website cannot be delivered securely without them.
3.3 Information from third parties
Where you have given the relevant consent, or where permitted by applicable law, we may receive information about you from advertising and analytics platforms, data enrichment and firmographic providers, business-contact databases, publicly available sources, and our own clients and partners. We may combine that information with information we collect directly in order to understand our audience, qualify inbound interest, and tailor our communications and advertising. In the EEA, the UK, and Switzerland we only combine such data for marketing purposes where you have consented.
We do not intentionally collect personal information from anyone under 16, and our Website is not directed to children (see Section 14).
4. Cookies, tags, and similar technologies
4.1 The three categories we use
Our consent manager groups every technology on the Website into one of three categories.
| Category | What it does | Behavior |
|---|---|---|
| **Strictly necessary** | Delivers and secures the Website: security and abuse prevention, load balancing, routing, and storing your consent choice itself | Always active. Cannot be switched off, because the Website will not function without it. Not used for analytics or advertising. |
| **Analytics** | Measures how the Website is used so we can improve content, navigation, and performance | Loads only in line with your consent choice |
| **Advertising** | Measures campaign performance and enables advertising and remarketing, including cross-context behavioral advertising | Loads only in line with your consent choice |
Google Tag Manager is deliberately classified under Advertising, not as a necessary or analytics technology. A tag container can be configured to deploy any tag, so we apply our strictest category to it.
4.2 The specific technologies we run
The following is the complete list of non-essential third-party technologies deployed on the Website as of the effective date of this policy. Durations shown are the vendor defaults and may be shortened by your browser.
| Technology | Provider | Category | Purpose | Typical cookie / storage lifetime |
|---|---|---|---|---|
| Google Analytics 4 | Google LLC / Google Ireland Ltd. | Analytics | Aggregate traffic, audience, and content-performance measurement | _ga, _ga_<container>: up to 2 years by default, in practice capped near 13 months by browser limits Google Analytics Help |
| Hotjar | Hotjar Ltd. (Contentsquare group) | Analytics | Heatmaps, aggregated session replay, and on-site feedback to diagnose usability problems | _hjSessionUser_*: 365 days; _hjSession_*: 30 minutes UK Research and Innovation cookie register |
| Metricool | Metricool Software, S.L. | Analytics | Attribution of visits from our social and content channels, and content-performance reporting Metricool cookies policy | Session to 2 years, depending on the tracker set |
| Google Tag Manager | Google LLC / Google Ireland Ltd. | Advertising | Container used to deploy and manage the tags listed here | No cookie of its own; governed by the tags it deploys |
| Google Ads | Google LLC / Google Ireland Ltd. | Advertising | Conversion measurement and remarketing | _gcl_aw, _gcl_dc, _gcl_au: approximately 90 days Google Ads cookie reference |
| Meta Pixel | Meta Platforms, Inc. / Meta Platforms Ireland Ltd. | Advertising | Conversion measurement and audience building for Facebook and Instagram advertising | _fbp, _fbc: approximately 90 days, refreshed on activity independent cookie analysis |
| LinkedIn Insight Tag | LinkedIn Corporation / LinkedIn Ireland Unlimited Company | Advertising | Conversion measurement, audience matching, and remarketing for LinkedIn advertising | bcookie: 1 year; li_sugr: up to 90 days; UserMatchHistory, AnalyticsSyncHistory: 30 days LinkedIn cookie table |
Each provider processes the data it receives under its own privacy terms. We do not upload the contents of your platform account or files you provide to us into any of these advertising or analytics platforms.
4.3 How consent is applied by region
Because the applicable rules differ by jurisdiction, our consent manager determines your region server-side from the geolocation header provided by our hosting infrastructure before any non-essential technology is requested.
| Where you are | Default state | How it works |
|---|---|---|
| EEA, United Kingdom, Switzerland | Analytics **off**, Advertising **off** | Consent-first. No analytics or advertising technology is requested until you affirmatively accept it. "Accept" and "Reject" are presented with equal prominence, size, and visual weight, and refusing is no harder than accepting. |
| United States and all other locations | Analytics **on**, Advertising **on** | Opt-out. Measurement runs on arrival and you may withdraw either category at any time via "Your Privacy Choices." |
| Location cannot be determined | Analytics **off**, Advertising **off** | Treated as if you were in the EEA — we default to asking. |
4.4 Google Consent Mode v2
We implement Google Consent Mode v2 and set consent signals before any Google tag loads. Under the consent-first regime, ad_storage, ad_user_data, and ad_personalization are set to denied by default; analytics_storage is set to granted only when you accept the Analytics category. Signals are updated in real time when you change your choice, without requiring a page reload.
4.5 Global Privacy Control
We recognize and honor the Global Privacy Control ("GPC") signal. When your browser transmits GPC, we automatically record an opt-out of the Advertising category, including the sale or sharing of personal information for cross-context behavioral advertising, and we tell you that we have done so rather than asking you again. This enforcement is applied when your preference is written, not merely in the interface, so it cannot be reversed by interacting with the on-page controls.
4.6 Spam protection on our forms
Forms on the Website are protected by Cloudflare Turnstile, which checks that a submission is being made by a person rather than an automated script. Turnstile sets no cookies and does not profile you across sites, so it operates as strictly necessary security technology and does not require your consent. The check runs only at the moment you submit a form. Cloudflare processes the request under its own privacy terms.
4.7 Changing or withdrawing your choice
Select "Your Privacy Choices" in the footer of any page to reopen the preference panel and change any category, including withdrawing consent you previously gave. Withdrawal takes effect immediately for future processing. It does not undo processing that already lawfully occurred. Stored preferences expire after 12 months, at which point we ask again. You can also block or delete cookies through your browser settings, though doing so may affect how parts of the Website function.
5. How we use personal information
- Operate, secure, maintain, and improve the Website and our platform and services
- Respond to inquiries, deliver requested assessments and reports, and provide support
- Schedule and conduct Fit Calls, discovery, and client engagements
- Administer accounts, contracts, invoicing, and payments
- Measure and improve content, navigation, usability, and site performance
- Measure marketing performance and, subject to your choices, deliver and personalize advertising and remarketing
- Send service and account communications, and — subject to your choices and applicable law — marketing communications you can unsubscribe from at any time
- Build aggregated and de-identified insights about our audience and markets
- Detect, investigate, and prevent fraud, abuse, and security incidents
- Comply with legal obligations and enforce our agreements
We do not use your personal information to make decisions about you by solely automated means that produce legal or similarly significant effects.
6. Legal bases (EEA, UK, and Switzerland)
| Purpose | Legal basis |
|---|---|
| Delivering and securing the Website; strictly necessary storage; spam protection on forms | Legitimate interests (Art. 6(1)(f)) and, for the storage itself, the strictly-necessary exemption under the ePrivacy Directive as implemented locally |
| Responding to your inquiry; performing an engagement | Contract or steps prior to contract (Art. 6(1)(b)) |
| Analytics, advertising, remarketing, and any non-essential cookies or similar technologies | Your consent (Art. 6(1)(a)), obtained before the technology loads |
| Marketing email to business contacts, where permitted | Consent, or legitimate interests where local law allows a soft opt-in |
| Legal, tax, and accounting records; responding to lawful requests | Legal obligation (Art. 6(1)(c)) |
| Fraud prevention, security, and defending legal claims | Legitimate interests (Art. 6(1)(f)) |
Where we rely on consent, you may withdraw it at any time as described in Section 4.7. Where we rely on legitimate interests, you may object as described in Section 11.
7. How we share personal information
We do not sell your email address or other contact information for money, and we do not distribute, sell, or barter data you upload into our platform or services.
We disclose personal information to:
- Service providers and processors acting on our instructions — hosting and content delivery (Vercel), content management (Sanity), spam protection (Cloudflare), CRM and marketing automation (HubSpot), scheduling (Calendly), email delivery, video conferencing (Zoom), accounting and payments, and support tooling. They are bound by contract to use the information only to provide services to us. Where required, we use data processing agreements including the applicable EU/UK Standard Contractual Clauses.
- Analytics providers listed in Section 4.2, where the Analytics category applies.
- Advertising platforms listed in Section 4.2, where the Advertising category applies. Under California and several other U.S. state laws, enabling these technologies constitutes "sharing" personal information for cross-context behavioral advertising, and in some interpretations a "sale." You can stop it at any time via "Your Privacy Choices" or by sending a GPC signal.
- Professional advisors — legal, accounting, and insurance advisors, under duties of confidentiality.
- Authorities, where disclosure is necessary to comply with an enforceable legal request such as a subpoena or warrant, or to protect rights, safety, or property.
- A successor entity, in connection with a merger, acquisition, financing, reorganization, or sale of assets. We will use commercially reasonable efforts to notify you by posting at https://ignitexds.com or by email.
We do not knowingly sell or share the personal information of consumers under 16.
8. How long we keep information
| Data | Retention |
|---|---|
| Consent preference record | 12 months, then re-requested |
| Server and security logs | Retained by our hosting provider for a short operational period and used only for security, abuse prevention, and diagnostics |
| Google Analytics 4 event and user data | 14 months |
| Hotjar recordings and heatmaps | 365 days |
| Advertising platform identifiers | Per the vendor lifetimes in Section 4.2, generally 30 days to 1 year |
| CRM records for prospects and clients | Kept while the relationship is active and until you ask us to delete them |
| Contracts, invoices, and tax records | As required by law, generally 7 years |
| Support tickets and correspondence | Kept while the relationship is active and until you ask us to delete them |
When information is no longer needed we delete it or de-identify and aggregate it so it can no longer be linked to you.
9. International transfers
We are based in the United States, and personal information may be processed in the United States and in other countries where we or our service providers operate. Laws in those countries may differ from those where you live. Where we transfer personal information out of the EEA, the UK, or Switzerland, we rely on an appropriate transfer mechanism — the European Commission's Standard Contractual Clauses (with the UK Addendum where applicable), an adequacy decision, or a provider's certification under the EU-U.S. Data Privacy Framework and its UK and Swiss extensions — together with supplementary measures where required. You may request further detail using the contact information in Section 17.
10. Security
We maintain administrative, physical, and technical safeguards appropriate to the sensitivity of the information we hold, including encryption in transit, access controls, least-privilege permissions, and vendor due diligence. Payment card data is stored and processed only by PCI-compliant providers. We do not modify your personal information other than as instructed, disclose it except as compelled by law or permitted by this policy, or access platform data except to provide maintenance, verification, troubleshooting, or support you have requested.
No system is perfectly secure, and we cannot guarantee that our measures will defeat every unauthorized attempt to obtain information. You are responsible for choosing strong passwords and keeping them confidential; where you authenticate through a third-party identity provider, those credentials must also be kept secure. If an incident occurs, we will notify affected individuals and regulators where required by law.
11. Your rights and choices
11.1 If you are in the EEA, the UK, or Switzerland
You have the right to request access to your personal information; correction of inaccurate information; erasure; restriction of processing; portability; and to object to processing based on legitimate interests, including for direct marketing. Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of earlier processing. You also have the right to lodge a complaint with your supervisory authority — for UK residents, the Information Commissioner's Office — although we would appreciate the chance to address your concern first.
11.2 If you are a California resident
Under the California Consumer Privacy Act as amended by the CPRA, you have the right to know what personal information we collect, use, disclose, and share; to access and receive a portable copy; to correct inaccurate personal information; to delete personal information; to opt out of the sale or sharing of personal information for cross-context behavioral advertising; to limit the use and disclosure of sensitive personal information; and not to be discriminated or retaliated against for exercising these rights.
- To opt out of sale or sharing: use the "Your Privacy Choices" link in the footer of any page, or transmit a Global Privacy Control signal, which we honor automatically.
- Sensitive personal information: we do not use or disclose sensitive personal information for purposes beyond those permitted under CCPA regulations, so no separate limitation right is triggered. We do not collect Social Security numbers, precise geolocation, biometric data, or health information through the Website.
- Categories collected, sources, purposes, and disclosures: see Sections 3, 5, and 7. The statutory categories we collect are identifiers, commercial information, internet or other electronic network activity information, professional or employment-related information, approximate geolocation at country level, and inferences drawn from the foregoing.
- Financial incentives: we offer none.
11.3 If you are in another U.S. state with a comprehensive privacy law
Residents of states including Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, and others with comparable laws have rights to access, correct, delete, and obtain a portable copy of their personal data, and to opt out of targeted advertising, sale, and certain profiling. Use "Your Privacy Choices" or contact us as described below. Where your state provides a right to appeal a denied request, we will explain the appeal process in our response.
11.4 How to exercise your rights
Email info@ignitexds.com with the request you are making and enough information for us to locate your records. We will verify your identity in a manner proportionate to the sensitivity of the request and will respond within the time required by applicable law — generally 45 days under U.S. state laws (extendable once) and one month under the GDPR and UK GDPR (extendable by two further months for complex requests). An authorized agent may submit a request on your behalf with proof of authorization. We will not charge a fee for a first reasonable request, and we will not treat you differently for making one.
12. Do Not Track and Global Privacy Control
There is no consistent industry standard for the browser "Do Not Track" header, and we do not respond to it. We do recognize and honor Global Privacy Control as described in Section 4.5.
13. Third-party links and embedded content
The Website links to and embeds content from third-party sites and services that we do not control, including scheduling, video, and social platforms. Their own privacy policies govern the information they collect. We provide these links and embeds for convenience and information, and we are not responsible for those services. Sites you visited before arriving here may place information in the URL used to reach us, which our server logs may capture; we do not control those sites.
14. Children
The Website and our services are intended for business use by adults. We do not knowingly collect personal information from children under 16 (or under 13 for purposes of COPPA). If you believe a child has provided us with personal information, contact us and we will delete it.
15. Marketing communications
You may unsubscribe from marketing email using the link in any message or by contacting us. We will still send transactional and service messages related to your account, an active engagement, or a request you made.
16. Changes to this policy
We may revise this policy from time to time. When we do, we will update the "Last updated" date above and post the revised policy at https://ignitexds.com. If the changes are material, we will provide more prominent notice — for example, a Website notice or an email — and, where consent is required, we will obtain fresh consent before relying on the change. Your continued use of the Website after a revision takes effect indicates acceptance of the updated policy.
17. Contact us
Ignite XDS, Inc. 519 W. Main St., Brighton, MI 48116, United States
Privacy inquiries and requests: info@ignitexds.com General complaints and disputes: issues@ignitexds.com
