Ignite XDS

Ignite XDS

Privacy Policy

How we collect, use, and protect personal data — and the choices you have over analytics, advertising, and the sale or sharing of your information.

Ignite XDS, Inc. (dba Get2Friday, dba Get2Business) — "Ignite XDS," "we," "us," "our"

Effective date: 2 September 2026 Last updated: 2 September 2026 Supersedes: Privacy Policy dated May 11, 2022

1. What this policy covers

This Privacy Policy explains what personal information Ignite XDS collects when you visit https://ignitexds.com and our related subdomains, campaign sites, and client-facing tools (together, the "Website"), how we use it, who we share it with, how long we keep it, and the choices and rights you have.

"Personal information" (also called "personal data") means information that identifies, relates to, describes, or could reasonably be linked with you — either directly or in combination with other information. Where this policy uses defined terms not explained here, they carry the meaning given in our End User License Agreement (the "User Agreement").

This policy applies to visitors, prospects, clients, and users of our platform and services worldwide. If you are in the European Economic Area ("EEA"), the United Kingdom, or Switzerland, Section 6 explains the legal bases we rely on. If you are a resident of California or another U.S. state with a comprehensive privacy law, Section 11 explains your specific rights.

2. Your privacy choices, in short

  • We do not run non-essential tracking on you until we are allowed to. In the EEA, the UK, and Switzerland — and anywhere we cannot determine your location — nothing beyond strictly necessary technology loads until you accept it.
  • Everywhere else, you can turn it off. Analytics and advertising technologies load by default, and you can withdraw them at any time.
  • The control is always one click away. A "Your Privacy Choices" link appears in the footer of every page. It opens the same preference panel you saw on your first visit and lets you change or withdraw any category at any time. For California residents, that link is also our opt-out mechanism for the sale or sharing of personal information.
  • We honor Global Privacy Control. If your browser or extension transmits a GPC signal, we treat it as a valid opt-out of advertising and cross-context behavioral advertising automatically. You do not need to do anything else, and the setting cannot be overridden by us or by the on-page interface.
  • Your choice expires. Stored preferences last 12 months, after which we ask again.

3. Information we collect

3.1 Information you give us

CategoryExamplesWhen
Identifiers and contact dataName, business email, phone number, company name, job title, city, state, country, postal codeForms, Outside-In Analysis requests, Fit Call bookings, newsletter and resource downloads
Professional and firmographic dataIndustry, employee count, revenue range, role, stated business challengesDiscovery and assessment forms, diagnostic tools
Account credentialsUsername, confirmed email address, passwordPlatform registration, where applicable
Content you submitMessage contents, uploaded documents, diagnostic answers, support ticketsContact and inquiry forms, support requests
Billing informationPayment card and billing details, processed by PCI-compliant payment providersPaid engagements
PreferencesCommunication preferences, consent choices, optional demographic detailsPreference center, consent manager

3.2 Information collected automatically

CategoryExamples
Device and connection dataIP address, browser type and version, operating system, device type, screen size, language
Usage dataPages viewed, referring URL, time on page, scroll depth, links and buttons clicked, form interactions, search terms used in on-site tools
Approximate locationCountry-level location derived from the network-edge geolocation header supplied by our hosting provider (Vercel). We use this solely to decide which consent regime to apply. We do not use it for advertising and we do not store precise GPS location from the Website.
Interaction recordingsWhere analytics consent is in effect, aggregated session replays and heatmaps of pointer movement, clicks, and scrolling (see Hotjar in Section 4.2)
Server logsRequests to our servers, response codes, security and abuse signals

Our server logs, security controls, load balancing, and record of your consent choice operate on all visits, including before any consent decision, because the Website cannot be delivered securely without them.

3.3 Information from third parties

Where you have given the relevant consent, or where permitted by applicable law, we may receive information about you from advertising and analytics platforms, data enrichment and firmographic providers, business-contact databases, publicly available sources, and our own clients and partners. We may combine that information with information we collect directly in order to understand our audience, qualify inbound interest, and tailor our communications and advertising. In the EEA, the UK, and Switzerland we only combine such data for marketing purposes where you have consented.

We do not intentionally collect personal information from anyone under 16, and our Website is not directed to children (see Section 14).

4. Cookies, tags, and similar technologies

4.1 The three categories we use

Our consent manager groups every technology on the Website into one of three categories.

CategoryWhat it doesBehavior
**Strictly necessary**Delivers and secures the Website: security and abuse prevention, load balancing, routing, and storing your consent choice itselfAlways active. Cannot be switched off, because the Website will not function without it. Not used for analytics or advertising.
**Analytics**Measures how the Website is used so we can improve content, navigation, and performanceLoads only in line with your consent choice
**Advertising**Measures campaign performance and enables advertising and remarketing, including cross-context behavioral advertisingLoads only in line with your consent choice

Google Tag Manager is deliberately classified under Advertising, not as a necessary or analytics technology. A tag container can be configured to deploy any tag, so we apply our strictest category to it.

4.2 The specific technologies we run

The following is the complete list of non-essential third-party technologies deployed on the Website as of the effective date of this policy. Durations shown are the vendor defaults and may be shortened by your browser.

TechnologyProviderCategoryPurposeTypical cookie / storage lifetime
Google Analytics 4Google LLC / Google Ireland Ltd.AnalyticsAggregate traffic, audience, and content-performance measurement_ga, _ga_<container>: up to 2 years by default, in practice capped near 13 months by browser limits Google Analytics Help
HotjarHotjar Ltd. (Contentsquare group)AnalyticsHeatmaps, aggregated session replay, and on-site feedback to diagnose usability problems_hjSessionUser_*: 365 days; _hjSession_*: 30 minutes UK Research and Innovation cookie register
MetricoolMetricool Software, S.L.AnalyticsAttribution of visits from our social and content channels, and content-performance reporting Metricool cookies policySession to 2 years, depending on the tracker set
Google Tag ManagerGoogle LLC / Google Ireland Ltd.AdvertisingContainer used to deploy and manage the tags listed hereNo cookie of its own; governed by the tags it deploys
Google AdsGoogle LLC / Google Ireland Ltd.AdvertisingConversion measurement and remarketing_gcl_aw, _gcl_dc, _gcl_au: approximately 90 days Google Ads cookie reference
Meta PixelMeta Platforms, Inc. / Meta Platforms Ireland Ltd.AdvertisingConversion measurement and audience building for Facebook and Instagram advertising_fbp, _fbc: approximately 90 days, refreshed on activity independent cookie analysis
LinkedIn Insight TagLinkedIn Corporation / LinkedIn Ireland Unlimited CompanyAdvertisingConversion measurement, audience matching, and remarketing for LinkedIn advertisingbcookie: 1 year; li_sugr: up to 90 days; UserMatchHistory, AnalyticsSyncHistory: 30 days LinkedIn cookie table

Each provider processes the data it receives under its own privacy terms. We do not upload the contents of your platform account or files you provide to us into any of these advertising or analytics platforms.

4.3 How consent is applied by region

Because the applicable rules differ by jurisdiction, our consent manager determines your region server-side from the geolocation header provided by our hosting infrastructure before any non-essential technology is requested.

Where you areDefault stateHow it works
EEA, United Kingdom, SwitzerlandAnalytics **off**, Advertising **off**Consent-first. No analytics or advertising technology is requested until you affirmatively accept it. "Accept" and "Reject" are presented with equal prominence, size, and visual weight, and refusing is no harder than accepting.
United States and all other locationsAnalytics **on**, Advertising **on**Opt-out. Measurement runs on arrival and you may withdraw either category at any time via "Your Privacy Choices."
Location cannot be determinedAnalytics **off**, Advertising **off**Treated as if you were in the EEA — we default to asking.

4.4 Google Consent Mode v2

We implement Google Consent Mode v2 and set consent signals before any Google tag loads. Under the consent-first regime, ad_storage, ad_user_data, and ad_personalization are set to denied by default; analytics_storage is set to granted only when you accept the Analytics category. Signals are updated in real time when you change your choice, without requiring a page reload.

4.5 Global Privacy Control

We recognize and honor the Global Privacy Control ("GPC") signal. When your browser transmits GPC, we automatically record an opt-out of the Advertising category, including the sale or sharing of personal information for cross-context behavioral advertising, and we tell you that we have done so rather than asking you again. This enforcement is applied when your preference is written, not merely in the interface, so it cannot be reversed by interacting with the on-page controls.

4.6 Spam protection on our forms

Forms on the Website are protected by Cloudflare Turnstile, which checks that a submission is being made by a person rather than an automated script. Turnstile sets no cookies and does not profile you across sites, so it operates as strictly necessary security technology and does not require your consent. The check runs only at the moment you submit a form. Cloudflare processes the request under its own privacy terms.

4.7 Changing or withdrawing your choice

Select "Your Privacy Choices" in the footer of any page to reopen the preference panel and change any category, including withdrawing consent you previously gave. Withdrawal takes effect immediately for future processing. It does not undo processing that already lawfully occurred. Stored preferences expire after 12 months, at which point we ask again. You can also block or delete cookies through your browser settings, though doing so may affect how parts of the Website function.

5. How we use personal information

  • Operate, secure, maintain, and improve the Website and our platform and services
  • Respond to inquiries, deliver requested assessments and reports, and provide support
  • Schedule and conduct Fit Calls, discovery, and client engagements
  • Administer accounts, contracts, invoicing, and payments
  • Measure and improve content, navigation, usability, and site performance
  • Measure marketing performance and, subject to your choices, deliver and personalize advertising and remarketing
  • Send service and account communications, and — subject to your choices and applicable law — marketing communications you can unsubscribe from at any time
  • Build aggregated and de-identified insights about our audience and markets
  • Detect, investigate, and prevent fraud, abuse, and security incidents
  • Comply with legal obligations and enforce our agreements

We do not use your personal information to make decisions about you by solely automated means that produce legal or similarly significant effects.

6. Legal bases (EEA, UK, and Switzerland)

PurposeLegal basis
Delivering and securing the Website; strictly necessary storage; spam protection on formsLegitimate interests (Art. 6(1)(f)) and, for the storage itself, the strictly-necessary exemption under the ePrivacy Directive as implemented locally
Responding to your inquiry; performing an engagementContract or steps prior to contract (Art. 6(1)(b))
Analytics, advertising, remarketing, and any non-essential cookies or similar technologiesYour consent (Art. 6(1)(a)), obtained before the technology loads
Marketing email to business contacts, where permittedConsent, or legitimate interests where local law allows a soft opt-in
Legal, tax, and accounting records; responding to lawful requestsLegal obligation (Art. 6(1)(c))
Fraud prevention, security, and defending legal claimsLegitimate interests (Art. 6(1)(f))

Where we rely on consent, you may withdraw it at any time as described in Section 4.7. Where we rely on legitimate interests, you may object as described in Section 11.

7. How we share personal information

We do not sell your email address or other contact information for money, and we do not distribute, sell, or barter data you upload into our platform or services.

We disclose personal information to:

  • Service providers and processors acting on our instructions — hosting and content delivery (Vercel), content management (Sanity), spam protection (Cloudflare), CRM and marketing automation (HubSpot), scheduling (Calendly), email delivery, video conferencing (Zoom), accounting and payments, and support tooling. They are bound by contract to use the information only to provide services to us. Where required, we use data processing agreements including the applicable EU/UK Standard Contractual Clauses.
  • Analytics providers listed in Section 4.2, where the Analytics category applies.
  • Advertising platforms listed in Section 4.2, where the Advertising category applies. Under California and several other U.S. state laws, enabling these technologies constitutes "sharing" personal information for cross-context behavioral advertising, and in some interpretations a "sale." You can stop it at any time via "Your Privacy Choices" or by sending a GPC signal.
  • Professional advisors — legal, accounting, and insurance advisors, under duties of confidentiality.
  • Authorities, where disclosure is necessary to comply with an enforceable legal request such as a subpoena or warrant, or to protect rights, safety, or property.
  • A successor entity, in connection with a merger, acquisition, financing, reorganization, or sale of assets. We will use commercially reasonable efforts to notify you by posting at https://ignitexds.com or by email.

We do not knowingly sell or share the personal information of consumers under 16.

8. How long we keep information

DataRetention
Consent preference record12 months, then re-requested
Server and security logsRetained by our hosting provider for a short operational period and used only for security, abuse prevention, and diagnostics
Google Analytics 4 event and user data14 months
Hotjar recordings and heatmaps365 days
Advertising platform identifiersPer the vendor lifetimes in Section 4.2, generally 30 days to 1 year
CRM records for prospects and clientsKept while the relationship is active and until you ask us to delete them
Contracts, invoices, and tax recordsAs required by law, generally 7 years
Support tickets and correspondenceKept while the relationship is active and until you ask us to delete them

When information is no longer needed we delete it or de-identify and aggregate it so it can no longer be linked to you.

9. International transfers

We are based in the United States, and personal information may be processed in the United States and in other countries where we or our service providers operate. Laws in those countries may differ from those where you live. Where we transfer personal information out of the EEA, the UK, or Switzerland, we rely on an appropriate transfer mechanism — the European Commission's Standard Contractual Clauses (with the UK Addendum where applicable), an adequacy decision, or a provider's certification under the EU-U.S. Data Privacy Framework and its UK and Swiss extensions — together with supplementary measures where required. You may request further detail using the contact information in Section 17.

10. Security

We maintain administrative, physical, and technical safeguards appropriate to the sensitivity of the information we hold, including encryption in transit, access controls, least-privilege permissions, and vendor due diligence. Payment card data is stored and processed only by PCI-compliant providers. We do not modify your personal information other than as instructed, disclose it except as compelled by law or permitted by this policy, or access platform data except to provide maintenance, verification, troubleshooting, or support you have requested.

No system is perfectly secure, and we cannot guarantee that our measures will defeat every unauthorized attempt to obtain information. You are responsible for choosing strong passwords and keeping them confidential; where you authenticate through a third-party identity provider, those credentials must also be kept secure. If an incident occurs, we will notify affected individuals and regulators where required by law.

11. Your rights and choices

11.1 If you are in the EEA, the UK, or Switzerland

You have the right to request access to your personal information; correction of inaccurate information; erasure; restriction of processing; portability; and to object to processing based on legitimate interests, including for direct marketing. Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of earlier processing. You also have the right to lodge a complaint with your supervisory authority — for UK residents, the Information Commissioner's Office — although we would appreciate the chance to address your concern first.

11.2 If you are a California resident

Under the California Consumer Privacy Act as amended by the CPRA, you have the right to know what personal information we collect, use, disclose, and share; to access and receive a portable copy; to correct inaccurate personal information; to delete personal information; to opt out of the sale or sharing of personal information for cross-context behavioral advertising; to limit the use and disclosure of sensitive personal information; and not to be discriminated or retaliated against for exercising these rights.

  • To opt out of sale or sharing: use the "Your Privacy Choices" link in the footer of any page, or transmit a Global Privacy Control signal, which we honor automatically.
  • Sensitive personal information: we do not use or disclose sensitive personal information for purposes beyond those permitted under CCPA regulations, so no separate limitation right is triggered. We do not collect Social Security numbers, precise geolocation, biometric data, or health information through the Website.
  • Categories collected, sources, purposes, and disclosures: see Sections 3, 5, and 7. The statutory categories we collect are identifiers, commercial information, internet or other electronic network activity information, professional or employment-related information, approximate geolocation at country level, and inferences drawn from the foregoing.
  • Financial incentives: we offer none.

11.3 If you are in another U.S. state with a comprehensive privacy law

Residents of states including Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, and others with comparable laws have rights to access, correct, delete, and obtain a portable copy of their personal data, and to opt out of targeted advertising, sale, and certain profiling. Use "Your Privacy Choices" or contact us as described below. Where your state provides a right to appeal a denied request, we will explain the appeal process in our response.

11.4 How to exercise your rights

Email info@ignitexds.com with the request you are making and enough information for us to locate your records. We will verify your identity in a manner proportionate to the sensitivity of the request and will respond within the time required by applicable law — generally 45 days under U.S. state laws (extendable once) and one month under the GDPR and UK GDPR (extendable by two further months for complex requests). An authorized agent may submit a request on your behalf with proof of authorization. We will not charge a fee for a first reasonable request, and we will not treat you differently for making one.

12. Do Not Track and Global Privacy Control

There is no consistent industry standard for the browser "Do Not Track" header, and we do not respond to it. We do recognize and honor Global Privacy Control as described in Section 4.5.

13. Third-party links and embedded content

The Website links to and embeds content from third-party sites and services that we do not control, including scheduling, video, and social platforms. Their own privacy policies govern the information they collect. We provide these links and embeds for convenience and information, and we are not responsible for those services. Sites you visited before arriving here may place information in the URL used to reach us, which our server logs may capture; we do not control those sites.

14. Children

The Website and our services are intended for business use by adults. We do not knowingly collect personal information from children under 16 (or under 13 for purposes of COPPA). If you believe a child has provided us with personal information, contact us and we will delete it.

15. Marketing communications

You may unsubscribe from marketing email using the link in any message or by contacting us. We will still send transactional and service messages related to your account, an active engagement, or a request you made.

16. Changes to this policy

We may revise this policy from time to time. When we do, we will update the "Last updated" date above and post the revised policy at https://ignitexds.com. If the changes are material, we will provide more prominent notice — for example, a Website notice or an email — and, where consent is required, we will obtain fresh consent before relying on the change. Your continued use of the Website after a revision takes effect indicates acceptance of the updated policy.

17. Contact us

Ignite XDS, Inc. 519 W. Main St., Brighton, MI 48116, United States

Privacy inquiries and requests: info@ignitexds.com General complaints and disputes: issues@ignitexds.com