Privacy
This page explains what gets collected when you visit goodturndigital.com, why, and what you can do about it. The short version: forms collect what you type, cookies are minimal, and nothing gets sold to anyone.
Who runs this
Good Turn Digital is a one-person consultancy operated by Trevor Zalkind in Denver, Colorado. There is no marketing team, no data team, and no third-party processor handling your information. If you want to ask about anything on this page, the answer comes from me directly: hello@goodturndigital.com.
What gets collected
When you fill out a form (contact, newsletter, lead magnet, booking) - whatever you type into it. Name, email, organization, project context, time slots, the path you selected on the intake form. Honeypot and Turnstile checks happen invisibly to filter out bots.
When you visit the site - routine server-side logging from Cloudflare (IP, user agent, referrer, request timestamp). This is the same kind of log every web host produces.
When you book a call - Cal.com captures your name, email, organization, what you're interested in, how you found me, the meeting time, and any notes you add. The booking is also written to my Google Calendar so the slot is actually held, which means Google sees those same details. Paid strategy sessions are invoiced after the session, so no payment details are collected on this site.
Cookies - two small cookies record where you came from so I can tell which channels actually work (LinkedIn, search, a referral, a direct visit). More on those further down.
Why it gets collected
To respond to your inquiry. To send the newsletter you opted into. To run the booking calendar. To know whether the work I do on LinkedIn or referrals is paying off. That's the whole list.
No data gets sold. No profiles get built. A short list of analytics tools runs on the site to tell which marketing channels actually convert. They are named in the cookies section below, and they fire only outside the EU, UK, and Switzerland.
Where it lives
Form submissions land in four places. The first three I run myself:
- A private database (NocoDB) on a server in my home office in Denver
- A CRM (Twenty), also on that same server, where an inquiry becomes a contact record
- A workflow tool (n8n) that routes the submission to ntfy for a push notification on my phone
- Cloudflare D1, used as a write-ahead log on the edge so nothing gets lost if my home server is offline
The fourth is Brevo, an email service in France. It holds your name and email so the newsletter and any resource you requested can actually be sent. It receives contact details only - never your message, project context, or booking notes.
Bookings live on Cal.com, self-hosted on my server, and sync to my Google Calendar. The site itself is hosted on Cloudflare Pages (US edge network). The typeface is served from this site's own domain, so loading a page here does not send your IP address to Google Fonts or any other font provider.
Who else sees it
- Cloudflare sees inbound traffic and form submissions in transit, but doesn't store form contents
- Brevo stores your name and email to send the newsletter and any resource you asked for. Their servers are in the EU.
- Google Calendar receives your booking - name, email, time, and any notes - because that is the calendar my availability is checked against. If you would rather Google not see it, email me instead of booking.
- Cal.com is self-hosted, so apart from the Google Calendar sync above, the only people who see your booking are me and the email-confirmation pipeline
- My CRM (Twenty) is self-hosted on my own server, not a SaaS platform, so no CRM vendor receives your data
- No payment processor - paid sessions are invoiced after the fact, and no card details touch this site
- No ad networks. A small set of analytics tools - listed in the cookies section below - measure aggregate visit volume and which channels convert. None of them receive form contents, payment information, or any data you type into a form.
How long it gets kept
Lead and project data sticks around for the life of the engagement plus a reasonable archive window for project records, usually one to two years. Newsletter subscriptions stay until you unsubscribe (one click, link in every send). The two attribution cookies expire after 90 days, or whenever you clear them. Server logs follow Cloudflare's defaults, which is a short retention window measured in days.
If you want anything older deleted, send an email and it gets done.
Your rights
You can ask me what data I have on you. I'll send it back. You can ask me to delete it, correct it, or stop using it. Each of those is a same-week response.
For EU, UK, and Swiss residents: those are your rights under GDPR, UK GDPR, and FADP respectively. Same email gets it done.
Cookies on this site
Two first-party cookies do marketing attribution, plus whatever the third-party tools listed further down set on top of those:
- gtd_first_touch - records the first session that brought you to the site (UTM tags, referring site, landing page, timestamp). Set once per visitor, expires after 90 days.
- gtd_last_touch - records your most recent session. Updated on every visit.
Both are JSON-encoded values, and both get sent along with any contact form submission so I can connect a lead to where it came from.
Geofenced. Visitors in the EU, EEA, UK, and Switzerland are detected at the edge (via Cloudflare's country signal), and the cookies are not written for them. Those regions require prior opt-in consent for non-essential cookies under the ePrivacy Directive. Rather than putting up a consent banner, the simpler answer is to not set the cookies in the first place. The form still works, the contact still reaches me, the attribution just isn't recorded.
Cloudflare may also set a short-lived session cookie of its own for bot protection. That's a network-layer thing, not a site behavior, and isn't read or used by anything on this domain.
Third-party analytics
A handful of analytics scripts also run on the site. Each one is named here so you know exactly what's loaded.
Loaded for everyone, no cookies set:
- Cloudflare Web Analytics - aggregate page-view counts and Core Web Vitals. No cookies, no fingerprinting, no cross-site tracking.
- Umami - a self-hosted, cookieless visit counter that I run on my own server. Anonymous aggregate counts only, no individual user profiles.
Loaded only outside the EU, EEA, UK, and Switzerland (same geofence as the attribution cookies above):
- Google Analytics 4 - aggregate audience and behavior reporting. Sets the
_gafamily of cookies. Used to size the audience and check which pages convert. - Microsoft Clarity - anonymized session recording and heatmaps so I can see where pages confuse people. Sets Clarity's session cookies. Recordings exclude form input by default.
Visitors in the geofenced regions don't get these scripts loaded at all. They aren't blocked by a banner you can decline. They never reach your browser.
Children
This site isn't directed at anyone under 16. Don't sign up for the newsletter or fill out the contact form if you're younger.
When this policy changes
If anything material changes (a new system added, a new third party, a new data type collected), the change shows up here and the "last updated" date at the top gets bumped. The full history is in this site's git log if you want to see what changed and when.
How to reach me
Privacy questions, deletion requests, or anything else on this page - hello@goodturndigital.com.