Buell EA, LLC ("Buell EA", "we", "us", "our") is a consulting and technology company in Canal Fulton, Ohio. Companion documents: our Terms of Service and our Policies page, which holds the cookie table, the affiliate disclosure, the full list of Google API scopes we request, retention periods, and how to report a security issue. This version is effective September 4, 2026 and replaces the April 7, 2026 policy.
1. What this policy covers
This policy applies to:
- buellea.com — our public website, including the contact form, the help center, and the shop pages.
- The BuellEA platform — the business application at buellea.com used by our customers ("tenants") and their staff: CRM, time tracking, invoicing, expenses, projects, files, marketing, ERP, and the client portal.
- Services we run for customer websites — search-engine and analytics measurement, lead intake from contact forms, and the partner ad network, on websites we build, host or measure for customers.
- Consulting engagements — the reports and measurements we deliver to consulting clients.
2. Two roles: data you give us, and data we hold for our customers
We handle personal information in two different capacities, and your rights differ between them.
- As the responsible party ("controller") for information about visitors to buellea.com, people who contact us, and the people who hold accounts on the platform. Sections 3 through 12 describe this.
- On behalf of our customers ("processor") for the business data our customers put into the platform or route through it: their CRM contacts and leads, the people who use their client portal, inquiries submitted on their websites, and the search and analytics data about their web properties. Our customers decide what is collected and why; we process it under their instructions and our Terms of Service. If your information is in a customer's account, please direct requests to that customer. We will help them respond.
3. Information we collect directly
Account information
When an account is created on the platform we collect a name, an email address, a company or organization name, and optionally a phone number and job title. Passwords are hashed with bcrypt and never stored in readable form.
Contact form on buellea.com
The contact form asks for your name, email address, message, and optionally a phone number and company. The submission is stored as a lead in our own CRM so we can reply. Your IP address is used only to rate-limit submissions and is not stored with your inquiry. Submitting the form also fires a conversion event to Microsoft Advertising (see section 5).
Website usage on buellea.com
buellea.com loads Google Tag Manager, which sends page views and a small set of standard events (for example phone and email link clicks, and contact-form submission) to Google Analytics 4. It also loads the Microsoft Advertising universal event tag. Both set cookies; both are listed with their names and lifetimes on the Policies page. Our hosting provider keeps ordinary web-server logs (IP address, user agent, requested URL, timestamp) for security and operations.
Email you exchange with us
When you email us, the message and its metadata are stored in our CRM mailbox so we can track the conversation. See section 6 for how our own tooling reads that mailbox.
4. Information we process on behalf of customers
Business data in the platform
Depending on the modules a customer uses, their account holds contact names, email addresses, phone numbers, addresses, company details, communication history, sales pipeline records, time entries, invoices and billing addresses, expense records and receipt images, project plans, marketing campaign and form data, product and supplier catalogs, and files they upload. Customers of our customers may receive magic-link access to a client portal showing their own quotes, invoices, time and files.
Inquiries from customer websites
Contact forms on websites we build or operate for customers post their submissions (name, email, message, and whatever else the form asks) to our platform, where they are stored in that customer's CRM. Each submission is checked with a hidden field and a timing check to reject automated spam; a token identifies which customer's website it came from.
Crawler telemetry from customer websites
For websites enrolled in our measurement service, the website's own server reports to us each request made by a known search-engine or AI crawler (Googlebot, Bingbot, ClaudeBot, GPTBot and similar, identified by user agent). For each such request we receive the requested path, the response status, the time, the crawler's user-agent string, the requesting IP address, and the result of verifying that address against the crawler operator's published ranges or reverse DNS. This beacon reports crawler traffic only; it does not report requests from human visitors. Raw records are kept for 30 days and then reduced to daily counts, which are kept for one year. Dashboards show aggregate counts and never display individual request records, addresses or user agents.
Search and analytics data about customer properties
With the customer's authorization we read data about their web properties from Google Search Console (queries, impressions, clicks, positions, sitemap status, index coverage), Google Analytics 4 (daily metrics and aggregate event counts), Bing Webmaster Tools, and, for advertising engagements, Google Ads. These are aggregate reports about a website, not records about identified individuals; they are stored in the customer's tenant.
Email open and click tracking
Email sent from the CRM or Marketing module may include a one-pixel image and rewritten links. When a recipient's mail client loads the image we record that the message was opened and when; when a recipient clicks a tracked link we record the time, the destination, and the recipient's IP address before redirecting them. The customer who sends the email controls whether tracking is used and is responsible for telling their recipients. Recipients can prevent open tracking by disabling remote images in their mail client.
Partner ad network
We serve advertisements for partner businesses on participating websites we operate. When an ad is displayed or clicked we record the website, the placement, the ad, and the time. To avoid counting the same view twice we also record the requesting IP address, user-agent string, referring page and language preference of the request. Clicks redirect to the advertiser's page or to Amazon. We do not build profiles of individuals across sites and we do not sell this data.
5. Analytics and advertising tags on our own site
- Google Analytics 4 via Google Tag Manager (container GTM-MNJJT4ZG). Used to understand which pages are read and which actions are taken. Google's IP-anonymization is on by default in GA4. Opt out with Google's browser add-on or by blocking the cookies named on the Policies page.
- Microsoft Advertising universal event tag (tag 343249053). Used to measure whether our advertising leads to contact-form submissions. Microsoft's cookie and opt-out information is at their personalized ads page.
Neither tag is loaded inside the client portal or the logged-in application's data pages for the purpose of advertising; they are present on our public marketing pages and on the login and registration screens.
6. Google user data
Several platform features connect to a Google account with your explicit OAuth authorization. You choose which account and which permissions; you can revoke either at any time from the platform's connection settings or from your Google Account permissions page. The complete list of scopes we request, and the feature each one serves, is on the Policies page. In summary:
- Gmail for the CRM — read and sync your inbox and sent folder into the CRM, and send email you compose in the CRM from your own address.
- Gmail for the owner's Assistant — a metadata-only scan (message IDs, labels, timestamps, headers; subjects are truncated to 80 characters; bodies, snippets and attachments are never requested) used to surface unanswered threads; an explicit, per-thread read of one conversation when you ask for a follow-up draft, shown transiently and never stored; and, only after a separate grant, the ability to create a draft in your Gmail. The Assistant never sends, deletes, labels or archives mail.
- Google Calendar — two-way sync between CRM activities and your calendar, and read-only display of your day for the Assistant.
- Google Search Console — read search performance, sitemap status and index coverage for properties you own; submit or remove sitemaps when you ask us to.
- Google Analytics — import daily metrics and aggregate event counts from properties you attach; a separate connection with edit permission is used, after an explicit confirmation step, to create or remove key events.
- Google Ads — read campaign performance and spend for advertising engagements.
- Your Google email address — to label which account is connected.
Buell EA's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In practice that means:
- We use Google user data only to provide or improve the user-facing feature you authorized. We do not use it for advertising, and we do not sell it.
- We do not transfer Google user data to others except to provide the feature (for example, showing your emails in the CRM to you), with your consent, for security, or when the law requires it.
- Humans at Buell EA do not read your Google data unless you have asked us to for support, it is necessary for security or abuse investigation, or the law requires it.
- We do not use Google user data, including Gmail content, to develop, improve or train generalized artificial-intelligence or machine-learning models. Where an AI feature processes an email you selected (section 7), that processing is bounded to the request you made and the text is not retained.
- Access and refresh tokens are encrypted at rest and are deleted when you disconnect.
7. Artificial-intelligence features
Some features send content to Anthropic's Claude API: drafting an email reply, extracting contacts from a pasted document, summarizing a thread, suggesting quote line items, classifying a captured note, writing ad copy. Only the specific content you ask to process is sent, and only when you trigger the feature. Anthropic does not use API inputs or outputs to train its models. We record which feature ran, for which tenant, and what it cost; for features that process email we do not log the prompt or the response text. Push-to-talk voice capture is transcribed in your browser and only the resulting text reaches us; no audio is stored. AI output is a suggestion for you to review, never an action taken on your behalf without a confirmation step.
8. Why we use information, and the legal basis
- To provide the platform and services you or your organization signed up for (performance of a contract).
- To respond to inquiries, send service notices such as security alerts and billing messages, and support you (contract and legitimate interest).
- To keep the platform secure, prevent abuse and enforce our terms (legitimate interest).
- To understand how our website is used and measure our own advertising (consent where required by your local law; otherwise legitimate interest).
- To meet legal obligations such as tax and accounting records.
We do not sell personal information, and we do not share it with third parties for their own marketing.
9. Who we share information with
We share personal information only with the providers below, each acting on our instructions to run a part of the service, and otherwise only when the law requires it or to protect the rights and safety of Buell EA, our customers or the public. The current list, with the role each plays, is maintained on the Policies page.
- Hostinger — hosting and databases, in the United States.
- Google — Workspace email delivery, Tag Manager and Analytics on our site, and the APIs you authorize under section 6.
- Microsoft — Advertising conversion measurement on our site and Bing Webmaster Tools for measurement customers.
- Zoho — accounting (Zoho Books) and subscription billing (Zoho Billing). Payment card details are entered on Zoho's hosted pages and never reach our servers.
- Anthropic — the AI features in section 7.
- Amazon — affiliate product links on our shop pages and in the ad network (see the affiliate disclosure on the Policies page).
- Todoist and Shopify — only when a user connects those services; read access to tasks, and store synchronization for ERP customers, respectively.
10. Security
- All connections use TLS. Cookies for logged-in sessions are marked secure and same-site.
- OAuth tokens and other credentials are encrypted at rest with AES-256-CBC; passwords are bcrypt-hashed.
- Every business record is scoped to its tenant, and every request is checked against that scope before data is returned.
- Dashboards that summarize crawler traffic expose aggregate counts only, never request-level identifiers.
- Backups are taken regularly. Access to production is limited to Buell EA's platform administrator, over key-based SSH.
- If we learn of a breach affecting your personal information we will notify you and any regulator we are required to notify without undue delay.
No system is perfectly secure. If you find a vulnerability, please tell us before telling anyone else; the process is on the Policies page.
11. How long we keep information
- Accounts and business data — for as long as the account is active, then 90 days after cancellation to allow reactivation, after which it is deleted. You can ask for earlier deletion.
- Contact-form inquiries — kept in our CRM as part of the relationship record; ask us and we will delete yours.
- Crawler telemetry — raw request records 30 days; daily aggregates one year.
- Email open and click events, ad impressions and clicks — kept with the message or campaign record they belong to, for as long as that customer's account exists.
- Search Console, Analytics and Ads data — kept in the customer's tenant for reporting for as long as the property stays attached.
- Server logs — per our hosting provider's rolling retention.
- Financial records — as long as tax law requires.
12. Your rights and choices
Wherever you live, you can ask us to tell you what personal information we hold about you, correct it, delete it, or give you a copy in a portable format; you can object to or restrict certain processing; and you can withdraw a consent you gave. Account holders can correct their own details in account settings and export module data as CSV. Google and other integrations can be disconnected at any time from connection settings or from the provider's side.
- European Economic Area, United Kingdom and Switzerland — the rights above are the ones granted by the GDPR and UK GDPR. Our services are hosted in the United States; where we transfer data from those regions we rely on standard contractual clauses with our providers. You may complain to your local supervisory authority.
- California — we do not sell or share personal information as the CCPA defines those terms, and we do not use it for cross-context behavioral advertising. You will not be treated differently for exercising your rights.
- Do Not Track — our website does not change its behavior in response to browser Do Not Track signals; use the cookie controls on the Policies page instead.
To exercise any right, email djbuell@buellea.com. We will confirm your identity in a way proportionate to the request and respond within 30 days. If your information sits in a customer's account (section 2), we will pass the request to that customer and help them answer it.
13. Children
The platform and website are for business use and are not directed at children under 16. We do not knowingly collect personal information from children; if you believe we have, email us and we will delete it.
14. Changes to this policy
We will post changes here and update the effective date. For material changes affecting account holders we will also email the account's primary address at least 14 days before the change takes effect. Continued use after the effective date means you accept the revised policy.