Skip to content
willowark

Legal

Privacy Policy

Effective: ⚠️ NEEDS BLAKE · Last updated: September 2, 2026Draft — legal review pending

⚠️ NEEDS BLAKE / legal review. This page is a factual inventory of what the willowark.com site collects and does, written by the engineers who built it so a lawyer can turn it into a policy. Every section below is a stub with the facts; none of it is legal text. The page stays noindex until STATUS records legal sign-off.

1. Who we are

Willowark (⚠️ NEEDS BLAKE: legal entity name, state of formation, mailing address — the mailing address is read from the Company OS setting company.mailingAddress and shown in email footers and on the subscribe pages once set). Contact for privacy questions: sales@willowark.com (⚠️ NEEDS BLAKE: confirm the address to publish).

2. What the site collects, and where it goes

2.1 Contact and lead forms

Every "Describe the problem" / contact form submits: name, work email, company (optional), a message, an optional mobile number, an SMS-consent checkbox, plus the form's source (which page), UTM parameters from the URL, the referrer, the landing page, and first-touch / last-touch attribution (see 2.3). A honeypot field rejects bots. Submissions are stored in the Willowark Company OS database (leads, contacts, companies, activities) and are used to reply to the inquiry and to score the lead. Rate limit: 10 submissions per minute per IP address.

2.2 Newsletter, guide, and event signups

The subscribe forms collect: email, optional name, the signup source (newsletter, a specific guide, an event), UTM parameters, and the IP address at signup. Signup is double opt-in: a confirmation email is sent and no marketing email is sent until the link is clicked. Records live in subscribers, contacts, lists, and list_members. Guide signups add the reader to the newsletter list and the guide's list.

2.3 Attribution stored in the browser

localStorage holds first-touch and last-touch attribution (UTM parameters, referrer, landing page, timestamp) so a later form submission can carry where the visitor originally came from. This is written by the site's own script, not by a third party, and is submitted only with a form. No advertising identifiers are stored.

Page views, CTA clicks, video plays, scroll depth, navigation opens, and form events are sent to PostHog or Google Analytics 4 only when the respective key is configured, and only after the visitor accepts the consent banner (Google consent mode default is "denied"). The consent choice is stored in localStorage. ⚠️ NEEDS BLAKE: which analytics provider is live in production, its data-retention setting, and whether IP anonymisation is on.

2.5 Scheduling (Calendly)

The contact page embeds Calendly's scheduling widget, which loads Calendly's script and iframe from calendly.com when the widget scrolls into view. Booking a call sends the details you enter to Calendly under Calendly's privacy policy; Calendly then notifies Willowark's Company OS by webhook (event, invitee name and email, time). ⚠️ NEEDS BLAKE: link to Calendly's policy; confirm the account owner.

2.6 SMS

If a visitor provides a mobile number and ticks the consent box, Willowark may send transactional and follow-up texts through Twilio about that inquiry. Reply STOP to opt out, HELP for help; opt-outs are recorded and honoured automatically. ⚠️ NEEDS BLAKE: A2P 10DLC registration status, message frequency statement, carrier disclosure wording.

2.7 Email delivery and tracking

Marketing email is sent through a bulk provider (Resend) with List-Unsubscribe headers and a one-click unsubscribe endpoint; opens/clicks may be recorded by the provider. Transactional and 1:1 email is sent from Willowark's Google Workspace mailboxes. ⚠️ NEEDS BLAKE: confirm providers in production.

2.8 Payments and signatures (when used)

Invoices may be issued through Stripe (card/ACH; Stripe handles payment data — Willowark never stores card numbers) and contracts may be signed through DocuSign; both apply only to clients who engage Willowark, under those providers' terms. ⚠️ NEEDS BLAKE: confirm which are active.

2.9 Server logs and security

The hosting platform keeps standard request logs (IP address, user agent, URL, timestamp) for security and debugging. ⚠️ NEEDS BLAKE: hosting provider and log retention.

3. How the information is used

To answer inquiries, schedule calls, deliver guides and the newsletter people asked for, run the projects clients hire Willowark for, invoice, and understand which pages and campaigns lead to conversations. Willowark does not sell personal information. AI models (Anthropic Claude) are used inside the Company OS to draft replies and summarise inquiries; drafts are reviewed by a person before anything is sent, and inquiry content is not used to train models. ⚠️ NEEDS BLAKE: confirm this wording with the provider's terms.

4. Your choices

  • Unsubscribe from marketing email in one click from any email, or at /unsubscribe; change lists at /preferences.
  • Reply STOP to any text.
  • Decline analytics in the consent banner; clear localStorage to remove attribution and the consent choice.
  • Ask for access, correction, or deletion of your information by emailing sales@willowark.com (⚠️ NEEDS BLAKE: process, response time, identity verification).

5. Retention

Leads, subscribers, and their activity are kept in the Company OS as business records. ⚠️ NEEDS BLAKE: retention periods (e.g. unconverted leads after N months, unsubscribed addresses kept only as a suppression record), and backup retention at the hosting provider.

6. Children, international visitors, and changes

The site is for businesses and is not directed at children. Willowark is based in New York, USA; visitors elsewhere should assume their data is processed in the United States. ⚠️ NEEDS BLAKE: GDPR/UK/CCPA positions, and how changes to this policy are announced.

7. Contact

Questions about this page: sales@willowark.com, or the contact form.

Questions about this page? Contact us or email sales@willowark.com.