Privacy Policy
What GLR does with your information, how long it is kept, and what deletion actually means here.
- Version
- 1.7.0
- Last updated
- 19 September 2026
- Effective date
- 19 September 2026
Who this covers, and where things stand today
This Privacy Policy covers the information GLR handles when it provides the Lead Recovery founding pilot to a home-service business. It is written for the business we work with, and it also describes what happens to information about that business's own customers and leads, because that is most of what the service touches.
It also covers what happens before any of that. The website has three forms you can send something to us through — “See If GLR Fits”, “Request Audit Details” and “Ask for a Free Demo” — and you do not have to be a customer to use any of them. Most people who use one will never become a customer, so what happens to what you send is described here too.
One thing should be said before anything else, because it changes how the rest reads. The live environment that holds this information now exists and is in use, and GLR has run the full setup against its own business first — including a Google Sheet the service created. What follows describes how the service is designed and built to behave, and it is written for the businesses we work with as that work begins. It does not say how many businesses are on the service, or what results it has produced.
What information the service handles
Seven kinds of information, and nothing beyond what the agreed work needs:
- The enquiry you send through the website — if you use the “See If GLR Fits” form, the answers you give it: your business name, service area and website, how leads reach you, where follow-up breaks down, roughly how many leads you get, what you use today, who handles follow-up, and how to reach you. Only what the form asks for. The form sets no cookie, runs no tracker, and gathers nothing about you from anywhere else.
- The request you send through the website for Audit details — if you use the “Request Audit Details” form, the answers you give it: your name, your business name, your email address, whether you would rather hear back by email or by phone, the phone number if you choose phone, whether you have already sent us the “See If GLR Fits” form, and anything you choose to add in your own words. It asks less than the other form on purpose, because here you are asking us for something rather than describing your operation, and you are never asked to repeat what you have already told us. Only what the form asks for, and the same holds: no cookie, no tracker, nothing gathered from anywhere else.
- The request you send through the website to see a demo — if you use the “Ask for a Free Demo” form, the answers you give it: your name, your business name, your business email address, the kind of work you do, and — only if you choose to give them — a phone number, a website, and anything you would like the walkthrough to focus on. It asks the least of the three forms on purpose, because here you are asking to be shown something rather than describing your operation. It asks for no payment detail, takes no upload, and asks for nothing sensitive. Only what the form asks for, and the same holds: no cookie, no tracker, nothing gathered from anywhere else.
- Information you give us about your business and your leads — business contact details, enquiry and lead lists, past-lead spreadsheets, notes about your services and service area.
- Account and setup information — who is on your account, your business name and branding, which package you are on, and how you have configured the service.
- Connection details for the outside services you link — the minimum needed to read from or prepare work in Google Sheets and any other connection you approve. Your email account is not one of them: GLR holds no mailbox credential and no mailbox access. GLR never asks you to send a password, private key, API key, access token, or other secret. Where a service offers its own secure authorization process, such as an OAuth connection, the connection credential it creates is held in the approved credential system and is never copied into messages, documents, or customer records.
- Operational records — activity and error records, review and approval records, security records, and evidence that the work was done correctly. These are how anything can be checked, corrected, or explained afterwards.
All three forms do one thing you cannot see, and it is fairer to name it than to leave it under “nothing in the background”. So that a single source cannot flood them, the connection your submission arrives on is reduced to a short value, and that value is used to count recent submissions from the same source and for nothing else. It is not written into the record of what you sent, it is held only in the memory of the machine that handled the submission, and it goes when that hour has passed or that machine is recycled. It is not used to identify you, it is not used for advertising, and it does not follow you anywhere or across any other website.
Why it is handled
For these purposes only:
- running the service you bought, and doing the work agreed with you
- finding and fixing problems when something does not work
- keeping the service and your information secure, including recording when the system refused to do something
- keeping records that let the work be checked afterwards
- supporting you, and answering your questions
- improving the product, using what we learn about how it is used rather than the contents of your customer lists
- ordinary lawful business administration — invoicing you, and keeping our own records
What GLR does not do with it
We do not sell your information, and we do not sell or share it for advertising.
Your information is not used to train models. Neither is the content of your conversations with us.
GLR does keep notes from sales and support conversations so it can explain and deliver the product better — what confused people, what needed repeating, which explanations landed. Those notes exclude secrets and credentials, payment information, regulated data, confidential information that is not needed for the lesson, and unnecessary personal information. A note that contains any of those is refused outright rather than trimmed down, and nothing learned this way changes how GLR works until a person has reviewed and approved it.
Sending one of the website forms does not sign you up for anything else. Asking for a demo, asking for Audit details, or telling us about your operation lets GLR write back about that — and it is not agreement to a mailing list, a sequence of follow-ups, or any unrelated marketing. If GLR ever wants to send you something beyond a reply to what you asked, it will ask you first.
Your leads are yours. They are not pooled, not shared with another business, and not reachable from anyone else's account.
Outside services
The pilot connects to a small number of outside services, and only ones you approve. Their status today is exactly this:
- Google Sheets — connected, and it both reads and writes. The service reads the sheet you point it at, and it sets that sheet up: it creates the tabs your leads are kept in, adds columns, writes the heading row, and formats them. It does not delete tabs or remove rows — it has no ability to.
- Your email account — NOT CONNECTED. The service prepares drafts for you to copy or open in your own email app, and you send them yourself. GLR holds no key to your mailbox and cannot read, write, draft, or send from it.
- Slack — NOT CONNECTED. The service does not connect to your Slack workspace and delivers nothing into it. If a Slack connection is ever offered, it will need a separate connection you authorize, and how it handles your information will be set out here before it is used.
- Claude — used as an assistant where you opt in. It advises; it never decides or approves anything.
- Stripe — the approved payment method for the founding pilot: used to issue invoices, provide secure payment links, and process payments. Stripe handles the payment information entered through its service. GLR does not directly receive or store full payment-card details.
- Retell (voice) — not connected. It is planned for a later package and is switched off entirely today.
- n8n (workflow automation) — connected, and used for one thing: it carries what you send through the website forms. For a “See If GLR Fits” enquiry and a “Request Audit Details” request it passes your answers to storage and emails GLR so a person can read them, and it keeps a record of that run; the two travel as different kinds of record and are kept apart from each other. The “Ask for a Free Demo” form is built and is NOT SWITCHED ON. The handling behind it is now set up: a demo request is passed to storage and emailed to GLR so a person can read it, and n8n keeps a record of that run; it travels as its own kind of record, kept apart from the other two. Because the form is not switched on, no demo request has been submitted through it. n8n is not connected to your leads, your Google Sheet, or anything in the service GLR delivers to a customer.
Nothing else is connected. Stripe is the only outside service that handles payment information, and no advertising service and no analytics service reads your information.
Where your information is handled
During the founding pilot the work is done by a GLR operator, and your workspace is kept separate from every other customer's. GLR does not sell your information, and nothing here is passed to an advertising or analytics company.
The service runs on outside infrastructure, and it is fairer to name it than to describe GLR as a closed system. These are the companies that hold or handle your information, and what each one actually does:
- Vercel — runs the website and the signed-in area. Your information passes through it while you are using the service. It is the host rather than the record: your leads and your workspace records are not stored there.
- Clerk — handles signing in. It holds the identity you sign in with: your name, your email address, and which organization you belong to. It does not hold your leads.
- Supabase — the company that stores your workspace's records: your organization, your workspace, who has access, and the service's own activity log. It also stores what you send through the website forms, and each kind is held separately — a “See If GLR Fits” enquiry in one place, a “Request Audit Details” request in another. The “Ask for a Free Demo” form is not switched on; when a demo request is submitted, it is stored here too, in its own place, kept apart from the other two. Its servers are in the United States.
- n8n — the workflow service that carries what you send through the website forms, as described under Outside services above. It holds the record of that run. A demo request submitted through the “Ask for a Free Demo” form is carried through here, and the record of that run is held here too. Its servers are in the United States. It holds nothing else of yours.
- Google (Google Sheets) — holds your leads, in the sheet the service sets up for you. That sheet is described under Outside services above, and it is where your lead information actually lives day to day.
- Stripe — payments only, as described above. GLR does not receive or store full payment-card details.
- Slack — GLR's OWN internal operations channel, and not a place your records go. It receives redacted signals about whether the service is running: counts and status, with identifying values removed before they are sent. It is named here because it is real infrastructure, not because your information is in it.
Anything else GLR uses internally — the password vault that holds GLR's own keys, the machine an operator works from — holds no customer records and is not a route your information travels.
GLR offers no data-processing addendum and no cross-border transfer commitment today. If you need either, say so before you share anything — that is a conversation, not a form.
How long it is kept
Your information is kept for as long as we are working together, plus a wind-down period of 30 days. After that it is deleted. If you ask us in writing to delete it sooner, we delete it sooner. Nothing is kept indefinitely.
What you send through any of the website forms is kept for 30 days after GLR closes off your request, and then deleted. For a “See If GLR Fits” enquiry or a “Request Audit Details” request, closing it off means one of four things: you decide to go ahead, you tell us no, GLR decides your request is not one it should take on, or the request is otherwise formally closed. For an “Ask for a Free Demo” request it also means one of four things: the demo has been given, you tell us no, you stop pursuing it and GLR formally closes the request, or GLR decides it will not go ahead. The 30 days run from that point — not from when you pressed send, and not from any payment. If you ask us to delete it sooner, we do. It is deleted whichever way the answer went; if you do go on to work with us, what happens after that is the paragraph above.
The 30 days is GLR's own figure, chosen as the shortest period that still leaves room to hand things back or sort out a problem after the work ends. No lawyer has confirmed it is the right one, and that is stated here rather than left to be assumed.
One honest limitation: nothing counts those 30 days down automatically today. The deletion itself is built and tested, but no scheduler runs it, so for now the period is kept by a person doing it. If that matters to you, ask — it is a fair question and it has a real answer.
What deletion actually does
Deletion here is a hard delete. Your records are removed — not hidden, not archived, not turned into anonymous rows that stay behind. There is deliberately no anonymise option, because a promise of deletion that leaves the shape of your data in place would need a caveat we would rather not have to write.
It happens as one piece of work: either all of it goes or none of it does. A half-finished deletion is worse than none, because you would have been told your information was gone while some of it quietly was not.
The two things that outlive a deletion
Two kinds of internal record remain after your data is deleted. Neither contains your data, and both are described here rather than buried, because “everything is deleted” would not be strictly true otherwise.
- A short record that a deletion happened. It holds a meaningless identifier for your workspace, the date, and a four-way note of why the deletion was requested. No business name, no email address, no web address, no content, and no counts of anything. It is kept for up to 90 days and then it goes too. It exists so that restoring an older backup cannot quietly bring back data you asked us to delete.
- Records of occasions when the system refused to act. These are written before anyone is identified and carry no reference to a customer at all, so they cannot be traced to you and a deletion request cannot reach them. Nothing of yours is in them. They stay because of how they are written, not because of an exception carved out of your deletion.
Together these are the smallest thing that can make a deletion stick. Everything else of yours goes.
Backups and recovery
The live environment now exists and is in use. There is still no live backup of customer information running against it — the path described below has been built and exercised once, which is not the same as a backup running over your data today.
The backup and recovery path itself has been built and exercised once, against an internal test system containing no customer information. What that exercise showed is worth stating plainly, because it is unusual and it is true: a restored copy comes back complete and correct, and it is not usable until a separate security step has been applied to it and checked. Completeness and safety are two different results and GLR reports both.
Continuous point-in-time recovery has not been purchased. GLR does not offer a recovery-time or recovery-point commitment, and a backup taken before a deletion is not rewritten the moment the deletion runs — which is exactly what the short deletion record described above is for.
How your information is protected
These are controls GLR actually operates, described as controls rather than as promises:
- Each customer's information is kept separate from every other customer's, enforced by the system rather than by care.
- Accounts get the least access that lets them do their job, and the service refuses work that would exceed it.
- You are never asked for a password, key, or secret, and none is ever stored in a document, pasted into a message, or written into a customer record. A connection credential created by an approved authorization process is held only in the approved credential system.
- Consequential actions need a named human approval recorded at the time.
- When the system refuses to do something, the refusal is recorded, so a refused action leaves a trace rather than looking like nothing happened.
- GLR staff reach a customer's information only through a restricted, recorded route, never by quietly stepping around the separation.
GLR does not make absolute statements about security, and holds no security or compliance certification. What it can say is what it built, what it tested, and what it refuses to do — which is what this section is.
Your requests about your information
You can ask GLR to show you what it holds about your business, correct it, give you a copy, stop using it, or delete it. Ask the GLR operator running your pilot, in writing, and it gets done.
Requests are handled by a person, not by a button in the product — that part is not built yet. In practice that means a reply within a few working days rather than instantly, and GLR would rather tell you that than print a response time it has never measured.
If the information is about your own customers rather than about your business, you are the one who decides what happens to it. GLR acts on your instructions.
No promises about outcomes
This page describes how information is handled. No guarantee of leads, bookings, recovered revenue, response rates, or any other business outcome is made here or anywhere else.
Changes, and getting in touch
When this Privacy Policy changes, the version and date at the top change with it, and you will be told about anything that materially affects you.
Questions, requests, and anything that has gone wrong go to Automation@glrholdingsllc.com, or to the GLR operator running your pilot.
This wording is GLR's own and is not attorney-reviewed. GLR has approved it and uses it for the founding pilot; no lawyer has read it, and GLR says so rather than leaving it to be assumed.