Privacy Policy
Effective date: August 18, 2026
Last updated: August 18, 2026
Bradford Strategies LLC (“Bradford Strategies,” “we,” “us,” or “our”) operates https://bradfordstrategies.com (the “Site”) and provides search, content, advertising, and web development services (the “Services”). This Privacy Policy explains what personal information we collect through the Site, why we collect it, who we share it with, how long we keep it, and the choices and rights you have.
This policy covers our own Site and our own marketing. It does not cover how we handle data on behalf of clients when we act as a service provider or processor — see Section 15.
If you only read one thing: we collect contact details you give us, we use analytics and marketing tools to understand how the Site is used and where our leads come from, we do not sell your personal information for money, and we do not share mobile phone numbers or SMS consent data with anyone for marketing.
1. Contact Us About Privacy
| Entity | Bradford Strategies LLC, a Pennsylvania limited liability company |
|---|---|
| Mailing address | 306 S New St Ste 110, Box 116, Bethlehem, PA 18015 |
| Privacy email | [email protected] |
| Phone | 610-442-7624 |
For questions about these terms, DMCA notices, or legal escalations, use [email protected].
2. Information We Collect
2.1 Information you give us
| Category | Examples | When |
|---|---|---|
| Identifiers | Name, business name, email address, phone number, mailing address | Contact forms, quote and audit requests, newsletter signup, scheduling a call |
| Professional information | Job title, industry, company size, website URL, current marketing spend range, service interests | Intake and proposal forms |
| Commercial information | Services inquired about or purchased, proposal and contract history, billing contact details | Sales process and engagement |
| Communications content | The content of emails, form messages, chat conversations, text messages, and — where you have consented — call recordings and transcripts | Any time you contact us |
| Marketing preferences | Email subscription status, SMS consent status and the record of how it was given, topic preferences | Signup and preference changes |
We do not ask for and do not want government identification numbers, payment card numbers, health information, precise geolocation, biometric data, or any other category of sensitive personal information through the Site. Do not send them to us through a web form. If you send us sensitive information anyway, we delete it when we notice it.
2.2 Information collected automatically
When you visit the Site, the following is collected automatically, mostly through cookies and similar technologies described in our Cookie Policy:
- Device and connection data — IP address (often truncated or de-identified by the tool that receives it), browser type and version, operating system, device type, screen and viewport dimensions, language, and time zone.
- Usage data — pages viewed, time on page, scroll depth, clicks and taps, referring URL, exit pages, and the search terms or advertising campaign that brought you here.
- Marketing attribution data — UTM parameters, Google click identifiers (
gclid), referring source and medium, and landing page.
2.3 Information from third parties
- Advertising and analytics platforms — aggregated and de-identified performance and audience reporting from Google.
- Business data sources and public records — company details we look up as part of prospecting or preparing an audit, such as your public website, Google Business Profile, and published business listings.
- Referrals — contact details a mutual contact or partner provides when they refer you to us.
- Your own systems, with your authorisation — where you are a client and you grant us access to your Google Analytics, Google Search Console, Google Ads, Google Business Profile, CRM, or website admin, we receive data from those systems under Section 15.
We do not purchase consumer marketing lists, and we do not text or call numbers obtained from a lead vendor. See our SMS Terms.
3. Why We Use Your Information
| Purpose | What this looks like | Legal basis under GDPR/UK GDPR |
|---|---|---|
| Respond to your inquiry | Replying to a form, email, call, chat, or text | Steps prior to entering a contract; legitimate interests |
| Provide and administer the Services | Onboarding, project delivery, reporting, invoicing, support | Performance of a contract |
| Site operation and security | Serving pages, load balancing, fraud and abuse prevention, spam filtering, backups | Legitimate interests; legal obligation |
| Measure and improve the Site | Analytics, A/B testing, heatmaps, session review, fixing usability problems | Consent (where required); legitimate interests |
| Marketing and attribution | Email marketing to people who opted in, retargeting audiences, measuring which channels produce leads | Consent (where required); legitimate interests |
| SMS messaging | Sending appointment, project, and — where separately consented — promotional texts | Consent |
| Legal and compliance | Records retention, responding to legal process, enforcing our terms, defending claims | Legal obligation; legitimate interests |
Where we rely on legitimate interests, we have considered whether our interest is overridden by your rights and have limited what we collect accordingly. You can object at any time using the contact details in Section 1.
We do not use your personal information to make decisions about you by automated means that produce legal or similarly significant effects.
4. Cookies, Analytics, and Tracking Technologies
The Site uses cookies, pixels, local storage, and similar technologies. The Cookie Policy lists every category and, tool by tool, what is set and for how long.
Summary of what runs on the Site:
| Tool | Provider | What it does |
|---|---|---|
| Google Analytics 4 | Google LLC | Site traffic and engagement measurement |
| Google Search Console | Google LLC | Search performance reporting (no cookies set on visitors) |
| Google Ads and the Google tag | Google LLC | Conversion measurement and remarketing |
| HubSpot | HubSpot, Inc. | CRM, forms, email marketing, visitor tracking |
Controlling tracking. Use the Cookie Settings link in the Site footer to review and change your choices at any time. Non-essential cookies are blocked until you consent if you are visiting from the European Economic Area, the United Kingdom, or Switzerland. You can also block or delete cookies in your browser, and you can opt out of Google Analytics across all sites using the Google Analytics Opt-out Browser Add-on.
Global Privacy Control.
5. How We Share Information
We do not sell your personal information for money. We disclose personal information only as described here.
5.1 Service providers and processors
These vendors process personal information on our behalf, under contract, and are not permitted to use it for their own purposes.
| Vendor | What they receive | Their role |
|---|---|---|
| WP Engine | Server logs, IP addresses, form submissions in transit | Website hosting and CDN |
| Google LLC | Site usage events, advertising identifiers, hashed conversion data where enhanced conversions are enabled | Analytics and advertising measurement under Google’s terms. |
| HubSpot, Inc. | Names, email addresses, phone numbers, company details, form and email engagement, site page views tied to a contact record | CRM and marketing platform. HubSpot acts as our processor and, for California purposes, as a service provider that does not sell or share personal information. |
| Twilio Inc. | Mobile phone numbers, message content, and delivery metadata | SMS delivery. Twilio acts as our processor for messages we send, and as an independent controller of a limited set of data it needs for network security, abuse prevention, and legal compliance. |
| HubSpot Meetings | Name, email, meeting details | Appointment scheduling |
Mobile carriers also receive the phone number and message content necessary to deliver a text message. Carriers are not our vendors and we do not control what they retain.
5.2 Advertising partners
Where you have consented, Google receives advertising identifiers so we can measure conversions and show ads to people who have visited the Site. Under several state privacy laws this counts as “sharing” for cross-context behavioral advertising or as a “sale,” even though no money changes hands. You can opt out — see Section 4 and Section 8.
5.3 Other disclosures
- Professional advisers — our attorney, accountant, and insurers, under duties of confidentiality.
- Legal process — where we are required to by law, subpoena, court order, or other legal process, or where disclosure is necessary to protect our rights, safety, or property, or that of others. Where we are permitted to notify you first, we will.
- Business transfer — if Bradford Strategies is acquired, merged, or its assets are sold, personal information may transfer as part of that transaction. We will post notice on the Site if the new owner intends to use it in a materially different way.
We never share mobile phone numbers or SMS consent data with third parties or affiliates for marketing purposes. See Section 6.
6. Phone Calls, Text Messages, and Recording
6.1 Text messaging
We do not share, sell, or provide your mobile phone number or messaging consent data to third parties or affiliates for marketing or promotional purposes. Mobile phone numbers collected for SMS and the record of your consent are used solely to operate our messaging program and are disclosed only to the messaging provider and mobile carriers that deliver the message.
You must opt in before we text you. Message frequency varies. Message and data rates may apply. Reply STOP to any message to stop, or HELP for help. Full details are in our SMS Terms and Consent page.
6.2 Calls and call recording
We do not record phone calls. We do capture the phone number you called from and basic call metadata for attribution purposes.
7. How Long We Keep Information
| Record type | Retention |
|---|---|
| Website analytics events | Per the retention setting in Google Analytics, then deleted. Aggregate reports may be kept longer. |
| SMS message records | Available in Twilio for up to 13 months, after which they are no longer retrievable through Twilio’s console or API. Consent records are kept for at least 4 years after opt-out, because that is the TCPA limitations period and the consent record is our defense. |
| Lead and prospect records | 3 years from last meaningful contact, then deleted or de-identified |
| Client records, contracts, and deliverables | Term of the engagement plus 7 years |
| Billing and tax records | 7 years |
| Email marketing subscriber records | Until you unsubscribe, plus a permanent suppression entry so we do not re-add you |
| Backups | Overwritten on a rolling 30-day cycle |
Where we are required to keep something longer to comply with law or to resolve a dispute, we keep only what is necessary for that purpose.
8. Your Privacy Rights
We extend the rights below to every visitor, regardless of where you live. Where a state or country gives you a right we have not listed, you have that right too.
8.1 Rights available to everyone
- Know and access — what we hold about you, where it came from, why we have it, and who we disclosed it to.
- Correct — fix inaccurate information.
- Delete — have your information erased, subject to records we must keep by law.
- Portability — receive a copy in a portable, machine-readable format.
- Opt out of targeted advertising and of any sale or sharing of personal information.
- Opt out of marketing — unsubscribe from email, reply STOP to texts.
- Limit the use of sensitive personal information — we do not collect it through the Site, but the right stands.
- Appeal — if we deny a request, you may appeal (Section 8.4).
- No retaliation — we will not deny you services, charge you a different price, or give you a lower level of service for exercising a privacy right.
8.2 State-specific notes
Pennsylvania. As of the effective date of this policy, Pennsylvania has no comprehensive consumer privacy law in force. House Bill 78, the Consumer Data Privacy Act, passed the Pennsylvania House in October 2025 and remains pending in the Senate. We give Pennsylvania residents the rights in Section 8.1 as a matter of policy. Pennsylvania’s Breach of Personal Information Notification Act, 73 P.S. § 2301 et seq., applies to us and is addressed in Section 9.
California (CCPA/CPRA). In the preceding 12 months we collected the categories in Section 2 for the purposes in Section 3, from the sources in Section 2, and disclosed them to the recipients in Section 5. We do not sell personal information for monetary consideration. We do share personal information for cross-context behavioral advertising when you consent to advertising cookies, and you may opt out through the Do Not Sell or Share link, the Cookie Settings control. We do not have actual knowledge that we sell or share the personal information of consumers under 16. We do not collect sensitive personal information through the Site. You may use an authorized agent (Section 8.3).
Colorado, Connecticut, Delaware, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Texas, Virginia, Utah, Iowa, Tennessee, Indiana, Kentucky, Rhode Island, Florida. These states have comprehensive consumer privacy laws in effect. Residents have the rights in Section 8.1, subject to each statute’s own limits and thresholds. Minnesota residents additionally have the right to question the result of profiling and to review the personal data used in it; we do not profile in a way that produces legal or similarly significant effects. Oregon residents may request a list of the specific third parties to which we have disclosed personal data.
We update this list when a new law takes effect, not when it is passed. Laws enacted but not yet in force as of the effective date of this policy include Louisiana and Oklahoma (January 1, 2027), Alabama (May 1, 2027), and Vermont (January 1, 2028).
Nevada. Nevada residents may direct us not to sell covered information. We do not sell it.
8.3 How to submit a request
Email [email protected] with the subject line “Privacy Request,” or write to the address in Section 1. Tell us which right you are exercising and give us enough detail to find your records.
Verification. To protect you, we verify requests before acting. Usually that means confirming control of the email address or phone number in our records, and matching two or three data points you give us against what we hold. For deletion requests we may ask for a second confirmation. We do not require an account.
Authorized agents. An agent may submit a request on your behalf with written permission signed by you, or a valid power of attorney. We may contact you directly to confirm.
Timing. We acknowledge within 10 business days and substantively respond within 45 days. If we need more time we will tell you why and take up to 45 additional days. There is no charge for a reasonable request; we may charge or decline if a request is manifestly unfounded, excessive, or repetitive, and we will tell you why.
8.4 Appeals
If we deny your request, reply to our decision within 60 days with the word “Appeal.” A person who was not involved in the original decision will review it and respond in writing within 45 days, explaining the outcome and the reasons. If your appeal is denied you may contact your state Attorney General. California residents may also contact the California Privacy Protection Agency.
9. Security and Breach Notification
We use administrative, technical, and physical safeguards appropriate to the size of our business and the sensitivity of the data, including:
- TLS encryption in transit across the Site and our forms
- Multi-factor authentication on business-critical accounts (email, hosting, CRM, advertising platforms)
- A password manager and unique credentials per system; no shared logins
- Access limited to the people who need it for their role, removed promptly when a person or contractor leaves
- Vendors selected in part on their security posture and bound by written data protection terms
- Regular software and plugin updates on the Site, and automated backups
No system is perfectly secure and we do not promise that ours is. If a breach of your personal information occurs, we will notify you and the appropriate authorities as required by Pennsylvania’s Breach of Personal Information Notification Act, 73 P.S. § 2301 et seq., and by any other law that applies to you.
10. Children
The Site is for business audiences and is not directed to children. We do not knowingly collect personal information from anyone under 16. If you believe a child has given us information, email [email protected] and we will delete it.
11. International Visitors and Transfers
We are based in the United States. Our vendors are US-headquartered but may process or store data outside the United States through their own infrastructure and sub-processors; where they do, they are bound by the data protection terms in our contracts with them. If you access the Site from outside the United States, your information will be transferred to and processed in the United States, where privacy laws may differ from those in your country.
12. Do Not Track
Browsers may send a “Do Not Track” signal. There is no agreed standard for how a website should respond, so we do not respond to DNT.
13. Third-Party Sites and Content
The Site links to other websites and may embed third-party content such as maps, video players, or scheduling widgets. Those providers set their own cookies and follow their own privacy policies. This policy does not cover them. Review the policy of any site you visit from here.
14. Job Applicants
If you apply for a role or contract with us, we collect the information in your application and use it solely to evaluate your candidacy and, if we hire you, to onboard you. We keep applications for 12 months and then delete them. California job applicants have the rights in Section 8.1 with respect to that information.
15. When We Act on Behalf of a Client
Much of what we do involves handling personal information that belongs to a client’s customers or website visitors — for example when we manage a client’s Google Analytics, run their advertising, operate their CRM, or build their website.
In those engagements the client is the controller or business, and Bradford Strategies is a processor or service provider. We process that information only on the client’s documented instructions, only for the purposes in our agreement with them, and never for our own marketing. We do not sell or share it. We assist the client in responding to privacy requests and in meeting their own obligations, and we delete or return the data at the end of the engagement in accordance with the agreement.
If you are a customer of one of our clients and you want to exercise a privacy right, contact that business directly. They control the data. If you contact us instead, we will forward your request to them and let you know we have done so.
Our data processing terms are available to clients on request and are incorporated into our services agreement.
16. Changes to This Policy
We may update this policy. When we do, we change the “Last updated” date at the top. If a change is material — for example a new category of data, a new purpose, or a new class of recipient — we will post a notice on the Site for at least 30 days and, where required, ask for your consent. Prior versions are archived and available on request; if a question arises about our practices on a particular date, the version in effect on that date governs.
17. Questions
Email [email protected] or write to Bradford Strategies LLC, 306 S New St Ste 110, Box 116, Bethlehem, PA 18015. We read every message.
