Privacy policy
Last updated 19 July 2026
Short version: this website runs Google Analytics on most of its pages, and that's the only outside service involved. There are no forms, no advertising pixels and no session recording. Every cookie and stored value is listed below. The only place you hand over your name and email is the booking page, and that's run by Cal.com.
Who we are
Operational Roofing builds custom software systems for roofing companies. This policy covers the website at operationalroofing.com. If you want anything here explained or acted on, email hashir@ripeseed.io.
What this website collects
The site is a set of static files served from Amazon S3 through Amazon CloudFront. There is no database behind it, no login, no contact form and no comment system.
We run Google Analytics 4, loaded from googletagmanager.com. It exists for one reason: we pay for ads, and we need to know which ones bring people who actually book a call. Here is what it records:
- Your device, browser, operating system and screen size.
- A rough location — city level at best — worked out from your IP address.
- The page that sent you here, and any campaign tags on the link you clicked.
- Which pages you viewed, how long you stayed and how far down you scrolled.
- Which buttons you clicked, including every "Book a Call" button.
- Whether the demo video played, and whether you watched it to the end.
- Whether you moved the sliders on the calculator, and the figures it worked out.
- Clicks on links to our own blog posts.
- If you click the same spot three times over — usually a sign something looked clickable and wasn't. We record the tag and class name of what you hit, like "div.card". Not where it was on screen.
- The moment your cursor leaves the top of the window, which normally means you're about to close the tab. We record how many seconds you'd been on the page. Nothing else.
Some of that comes from the page itself and some from enhanced measurement, a set of defaults Google switches on in its own console rather than in our code — clicks on links that lead off this site are the notable one. So read the list as what we ask for, not as a ceiling on what Google's defaults add.
None of that is attached to your name. Google gives your browser a random ID and the records hang off that. Those records expire after 14 months — the longest window Google offers, and the one this property runs. What outlives them is the aggregate: counts like how many people read a page last March, which aren't tied to any browser.
Your IP address. Google uses it to work out the rough location above, then discards it. Google Analytics never shows us a raw IP address. Amazon Web Services also processes the technical request data any web server sees — IP address, browser type, page requested — to deliver the page and protect the service. We keep those server access logs for 90 days, then they are deleted automatically. Each line holds an IP address, the browser's user-agent string, the page requested and the time. We read them for two things: to tell real visitors apart from the search-engine and AI crawlers that never run the analytics code above, and to find broken links and errors. We do not use them to build a profile of you, and they are never combined with the analytics data.
Cookies and browser storage
Here is everything the site can put in your browser. The cookies are Google's; the local storage values are ours.
- _ga — set by Google Analytics, expires after 2 years. Holds the random ID for your browser.
- _ga_<measurement id> — set by Google Analytics, expires after 2 years. Keeps track of the current visit.
- _gcl_au — set by Google's tag only once Google Analytics is connected to Google Ads, expires after 90 days. It ties a booking back to the ad that paid for the click. Until we switch that connection on, it never appears.
- or_attr — local storage. Remembers the campaign tags on the link you first arrived through, so a call booked three weeks later still credits the right ad. The clock starts when it is first written and is never pushed forward: once 90 days are up, the next page of ours you open deletes it.
- or_debug — local storage. Only ever set if someone visits with "?or_debug=1" in the address bar, which marks a browser as ours so our own visits stay out of the numbers.
Clearing cookies and site data in your browser removes every one of them. Nothing on the site breaks if you do.
What we deliberately don't do
This part matters more than the list above, so we'll be specific.
- No session replay and no heatmaps. Two things on the page do watch the cursor, and both are in the list above: a count of repeated clicks in one spot, and a check for the cursor leaving the top of the window. Neither one sends where your cursor was. Coordinates, keystrokes, the contents of your screen, and anything that could be played back as video are never transmitted and never stored — not by us, not by Google.
- No advertising pixel. Meta, Google Ads, TikTok, LinkedIn — none of them are on this page. Nothing here builds an ad audience out of you.
- No fingerprinting. Nothing tries to identify your browser through canvas, fonts, hardware or any other indirect signal.
- No data brokers. We don't buy lists, we don't enrich visitors against third-party databases, and we don't try to work out which company an anonymous visitor came from.
Fonts and other files
Every font, image, video and script the site uses is served from our own domain. Google Analytics is the single exception, and it is the only third party your browser contacts on the pages that carry it: the home page, the blog index, every blog post, and the confirmation page you land on after booking. This privacy page and the 404 page carry no script at all, so viewing either one contacts nobody but us.
When you book a call
The "Book a Call" buttons take you to Cal.com, a separate scheduling service. If you book, you give Cal.com information such as your name, your email address and anything you type into the booking notes. That happens on their platform under their terms, and we receive the booking details so we can turn up to the call.
When you click one of those buttons, we add the campaign tags from your visit and your Google Analytics browser and session IDs to the link. That is how a booked call gets matched back to the ad that produced it. It tells Cal.com nothing about you beyond what you type in yourself. After you book, Cal.com sends you to a thank-you page on our site, and that page records that a booking completed.
- What we do with it: contact you about the call you booked, and follow up about working together.
- What we don't do with it: sell it, rent it, or hand it to anyone for their own marketing.
- How long we keep it: as long as we're in contact about a possible or active engagement, and afterwards only where we need it for records. Ask and we'll delete it.
Cal.com is an independent company and its handling of your data is governed by its own privacy policy, not this one. Read it at cal.com/privacy.
If you email us, we keep the message and your address so we can reply and keep track of the conversation. Nothing more.
Turning the tracking off
Global Privacy Control. If your browser or an extension sends a Global Privacy Control signal, we read it and switch off Google's advertising signals for your visit. Basic measurement — pages viewed, buttons clicked — stays on. We don't show a cookie banner, because our traffic is US-based and no US state requires opt-in consent for analytics.
Do Not Track. We do not act on the older Do Not Track header. No agreed standard ever emerged for what a website should do when it sees one, so claiming we honour it would mean nothing.
You can also opt out of Google Analytics everywhere with Google's browser opt-out add-on, change what Google uses your activity for at adssettings.google.com, or block the tag with any content blocker. Any of those works on this site and none of them breaks it.
Your rights over your information
Wherever you live, you can ask us what we hold about you, ask us to correct it, or ask us to delete it. Depending on where you live — for example, under the CCPA in California, or the GDPR in the UK and EU — you may also have the right to object to certain processing, to receive a copy of your data in a portable format, and to complain to a data protection regulator.
We do not sell personal information for money, and we don't hand it to anyone for their own marketing. Some US privacy laws treat analytics that feed an advertising platform as "sharing" — which is exactly why we honour Global Privacy Control, and why turning it on shuts Google's advertising signals off. To exercise any of these rights, email hashir@ripeseed.io. We'll respond within 30 days.
Children
This is a business-to-business website. It isn't directed at children and we don't knowingly collect information from anyone under 16.
Changes to this policy
If we add anything that changes what's collected — an advertising pixel, session recording, a contact form — we'll update this page and change the date at the top before it goes live.