POLARITYAGENCY
The Polarity Agency

The Polarity Agency / Privacy notice

Privacy notice.

What we collect, why, and what you can ask us to do about it.

Polarity Management LLC, a New Jersey limited liability company at 101 Vera King Farris Drive, Galloway, NJ 08205, trading as The Polarity Agency. We are the controller of the information described here.

Effective 30 July 2026 · Version 2.1, revised 26 August 2026

What changed in 2.1: sections 3.2, 6.2, 6.3 and 6.4, so that what this notice says about your browser storage matches what our software actually does. The value recording where you arrived from lives longer than the notice previously said, and now says so. One item the notice listed is gone, because no such thing was ever stored. Nothing new is collected, and the version number moved so this text can be told apart from the one before it.

We wrote this to be read. If anything here is unclear, or you want something done with your information, email inquiries@polarityagc.com and a person will answer you.

1. The short version

You come to this site, and we would like to work with you. To do that we need a few things from you, and our website records a few things automatically. Here is all of it, honestly:

We do not sell your information. We do not buy it from data brokers. We use no third-party analytics service, no advertising pixels, no tracking cookies, and no session-replay or heatmap tools. Nothing you tell us is used to advertise to you anywhere.

We would rather tell you exactly what we record than claim we record nothing. The list above is the whole list.

2. What you send us

2.1 Our enquiry form asks for your name, your email, your business name, and a message describing what you need. Depending on which form you use, it may also ask what you are interested in, any links you want to share, and whether we have spoken before.

2.2 On the consultation form you may attach files. This is optional, an enquiry without attachments is complete, and not attaching anything is never held against you. We accept up to 5 files totalling 4 MB, in PDF, plain text, CSV, PNG, JPEG or WebP. We check that a file's actual contents match the type it claims to be, and reject anything else. We do not run anti-malware scanning.

2.3 Please do not send us passwords, security codes, multi-factor authentication secrets, payment card numbers, government ID numbers, health records, or anything confidential that belongs to someone else without their permission. We do not ask for any of it, and a system that never receives something cannot leak it. If you send one anyway, we will delete it and tell you to change it.

2.4 If you send us information about another person, please make sure you are allowed to. If they contact us about it, we will deal with them directly.

3. What the website records on its own

3.1 When you load a page, our own server records the page path, the site that referred you, the page you first landed on, any campaign tag in your link (utm_source, utm_medium, utm_campaign, utm_term, utm_content, gclid, msclkid), your screen size, and a scrambled visitor identifier. This is our own first-party measurement; it does not leave our server, no advertising network sees it, and it is not a third-party analytics product. We use it to answer one question: is anyone finding us, and from where.

3.2 When you send an enquiry, four of those values travel with it, the referrer, the landing page, the campaign tag and when we first saw you, and are stored alongside your enquiry. That means an enquiry in our inbox carries a note of where it came from. "When we first saw you" is not this visit and it is not this browser session. It is the first-touch value described in section 6.2, which your browser keeps for up to 30 days, so it can be older than the enquiry by weeks.

3.3 If your browser sends a Do Not Track signal, we skip the page measurement in 3.1 entirely.

3.4 We also log recognised search-engine and AI crawlers separately, so we can see which ones read the site. That log contains no personal information about human visitors.

3.5 We do not fingerprint your device or browser beyond the screen size named in 3.1, we do not collect precise location, we do not track you across other websites, and we run no social login or embedded social widget that would report your visit to anyone.

4. Your IP address

4.1 We do not store your IP address. Before anything is written down, it is put through a keyed one-way hash using a secret held on our server, and only the result is kept.

4.2 Being honest about what that does and does not achieve: the same address always produces the same hash, which is exactly what makes rate-limiting work, and it also means the value is still personal data, not anonymous data, and we treat it that way. Its protection rests on our key staying secret. Your raw address may also appear briefly in our hosting provider's own edge logs, which we do not control.

5. What we use it for

5.1 To read your enquiry, decide whether we are a fit, and reply to you.

5.2 To do the work, if we go on to work together, and to invoice you for it.

5.3 To keep the site up and stop abuse. That is what the hashed IP and rate limiting are for.

5.4 To understand which of our efforts reach people. That is what section 3 is for.

5.5 To meet our legal obligations, and to establish or defend a legal claim if one arises.

5.6 If we ever want to use your information for something not on this list, we will ask first.

5.7 In the EEA and the UK, our legal bases are: performing a contract or taking steps before one at your request (5.1, 5.2); our legitimate interests in a secure, functioning, sustainable business (5.3, 5.4); legal obligation (5.5); and consent where we ask for it. You can object to anything we do on legitimate interests, see section 9.

6. What is stored on your device

6.1 We set two cookies, both of them necessary and neither used for tracking. A session cookie that lasts 12 hours protects our forms against cross-site request forgery. Our older owner-access gate issues an 8-hour cookie to whoever holds a single shared key, and we can revoke it from our side immediately. Workspace members who sign in individually get a separate session token from our authentication provider instead, held in browser storage, see section 6.2.

6.2 We also use your browser's own storage. We name the keys, because a list you cannot check against your own browser is not a list you can hold us to, and this is the complete one:

6.3 None of these are advertising technologies and none of them are third party. There is no ad network, no data broker and no analytics vendor holding any of them. You can clear them at any time in your browser and the site will still work. If we ever add analytics or advertising technology, we will build a real consent mechanism and tell you 30 days before it goes live.

6.4 One of them deserves a straight answer rather than a comfortable one. The where-you-arrived-from value, polarity_first_touch, is not needed to show you this site, and because it survives up to 30 days it can join a visit today to a visit two weeks ago on the same device. That is a difference in kind from the theme choice and the animation flag, which do nothing across visits. So we are not going to tell you it is strictly necessary storage exempt from consent in the EEA or the UK on our own say so. Whether consent is required for it there is an open question we have flagged for legal review rather than answered ourselves, and if the answer is that it is, we will ask you before storing it rather than after. Until then: it is first-party, it holds no name, email or IP address, clearing your browser storage removes it, and nothing on the site breaks when it is gone.

7. Who else sees it

7.1 We keep this list short on purpose. Your information reaches:

7.2 That is all of them. No advertising network, no data broker, no analytics vendor, no enrichment service, no list vendor. We will name the specific providers if you ask.

7.3 We may also disclose information if the law genuinely requires it, and if that happens we will review the demand, push back on anything overbroad, and tell you unless we are legally forbidden from doing so. We will not volunteer your information to any authority without legal compulsion or a genuine emergency.

7.4 This notice covers what we do. It does not cover other people’s websites you reach from links here, and it does not cover a brand, publisher, sponsor or counterparty we introduce a client to, once information reaches them, they decide what happens to it and their own privacy terms apply. We will tell you before any first disclosure into a new relationship of that kind.

7.5 On production start-up our server pings the IndexNow search network with page addresses so search engines learn the site changed. No personal information is sent.

7.6 If our business is ever sold or merged, information may transfer as part of it, under confidentiality, and the buyer would be bound by this notice or would have to give you notice and a choice.

7.7 We use AI-assisted tools in our own work, drafting, summarising, research. We do not put your confidential material into any tool that trains on what it is given. No application is ever decided by an automated system: a person reads every one. You can ask us not to use AI-assisted tools on your material, and for enquiries we will honour that without conditions.

8. How long we keep it, and what we owe you here

8.1 Being straight with you, because this is the part most privacy notices overstate: we do not currently run an automatic deletion schedule. Enquiries, the records of what we decided, and any files you attached are kept until we delete them by hand. Our page-measurement and crawler logs stop accepting new entries once they reach a size limit, but old entries are not aged out.

8.2 What that means for you in practice: if you want your information deleted, ask us and we will do it, see section 9. We will not tell you an automated purge has already handled it when it has not.

8.3 Building that automatic purge is work we owe, and it is on our list. When it is running, this section will say so and will state the actual periods.

8.4 Some things do expire on their own today: the session cookie after 12 hours, the login cookie after 8 hours, and workspace invitations after 7 days and one use.

8.5 If we are legally required to preserve something for a dispute or an investigation, we will keep it until that ends.

9. What you can ask us to do

9.1 Whoever you are and wherever you live, you can ask us to: tell you what we hold about you and where we got it; correct it; delete it; give you a copy in a portable form; stop or limit a particular use; object to anything we do on the basis of legitimate interests; or withdraw a consent you gave us.

9.2 We extend these to everyone, whether or not the law where you live requires it.

9.3 Email inquiries@polarityagc.com with "Privacy request" in the subject. We will acknowledge you within 10 business days and answer within 30 days, or tell you why we need longer.

9.4 It is free, and asking is never held against you or your application. We will not ask you to send a government ID, a photograph of yourself, or a Social Security number to prove who you are, replying from the address you contacted us on is normally enough. An authorised representative can act for you.

9.5 If we have to refuse part of a request, because the law requires us to keep something, or because it would expose someone else's information, we will tell you which part and why.

9.6 If you are unhappy with our answer, you can reply and ask us to look again, and you can complain to your data protection authority or state Attorney General at any time. You do not have to come to us first.

9.7 We run no loyalty scheme, referral bounty or price difference that asks you to trade information for a benefit. We do not sell personal information or share it for cross-context behavioural advertising, and we have not done so in the past twelve months. That is true for everyone, including anyone under 16. So a "do not sell my information" request has nothing to act on, and a Global Privacy Control signal changes nothing about how we treat you; there is nothing for it to switch off.

10. Keeping it safe

10.1 Our security approach starts with collecting less, because the safest record is the one that was never created.

10.2 In practice: everything travels over an encrypted connection; our forms are protected against cross-site request forgery and rate-limited against abuse; uploads are checked so a file's real contents must match its declared type; access to enquiries is limited to the people reviewing them; and IP addresses are hashed as described in section 4.

10.3 Worth knowing, and stronger than we used to claim: files you attach cannot be downloaded back through this website by anyone, including us. There is no route in our software that reads them out. Our own admin view shows only a file's name, size and type.

10.4 Being precise about logins rather than making a blanket claim: our workspace accounts require multi-factor authentication for privileged access. Our older owner-access gate is a single shared key without a second factor, and we are replacing it.

10.5 No system is perfectly secure and we will not pretend otherwise. If something happens that puts your information at risk, we will investigate, contain it, and tell you and any regulator we must, within the time the law requires. Because we never accept passwords or card numbers, no incident here can expose those from us.

10.6 If you find a vulnerability, tell us at inquiries@polarityagc.com. We will not pursue anyone who reports something in good faith and does not access or damage other people's data.

11. Where your information goes

11.1 We are based in the United States and our systems run there, so sending us information from elsewhere means transferring it to the US.

11.2 For transfers from the EEA, the UK or Switzerland we rely on the European Commission's standard contractual clauses and the UK addendum, and we assess whether they are adequate in the circumstances. We are not self-certified to the EU–US Data Privacy Framework. Ask us and we will send you a copy of the clauses.

11.3 We have not appointed an EU or UK representative, and we do not currently meet the threshold that requires a data protection officer. If that changes, this section will change with it.

12. Children

This site is for businesses and is not directed at children. We do not knowingly collect information from anyone under 18, and where the law sets a lower threshold for consent (13 in the United States, up to 16 in parts of Europe), we apply whichever is more protective. If you believe a child has sent us something, tell us and we will delete it promptly.

13. Working for a client

When we run systems on behalf of a client, we handle their customers' information on their instructions rather than our own. In that role the client decides what happens to it and their own privacy notice applies. We will only take that on under a written data processing agreement, and we will tell you plainly that ours is still being finalised, so we are not doing that work yet.

14. Automated decisions

14.1 No application is accepted or declined by a machine. People read them.

14.2 Two automated things do touch you, and neither judges you: rate limiting, which may briefly refuse a request if it arrives too fast or looks automated, and our email provider's spam filtering, which may quarantine a message. Neither scores you and neither affects how your application is assessed.

14.3 If either wrongly blocks you, email us and a person will sort it out.

14.4 We do not build behavioural profiles, we do not score applicants, and we do not train any model of our own on your information.

15. Changes, and how to reach us

15.1 We review this notice at least once a year. If we change it materially we will give at least 30 days' notice before the change takes effect, and we will keep previous versions available on request.

15.2 Everything, questions, privacy requests, complaints, a request for the list of our providers, or a copy of our transfer clauses, goes to inquiries@polarityagc.com, or by post to Polarity Management LLC, 101 Vera King Farris Drive, Galloway, NJ 08205.

15.3 If you need this notice in another format to read it comfortably, ask and we will provide one.

Return to Polarity