Privacy
The short version: we collect what we need to build the rebuilds you asked for and to reply to you, plus a few things our host records on its own. We don't sell it, we don't feed it to advertising networks, and if you want it gone, one email removes it.
Who we are
Aff Tech Wiz is Tim Griffith LLC. Anything on this page — questions, corrections, deletion — goes to tim@afftechwiz.com.
What we collect
- What you type into the form. Your name, email, the brand, the ad link and the monthly ad spend range. If you open the optional section: your company, phone, a Telegram or WhatsApp handle, how you heard about us — and, if that wasn't on our list, what it was instead — how many ads you test in a month, and who makes your creative today. Only the name, email, brand and the ad itself are needed — the rest is yours to skip. Two fields fill themselves in: which of our pages you sent it from, and one box kept empty on purpose, because only a bot types in it.
- What our host files with it. Netlify takes the submission for us, and records three things off the request itself: your IP address — the address, not a hash of it — the page you sent it from, and your browser's user-agent string. They arrive with the submission whether we want them or not, nothing we run reads them, and they sit in that record until it's deleted. Spelling it out because the analytics line below says no IP address is stored: that is true of the analytics events, and only of those.
- The ad you send. A link, or the video file itself if you upload one. An uploaded file goes from your browser straight to our Google Drive; our own server hands your browser an upload slot and never receives the file.
- First-party page analytics. Viewing one of our offer pages, playing
one of the example videos, starting the form, uploading a file, or reaching the
confirmation page after you send it each send one short
event to this same site. (Not this page — reading the policy is measured nowhere.) The event holds a timestamp, which page, which action, a short label
(a file extension, say), the website you arrived from — its name only, like
google.com, never the full address you came from — any tag we put on our own link so we can tell which of our emails or posts you followed, and your browser's user-agent string. That event holds no name, no email, no IP address and no identifier that could follow you anywhere. - A recording of your visit, and a product-analytics record beside it. We use PostHog to understand where these pages lose people. It is served from our own domain — your browser never contacts anyone else to load it — but the data does go to PostHog, and it collects more than the events above, so here is all of it. It records the visit itself: the pages you moved through, where you scrolled, what you clicked, and a replay of that as a video we can watch back. Everything you type into the form is blanked out before it leaves your browser — the name, the email, the phone number, the handle. The masking runs on your machine, so the unmasked text never reaches PostHog and there is no version of it to hand over or leak. It also records your IP address, your approximate city from it, your browser, and your device and screen size. And it puts a random identifier on your device so a second visit is recognised as the same visitor rather than a new one — that is the thing the events above deliberately do not do, and it is the honest trade for being able to tell twelve visits from twelve people. It is not your name and we cannot turn it into one, but it does follow you between visits to this site.
- Technical telemetry from the same tool. Alongside the recording, PostHog collects things about how the page ran rather than about you: how fast it loaded and drew (standard web performance timings), the position of your pointer and your clicks — which is what builds a heat map of where people look and tap — the browser console's own messages, and the details of any JavaScript error that happens while you're here, including the error text and the line of our code it came from. The console and the error text are ours, not yours: they are our code complaining about itself. It also times the network requests this page makes back to us — which request, and how long it took — but never what was inside them.
- An abuse counter, if you upload. Uploading is the one thing here that costs us something to leave open, so it is rate limited. To do that we store a one-way hash of your IP address alongside an hourly count. We do not store the address itself, and the hash cannot be turned back into one.
What we do with it
Build the rebuilds and email them to you. Reply to you, and follow up about the work. Read the analytics to see which pages do their job — page-by-page totals, a list of the most recent events with each one's user-agent string beside it, and, in PostHog, the funnel from landing on a page to sending the form, plus recordings of individual visits when we're trying to work out why a page loses people. Count uploads per hour, against that hashed address, so one person can't close the free door on everyone else. That is the entire list. We do not use any of it to build a profile of you, to score you, or to target you with advertising anywhere.
What we never do
- Sell, rent, or trade your details. Nobody buys this list because there is no list to buy.
- Run advertising or ad-network scripts. There are no ad pixels here, nothing from an ad network, no external fonts, and nothing that follows you off this site to somewhere else. The one third-party tool on these pages is the product analytics described above, and it is served from our own domain rather than someone else's.
- Set an advertising cookie, or any cookie that works across other people's websites. Two things go on your device, both first-party and both listed above: the analytics identifier, which is only ever read back by this site, and a single session-storage entry when you submit the form — which page you came from, the time you sent it, and the booking link that page offers, if it offers one — so the confirmation page can show you your delivery deadline. That second one disappears when you close the tab. You can clear either from your browser at any time; nothing here tries to put it back by another route.
- Add you to a mailing list you didn't ask to be on.
Who else handles it
- Netlify hosts this site, stores the form submissions — each one with the IP address, referrer and user-agent described above — and stores the analytics events.
- Google Drive holds the video file, if you upload one: a shared drive Tim Griffith LLC owns, where the file lands under your own filename with a timestamp in front of it.
- PostHog receives the recordings and the product-analytics records described above, including the IP address and the identifier. Their servers are in the United States. Nothing you type into the form reaches them.
- If you follow a link off this site — a scheduling page, for example — whatever you do there is covered by that service's own policy, not this one.
Beyond those three, nobody. We don't sell your details, we don't share them with partners or ad networks, and nothing here feeds anyone else's tool.
How long we keep it
Your submission — the IP address, referrer and user-agent our host filed with it included — and the ad you sent stay in our records while we're working on them and for as long as it's reasonable that we'd follow up. Analytics events are written to a log file per day and kept as history. Neither is on an automatic purge, so the honest answer is: until you ask, or until we clear it out. The recordings and analytics held at PostHog are the one exception: those age out on PostHog's own retention schedule, which we don't set and can't extend.
Ask and it goes. Email tim@afftechwiz.com and we will remove your submission — the record at Netlify, that IP address with it — the ad you sent us and anything built from it, and your recordings and analytics at PostHog, and confirm when it's done. You can ask for a copy of what we hold the same way.
If you would rather not be recorded at all, turn on your browser's do not track setting: we check it, and when it is on nothing is recorded and no identifier is set. The pages work exactly the same either way. And one thing you would not guess, so we will say it plainly: the analytics are served from our own domain rather than PostHog's, which means a content blocker that would normally catch them may not. That is a deliberate choice on our part, and it is why the do not track switch is the one that actually works here.
Changes
If any of the above stops being true, this page changes with it.
Last updated 31 July 2026.