back to EV1 Labs

Privacy.

The public site is static and intentionally low-data. It uses cookie-free first-party metrics to understand page views, source attribution and buyer actions without ad pixels, remarketing or cross-session advertising profiles. Contact details are received only when a visitor submits a brief or sends an email.

static site first-party metrics local Daily Signal traces
site data

Cookie-free metrics

EV1 Labs records aggregate page, source and CTA signals through its own Worker endpoint. It does not set analytics cookies, create remarketing audiences or run Google, Meta or LinkedIn pixels. The metrics script may use sessionStorage for a random per-tab session id and first-touch UTM/referrer while you navigate the site. These aggregate records may include a coarse country code supplied by Cloudflare and may be stored in a Cloudflare D1 database for first-party reporting. EV1 Labs can explicitly mark its own QA tab so those checks stay outside visitor KPIs.

daily signal

Local-only scores

The Daily Signal game may save a nickname and score in the visitor's own browser storage. It is not a public leaderboard or server-side account system.

submitted brief

You choose what to send

When you submit the brief form, EV1 Labs stores the contact email, company or product name, the workflow context you provide, the selected route and limited first-touch attribution in its Cloudflare D1 database so the inquiry can be answered. The same context is received when you choose the email fallback. No IP address is stored as a lead field. Do not send secrets, passwords, production credentials, identity documents or customer records.

controller and purpose

Why EV1 Labs uses the data

EV1 Labs is the controller for the site metrics and submitted inquiries described here. Contact tiger@ev1labs.com. Brief data is used to answer your request and take steps you ask for before a possible contract. Low-data site measurement, service security and abuse prevention rely on EV1 Labs' legitimate interests in operating and improving this public service.

retention and providers

Limited storage

A submitted brief becomes eligible for deletion after 12 months. If the inquiry becomes client work, any contract or accounting record is handled separately for the period required by the contract or law. Aggregate first-party metrics become eligible for deletion after 13 months. EV1 Labs reviews these thresholds at least monthly and removes expired rows in an approved retention run, so a record may remain until the next periodic run. Cloudflare processes the site, Worker and D1 data on EV1 Labs' behalf; an email provider processes the email fallback. The data is not sold or used for advertising audiences.

your rights

Access, correction and deletion

You may ask EV1 Labs to access, correct, delete or restrict your personal data, object to legitimate-interest processing, or receive data you supplied where portability applies. Contact tiger@ev1labs.com. You may also complain to the Lithuanian State Data Protection Inspectorate. EV1 Labs does not use the brief for automated decisions or profiling.

what is measured

Small event payload

The first-party metrics event can include page path, referrer hostname, approved UTM tags, first-touch attribution, language route, coarse device class, section id, scroll depth, engagement time, viewport size, coarse country code, link click type, CTA event id and whether the server accepted a brief. The aggregate metrics record does not include brief text, contact email, private messages, passwords, IP addresses as stored report fields, persistent cross-session profiles or full query strings. Contact details and brief text stay in the separate inquiry record used to answer the sender, not in the growth dashboard or retargeting audiences.

client work

Privacy is part of scope

Product builds should define what data is collected, where it lives, who can access it and what must be avoided before launch.

next signal

Send only what is useful.

A first brief needs product context, not private credentials. Keep sensitive access details out of the form and the email fallback.

Open brief