site data
Cookie-free metrics
EV1 Labs records aggregate page, source and CTA signals through its
own Worker endpoint. It does not set analytics cookies, create
remarketing audiences or run Google, Meta or LinkedIn pixels. The
metrics script may use sessionStorage for a random per-tab session
id and first-touch UTM/referrer while you navigate the site. These
aggregate records may include a coarse country code supplied by
Cloudflare and may be stored in a Cloudflare D1 database for
first-party reporting. EV1 Labs can explicitly mark its own QA tab
so those checks stay outside visitor KPIs.
daily signal
Local-only scores
The Daily Signal game may save a nickname and score in the visitor's
own browser storage. It is not a public leaderboard or server-side
account system.
submitted brief
You choose what to send
When you submit the brief form, EV1 Labs stores the contact email,
company or product name, the workflow context you provide, the
selected route and limited first-touch attribution in its
Cloudflare D1 database so the inquiry can be answered. The same
context is received when you choose the email fallback. No IP
address is stored as a lead field. Do not send secrets, passwords,
production credentials, identity documents or customer records.
controller and purpose
Why EV1 Labs uses the data
EV1 Labs is the controller for the site metrics and submitted
inquiries described here. Contact
tiger@ev1labs.com.
Brief data is used to answer your request and take steps you ask
for before a possible contract. Low-data site measurement, service
security and abuse prevention rely on EV1 Labs' legitimate
interests in operating and improving this public service.
retention and providers
Limited storage
A submitted brief becomes eligible for deletion after 12 months.
If the inquiry becomes client work, any contract or accounting
record is handled separately for the period required by the
contract or law. Aggregate first-party metrics become eligible for
deletion after 13 months. EV1 Labs reviews these thresholds at
least monthly and removes expired rows in an approved retention
run, so a record may remain until the next periodic run. Cloudflare
processes the site, Worker and D1 data on EV1 Labs' behalf; an
email provider processes the email fallback. The data is not sold
or used for advertising audiences.
your rights
Access, correction and deletion
You may ask EV1 Labs to access, correct, delete or restrict your
personal data, object to legitimate-interest processing, or receive
data you supplied where portability applies. Contact
tiger@ev1labs.com.
You may also complain to the
Lithuanian State Data Protection Inspectorate.
EV1 Labs does not use the brief for automated decisions or
profiling.
what is measured
Small event payload
The first-party metrics event can include page path, referrer
hostname, approved UTM tags, first-touch attribution, language
route, coarse device class, section id, scroll depth, engagement
time, viewport size, coarse country code, link click type, CTA event
id and whether the server accepted a brief. The aggregate metrics
record does not include brief text, contact email, private
messages, passwords, IP addresses as stored report fields,
persistent cross-session profiles or full query strings. Contact
details and brief text stay in the separate inquiry record used to
answer the sender, not in the growth dashboard or retargeting
audiences.
client work
Privacy is part of scope
Product builds should define what data is collected, where it lives,
who can access it and what must be avoided before launch.