LEGAL

LAST UPDATED ·

Privacy policy.

What wroe.io collects, why, who helps us process it, and the choices you have. Written in plain English. If something is unclear, email ricky@wroe.io.

THE SHORT VERSION

ON THIS PAGE
  1. 01Who we are
  2. 02What we collect and when
  3. 03Cookies and browser storage
  4. 04Email checks
  5. 05How and why we use your information
  6. 06Who we share it with
  7. 07How long we keep it
  8. 08How we protect it
  9. 09International transfers
  10. 10Your rights
  11. 11Hiring inquiries
  12. 12Children
  13. 13Links to other sites
  14. 14Changes to this policy
  15. 15Contact

01

Who we are

Wroe is a growth practice run by Ricky and based in Miami, USA. We work with DTC and eCommerce brands. For this website, Wroe decides how and why your information is used. For GDPR purposes that makes Wroe the “controller”.

This policy covers wroe.io and the forms and emails that belong to it.

Contact for anything privacy-related: ricky@wroe.io

02

What we collect and when

When you fill in the application form

The form asks for:

  • Your answers: monthly revenue range, the biggest thing holding growth back, when you want to start, and your role.
  • Contact details: your first name and email address.
  • Your website (optional): you can leave it blank.

When you submit, your browser also sends:

  • How you found us: any campaign tags in the link you arrived on (utm_source, utm_medium, utm_campaign, utm_term, utm_content) and ad click IDs (gclid from Google, fbclid from Meta).
  • The page address you submitted from, and the referring page your browser reports, if any.
  • Your calculator estimate, if you used the revenue-leak calculator in the same browser session: the revenue figure you entered, the estimate it showed, and the issues you selected.

We also store:

  • An email check result. Before saving your application, we check that the email address can receive mail (see Email checks). We store the outcome, for example “deliverable”, “domain valid” or “unverified”. When Abstract API runs the check, we also store the basic flags it returns, such as whether the address looks disposable, role-based (like info@) or free webmail.
  • Record details. A random application ID, the date and time, the application’s status (submitted, scheduled or cancelled), the booking link we generated for you, a policy version reference, and a short log of what happened to the application (for example, that a booking was confirmed or an email was sent).

We do not store your IP address with your application.

When you book a call

After you submit the form, a Calendly booking calendar appears. We pre-fill it with your first name, email and campaign tags, plus your application ID so we can match the booking to your application. Anything you type into the calendar goes to Calendly. That includes the time you pick, your name and email, and any answers to Calendly’s questions.

When booking notifications are switched on, Calendly tells us when a booking is made or cancelled. We match it to your application by the application ID, or by your email address if the ID is missing. We store the booking’s reference links, the status and the time it was confirmed.

When you email us

We keep the emails you send us and our replies, so we can continue the conversation you started.

When you simply browse

  • Hosting and security logs. Like every website, our host (Cloudflare) processes technical data to deliver pages and protect the site: your IP address, browser type, the pages requested, and the time. If a page fails to load, your browser may also send Cloudflare a short network-error report.
  • Cookieless visitor statistics. We use Cloudflare Web Analytics to see aggregate numbers, such as page views, referrers, countries and page speed. Its small script loads from Cloudflare (static.cloudflareinsights.com). It doesn’t use cookies or local storage, and it doesn’t build a profile of you.
  • In-page events. The site records simple interaction events, such as “form step 2 viewed” or “calculator used”, in the page’s memory. No analytics or advertising tool reads these events today, and they are discarded when you leave the page. If we ever connect a tool to them, we’ll update this policy first.

We don’t use the Meta Pixel, Google Analytics or any advertising tags on wroe.io. Our fonts and videos are served from our own domain, so browsing the site doesn’t send requests to Google Fonts or a video host.

If you applied through our older form

Applications sent through the form this site used until September 2026 hold that form’s answers instead: your name, email, monthly revenue range, whether you run a DTC brand, how you found us (campaign tags, page address and referrer), and whether and when you chose “Allow” for Meta measurement. They can also hold Meta’s browser and click identifiers (fbp, fbc) if your browser had them. See Who we share it with for how these were used.

03

Cookies and browser storage

The site sets no cookies. It uses your browser’s session storage, which the browser deletes when you close the tab or window, for at most two things. A plain visit stores neither:

  • wroe:utm

    What it holds

    Campaign tags and click IDs from the link you arrived on (only if that link carried any)

    Why

    So “how you found us” isn’t lost as you move around the site

  • wroe:calculator

    What it holds

    Your calculator inputs and estimate (only after you use the calculator)

    Why

    So the estimate can be attached to your application if you apply

Neither item leaves your browser unless you submit the application form.

Third-party cookies from the booking calendar. The Calendly calendar is a frame loaded from calendly.com. It appears only after you submit the form. Calendly may set its own cookies and load its own security, payment and analytics tools inside that frame. Calendly controls those cookies, not Wroe. See Calendly’s cookie notice (opens in a new tab) and privacy notice (opens in a new tab). To avoid them, email us instead of using the calendar.

04

Email checks

To keep out fake and mistyped addresses, we check your email before saving your application:

  • We refuse a short list of known disposable-email domains.
  • We send your email address to Abstract API, an email-validation service, which reports whether it looks deliverable.
  • If Abstract API doesn’t answer, we look up the email domain only (for example brand.com, never the full address) through the public DNS services of Cloudflare and Google. This checks that the domain can receive mail.

If the check fails, the form asks for a different address. If no DNS service answers at all, we accept your application and mark the address “unverified”. This check only confirms the address can receive mail. It isn’t a judgement about you. If you believe the check is wrong, email ricky@wroe.io directly.

05

How and why we use your information

  • Review your application, reply to you and set up the call you asked for

    Information used

    Form answers, contact details, website, calculator estimate, booking details

    Legal basis (EU/UK visitors)

    Taking steps at your request before a possible contract (Art. 6(1)(b) GDPR)

  • Send you pre-call instructions after you book

    Information used

    Name, email, booking status

    Legal basis (EU/UK visitors)

    Taking steps at your request (Art. 6(1)(b))

  • Understand which channels and pages bring enquiries

    Information used

    Campaign tags, click IDs, page address, referrer

    Legal basis (EU/UK visitors)

    Our legitimate interest in measuring our own marketing (Art. 6(1)(f))

  • Block fake, disposable or mistyped emails

    Information used

    Email address or domain, check result

    Legal basis (EU/UK visitors)

    Legitimate interest in keeping our records accurate and our inbox free of abuse (Art. 6(1)(f))

  • Keep the site running, secure and fast; count visits in aggregate

    Information used

    Hosting logs, cookieless statistics

    Legal basis (EU/UK visitors)

    Legitimate interest in operating a secure website (Art. 6(1)(f))

  • Keep business records and meet legal obligations

    Information used

    Correspondence, records of work

    Legal basis (EU/UK visitors)

    Legal obligation (Art. 6(1)(c)) and legitimate interest

  • Measure advertising (older form only, see “Who we share it with”)

    Information used

    Hashed email and first name, IP address, browser type, Meta browser and click IDs, page address, revenue range

    Legal basis (EU/UK visitors)

    Your consent (Art. 6(1)(a))

We don’t add you to a marketing mailing list, and we don’t make decisions about you that have legal or similarly significant effects based solely on automated processing.

06

Who we share it with

We don’t sell your information. We share it only with service providers that help us run this process. They act on our instructions:

  • Cloudflare hosts the website, runs our form API and stores applications in its database service (D1). It also provides the cookieless statistics and the DNS lookups described above.
  • Calendly provides the booking calendar and, when booking notifications are switched on, tells us when a booking is made or cancelled.
  • Resend delivers two kinds of email: a notification to us with your application details, and, after you book, a pre-call checklist to you.
  • Abstract API checks that your email address can receive mail.
  • Google Public DNS receives only your email’s domain name during the email check, as a backup to Cloudflare’s DNS.
  • Our internal tools. We may forward a copy of your application, including your answers, contact details, how you found us and the email check result, to our own CRM or workflow tool over an encrypted (HTTPS) connection.

Meta (older form only). The current site doesn’t send anything to Meta. Until September 2026 our application form offered an optional “Allow” button for Meta measurement. If an application is submitted through that older form and you chose “Allow”, we may send Meta a hashed (scrambled) version of your email and first name, your IP address, browser type, Meta’s browser and click identifiers, the page address you applied from and your revenue range. We send this when the application is saved and again if you book a call. This lets us measure whether our ads led to applications and booked calls. Without “Allow”, nothing is sent. The event has no effect on whether we accept your application.

We may also disclose information when the law requires it, to protect our rights or others’ safety, or to a successor if Wroe’s business is ever transferred.

07

How long we keep it

  • Applications and booking records: while we’re talking or working together, and then for up to 24 months after our last contact if you don’t become a client. After that we delete them. You can ask us to delete them sooner.
  • Client records and correspondence: as long as needed for the work and for tax and accounting obligations.
  • Session storage: until you close the tab.
  • Hosting logs and statistics: kept by Cloudflare under its own retention schedule.
  • Calendly data: kept by Calendly under its settings and policies. We can cancel or delete a booking on request.

08

How we protect it

  • All traffic to wroe.io is encrypted (HTTPS).
  • Applications are stored in a private database that only Wroe can access. The form API only accepts well-formed data of limited size.
  • Forwarded copies of applications go only over HTTPS to the address we set. Redirects to anywhere else are refused.
  • The current form’s error logs are designed to leave out email addresses and form answers.
  • We will never ask for your passwords or one-time codes. If we need access to a platform, we’ll ask you to invite us through that platform’s own user or collaborator settings.

No system is perfectly secure. If a breach affects your information, we’ll tell you and the authorities where the law requires it.

09

International transfers

Wroe is based in the United States, and our providers operate worldwide. If you’re in the EU, UK or Switzerland, your information will be transferred to and processed in the US and possibly other countries. Where required, we rely on appropriate safeguards, such as the European Commission’s Standard Contractual Clauses (and the UK addendum) in our providers’ data processing terms. You can ask us for more detail.

10

Your rights

Everyone. You can ask us to access, correct or delete your information, or to stop contacting you. Email ricky@wroe.io.

EU, UK and Swiss visitors. You also have the right to:

  • get a copy of your data in a portable format
  • object to processing based on our legitimate interests
  • restrict processing
  • withdraw consent at any time (this doesn’t affect what we did before)
  • complain to your data protection authority. In the UK that’s the Information Commissioner’s Office (ico.org.uk (opens in a new tab)).

California residents. You have the right to:

  • know what personal information we collect, use and disclose, including the specific pieces we hold about you
  • have it deleted or corrected
  • not be discriminated against for using these rights

In the last 12 months we collected the categories described above:

  • Identifiers: name, email, application ID
  • Commercial information: your business answers
  • Internet activity: pages, referrer, campaign tags, ad click IDs
  • Inferences: the calculator estimate you generated

We collected them from you, your browser and Calendly, for the purposes above. We have not sold personal information. The current site doesn’t share it for cross-context behavioral advertising. The only exception is the older form described above: if you chose “Allow” there, we may have shared hashed identifiers with Meta for ad measurement. To opt out, email us or simply don’t choose “Allow”. We don’t knowingly sell or share the information of anyone under 16. You can use an authorized agent. We’ll verify requests by confirming control of the email address on file.

We respond within one month (45 days for California requests). Where the law allows, we may extend that once and will tell you why. There’s no charge.

11

Hiring inquiries

If you email us about working at Wroe, we’ll use what you send only to consider you for current or future roles. We’ll delete it when you ask.

12

Children

This site is for businesses. It isn’t directed at children, and we don’t knowingly collect information from anyone under 16. If you believe a child has sent us information, email us and we’ll delete it.

13

Links to other sites

Our site links to LinkedIn, GitHub and the online stores we’ve worked on. Those sites have their own privacy practices, which we don’t control.

14

Changes to this policy

When our practices change, we’ll update this page and the date at the top. If a change materially affects how we use information we already hold, we’ll tell you before it applies, for example by email if you’ve applied.

15

Contact

Questions, requests or complaints: ricky@wroe.io

Effective . This replaces the earlier version of this policy.