Privacy Policy
Last updated: October 1, 2026
This Privacy Policy explains how Trojan Digital Marketing ("we," "us," or "our") handles information when you visit trojandigitalmarketing.com, contact us, and use our free and paid tools.
Who We Are
Trojan Digital Marketing provides SEO, AEO, GEO, website design, paid advertising, social media management, video editing, and AI automation services for businesses across the United States and worldwide. You can reach us through our contact page or by phone at (317) 981-2386.
What We Collect
Website requests. Hosting and security providers process technical request information, which can include an IP address, browser information, the requested page or resource, and request time, to deliver and protect the website. This is separate from information you choose to enter into a form.
Contact submissions. When you submit the contact form, the details you enter, including contact information and your message, are sent to our hosting provider and stored in our database for the owner's contact inbox. We use submissions to respond to inquiries and manage related follow up. Submitting the form does not subscribe you to a mailing list.
Website AI Chat
When you send a chat question, our website chat service receives the question, your chosen agent role and limited earlier chat context. For live AI answers, we send this information and relevant public website text to Cloudflare AI. Use public business details; keep passwords, payment details and private records out of chat. Cloudflare processes information under its own terms and Privacy Policy.
The chat uses a session cookie and usage counters to limit requests. The open dialog keeps the current conversation in browser memory and lets you clear it. Chat questions are not saved as contact inquiries. A callback preference needs our team's confirmation. Your contact details and request reach our inquiry inbox only when you choose to send the contact form.
Campaign Attribution and Measurement
We use a first party cookie lasting up to 90 days to remember how a visitor first found us and connect a later inquiry to that visit. It can contain a limited advertising click identifier, campaign source, medium, name, keyword and content labels, the first page visited without its query string, and the referring website's domain. It does not contain the name, email address, phone number or message you enter in a contact form. If you contact us, this attribution is stored with your inquiry. A return visit without campaign information does not replace an existing campaign record.
This first party attribution is separate from Google tag consent and is saved on landing without waiting for a banner choice. If cookies are blocked, the site can retain attribution in the current tab and pass it to a contact link. Browsers can delete or shorten storage, so 90 days is a maximum requested lifetime, not a guarantee.
When Google measurement is configured, Google Tag Manager can load Google Ads and analytics tags to measure website activity and verified inquiries. Regional defaults enable advertising storage, analytics storage, advertising data use and ad personalization for visitors identified as being in the United States; these defaults are off for visitors elsewhere or whose country cannot be determined. Use the Your privacy choices link in the footer to turn Google advertising and analytics measurement cookies on or off. Saving your choice overrides the regional defaults. Google may still receive limited measurement signals without cookies when this setting is off. A Global Privacy Control signal from your browser turns off advertising data use and ad personalization for Google tags. These Google settings do not disable the separate first party attribution cookie described above.
Local document and image tools. The invoice, estimate, image conversion, PDF, and PDF signing tools process the information and files used to create their output in your browser. These tool workflows do not upload your document or image contents to our servers. Locally saved settings or drafts, where supported, remain in browser storage. This does not apply to a contact submission, an audit request, or an owner media upload, which use the separate services described here.
Audit requests. The public website URL and your selected scope are sent to our audit backend. It retrieves the requested page and, in sample mode, up to four additional same origin pages, plus robots and sitemap information. The backend checks public DNS before fetching. Audited servers receive a request from our service. A daily hashed request identifier limits abuse. Reports are returned to your browser; optional saved history remains in browser storage. The auditor does not call PageSpeed Insights or retrieve private analytics.
Jev Website Scanner. The Jev Website Scanner is built and run by Trojan Digital Marketing and uses Jev, an AI model from TypeSafe. Before a scan starts, you tick a box to confirm you own or manage the site, or have permission to review it. The scanner reads pages from the site you enter and, for a paid audit, from the competitors you name. It follows robots.txt on every site it reads: it reads only pages open to our audit bot (TrojanAuditBot) and Googlebot, and it won't scan a site whose robots.txt closes its home page or can't be read. It stops at a bot check instead of getting around it, and page reads, redirects included, stay on the scanned site. It checks public DNS before each request and identifies itself to the sites it reads as TrojanAuditBot. We send the page text and the business details you type to TypeSafe, which runs Jev and sends back answers to set questions. The outside services the scanner uses are listed under Jev Website Scanner services below. Don't type personal or confidential information into the business fields.
Each scan is saved in our database, so closing the tab loses nothing and you can come back to a scan and compare a rescan with it. With each scan we store the site's address and page list, the page results, the business details you type (name, services, services you don't offer, towns, customers, average job value, license and competitors), your email, a Search Console export (or Ahrefs Top pages) if you add one, and a hashed version of your IP address (IPv6 counted by its /64 block) that we use for daily limits. Before a site lookup, a quick bot check from our hosting provider may confirm a person is using the page.
We use your email to send you the report link, which Resend delivers, and to keep free scans fair. We look up whether its domain can receive mail (only the part after the @), and we keep a hashed version of the address to count its free scans, up to 3 a day and 10 in 30 days. Our team can see the sites scanned with the email used, to help when you ask and to stop abuse. If you buy an audit or a rescan, Stripe also uses the email you give at checkout to send your receipt. Your email goes on our newsletter only if you tick the newsletter box on the scan form, which has its own double opt-in, and the report email mentions the newsletter without signing you up.
Your report lives at its own link, which works as long as we keep the scan. Anyone with that link can open the report and use an unused included rescan, so share it only with people you trust. Our team can open any report from our admin page to check the scanner's quality and to help you when you ask. In your browser, the business details you type and a list of your recent scans are kept in localStorage.
Owner editor and published media. The owner editor uses sign in through Sites' Sign in with ChatGPT or the access control our hosting provider runs for the site. The selected provider processes authentication and session information. Media the owner uploads for publication is stored with our hosting provider and served as public website content. Published media can be accessed by visitors and should not contain confidential information.
Internal SMS Alerts
When enabled, Trojan Digital Marketing LLC uses recurring automated SMS to notify its existing account owner about verified inquiries and business calls, including AI-reported qualified callers. The owner requests enrollment by reading the disclosures and sending the completed email template at our SMS consent instructions from the email address already associated with the owner account. The administrator verifies the request against the existing owner record and approved private alert destination before activation. Website visitors and callers are not enrolled in this SMS program, and an email from another person does not activate alerts.
We process the recipient's name, mobile number, sender email address, dated consent email, message content, and delivery information to provide these alerts. We retain the consent email privately as the enrollment record and do not publish it or the recipient's mobile number. Twilio and other necessary service providers process this information for delivery and operation. We do not sell mobile information or share mobile numbers, SMS opt-in information, or messaging consent with third parties or affiliates for their marketing or promotional purposes.
Message frequency varies with business activity. Message and data rates may apply. Reply STOP to stop messages. For help with this program, questions about your information, or another way to request that alerts stop, email support@trojandigitalmarketing.com. See our internal SMS alert terms.
Optional Newsletter: Trojan Digital Insight
Newsletter signup is separate from tools and contact inquiries. When available, we collect the email address you submit, your explicit consent, consent and confirmation times, the source page and selected topic, plus your name and phone number if you choose to add them. We use your name to greet you in our emails. We use your phone number only to call you when you ask us to, and we don't send marketing texts. We send a confirmation link and add the address to the newsletter only after you confirm, and then we send one welcome email. We do not attach audit results, financial calculations, document contents or invoice customer information to a signup. You can unsubscribe through each marketing email. We retain opt out and suppression records to help prevent another send. Pending requests whose confirmation token expired more than 30 days ago are removed when later signup requests run the cleanup.
What We Do Not Collect or Use
We have not added session recording, heatmap software or display ads to this website. We do not sell, rent, or trade personal information. Contact details are provided when you contact us, and owner authentication protects the editor. The public tools do not require registration.
Third Party Services
Hosting. Our hosting provider runs the website and provides the contact processing, database, audit and Jev Website Scanner backend, and published media storage described above. It may process technical request information for operation and security.
Jev Website Scanner services. These services receive public page text, page addresses and the business details you type in, as set out here, and each handles that information under its own terms and privacy policy. TypeSafe runs Jev, the AI model that scores each page. It receives the page text and your business details when a scan runs, including competitor pages in a paid audit, and it returns Jev's answers to our server. For a paid audit, Anthropic receives your weakest page's text, fact sentences from your site, and the business name, services, towns and services you don't offer that you typed, so its Claude model can write the before and after. Google PageSpeed Insights receives page addresses for the mobile speed test: the home page on every scan, free ones included, and one more page in a paid audit or rescan.
Stripe payments. Stripe handles payments for audits and rescans, including your card details and the email you give at checkout, and it sends your receipt. We don't see or store your card number. See the Stripe Privacy Policy.
Self hosted resources. The site's fonts and PDF libraries are served with the website. The site does not request those fonts from Google Fonts or those PDF libraries from a third party code CDN.
Resend email delivery. When newsletter signup is enabled, Resend processes confirmation messages and newsletter delivery. Resend also sends the Jev Website Scanner report link to the email you enter. Confirmed email addresses, with your name if you add one, are added to our newsletter segment. Provider records may include delivery, bounce, complaint and unsubscribe events. See the Resend Privacy Policy. Resend handles the unsubscribe link in marketing emails.
Optional map. The OpenStreetMap map loads only after you choose to load it. That action connects your browser to OpenStreetMap services, which can receive technical request information such as your IP address and browser details. See the OpenStreetMap Foundation Privacy Policy. Loading the map is optional.
Owner sign in. Sign in with ChatGPT is subject to the OpenAI Privacy Policy. Where our hosting provider's access control protects the editor, its authentication and session handling applies. These sign in services protect the owner editor.
Google measurement. When enabled, Google Ads and analytics process measurement information under the settings described above. Google Ads website call measurement may replace our displayed number with a Google forwarding number after an eligible ad click and measure call duration. Phone link clicks alone are not treated as completed calls. See Google's Privacy Policy and how Google uses information from partner sites.
Cookies and Local Storage
Browser storage may retain tool settings or drafts where a tool supports saving them. Owner authentication and hosting security may use cookies or similar session technologies. We also use the first party attribution cookie described above, and configured Google tags may use measurement cookies according to their effective settings. See our Cookie Policy for the purposes and available controls.
Local storage is a browser storage technology. It is not automatically attached to each request in the way applicable cookies are, but website code can read it. Privacy and storage access rules can apply to local storage.
Your Rights
Depending on your location and the laws that apply, you may have rights to request access, correction, deletion, restriction, or portability of personal information, or to object to certain processing. Where processing relies on consent, you may have the right to withdraw it. Applicable rights and exceptions vary.
Use our contact page or call (317) 981-2386 to make a privacy request or ask about information associated with an inquiry. We may need information to identify the relevant record and confirm that a request is authorized. Your browser's controls can remove information saved locally by the tools.
Data Retention
Contact submissions are kept for responding to inquiries and related administration. Retention depends on the purpose of the record and the configured storage, backup, authentication, and security services. Contact us about access or deletion of an inquiry. Provider records follow the applicable service settings and retention policies.
Jev Website Scanner scans are kept for 12 months from the day each one was made, so you can come back to them and compare a rescan. Then they're deleted with their pages, links and email and any competitor scans under them, and their report links stop working. Scans nobody started are deleted after 7 days, or 30 days when they went to checkout. Daily limit counters are deleted the next day. When a free scan is deleted, we keep its domain name and nothing else, so each domain still gets one free scan. Stripe and Resend keep their own payment and email records under their own policies.
The first party attribution cookie requests a maximum lifetime of 90 days. Other browser saved data remains until it is removed by the tool, your browser, or your own actions. Clearing site data can remove saved settings and drafts. Owner published media remains public while it is published; copies may also remain in browser or delivery caches.
Children's Privacy
Our website and tools are not directed at children under the age of 13. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will take steps to remove it.
Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the "last updated" date at the top of this page. We encourage you to review this page periodically.
Contact
If you have questions about this Privacy Policy, contact Trojan Digital Marketing through our contact page or call (317) 981-2386.