Legal

Privacy Policy

This is the privacy notice that governs vismountain.com. It explains what we collect, why we collect it, who else sees it, and what you can ask us to do about it.

A tracking plan from enquiry to CRMPhone calls, web forms and live chats all feed into one tagged event carrying the source, campaign and landing page, which is then written into the CRM alongside the enquiry, its owner and its outcome.EVERY ENQUIRY ARRIVES WITH ITS SOURCE ATTACHEDPHONE CALLWEB FORMLIVE CHATTAGGED EVENTSOURCECAMPAIGNLANDING PAGEYOUR CRMENQUIRYSOURCEOWNEROUTCOMEWITHOUT THIS, REPORTING IS GUESSING WHERE THE WORK CAME FROM.
A tracking plan from enquiry to CRM
In short

What does VIS Mountain do with my information?

VIS Mountain collects the name, email address, phone number, business name and message you type into a form or the chat window on vismountain.com, and uses them to reply to you, schedule a call and manage the relationship that follows. The site also runs Google Analytics 4, Google Ads conversion tracking and the Meta Pixel, and the analytics and marketing categories can be switched off at any time.

VIS Mountain does not sell personal information for money. You can ask to see, correct or delete what we hold by emailing hello@vismountain.com or calling (708) 669-9666, and we will not treat you differently for asking.

Written and maintained by the VIS Mountain team. Last reviewed . The sources behind it are listed below.

Orientation

How to read this policy

This is the operative privacy notice for vismountain.com. It is not a summary of a longer document, there is no other version, and nothing in it is waiting to be filled in. It applies to this website and to the enquiry, audit, and booking forms we run on it.

It is written to be read rather than skimmed. Where a plain answer exists, we give the plain answer. Where the honest answer is more complicated than most policies admit, such as what the word sale means once advertising tags are involved, we say that too instead of hiding behind the drafting.

One distinction runs through the whole page. We are a marketing agency, so we handle two very different kinds of information: data about the people who visit this website, and data that belongs to our clients and their customers. The rules we apply to each are different, and both are set out below.

If anything here is unclear, or you want us to confirm how a specific point applies to your own record, email hello@vismountain.com or call (708) 669-9666 and ask. We would rather answer a question than have you guess.

Who we are and how to reach us

VIS Mountain Marketing & Advertising is a marketing agency working with local businesses across the United States. We have been operating since 2019. For the information described on this page that we collect through vismountain.com, we are the business that decides why and how it is used.

Our head office is at 700 Commerce Drive, Ste 500, Oak Brook, IL 60523. The main number is (708) 669-9666 and the main email address is hello@vismountain.com.

Read the full breakdown: Who we are and how to reach us2 more paragraphsHide the full breakdown: Who we are and how to reach us

We also work from 691 N Church Rd, Ste 203, Elmhurst, IL 60126; 5111 Main St, Ste 150, Downers Grove, IL 60515; 1441 W Mockingbird Ln, Ste 600W, Dallas, TX 75247; 15310 Amberly Dr, Suite 250, Tampa, FL 33647; 8383 Wilshire Blvd, Ste 800, Beverly Hills, CA 90211; and 580 California St, Ste 1200, San Francisco, CA 94104.

For anything to do with your personal information, including a request to see it, correct it, or delete it, email hello@vismountain.com with "Privacy request" in the subject line, or call (708) 669-9666, or write to us at the Oak Brook address above. Every route reaches the same team.

Two roles, two sets of rules

When you visit this website, fill in a form, or start a chat, we decide what happens with that information. In privacy law terms we are the controller of it, and this policy is the notice that covers it.

When we work for a client, the picture changes. We run advertising accounts, customer relationship systems, analytics, and reporting on behalf of the businesses that hire us. The leads, patients, customers, and enquiries that flow through those systems belong to the client, not to us. We handle that data on the client's instructions and only for the purposes set out in the signed services agreement between us. In privacy law terms we are a processor, or a service provider, for that work.

Read the full breakdown: Two roles, two sets of rules3 more paragraphsHide the full breakdown: Two roles, two sets of rules

Practically, that means we do not take a client's customer list and use it to promote VIS Mountain, we do not merge one client's data into another client's account, and we do not sell it. How long that data is kept, how it is returned, and how it is destroyed at the end of an engagement are set by the services agreement and by the client's own retention decisions, not by this page.

If you are a client or a prospective client and you need a data processing addendum, we will provide one on request. If your engagement is covered by the Health Insurance Portability and Accountability Act, we will sign a business associate agreement where the engagement requires it. Neither document is published here. Both are handled during onboarding, so ask your contact or request one through the client portal and the current version will be sent to you to review and sign.

Two honest limits on that. There is no such thing as HIPAA certification for a vendor, so we do not claim it and you should treat anyone who does with caution. And this public website is not a covered system: the forms and the chat window on vismountain.com are ordinary business enquiry channels. Please do not send protected health information, patient records, financial account numbers, or passwords through them.

Information you give us

Our contact form, our free audit request, and our booking calendar all submit to the scheduling and customer relationship platform we run at go.vismountain.com. Those forms collect your name, your email address, your phone number, your business name, and whatever you choose to type into the message field. Nothing on those forms is collected in secret, and the fields you can see are the fields we get.

We use that information to reply to you, to schedule and hold a call, to prepare the audit or proposal you asked for, and, if you become a client, to manage the working relationship. The record stays in our customer relationship system so that the next person who speaks to you knows what was already discussed.

Read the full breakdown: Information you give us3 more paragraphsHide the full breakdown: Information you give us

The live chat window on this site is run by Knock Knock. When you open a chat, the conversation is stored so that our team can read it, reply to you, and follow up later if you left a question with us. If you give your name, email address, or phone number in the chat, that is stored with the conversation. Knock Knock also records the browsing session it is loaded on, including what is typed into forms on the page, which is why it sits in the measurement category rather than the necessary one and does not load at all until you accept measurement. Reject measurement, or simply leave the banner alone, and it is never requested.

If you call one of our numbers or email us directly, we keep the enquiry and our reply the same way we would keep any other business correspondence. If you book a call, we record the date, the time, your time zone, and the contact details you entered so we can meet you.

You decide how much to tell us. A short message asking us to call you back is enough to start a conversation, and you do not have to describe your business in detail in a web form to get a useful answer.

Information collected automatically

Like every website, this one is served by web infrastructure that keeps logs. Those logs record the IP address the request came from, the browser and operating system reported by your device, the address of the page requested, the time of the request, and the page that referred you. They exist so we can deliver the site, find faults, and detect abuse such as automated scraping or attacks on our forms.

We use Google Analytics 4, measurement ID GT-W628ZZG, to understand which pages people read, how they arrived, and which parts of the site are ignored. We look at this in aggregate. We are not trying to identify you personally from it, and we do not upload names, email addresses, or phone numbers into it.

Read the full breakdown: Information collected automatically3 more paragraphsHide the full breakdown: Information collected automatically

We use Google Ads conversion tracking, conversion ID AW-17107664728, and the Meta Pixel, pixel ID 591284313212705, to see which advertisement produced an enquiry and to build remarketing audiences so our own ads can be shown to people who have already visited this site. That is advertising measurement, and it is the part of this page most people care about. It is covered by the marketing category in our cookie preferences, and you can turn it off. The one exception is our Meta advertising funnel, the offer page at /offer/ and its booking confirmation at /booked/: there the Meta Pixel runs from page load without waiting for the cookie choice, because those pages exist for that advertising. The cookie policy says the same.

Web Engine is one of our own products. This site does not load anything from it. The Test your website field on the home page and the free audit page opens a Web Engine report in a new tab when you submit an address, and the address you typed is the only thing sent: it travels in that link, to Web Engine, because you asked for the report.

Two things we want to be explicit about, because plenty of agency sites are vague here. We do not run a LinkedIn advertising tag or a TikTok advertising tag on this website. We link to our profiles on those platforms, and a link is not a tracker: following one takes you to that platform, where that platform's own policy applies. And the list in the table below is the complete set of third parties running on this site as of the date at the top of this page. If we add one, this page and the cookie policy change at the same time.

The full inventory

Every third party that runs on this site

This is the whole list, not a representative sample. The category column is the consent category that gates each one. Necessary services run so the site can function at all. Analytics and marketing run only where you have allowed them.

ServiceWhat it doesLoads fromCategory
Google Analytics 4Measures which pages people visit and how they arrived, in aggregate. Measurement ID GT-W628ZZG.googletagmanager.comAnalytics
Google Ads conversion trackingAttributes form fills and calls to the ad that produced them, and builds remarketing audiences. Conversion ID AW-17107664728.googleadservices.comMarketing
Meta PixelAttributes enquiries to Facebook and Instagram ads, and builds remarketing audiences. Pixel ID 591284313212705.connect.facebook.netMarketing
Knock Knock live chatRuns the chat window and stores the conversation so we can reply.api.knock-knockapp.comNecessary
Scheduling and form platformRenders the booking calendar and receives contact and audit form submissions.go.vismountain.comNecessary

Google publishes its privacy policy at policies.google.com/privacy and explains what it does with data from sites that use its services at policies.google.com/technologies/partner-sites. Meta publishes its privacy policy at facebook.com/privacy/policy. Knock Knock publishes its privacy policy at knock-knockapp.com/privacy. The scheduling platform at go.vismountain.com and Web Engine at app.webengine.io are operated for VIS Mountain and are covered by this policy. The links section at the foot of this page takes you to each vendor policy directly.

Why we use this information

We use the information described above to answer enquiries and schedule calls; to prepare audits, proposals, and quotes; to deliver services to clients and to invoice for them; to keep the website secure and available and to investigate faults or abuse; to measure our own marketing so we know which channels are worth the money; and to meet legal, tax, and accounting obligations.

We do not use your enquiry to build a list we rent out, we do not enrich your record by buying data about you from brokers, and we do not make decisions about you by automated means that produce legal or similarly significant effects.

Read the full breakdown: Why we use this information1 more paragraphHide the full breakdown: Why we use this information

If you are contacting us from the United Kingdom or the European Economic Area, the lawful bases we would rely on are these. Answering an enquiry and preparing a quote is necessary to take steps at your request before entering a contract. Delivering an agreed service is necessary to perform that contract. Keeping the site secure and measuring our own marketing rests on our legitimate interests in running and improving a business, balanced against your interests. Non essential cookies and advertising tags rest on your consent, which you can withdraw. Keeping tax and accounting records rests on our legal obligations.

How long we keep things

Our practice is to keep an enquiry record for as long as the conversation or the relationship is live, and for a defined period after the last contact, so that we can pick up where we left off if you come back and so we have a record of what was said. Records tied to a signed engagement are kept for as long as that engagement runs and for a further period afterwards to cover contractual, tax, and accounting obligations.

Chat transcripts are kept so that a colleague can see the history of a conversation and follow up on it. Server and hosting logs are kept for a short operational window and are then rotated out. Analytics and advertising data held inside Google Analytics, Google Ads, and Meta is subject to those platforms' own retention settings and policies as well as ours.

We would rather tell you the truth than publish a number we cannot stand behind on every record type. We review these periods, and if you want to know the current retention period for a specific kind of record, ask us and we will confirm it in writing. If you ask us to delete your record and we are not required to keep it, we will delete it rather than wait for a period to expire.

Who we share information with

We share information with the service providers that make this business run: the scheduling and customer relationship platform at go.vismountain.com, the chat provider Knock Knock, our hosting and email providers, and our accounting and payment providers. They are permitted to use the information to provide their service to us, and not for their own purposes.

Where the marketing category is active, Google and Meta receive event data from this site, such as the fact that a page was viewed or a form was submitted, along with the identifiers their tags set in your browser. That is how conversion measurement and remarketing work. Once that data reaches them it is also governed by their own policies, which are linked at the foot of this page.

Read the full breakdown: Who we share information with2 more paragraphsHide the full breakdown: Who we share information with

We share information with our professional advisers, such as lawyers and accountants, where they need it to advise us. We will disclose information where the law requires it, for example in response to a valid legal process, and where it is necessary to establish or defend a legal claim or to protect the safety of a person. If the business is ever sold or merged, information would transfer as part of that transaction, and this policy would continue to apply to it until it is replaced by a notice that is not less protective.

We do not sell personal information for money. We want to be precise about the rest, because the word sale is defined broadly in California. Running advertising tags that share identifiers with Google and Meta so that you can be shown our ads later can count as a sale or as sharing for cross context behavioral advertising under California law, and as targeted advertising under the laws of several other states. We treat it that way rather than argue about it, which is why the marketing category is switchable and why we honor opt out preference signals. Turning the marketing category off stops it.

What you can ask for

Your rights over your information

Which of these you can enforce depends on where you live. We apply the same process to everyone who asks, wherever you are, because running two standards is more work than running one.

  • Know what we hold: ask us to confirm whether we hold information about you, and to tell you the categories we collected, why, where it came from, and who we disclosed it to.
  • Get a copy: ask for a copy of the specific pieces of personal information we hold about you, in a portable format where that is practical.
  • Correct it: tell us something is wrong and ask us to fix it.
  • Delete it: ask us to delete what we hold, subject to the narrow cases where the law lets us keep a record, such as a completed transaction or a legal obligation.
  • Opt out of sale or sharing: tell us not to share identifiers with advertising platforms for cross context behavioral advertising or targeted advertising.
See the full checklist: Your rights over your information4 more itemsHide the full checklist: Your rights over your information
  • Limit the use of sensitive personal information: we do not ask for sensitive personal information on this site and we do not use it to infer characteristics about you, so there is nothing here to limit. The right still stands and we will confirm that in writing if you exercise it.
  • Be treated the same either way: we will not deny you a service, charge you a different price, or give you a lower level of service because you exercised a privacy right.
  • Withdraw consent: where we relied on your consent, such as for analytics and advertising tags, you can withdraw it at any time through the cookie preferences control on this site.
  • Appeal: if we refuse a request, you can ask us to reconsider, and we will give you a written answer explaining the decision and how to escalate it to your state attorney general.

None of these rights is absolute. If we cannot do what you asked, we will tell you which exception we are relying on rather than simply declining.

State privacy laws, and what they mean for you

California. We have offices in Beverly Hills and San Francisco, and California residents have the strongest set of rights in the country under the California Consumer Privacy Act as amended by the California Privacy Rights Act. You have the right to know what we collect, use, disclose, and sell or share; the right to delete; the right to correct inaccurate information; the right to opt out of the sale or sharing of your personal information; the right to limit the use and disclosure of sensitive personal information; and the right not to be discriminated against for exercising any of them. You can use an authorized agent to make a request for you, in which case we will ask for written proof of their authority and may verify the request with you directly. The categories we collect are set out above; we collect them from you, from your device when you browse, and from the advertising platforms that report on our own campaigns.

Texas. Our Dallas office serves Texas, and the Texas Data Privacy and Security Act gives Texas residents the right to confirm whether we are processing their personal data and to access it, to correct it, to delete it, to obtain a portable copy, and to opt out of targeted advertising, the sale of personal data, and certain profiling. Texas also gives you a right to appeal if we decline a request, and the right to complain to the Texas Attorney General if the appeal is refused. Use the same contact details as everyone else.

Read the full breakdown: State privacy laws, and what they mean for you4 more paragraphsHide the full breakdown: State privacy laws, and what they mean for you

Illinois. Our head office is in Oak Brook and three of our seven offices are in Illinois. Illinois does not have a general consumer privacy statute of the California or Texas kind. It does have the Biometric Information Privacy Act, which is strict and well litigated, and which governs fingerprints, face geometry, voiceprints, retina and iris scans, and scans of hand geometry. We do not collect, capture, store, or use biometric identifiers or biometric information through this website or in the services we provide, so BIPA is not engaged by anything described on this page. We also come under the Illinois Personal Information Protection Act, which sets out how a business must notify people if their personal information is compromised in a breach.

Florida. Our Tampa office serves Florida. The Florida Digital Bill of Rights is written to reach a narrow set of very large companies measured by global revenue. We are not going to hide behind that threshold: if you live in Florida and want to exercise any right in the list above, use the same process and we will handle your request the same way we handle a California one.

Everywhere else in the United States. More states pass comprehensive privacy laws every year, and the rights they grant look broadly like the Texas list. Rather than publish a table that goes stale, we apply one process to every request from a United States resident. If your state law gives you something this page does not mention, tell us which right you are exercising and we will handle it under that law.

Outside the United States. We are a United States business serving United States clients, and we do not target the United Kingdom or the European Economic Area. If you are in the United Kingdom or the EEA and you contact us anyway, we will handle your information under this policy and give you the access, correction, deletion, objection, restriction, and portability rights that the General Data Protection Regulation and the United Kingdom GDPR describe, and you keep the right to complain to your own supervisory authority. Because we do not offer goods or services to people in those territories, we have not appointed a representative in the European Union or the United Kingdom. If that changes, we will name one here.

The process

How to make a request, and how we check it is you

There is no portal to sign up for and no form to hunt down. A plain email is enough.

  1. Tell us what you want

    Email hello@vismountain.com with "Privacy request" in the subject line, call (708) 669-9666, or write to VIS Mountain Marketing & Advertising, 700 Commerce Drive, Ste 500, Oak Brook, IL 60523. Say which right you are exercising: see it, copy it, correct it, delete it, or opt out.

  2. Give us enough to find you

    Tell us the email address or phone number you used when you contacted us, and roughly when. We can only search what we hold, and most of our records are keyed to an email address or a phone number.

  3. We verify the request

    We match the details you give us against our records, and we will usually confirm the request from the email address already on file. We ask for the least we can get away with. We do not ask for a government issued identity document for an ordinary access or deletion request. If we genuinely cannot tell that a request is yours, we will tell you that we cannot verify it rather than hand your information to someone else.

See the remaining steps: How to make a request, and how we check it is you2 more stepsHide the remaining steps: How to make a request, and how we check it is you
  1. An agent can act for you

    If someone is making the request on your behalf, send us written permission signed by you. We may still confirm directly with you that you authorized it, which is a protection for you rather than an obstacle.

  2. We respond

    California and Texas both give a business 45 days to respond, with one extension where a request is genuinely complex. We work to that timeline for everyone, we acknowledge requests when they arrive, and we tell you if we need the extension and why. If we refuse, we say which exception applies and how to appeal.

There is no charge for a reasonable request. If a request is manifestly unfounded or repetitive we may say so and explain why, which is what the law contemplates.

Do Not Track and Global Privacy Control

Most browsers include a Do Not Track setting. The web industry never agreed a standard for what a site must do when it receives that header, so a Do Not Track signal on its own does not tell us what you actually want. We do not treat it as a rights request.

An opt out preference signal is different, and Global Privacy Control is the one that matters in practice. Where your browser or an extension sends an opt out preference signal, we treat it as a request to opt out of the sale and sharing of personal information for that browser, and we do not require you to confirm it a second time.

Read the full breakdown: Do Not Track and Global Privacy Control2 more paragraphsHide the full breakdown: Do Not Track and Global Privacy Control

Two practical limits worth knowing. The signal applies to the browser and the device that sends it, so if you clear your site data, use a different browser, or switch to your phone, you will need it enabled there too. And an opt out stops information being shared going forward: it cannot reach back and remove data an advertising platform already received in an earlier visit. If you want that removed as well, ask us and we will make the deletion request we are able to make.

You can also open the cookie preferences control on this site at any time and turn the analytics and marketing categories off. Doing that is equivalent to sending the signal, and it is the simplest route if you are unsure whether your browser is sending one.

Children's privacy

This is a business to business website. Our services are sold to business owners and the people who make marketing decisions for them, and nothing here is designed for or directed at children.

We do not knowingly collect personal information from anyone under 16, and we do not sell or share the personal information of anyone under 16. If we learn that a child has given us information through a form or the chat window, we delete it.

If you are a parent or guardian and you believe a child has given us information, email hello@vismountain.com and we will find the record and remove it.

How we protect information

We take reasonable administrative, technical, and physical measures to protect the information we hold. The site is served over HTTPS so that what you submit is encrypted in transit. Access to our customer relationship system and our email is limited to the people who need it for their work, each of whom has an individual account rather than a shared login. We choose vendors that maintain their own security controls, and we review who has access when someone joins or leaves.

We will not tell you that any of this is impenetrable, because that would not be true of us or of anyone else. No website, email system, or database can be made completely secure, and any business that guarantees otherwise is selling you something. What we can commit to is that we do not collect information we do not need, we do not keep it longer than we have a reason to, and we treat a security problem as urgent.

If information we hold is ever compromised in a way that affects you, we will notify you and the relevant regulators as the law requires, and we will tell you what happened rather than issue a statement that says nothing.

Changes to this policy

The date at the top of this page is the date this version took effect. When we change something substantive, such as adding a third party to the table above or changing what we do with your information, we update that date and describe the change here rather than quietly editing the text.

We will not apply a materially different use to information we already hold without telling you and, where the law requires it, asking you first. If you keep using the site after a change, that is not us treating your silence as consent to something new: it simply means this version applies to your visit.

Common questions about this policy

Do you sell my personal information?

Not for money, and not to data brokers or list companies. The honest complication is that the advertising tags on this site pass identifiers to Google and Meta so we can measure our ads and show you ours again later, and California and several other states define sale or sharing broadly enough to cover that. We treat it as covered rather than argue the point, which is why the marketing category can be switched off and why we honor opt out preference signals.

How do I stop the advertising tags?

Open the cookie preferences control on this site and turn off the marketing category. That stops Google Ads conversion tracking and the Meta Pixel on this site from that point forward. Turning off analytics stops Google Analytics 4 as well. You can also send an opt out preference signal such as Global Privacy Control from your browser, which we treat the same way.

Can I ask you to delete the enquiry I sent you?

Yes. Email hello@vismountain.com from the address you used, or tell us which address and phone number you used, and ask us to delete the record. We will delete it unless we have a specific legal reason to keep part of it, such as a record of a completed transaction, and if that happens we will tell you exactly what we kept and why.

Will you sign a BAA or a data processing addendum?

Yes, on request. We work with medical and dental practices, and where an engagement is covered by HIPAA we will sign a business associate agreement. For other engagements we can provide a data processing addendum covering our role as a service provider. Neither is published on this site. Both are part of onboarding, so ask your contact or request one through the client portal and the current version will be sent to you to review and sign. We do not claim to be HIPAA certified, because no such certification exists, and this public website is not a HIPAA covered system.

You run our ad accounts and CRM. Is our customer data covered by this policy?

No, and that distinction matters. This policy covers information we collect through vismountain.com and use for our own purposes. Data inside a client's advertising accounts, customer relationship system, or analytics belongs to the client. We process it on the client's instructions under the signed services agreement, which is the document that governs retention, return, deletion, and security for that work.

Do you collect biometric information?

No. We do not collect, capture, store, or use fingerprints, face geometry, voiceprints, retina or iris scans, or scans of hand geometry, either on this website or in the services we deliver. That is worth stating plainly because our head office is in Illinois, where the Biometric Information Privacy Act sets strict rules for businesses that do.

How long will you keep my information?

For as long as the conversation or the relationship is live, and for a defined period afterwards so that we have a record of what was agreed and can help you if you come back. Records tied to tax, accounting, or a contract are kept for the period the law requires. If you want the current retention period for a specific type of record, ask us and we will confirm it in writing.

Questions about your information?

Email hello@vismountain.com with "Privacy request" in the subject line, or call (708) 669-9666. A person reads it, and you will get a straight answer.

Sources

Where this comes from.

Primary documentation and published research behind the guidance on this page.

Next step

Talk to the team

A short call, a look at how the business currently shows up, and a straight answer on what we would do first.