Privacy Policy
We collect your first name, work email, company, and role when you complete the Reliability Scorecard — to send you your results and follow up if you want a call. We use Google Analytics to understand how visitors use the site, and LinkedIn ads to reach engineers and CTOs. We never sell your data. You can manage or withdraw your cookie preferences at any time using the banner below or via .
Who we are
Reppl.sh LLC ("Reppl.sh", "we", "us", or "our") is a Site Reliability Engineering and Platform Engineering consultancy registered in the State of Delaware, United States. We operate the website at reppl.sh and related subdomains.
This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website, take our Reliability Scorecard assessment, or submit an inquiry. Please read it carefully. If you disagree with its terms, please stop using the site. Our Terms of Service govern the contractual relationship between you and Reppl.sh; this policy governs our personal-data practices only.
Governing law and venue for disputes are set out in our Terms of Service. The applicable substantive law is that of the State of Delaware, United States.
Data we collect
We collect information in three ways: directly from you when you submit a form, automatically when you browse our site, and through third-party analytics and advertising platforms.
| Category | What we collect | Source |
|---|---|---|
| Contact data | First name, business email address, company name (optional), and job title or role (dropdown) | Inquiry forms, Scorecard assessment email gate |
| Assessment data | Answers to the 40-question Reliability Scorecard, category scores, overall maturity score | Scorecard tool (scorecard.html) |
| Generated outputs | Your scored results page, radar chart, and any PDF saved via "Save as PDF". These outputs are derived from your answers and, once linked to your email, constitute personal data we hold. | Scorecard results engine |
| Usage data | Pages visited, time on page, referring URL, browser type, operating system, device type, approximate geographic region (city/country) | Google Analytics (consent-gated for EU/EEA/UK and California) |
| Advertising data | LinkedIn member attributes for ad targeting and conversion measurement (hashed where possible) | LinkedIn Insight Tag (consent-gated) |
| Technical data | IP address (anonymised), cookie identifiers, session identifiers stored in browser localStorage. Assessment answers are stored in localStorage client-side and are not transmitted to our servers until you submit the email gate form. | Automatically on site visit |
Our forms are not designed to collect, and we do not request, special-category personal data as defined under GDPR Article 9 (e.g. health data, religious beliefs, political opinions) or government-issued identifiers. If you voluntarily include such information in free-text responses or email correspondence, we will limit its use to responding to your inquiry and will delete it as soon as reasonably practicable.
The benchmark figures shown on the Scorecard results page ("Series B–D Average" and "Top Quartile") are currently static illustrative figures, not computed from real submitters' data. If this changes, we will update this policy to disclose that secondary purpose before any such computation takes place.
How we use your data
We use the information we collect for the following purposes:
- Service delivery — to respond to your inquiry, deliver your Scorecard results, and arrange a Diagnostic Call if requested.
- Lead follow-up — to send you your assessment results and, where you have indicated interest, to follow up about our reliability engineering services.
- Marketing communications — with your explicit consent, to send you relevant content such as reliability engineering insights and service updates. You may opt out at any time via the unsubscribe link in any email we send.
- Website improvement — to understand how visitors use our site, identify pages that perform poorly, and improve the user experience (analytics cookies, subject to your consent preferences).
- Advertising measurement — to measure the effectiveness of our LinkedIn advertising campaigns and understand which ads lead to meaningful engagement (advertising cookies, subject to your consent preferences).
- Legal compliance — to comply with applicable law, respond to lawful requests, and protect our legal rights.
Our legal bases for processing under GDPR are: legitimate interests for responding to direct inquiries and operating the website; contract performance when you request our services; and consent for marketing communications and non-essential cookies (analytics and advertising). Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.
Cookies & tracking
We use cookies, pixel tags, and browser localStorage. A cookie consent banner appears on your first visit (and can be reopened at any time via the link in our footer). Non-essential cookies — analytics and advertising — are blocked until you give consent. You can change your preferences at any time.
| Technology | Category | Purpose | Duration |
|---|---|---|---|
| reppl_consent | Essential | Stores your cookie consent preferences locally so we don't repeat the banner on every visit. | Until cleared |
| reppl_scorecard | Essential | Stores your in-progress Scorecard answers in localStorage so you can resume if you navigate away. No data is sent to our servers until you submit the email gate form. | Until cleared |
| Google Analytics (_ga, _gid) | Analytics | Measures site traffic, user behaviour, and referral sources. IP addresses are anonymised. Requires your consent before loading. | Up to 26 months |
| LinkedIn Insight Tag | Advertising | Conversion tracking, retargeting, and aggregate demographic insights for LinkedIn ad campaigns. Requires your consent before loading. | Up to 90 days (LinkedIn-controlled) |
You can also control cookies through your browser settings. Disabling cookies may affect site functionality. To opt out of Google Analytics across all sites, install the Google Analytics Opt-out Browser Add-on. To opt out of LinkedIn ads, visit LinkedIn's opt-out page.
LinkedIn advertising
We use the LinkedIn Insight Tag on our website to enable in-depth campaign reporting and to unlock aggregate insights about our website visitors. This allows us to:
- Measure conversions from LinkedIn ad campaigns (e.g. form completions, Scorecard starts).
- Retarget visitors with relevant ads on LinkedIn.
- Gain aggregate, anonymised demographic insights (job title, seniority, industry) about our site audience — without identifying individual visitors.
The LinkedIn Insight Tag sets a cookie in your browser. LinkedIn uses data processed through the Tag subject to LinkedIn's Privacy Policy. LinkedIn Ireland Unlimited Company acts as an independent controller for data processed for its own purposes; Reppl.sh acts as a joint controller with LinkedIn only for conversion and retargeting data directly associated with our campaigns.
You can opt out of LinkedIn's retargeting and analytics at any time by visiting linkedin.com/psettings/guest-controls/retargeting-opt-out. You may also use our to block the Insight Tag from loading entirely.
For EU/EEA/UK/Swiss residents, the LinkedIn Insight Tag is loaded only after you provide consent through our cookie banner, consistent with GDPR Article 6(1)(a) and the ePrivacy Directive. You may withdraw that consent at any time through the link in our footer.
California privacy rights (CCPA / CPRA)
This section applies to residents of California and supplements the rest of this policy. The California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (CCPA/CPRA), grants California residents specific rights regarding their personal information.
Do we "sell" or "share" your personal information? Under CPRA, "share" includes disclosing personal information to a third party for cross-context behavioural advertising — even without money changing hands. The LinkedIn Insight Tag, when active, transmits data to LinkedIn for the purpose of delivering targeted ads on LinkedIn's platform. This may constitute "sharing" personal information under CPRA's definition. We therefore treat use of the LinkedIn Insight Tag for advertising purposes as a "share" and provide a mechanism to opt out below.
We do not sell personal information for monetary consideration. We do not share personal information with unrelated third parties for their own independent marketing.
California residents may opt out of the sharing of their personal information for cross-context behavioural advertising at any time by using our , selecting "Reject" or disabling "Advertising" cookies. This will prevent the LinkedIn Insight Tag from loading. You may also submit an opt-out request to hello@reppl.sh with the subject "Do Not Sell or Share — CCPA".
CPRA-specific rights. In addition to the rights listed in §9, California residents have the right to:
- Correct inaccurate personal information we hold about you.
- Limit use of sensitive personal information — we do not collect sensitive personal information as defined under CPRA (e.g. precise geolocation, financial information, health data, biometric data). If this changes, we will update this policy.
- Non-discrimination — we will not discriminate against you for exercising your CCPA/CPRA rights.
- 12-month look-back — upon a verified access request, we will disclose personal information collected about you in the preceding 12 months, including categories of data, sources, business purposes, and third parties with whom it was shared.
To exercise your California rights, email hello@reppl.sh with the subject "CCPA/CPRA Rights Request." We will respond within 45 days, extendable once by a further 45 days with notice to you.
Third-party processors
We share data with the following service providers who process data on our behalf. We select processors that maintain industry-standard security certifications (such as SOC 2 or ISO 27001) appropriate to the data they process, and we use Data Processing Agreements or equivalent contractual mechanisms as required by GDPR Article 28. A full, dated list of our sub-processors is maintained at reppl.sh/subprocessors.
We will update the sub-processor list when we add or change processors. For material changes affecting EU/UK/Swiss personal data, we will provide notice via this policy page at least 30 days in advance where feasible.
| Processor | Purpose | Location |
|---|---|---|
| Formspree | Receives and forwards form submissions (contact inquiries, Scorecard gate submissions). Data is transmitted securely and forwarded to our business email. | United States |
| Google LLC (Analytics) | Website analytics and usage measurement. Analytics cookies require your consent before loading. EU Standard Contractual Clauses apply for EU/EEA data transfers. | United States |
| LinkedIn Ireland Unlimited Company | Advertising, conversion tracking, and audience insights via Insight Tag. Advertising cookies require your consent before loading. | Ireland / United States |
| Calendly | Processes booking data when you schedule a Diagnostic Call. Governed by Calendly's own privacy policy at the time of booking. | United States |
| Cloudflare | Content delivery, DDoS protection, and performance. IP addresses are processed transiently and not retained for analytics. | Global edge network |
We do not sell, rent, or trade your personal data to any third party for their own marketing purposes.
Data retention
We retain personal data for as long as necessary to fulfil the purpose for which it was collected, or as required by applicable law.
| Data type | Retention | Basis |
|---|---|---|
| Lead / contact data (name, email, company, role) | Up to 3 years from the last meaningful interaction | Legitimate interests in maintaining business relationships; GDPR storage limitation |
| Scorecard assessment answers | Up to 12 months | Service delivery and follow-up. Contact data from the same submission is retained separately on the 3-year schedule above; a deletion request against your email address will encompass both records. |
| Analytics data (Google Analytics) | 26 months (our configured GA4 retention window), then automatically deleted | Website improvement; analytics storage is consent-gated |
| LinkedIn Insight Tag data | Up to 90 days for retargeting; longer for aggregate insights (LinkedIn-controlled) | Advertising measurement; consent-gated |
| Email correspondence | Up to 5 years | U.S. business record-keeping best practice; Delaware statute of limitations for contract claims (3 years) plus a 2-year buffer for late-discovered claims |
When data is no longer required, we delete it securely or anonymise it. Deletion requests submitted under §9 or §6 will be honoured within 30 days. Note that data present in backup snapshots at the time of a deletion request may persist in those backups for up to 90 days until those backups are overwritten or expired, after which it will no longer be accessible or recoverable.
Your rights
Depending on your location, you may have the following rights regarding your personal data:
| Right | GDPR (EU/EEA/UK) | CCPA/CPRA (California) |
|---|---|---|
| Access | Request a copy of the data we hold | Request disclosure of data collected in the preceding 12 months |
| Rectification / Correction | Request correction of inaccurate data | Request correction of inaccurate data (CPRA) |
| Erasure / Deletion | Request deletion of your data | Request deletion of your data |
| Restriction | Request restriction of processing in certain circumstances | Opt out of sharing for advertising (see §6) |
| Portability | Receive your data in a structured, machine-readable format. We will provide it as CSV or PDF via email. | — |
| Objection | Object to processing based on legitimate interests or for direct marketing | Opt out of sale/sharing (see §6) |
| Withdraw consent | Withdraw consent at any time where processing is consent-based | — |
To exercise any of these rights, email hello@reppl.sh with the subject line "Privacy Request". We will respond within one month under GDPR (extendable by a further two months for complex or numerous requests, with notice to you), and within 45 days under CCPA/CPRA (extendable once by a further 45 days, with notice). We may need to verify your identity before processing your request.
EU/EEA/UK residents also have the right to lodge a complaint with their local data protection supervisory authority — for example, the Irish Data Protection Commission, the UK Information Commissioner's Office, or your national equivalent.
Security & breach notification
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These include:
- HTTPS encryption in transit for all pages and form submissions.
- Access controls limiting which personnel within Reppl.sh can access contact and lead data.
- Use of third-party processors that maintain industry-standard security certifications appropriate to the data they process — we review processors' compliance posture before onboarding and periodically thereafter.
- Personal data held in our CRM and email systems is protected by strong passwords, multi-factor authentication, and provider-level encryption at rest.
- Regular review of data handling practices and vendor security documentation.
No method of transmission over the internet or electronic storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.
Breach notification. In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify affected individuals and relevant supervisory authorities as required by applicable law — including GDPR Articles 33 and 34 (72-hour notification to the supervisory authority; without undue delay to affected individuals where the risk is high) and applicable U.S. state breach notification statutes (all 50 states have breach notification laws; we will comply with the law applicable to the affected individuals).
Children's privacy
Our website and services are directed exclusively at business professionals. We do not knowingly collect personal data from individuals under the age of 16. This also means our services are not directed at, and are not intended to be used by, children under 13 within the meaning of the U.S. Children's Online Privacy Protection Act (COPPA). If you believe we have inadvertently collected data from a minor, please contact us immediately at hello@reppl.sh and we will delete it promptly.
Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. For minor changes (e.g. clarifications, correcting processor details), updating the date is sufficient notice.
For material changes — those that meaningfully expand the categories of data we collect, the purposes for which we use it, or the third parties with whom we share it — we will provide more prominent notice: a banner on the site for a defined period and, where we hold your email address and you have previously given consent, an email notification.
Continued use of our website after changes are posted constitutes your acceptance of those changes. If you object to a material change, you may exercise your data rights under §9 or §6.
Contact us
For any questions about this Privacy Policy, to exercise your data rights, to raise a concern, or to submit a security disclosure, please contact us:
Reppl.sh LLC
1007 N Orange St. 4th Floor Suite #4811
Wilmington, Delaware 19801
United States
Privacy & data rights: hello@reppl.sh — subject line "Privacy Request"
Security disclosures: hello@reppl.sh — subject line "Security Disclosure"
EU & UK representative (Article 27 GDPR / UK GDPR): Reppl.sh is in the process of designating an EU and UK representative as required under GDPR Article 27 and its UK equivalent, given the volume of EU/UK visitors to our site. Until that appointment is completed, EU/EEA and UK data subjects may contact us directly at the address above. We will update this section with representative contact details once appointed.
We aim to respond to all privacy-related requests within 30 days (GDPR) / 45 days (CCPA/CPRA).