Privacy Policy
This policy explains what we collect through this website, why we collect it, who it is shared with, where it is stored, how long we keep it, and what you can do about it.
Last updated: 15 September 2026
This project-specific draft describes the website reviewed on 15 September 2026. The legal entity, address, governing law and proposed terms still need confirmation. This draft has not been approved for publication as the final policy or terms.
1. Who is responsible for your information
This site is operated under the brand Crabtree Advisory by {{LEGAL_ENTITY}} (“we”, “us”), whose registered address is {{REGISTERED_ADDRESS}}. We are the controller of the information described in this policy. You can reach us at any time at privacy@wearecrabtree.com.
We provide marketing and investor-visibility services to fund managers. This website is a marketing site: the only action it asks of you is to leave your work email in exchange for a complimentary Fund Visibility & Digital Authority Audit, which is delivered by a person on our team.
2. What we collect
2.1 Information you give us
There are three places on this site where you can submit information:
- The short form at the top of the page — your email address only.
- The full audit form — your email address, full name, firm name, years in the industry, and an approximate assets-under-management range.
- The contact panel in the corner of the page — your email address, and an optional phone number and message.
The full form requires email, full name, firm name, years in the industry and an AUM range. The short form and contact panel require only email. Please do not submit confidential fund information, material non-public information, or personal information about your investors through these forms.
2.2 Information we collect automatically
- Marketing attribution (only after optional consent) — the campaign parameters in the link you arrived
on (
utm_source,utm_medium,utm_campaign,utm_content,utm_term), advertising click identifiers (gclidfrom Google,fbclidfrom Meta), the page you landed on, and the site that referred you. We store two copies: the first visit we ever saw from your browser, and the most recent one. - Your IP address — sent to Cloudflare Turnstile to check that a submission is not automated, and used as the key of an abuse-prevention record that limits how often the same address can submit our forms.
- Timestamps — when a record was created and when it was last updated.
- Analytics and session data (only after optional consent) — page views, scrolling, clicks on our calls to action, form submissions and email confirmations, plus session recordings and heatmaps. Section 5 lists the providers involved and what each one does.
2.3 Information we derive about you — automated assessment
When you submit a form, our system automatically evaluates the enquiry and stores the result alongside it: a numeric score, a priority tier (for example low priority), and a score breakdown recording which inputs produced that score. The inputs are your stated years in the industry, assets-under-management range, whether your email domain is on a list of free email providers, and your marketing source. Firm name is not a scoring input.
This automated assessment assigns a follow-up priority to your enquiry and can label it as qualified for analytics. It is not a credit, eligibility or investment suitability assessment. You may ask us what score and tier we hold for you, ask us to correct the information behind it, or object to the assessment, by writing to privacy@wearecrabtree.com.
3. Why we use your information
- To respond to you and to prepare and discuss the complimentary audit.
- To confirm that the email address is yours — see section 4.
- To prioritise follow-up, using the automated assessment in section 2.3.
- Marketing follow-up — we contact confirmed addresses about our services. You can stop this at any time by telling us so.
- To measure our advertising and our site — which campaigns and pages lead to enquiries, and how the pages are actually used.
- Security and abuse prevention — bot checks and rate limiting, so the forms are not used to send mail to people who never asked for it.
- Internal notification — a card summarising a new enquiry is posted to our internal team channel, and a notification is emailed to our own team addresses.
Where the EU or UK GDPR applies to you, we rely on our legitimate interest in marketing our services to businesses and in keeping this site secure, on your consent where you have asked us to contact you, and on steps taken at your request before any engagement. You can object to processing based on legitimate interests at the address above.
4. How we use your email address — confirmed opt-in
After a form submission, the normal process sends a confirmation email and waits for confirmation before notifying our team. You confirm on the page opened from that email. There are exceptions: if the verification service is unavailable, sending fails, or a later submission reaches the five-send limit, the system can notify our team with the address marked unverified or its status marked unknown. Leaving an address unconfirmed does not prevent all internal sharing; it does not count as confirmation.
- The confirmation link expires after seven days.
- We store only a one-way SHA-256 hash of the confirmation token, never the token itself.
- We will not re-send a confirmation within ten minutes of the last one, and never more than five in total for the same address.
- Confirmation happens when you press a button, not by loading a link. This is deliberate: corporate mail-security systems open links in messages automatically, and a plain link would let a scanner confirm an address on your behalf.
5. Cookies and tracking technologies
5.1 Our own cookies
The necessary crabtree_consent_v1 cookie remembers your choice for 180 days.
It is not used to identify you for advertising. If browser storage is unavailable,
the choice lasts only for the current page. The attribution cookies below are optional
and are created only after you accept optional tracking.
-
fl_first_touch— a JSON record of the campaign parameters, landing page and referrer of your first visit. Path/, lifetime 180 days,SameSite=Lax,Secure. -
fl_last_touch— the same record for your most recent visit, with the same settings.
The same two values are also written to your browser’s local storage as a fallback, so clearing cookies alone may not remove them; clearing site data will.
5.2 Third-party technologies on this site
- Google Tag Manager (container
GTM-55FRQ4KD) — loads the measurement tags below. It is loaded only after you choose Accept all in Cookie preferences. - Google Analytics 4 (property
G-KSVGEJS8NZ) — site analytics. Events include page views, clicks on our calls to action, scroll depth, form submissions and email confirmations. - Microsoft Clarity (project
yhwzgnp1am) — session recording and heatmaps. Clarity replays how pages were used: mouse movement, scrolling, clicks and page content. We mark the email, phone and free-text fields on our forms so that what you type into them is masked in the recording, but other page content may be recorded while optional tracking is enabled. - Meta Pixel (
1626494355768748) — advertising measurement for our campaigns on Facebook and Instagram. With optional consent, it records page views and a conversion event only after an email address has been confirmed. - Cloudflare Turnstile — the bot check on our forms. It receives your IP address and signals from your browser.
- Google Fonts — typefaces are requested from Google’s font servers, which receive your IP address.
Optional tracking is off until you accept it. Google Tag Manager, Analytics, Meta Pixel, Clarity and our marketing attribution storage require optional consent. Reject optional leaves them off. Necessary hosting, security, form handling, confirmation emails and font delivery continue to work without that consent. Section 8 explains how to change or withdraw your choice.
6. Who we share your information with, and where it is stored
We use the providers below to operate the site and measure advertising. The legal classification of advertising disclosures as a sale or sharing under applicable privacy laws, and any required opt-out process, still need client and legal review. We do not claim here that advertising disclosures fall outside those definitions.
- Cloudflare — hosting for this site, the database that holds enquiries and the Turnstile bot check.
- Resend, which delivers through Amazon SES in the
us-east-1region — our confirmation and notification emails, sent frommail.wearecrabtree.com. - Google — Tag Manager, Analytics and Fonts.
- Microsoft — Clarity session recording and heatmaps.
- Meta — advertising measurement through the Pixel.
- Lark (Feishu) — a summary of each new enquiry is posted to our internal team channel.
These services may process information outside your country, including in the United States. Actual storage locations and the safeguards for international transfers must be confirmed with the providers before this draft is finalised.
7. How long we keep it
We will be straightforward about this: this site has no automatic deletion today. Enquiry records, email-confirmation records and the abuse-prevention records keyed to IP addresses are all retained indefinitely until we delete them, whether or not the address was ever confirmed. The seven-day expiry described in section 4 stops a confirmation link from working; it does not delete the record.
You can request deletion by emailing the address in section 8. There is no self-service deletion tool. A retention schedule, the person responsible for requests and a process for removing records from the database, emails and team notifications need to be confirmed.
8. Your choices and your rights
8.1 Ask us directly
Write to privacy@wearecrabtree.com to ask for a copy of what we hold about you, to have it corrected, to have it deleted, to object to the automated assessment in section 2.3, or to stop hearing from us. Please write from the address you gave us, or tell us which address to look up. Applicable law may require identity verification or permit some information to be retained. Depending on where you live, you may also have the right to complain to your data-protection authority.
8.2 Stop the tracking on this site
Open Cookie preferences to accept or reject optional tracking. Withdrawing consent saves a rejection, removes known tracking cookies and attribution storage on this site, and reloads the page to stop the scripts already loaded in that tab. This does not erase information previously received by a provider or cookies on a provider’s own domain. Reload other open tabs to apply the change there too.
- Your browser. Block or delete cookies and site data for this site, or
clear local storage as well. Clearing site data removes stored identifiers, including
fl_first_touchandfl_last_touch, but a later visit can recreate them if you accept optional tracking again. Clearing site data also clears your consent choice; optional tracking then stays off until a new choice is made. Private browsing does not itself stop tracking. Content blockers may block some trackers, depending on their configuration. - Google Analytics. Install Google’s official opt-out browser add-on
from
tools.google.com/dlpage/gaoptout, which stops Analytics on every site, including this one. - Microsoft Clarity. Microsoft offers an opt-out from Clarity through its
privacy controls, linked from the Clarity terms at
clarity.microsoft.com/termsand from the Microsoft privacy statement. - Meta. Manage what Facebook and Instagram do with off-platform activity through the ad preferences in your Meta Accounts Centre, including the “Activity off Meta technologies” controls.
- Global Privacy Control (GPC). When your browser sends GPC, this site treats it as a rejection of optional tracking, including when an older choice accepted it. The separate Do Not Track (DNT) signal does not change our consent settings. You can email us about previously stored records; GPC does not delete those records.
You can choose not to confirm your email. The exceptions in section 4 mean that an unconfirmed enquiry may still reach our team. Email us to request that follow-up stop.
9. Children
This site is aimed at investment professionals and is not directed to children. We do not knowingly collect information from anyone under 16. If you believe a child has submitted information to us, write to privacy@wearecrabtree.com and we will delete it.
10. Security
Enquiries are stored in a managed database with access limited to the people who need it, confirmation tokens are stored only as hashes, the forms are protected by a bot check and rate limiting, and the site is served over HTTPS. No method of transmission or storage is completely secure, and we do not claim otherwise.
11. Changes to this policy
If our practices change, we will update this page and change the date at the top. Where a change materially affects information we already hold, we will say so here rather than changing it quietly.
12. Contact
{{LEGAL_ENTITY}}, {{REGISTERED_ADDRESS}}. Email privacy@wearecrabtree.com for anything in this policy, including access, correction, deletion and opt-out requests.
Back to the homepage