Privacy Policy
What data we collect, why we collect it, and what your rights are. Written in plain language — no dark patterns, no buried clauses. If something here is unclear, write us at v@pointhigher.com.
01Who We Are
This Privacy Policy applies to pointhigher.com and any sub-pages (collectively, "the Site"), operated by Resonate Agency LLC (doing business as Point Higher), a Florida limited liability company headquartered in Miami, Florida.
For the purposes of US privacy law, Resonate Agency LLC is the controller of personal data collected through the Site. References to "we," "us," and "our" mean Resonate Agency LLC, doing business as Point Higher. References to "you" mean any person visiting the Site or contacting us through it.
02What We Collect
We collect only what's necessary to run the Site, answer inquiries, carry out the SCAN Audit and improve how the Site works. The table below is a complete list of what the Site collects and why. Section 04 names the outside services involved and what the Site keeps in your browser, and Section 06 says how long each thing is kept.
Contact Form
Name, email, phone, business name (optional), what you need help with, any other of our services you pick as also of interest (optional), budget (optional), your message, which of our service pages you came from if you used its button, and how you first found the Site (see ph_attribution in Section 04)
To respond to your inquiry
SCAN Audit: First Screen
Name, phone and email. They reach our team as soon as you continue past that screen, whether or not you go on to pay
To contact you about the audit you started, and to send the report if you buy it
SCAN Audit: Your Business
Business name, type of business and website address, sent to our scanner. It reads that website's public pages and shows what it finds in your browser. Neither what you entered nor what it finds is saved on our servers
To run the scan you watch on screen
SCAN Audit: Payment
Card and billing details, typed into HubSpot's checkout. They go to HubSpot, not to us. We see a record of the payment (who paid, the name, email and billing details given, the amount and the date) but never the full card number
To take payment and match it to your audit
SCAN Audit: Brief After Payment
Your email, business name, website and type of business, the area you serve, the service that matters most to you and anything else you tell us. Details you already gave earlier in the visit are filled in for you and shown back before you send
To carry out your SCAN Audit
Analytics Data
Pages viewed, time on page, referrer, device type, approximate country/region derived from your IP address, and a random identifier stored in cookies so repeat visits can be counted as one person
To understand how the Site is used
Behavior Recordings
Session replays of your visit — mouse movement, scrolling, clicks — and heatmaps built from them (via Microsoft Clarity). What you type into form fields is hidden; text shown on the page may be recorded (see Section 04)
To diagnose UX issues
Server Logs
IP address, timestamp, web address requested, browser user-agent. If a form can't be delivered to our team, what you entered is written to the log instead, so it isn't lost
Security and abuse prevention (Vercel hosting). To stop the scanner being run in bulk, it also counts scans per IP address for ten minutes, in memory only
Email Correspondence
Anything you send us by email or through forms
To carry on our communication
What We Do Not Collect
We do not collect payment card information. The SCAN Audit is paid through HubSpot Payments, whose checkout sits inside a HubSpot frame on the payment step: your card details are typed into HubSpot's form and go to HubSpot, never to our servers or to our page's own code. Other paid work is invoiced and paid by bank transfer or by card through a payment provider. Either way, we never see or store full card numbers.
We do not collect government identifiers (SSN, EIN beyond what's required for invoicing, passport numbers, etc.).
We do not collect biometric data, precise geolocation, or sensitive demographic categories (race, religion, sexual orientation, health information).
03How We Use It
We use the data above for the following limited purposes:
Responding to your inquiry. If you fill out a form or email us, we use your contact info to respond and to keep records of our exchange. If you start a SCAN Audit, we use your name, phone and email to run it and to email you about it; we call or text you about it only if you tick the optional box for calls and texts.
Text messages. If you agree on our contact form, or tick the optional box for calls and texts on the form that starts a SCAN Audit, we may call or text you about your enquiry or your SCAN Audit at the number you gave. Leaving that box empty never stops you starting or buying a SCAN Audit; we then contact you about it by email only. How often depends on the conversation, and message and data rates may apply. Reply STOP to any text and we stop texting you; reply HELP for help. Agreeing is not a condition of buying anything from us. We never share your mobile number, or your agreement to receive texts, with any third party or affiliate for their marketing or promotional purposes, and text-messaging opt-in data and consent are not shared with any third parties. The service providers in Section 04 that carry your enquiry to our team hold it only to do that.
Carrying out work you buy. If you buy a SCAN Audit, we use the payment record to match your payment to you, and your brief to carry out the audit.
Operating and improving the Site. Analytics tell us which pages work and which don't; session replays let us watch back an individual visit to see where someone got stuck, which the numbers alone only hint at. We also count how far visitors get through the SCAN Audit's steps and how many send a form, without their name or contact details attached.
Following up, only about what you asked for. We contact you about the inquiry you sent or the SCAN Audit you started. There is no newsletter on the Site, and we do not add anyone to a mailing list without asking first.
Legal obligations. If we're required by law to retain or produce records (court orders, tax requirements, etc.), we'll comply.
Security and abuse prevention. We use server logs to detect and block malicious activity (bot scraping, brute-force attempts, etc.).
We do not sell your personal data. We do not share it with advertisers or data brokers, and we do not use it for ad retargeting — no advertising pixel is installed on the Site. The measurement tools that do run are listed under "Third-Party Services" below.
04Third-Party Services
The Site is built on a small set of third-party services, each with its own privacy policy. We've kept this list as short as we can.
Three of them are measurement tags: Google Tag Manager (container GTM-TXQJW68R), Google Analytics 4 (property G-46W6MYBSZR) and Microsoft Clarity (project ylzr1csvmc). They load on every page of the Site, for every visitor, as soon as the page opens. We do not currently show a cookie banner and do not ask for your consent before they run. That is worth stating plainly rather than burying: if you are reading this from the EU or the UK, where analytics and session recording normally require your permission first, these tags will already have loaded by the time you reach this sentence. We serve businesses in the United States and have not built a consent gate for visitors elsewhere. Until we do, the way to stop them is your browser: turn on its tracking-protection features, or use an extension that blocks them, and the Site works normally without any of them. Between them they set cookies and similar identifiers in your browser, which tag it with a random number so repeat visits can be counted as one person rather than several. On pointhigher.com itself these are Google's _ga and _ga_46W6MYBSZR and Clarity's _clck and _clsk, and Clarity also keeps _cltk in the tab's session storage. Clarity's tag also calls Microsoft's own servers (c.clarity.ms and c.bing.com), and their replies can set Microsoft cookies under Microsoft's own domains: MUID, on bing.com and clarity.ms, which Microsoft describes as identifying a browser across Microsoft sites for advertising, site analytics and other purposes; SM and MR, which Microsoft uses to keep MUID in sync and up to date; SRM_B, which Bing sets alongside them; ANONCHK, which Microsoft says is always 0 for Clarity; and CLID, on clarity.ms, which records when Clarity first saw your browser on any site that uses it. A browser that refuses third-party cookies, as Safari does by default, stores none of these Microsoft cookies, but the calls to Microsoft's servers are still made. Google Analytics can also be switched off with Google's opt-out add-on. Note that blocking cookies alone only stops your visits being linked together: it does not stop the tags from running or Clarity from recording.
The Site also keeps a few records of its own in your browser's storage. They stay on your device, and reach us only in the ways described here:
ph_attribution — how you arrived: any campaign tags on the link you followed, a Google or Meta click id if one was present, the page you landed on and the site that referred you. It keeps your first visit for 90 days, and this visit until you close the tab. If you send the contact form, it travels with the form, which is how we know which campaign produced a real inquiry.
ph_scan_gate — the name, phone number and email you enter on the first screen of the SCAN Audit, so the next steps know who you are without putting your details in a web address. Once your details have reached our team, it also keeps a short code worked out from them, not the details themselves, so going back and pressing Start again does not send them twice. If you tick the optional box for calls and texts, it also remembers that you did, so going back shows your answer as you left it; changing the answer and pressing Start again sends your details to our team again, with the new answer. It is cleared when you close the tab and stops being used after two hours. Its email address is the one we pass to HubSpot's checkout and send with your brief.
ph_scan_context — the business name, type of business and website you enter in the SCAN Audit, and the service area the scan found on your site, so the brief after payment doesn't ask for them again. It is cleared as soon as your brief is sent, or when you close the tab.
ph_scan_steps — which step of the SCAN Audit you are on, the business name, type of business and website you entered, how many pages the scan read and how many findings it raised, so Back, Forward or a reload returns you to the same step instead of starting over. It also holds a short code worked out from your email address, not the address itself, so a second person using the same tab never sees your answers. It is cleared when you close the tab and stops being used after two hours.
ph_scan_result — the result of the scan of one website: what the scan read on that site's public pages and records and what it found, and how far a scan got if it was interrupted, so a reload or going back shows the same result instead of scanning again. It holds none of the name, phone or email you gave us, and the business name you typed is left out (it can hold what the scanned site itself publishes, such as a contact address shown on its pages); it holds a short code worked out from your email address, not the address itself, so a second person using the same tab never sees your scan. A new scan replaces it. It is cleared when you close the tab and stops being used after two hours.
ph_scan_brief_sent — only the time your brief was sent, so reloading that page shows it arrived instead of asking again. It holds none of your answers, is cleared when you close the tab and stops being used after two hours.
ph-portal — used only by the portal preview page, to remember whether you opened it and which view you chose. It holds nothing about you.
Clearing your browser's site data deletes all of them. The cookies above and ph_attribution never hold your name, phone number, email address or anything you type into a form, and we do not send those to Google or Microsoft. Two exceptions, stated plainly. First, the SCAN Audit screens show some of what you entered back to you — your first name, business name and website, and your email on the brief after payment — and the measurement tags run on those pages like any other, so Clarity's recording can include that text (see Microsoft Clarity below). Second, the email address you give at the start of the SCAN Audit is written into the web address of HubSpot's checkout, so the payment form arrives already filled in (see HubSpot Payments below). That web address is part of our page, so the measurement tags on the page are able to read it. The link that opens the checkout in a new tab does not carry your email, so clicking it gives Google Analytics nothing but the checkout's address. We have not set up any tag to collect any of this.
Here's the full inventory:
Vercel — hosts the Site and runs its server code. Sees your IP address as part of standard server operation, and keeps the server logs described in Section 02. Vercel Privacy Policy
Google Analytics 4 (GA4) — measures Site usage: pages viewed, where you arrived from, device and browser, and an approximate location worked out from your IP address. We load GA4 with Google's standard configuration and send it no personal identifiers of our own. It also records the short notes on the SCAN Audit and our forms described under Google Tag Manager, below. Google Privacy Policy
Google Tag Manager (GTM) — the container we use to add and manage measurement tags without changing the Site's code. It holds no analytics data of its own, but loading it is a request to Google that carries your IP address and browser user-agent like any other, and any tag we add to the container can set cookies of its own. The Site also hands the container short notes on what happened during your visit: that you sent the contact form (with which of our services it is about and how many others you picked), the first screen of the SCAN Audit or the brief after payment; which SCAN Audit step you reached; whether the scan finished or failed (and, if it failed, the message shown and what kind of failure it was); and how many pages, words, checks, findings and settings needing work it counted. The same notes go to GA4 directly. They never include your name, phone, email, business name or website. GA4 is not inside this container: the page loads it separately. Both are fetched from the same Google address, www.googletagmanager.com, so blocking that address stops both. Google Privacy Policy
Microsoft Clarity — records your session and replays it. That means a playable reconstruction of your visit: where the pointer moved, what you scrolled past, what you clicked, how long you paused, plus heatmaps built from all visits together. We watch these back to find where the Site confuses people. Clarity hides what you type into form fields, so your entries are not captured as readable text, and we have not turned that off. Other text shown on the page can be recorded as it appears, which on the SCAN Audit screens includes the details they show back to you, such as your business name. The SCAN Audit's first screen, which greets you by name, is hidden from recordings. Clarity sends what it records to Microsoft's servers at clarity.ms, and its tag also calls c.bing.com, a Microsoft domain. Those calls show Microsoft your IP address, as any web request does, and can set the Microsoft cookies named above. Microsoft Privacy Statement
HubSpot Payments — takes payment for the SCAN Audit. Its checkout is HubSpot's own page, shown inside a frame on the payment step, and HubSpot receives everything you type into it: card and billing details, name and email. So you don't have to type your email twice, we add the email address you gave at the start of the SCAN Audit to the checkout's web address (it is set on the checkout frame itself and is not written into our page, so the measurement tags above do not record it), along with the address of our page and a random code HubSpot uses to tell visits apart. So the payment step opens without a wait, the checkout starts loading out of sight as soon as you reach the report step, the step before payment, and HubSpot receives these at that point, whether or not you go on to pay. Once you are past the first screen of the SCAN Audit, your browser also opens a connection to HubSpot's servers ahead of time, which shows HubSpot your IP address, as any web request does. Because the checkout is a separate HubSpot page, neither our code nor the measurement tags above can see what you type into it, and any cookies it sets are HubSpot's, under HubSpot's policy. HubSpot and Stripe, the card processor HubSpot Payments runs on, handle the payment, and HubSpot keeps a record of it in our HubSpot account. HubSpot Privacy Policy
Telegram — how what you send reaches our team. When you send the contact form, continue past the first screen of the SCAN Audit, or send your brief after paying, our server passes what you entered to a private Telegram chat our team uses. For the contact form, that includes how you found the Site (ph_attribution) and, if you came from one of our service pages' buttons, which page. Our code can also send the same details by email through Resend, or save them in HubSpot or Prismic, but none of these is switched on today; if we switch one on, we will list it here first. Telegram Privacy Policy
Google Public DNS — used by our scanner. When you run a scan, our server reads the public pages of the website you name (up to 20 pages, plus its robots.txt and sitemap files), the way a search engine would, and says who it is (PointHigherBot) in every request. It also looks up that domain's public records, such as where its site and email are hosted, through Google's public DNS service, so Google sees the domain name, asked for by our server rather than by you. Google Privacy Policy
Advertising pixels — none are installed on the Site today. No Meta Pixel, and nothing that builds a retargeting audience from your visit. If we add one for a paid campaign, we'll list it here before it goes live. Meta Privacy Policy
Each service operates under its own terms, linked above, and each publishes its own compliance position — we rely on what they publish rather than certifying it ourselves. We chose them because they're industry-standard and configurable to minimize what's collected.
05Data Sharing
We share data only when:
It's necessary for the third parties listed above to provide their service to us (hosting, analytics, session replay, taking payment, delivering what you send through a form). This is how the analytics data and session replays described in Section 04 reach Google and Microsoft, and how your payment reaches HubSpot, who hold them on their own systems rather than ours. Each operates under contract terms or industry-standard data processing terms.
You're an active client and the members of our own team who deliver SEO, paid media and creative work see what their work requires. Everyone who handles client data is bound by written confidentiality terms.
We're legally required to disclose data — court orders, valid law-enforcement requests, regulatory inquiries, or to defend legal claims.
Business transfer. If Resonate Agency LLC merges, is acquired, or undergoes a similar transition, your data may transfer to the successor entity. We'll notify you if this happens.
We will never sell your personal data to third parties for their own marketing purposes.
06Data Retention
How long we keep things:
Form submissions and email correspondence: retained as long as the relationship is active, plus up to 3 years for record-keeping. This includes what you send from the SCAN Audit's first screen and your brief. Inactive prospects who never engaged are pruned annually.
Analytics data (GA4): the detailed record of visits is kept for up to 14 months, under GA4's data retention setting. Totals already counted into its reports, which do not identify anyone, are kept longer.
Microsoft Clarity recordings: retained for up to 13 months, per Clarity's default settings. This includes the session replays, not just the aggregate heatmaps built from them.
Cookies in your browser: each expires on its vendor's own schedule, set by Google and Microsoft rather than by us. As we measured them on September 24, 2026: _ga and _ga_46W6MYBSZR last up to about 13 months, _clck one year, _clsk one day and _cltk until you close the tab; Microsoft's MUID and SRM_B about 13 months, CLID one year, MR seven days, ANONCHK ten minutes and SM until you close the browser. You can clear them at any time in your browser settings; doing so gives you a new random identifier the next time you visit.
Records the Site keeps in your browser: ph_scan_gate, ph_scan_steps, ph_scan_result, ph_scan_context and ph_scan_brief_sent are cleared when you close the tab (ph_scan_gate, ph_scan_steps, ph_scan_result and ph_scan_brief_sent also stop being used after two hours, and ph_scan_context is cleared as soon as your brief is sent); ph_attribution keeps your first visit for 90 days, after which your next visit takes its place; ph-portal stays until you clear it. Clearing your browser's site data deletes all of them at any time.
Server logs: retained for up to 30 days for security and operational diagnostics. That includes any form that could not be delivered to our team and was written to the log instead.
Client engagement data, including payment records: retained for the duration of the engagement plus 7 years for tax, legal, and dispute-resolution purposes (matches Florida statute of limitations on contracts).
You can request earlier deletion of your data — see Section 07: Your Rights.
07Your Rights
Depending on the privacy laws applicable to you (Florida residents, California residents under CCPA/CPRA, or otherwise), you have the following rights:
Right to access. You can ask us what personal data we hold about you, and we'll provide a copy.
Right to correct. If something is wrong, ask us to fix it.
Right to delete. You can ask us to delete your personal data, subject to legal retention requirements (e.g., we may need to retain client engagement records for tax purposes).
Right to opt out. You can ask us to stop contacting you at any time: reply to any message from us, or email v@pointhigher.com, and we will stop.
Right to non-discrimination. We will not refuse service or charge different rates because you exercised a privacy right.
To exercise any of these rights, email v@pointhigher.com with the subject line "Privacy Request." We'll verify your identity (typically by replying to the email address we have on file) and respond within 30 days, as required by US privacy laws.
08Security
We take reasonable precautions to protect personal data, including HTTPS encryption across the Site, secure email infrastructure, access controls limiting who on our team can see what, and written confidentiality terms binding everyone who handles client data.
That said, no system is bulletproof. If we ever experience a data breach affecting your personal information, we will notify you within the timeframe required by applicable law (typically 30–45 days), describe what happened, and explain what we're doing about it.
09Children's Privacy
The Site and our services are intended for businesses and adults aged 18+. We do not knowingly collect personal data from children under 13. If you believe a child has provided us with personal information, contact us at v@pointhigher.com and we'll delete it.
10Changes to This Policy
We may update this Privacy Policy from time to time — typically when we add or remove third-party services, when laws change, or when we improve our internal data practices. Each time, we update the "Last Updated" date, put a short note of what changed at the top of this page, and add a dated entry to the list below. Entries stay in the list for at least 12 months.
An entry says so when a change is material — when it meaningfully affects your rights or how data is used. We won't make material changes silently.
What Changed
September 28, 2026 (material). The form that starts a SCAN Audit no longer has a required box. We use the name, phone and email you give there to run the SCAN Audit and to email you about it, and a notice under the button says so. Agreeing to calls and texts is a separate, optional box, empty until you tick it; leaving it empty never stops you starting or buying, and we then contact you by email only. Your answer reaches our team with your details, marked as agreed or not agreed, and ph_scan_gate remembers it for the tab. (The September 26 entry below describes the single required box this replaces.) A new record in your browser's tab, ph_scan_result, keeps the result of the scan of one website for up to two hours, so a reload or going back shows it instead of scanning again; it holds none of the name, phone or email you gave us and is cleared when you close the tab. The email we pass to HubSpot's checkout is now set on the checkout frame itself rather than written into our page, so the measurement tags, including Microsoft Clarity's session recordings, no longer record it; and the SCAN Audit's first screen, which greets you by name, is now hidden from recordings. Sections 03, 04 and 06 say so.
September 26, 2026 (material). The short notes the SCAN Audit and our forms hand Google Tag Manager — the step you reached, whether the scan finished or failed and what it counted, and that a form was sent — now also go to Google Analytics 4 directly, which records them in our reports. Until now they reached only the container, which had no tag to record them, so the step-by-step counting that Section 03 describes was not happening; it now is. They still never carry your name, phone, email, business name or website. Section 04 says so, and corrects two details: Google Tag Manager and Google Analytics 4 are fetched from the same Google address, www.googletagmanager.com, so blocking that address stops both (the policy had said blocking one did not block the other); and HubSpot's checkout starts loading as soon as you reach the report step. The record that keeps your place in the SCAN Audit has a new name, ph_scan_steps; it holds the same things and is cleared at the same times, and the copy under its old name is removed the next time the SCAN Audit saves your place. The contact form has a new optional question, Also Interested In, where you can pick other services you'd like to hear about; when you open the form from the button on one of our service pages, it also records which page that was. Both reach our team with the rest of the form, and Section 02 lists them. The note the form hands Google Tag Manager and Google Analytics 4 now also says which of our services the form is about and how many others you picked — never what you typed. The contact form's agreement now also covers calls and text messages about your enquiry, the form that starts a SCAN Audit now asks for the same agreement with a box of its own (it used to take agreement from pressing Start), says that message and data rates may apply and that replying STOP ends the texts (HELP for help), and Section 03 has a new paragraph on text messages: agreeing is not a condition of buying, and your mobile number and your agreement are never shared with anyone for their marketing.
September 24, 2026 (material). Section 04 now names every identifier Microsoft Clarity sets — _clck and _clsk on this Site, _cltk in the tab's session storage, and MUID, SM, MR, SRM_B, ANONCHK and CLID on Microsoft's own domains — and the Microsoft servers it contacts, including c.bing.com. Section 06 says how long each cookie lasts. Clarity was already setting these before; the policy had named only _clck and _clsk. Section 04 also lists a new record the SCAN Audit keeps in your browser so Back, Forward and reload return you to the same step (now named ph_scan_steps), and Section 06 says when it is cleared. It also says that ph_scan_gate now keeps a short code worked out from details that already reached our team, so they are not sent twice. The short notes the SCAN Audit hands Google Tag Manager now also count the checks a scan ran and name the kind of failure when one fails, and Section 04 says so. This section no longer promises notice by email and a banner on the Site for at least 14 days when a change is material: for the September 21–23 changes no such email was sent and no banner was shown. The note at the top of the page and this list take their place.
September 21–23, 2026 (material). The policy was rewritten to match what the Site actually does. It says the three measurement tags (Google Tag Manager, Google Analytics 4 and Microsoft Clarity) load for every visitor, including visitors in the EU and UK, with no cookie banner and no request for consent. It says Clarity records full session replays and that analytics locations come from your IP address, where the earlier version called both anonymized. It adds the SCAN Audit: what each of its screens collects; that your name, phone and email reach our team as soon as you continue past its first screen, whether or not you pay; the scanner and its Google Public DNS lookups; HubSpot's checkout and the email address it receives one step before the payment step; that Telegram is the one way forms reach our team today, where the earlier version listed four possible channels; and the records the Site keeps in your browser. It also says that a form which can't be delivered is written to our server logs, and Section 05 now describes who on our side sees client data.
11How to Contact Us
For privacy-related questions, requests under your rights above, or anything else covered by this policy:
Resonate Agency LLC (doing business as Point Higher)
Email: v@pointhigher.com · Subject: "Privacy Request"
Phone: +1 786 696 3876
Mailing: Available on request
We'll do our best to respond within a few business days, and within the 30-day window required by applicable US privacy laws for formal rights requests.