Privacy Policy
Last updated: July 2026
Information Gathered from Visitors
In common with other websites, our web server stores log files containing the visitor's IP address, browser type, referring page, pages visited, and time of visit. These logs are used solely for security monitoring and anonymous traffic analysis.
We use Plausible Analytics, a privacy-focused analytics service that does not use cookies, does not collect personal data, and is GDPR-compliant by default.
If you consent via the cookie banner, we also use Google Analytics 4 (loaded through Google Tag Manager) to understand aggregate usage patterns. Google Analytics sets cookies (such as _ga and _ga_*) that expire after 2 years. These scripts are loaded only after you accept cookies; if you decline, no Google cookies are set.
Tracking, Profiling & Automated Identification
We believe transparency beats fine print, so here is everything this site does to understand its visitors — including the parts most sites leave out:
- First-party page tracking: our own server records each page view with the path, referring page, IP address, browser user agent, and any campaign (UTM) parameters. This powers our traffic dashboards and abuse prevention. It never leaves our server.
- Company (not person) identification: we look up visitor IP addresses against a locally stored MaxMind GeoLite2 database to identify the organization or networka visit came from (for example, “a visitor from Acme Corp's network”). This lookup happens on our own server, identifies companies rather than individuals, and no data is sent to MaxMind or anyone else.
- Repeat-visit linking: we compute a short hash of IP address + browser user agent to connect repeat visits into one anonymous timeline. This record contains no name or email unless you later identify yourself (for example by signing in), at which point your visits are linked to your contact record.
- Engagement beacons: pages report anonymous scroll depth and time-on-page so we can tell which content is actually useful.
- Email tracking: emails we send record delivery, open, and click events so we know whether they arrived and were read.
- AI assistant processing: conversations with Finder AI (web chat, SMS, or phone) are processed by our AI systems and stored, including call transcripts, so the assistant can answer you and we can review quality.
To object to any of this processing or have your visit and contact records purged, email [email protected]. Retention windows for each record type are listed under Data Retention below.
Chat Page Context
While you use the chat widget, Finder AI can see the page you are on — its address, title, and visible text — so it can answer questions about what you are looking at. While the chat panel is open, it is also told short descriptions of elements you point at or text you select (for example, “the ‘Pricing’ heading”) so you can gesture at what you mean.
Nothing is captured while the chat is closed, form values and passwords are never read, and the widget shows a “Sees this page” indicator with an off switch whenever sharing is active. Shared page context is stored with the conversation like any other chat content.
Issue Reports
If you report a problem through the chat, your report — including a short excerpt of the conversation and, when page sharing is on, a snapshot of the page you were viewing — is emailed to IT Support Chicago staff so a human can act on it. If you include a contact address, staff may use it to follow up. To review or erase a report, email [email protected].
Account Data
If you create an account, we store your email address and display name (provided via Google OAuth, Microsoft OAuth, or magic link). This information is used only to authenticate you and personalize your experience.
Evaluation Data
When you use our evaluation tool, we store your company profile, weight preferences, and saved search results so you can return to them later.
Your evaluations are confidential. Your company profile, custom weights, and scored results are never shared with the vendors being ranked, never displayed publicly, never sold, and never used in our public ranking calculations. Only you can see your evaluations.
How We Use Your Data
- To provide the evaluation and ranking service
- To save your searches so you can return to them
- To detect and prevent abuse (rate limiting, fraud prevention)
- To improve the service (aggregate, anonymous usage analytics)
What We Do NOT Do
- We do not sell your data to anyone
- We do not share your data with vendors in our rankings
- We do not use your data for advertising
- We do not use third-party tracking cookies without your explicit consent. (Our own first-party attribution cookie, described under Cookies, is not one: it is httpOnly, advertising-free, follows you to no other site, and exists only so we can answer “how did you find us”.)
- We do not serve third-party advertisements
- We do not use your data to train AI foundation models. Our AI assistant (Finder AI) processes and stores your conversations to answer you (see Tracking above), but your data is never sold to, or used to train, third-party models.
Cookies
Essential cookies: We use a single httpOnly session cookie (isc_session) for authentication and a localStorage key to remember your cookie consent preference. These are necessary for the site to function.
First-party attribution cookie: A first-party cookie (topmspnearme_attrib, httpOnly, Secure, 30 days) remembers the landing page, the site that referred you, any advertising click identifier in the address, and campaign parameters of your first visit — solely so we can answer “how did you find us” when you later take an action here. It is read only by our own server and never shared. It is not consent-banner-gated because it is not a third-party or advertising cookie: it identifies no person, follows you to no other site, and exists only in your browser's conversation with this one origin. A small script on our pages also reports the address of the page your browser says referred you, because some browsers pre-load our pages in a way that hides that from our server.
Analytics cookies (opt-in): If you accept cookies via the consent banner, Google Analytics sets cookies (_ga, _ga_*) to distinguish unique visitors. These expire after 2 years.
No advertising cookies: Plausible Analytics does not set cookies of any kind. We do not serve ads and never set advertising or remarketing cookies.
You may withdraw cookie consent at any time by clearing isc_cookie_consent from your browser's localStorage, or by blocking cookies via browser settings. Blocking all cookies will prevent you from signing in.
Third Parties
We share data only with services necessary to operate the site:
- Resend: Email delivery for magic links
- Google OAuth / Microsoft OAuth: Authentication only
- Plausible Analytics: Anonymous, cookie-free web analytics
- Google Analytics / Google Tag Manager: Aggregate usage analytics (loaded only after cookie consent)
- Cloudflare: DNS and tunnel (no personal data stored)
- AI model providers (OpenAI, Google, xAI, Anthropic): when you interact with Finder AI by web chat, SMS, or phone, your conversation content (including call transcripts) is sent to one or more of these providers via their APIs solely to generate the response. We use API terms under which providers do not use this content to train their models.
- Twilio: SMS and voice-call transport (phone numbers and message/call content, as required to deliver the service)
None of these providers receive your data for their own marketing purposes.
SMS / Text Messaging Data
If you communicate with us via SMS or text message, your mobile phone number and message contents are used solely to respond to your inquiry. Your mobile information will not be sold, rented, or shared with third parties or affiliates for their own marketing purposes. Mobile opt-in data and consent are not shared with any third parties except service providers that help us operate our messaging program, and those providers are restricted from using your information for any other purpose.
Message frequency varies based on your interactions with us. Message and data rates may apply.
For full details on our text messaging program, see our SMS Terms & Conditions.
Persona Memory
Finder AI keeps a private, per-person memory: facts you share and your conversation history, so later conversations can pick up where you left off. Your memory is visible only to you (and to Top MSP Near Me staff reviewing quality) — never to other visitors — and this site's own published rankings and data always outrank remembered facts when they conflict.
- One memory across channels: memory is keyed to your verified mobile number, so your text and phone-call conversations with Finder AI share one memory per person.
- SMS always remembers: texting Finder AI keeps memory for your phone number (possession of the handset is the authentication); the first reply you receive says so and names the erasure keyword.
- Erasure by text — “FORGET”: text FORGET to +1 (872) 369-3924 and we permanently erase the stored memories, conversation history, and call transcripts for that number — and, if the number is verified on an account, that account's memory too. You get a confirmation text once the erasure has completed. FORGET is not STOP: STOP opts you out of receiving messages; FORGET erases what we remember.
- What FORGET does not delete: SMS consent records (kept for legal compliance), the deletion-audit record proving the erasure happened, usage metadata that contains no conversation content, and server and diagnostic logs.
- Recycled numbers: memory is keyed to the phone number itself. If a number is reassigned by a carrier, its new holder could encounter memory from the previous holder — text FORGET from the number to erase it.
- Caller-ID caveat: voice calls recall memory by the calling number, and caller ID can be spoofed — a determined attacker who spoofs your number on a call could expose that number's memories. If this concerns you, text FORGET to erase the memory, or skip verifying your number.
You can also request erasure of remembered data at any time by emailing [email protected].
Visitor Options
You may request deletion of your account and all associated data at any time by emailing [email protected].
You may block cookies via your browser settings, though this will prevent you from accessing account features. You may opt out of SMS messages at any time by texting STOP.
Data Retention & Deletion
Retention is enforced by an automated weekly job with these windows:
- Account and saved evaluation data: as long as your account exists
- Unsaved draft evaluations: deleted after 90 days of inactivity
- Sign-in and usage logs: 12 months
- Page-view and engagement records: 24 months
- Email delivery/open/click events: 24 months
- IP-to-organization lookups: 12 months
- Conversion records (which traffic source an action you took here arrived from, stored with the email on your account): 24 months; erased with account deletion
- AI-assistant fetch log (requests identifying themselves as ChatGPT, Claude, Perplexity and similar — agent name, page, time, network address; kept separately from visitor analytics and never counted as human traffic): 6 months
- Raw web-server logs: up to 90 days
- SMS consent records: for the life of the messaging program plus four years, as required for compliance
Upon account deletion, all associated personal data is permanently removed within 30 days.
Data Portability
Signed-in users can download everything we hold about them — account profile, saved searches, draft evaluations, activity logs, lead/conversion records, and stored conversations with Finder AI — as a JSON file from /api/account/export. No request or approval needed.
Account Deletion (Right to Erasure)
Signed-in users can delete their account and its data with a request to /api/account/delete, confirmed by typing the account email. This permanently erases your saved searches, evaluations, analyses, contact record and activity history, your email correspondence with us, and your conversations and memories with Finder AI — then removes the account itself and returns an itemized count of what was erased. Phone-call records keep only operational metadata; the transcripts are erased.
Deletion retains the narrow records law or basic security requires: SMS consent records, the deletion-audit record proving the erasure happened, security logs with the account link removed, and anonymized usage telemetry. Questions or problems: [email protected].
Changes to This Policy
We may update this Privacy Policy from time to time. Changes are effective when posted to this page, and the “Last updated” date above reflects the most recent revision. Your continued use of the site after changes are posted constitutes acceptance of the updated policy.
Contact
For privacy questions or data requests: [email protected]