WholeFunnel AI Request a demo
Request a demo

Privacy Policy

Last updated August 15, 2026.

WholeFunnel AI builds and runs full-funnel marketing systems. This policy explains what this website collects, which analytics and advertising tools run on it, where that data is sent, and how to opt out. It describes what is actually deployed on wholefunnel.ai as of the date above.

Who we are and how to reach us

This site is operated by WholeFunnel AI. For any question or request about the data described here, email support@wholefunnel.ai. That address reaches us directly and is monitored by a person.

What runs on this site

Every page of this website loads third-party analytics and advertising tags. They load when you arrive: we do not currently present a cookie consent banner, and we do not ask you to opt in before they run. The tools are Google Tag Manager (container GTM-ML2GGXJ8) and the Google tag loader (GT-NS494R3Q), which load and manage the rest; Google Analytics 4 (measurement ID G-GNS89E21W3, property 547992229); Google Ads (conversion and remarketing ID AW-18361535561); and the Meta Pixel (ID 2492362891230163) together with the Meta Conversions API. The site also offers a chat assistant, described in its own section below.

Google Analytics

Google Analytics 4 records how visitors use this site: pages viewed, how you arrived, an approximate location derived from your IP address, device and browser characteristics, and interactions on the page. It sets cookies so that one visitor can be distinguished from another across pages and visits. Visits by users logged in to this WordPress site are excluded from this collection. What Analytics collects is processed by Google on Google’s systems, under Google’s own terms and privacy policy.

Google Ads, remarketing, and click measurement

The Google Ads tag records conversions and builds remarketing audiences, which means you may be shown WholeFunnel AI advertising on Google properties and partner sites after visiting this site. When you arrive from a Google ad, Google’s auto-tagging appends a click identifier to the URL (the gclid parameter). That identifier is what lets a later action on this site be attributed back to the ad you clicked. When our Google advertising uses the feature Google calls enhanced conversions, a form you submit on this site (the demo request, the rescue form, or a rescue window request) also sends Google a one-way hashed (irreversible) version of the email address and phone number you entered — never the readable values — so Google can match the conversion to the ad click on its own systems. That feature is part of our advertising measurement; when we are not running Google advertising, nothing is sent to Google under it.

The Meta Pixel and the Conversions API

The Meta Pixel (ID 2492362891230163) runs on this website and records page views; when you submit a form requesting our services (the demo booking request, or the inquiry form on our integration and modernization page), it also records a lead event on the confirmation view. It reports these to Meta for advertising measurement and audience building. Alongside the browser-side pixel, we use the Meta Conversions API to send the same lead event once from our own server, carrying a shared event ID so Meta counts the browser and server copies as one event. When you submit a technical-rescue request (described below), it likewise records a contact event on the confirmation page; that contact event is browser-side only — it is not sent through the Conversions API. If you request a rescue window with a card hold (described below), a schedule event is recorded on the confirmation page and sent once from our own server through the Conversions API, carrying a shared event ID so Meta counts the browser and server reports as one event. What Meta receives is processed by Meta on Meta’s systems, under Meta’s own terms and data policy.

Server-side lead events: hashing of personal identifiers

It is worth stating plainly what the server-side integration sends. It transmits nothing automatically: server-side events are created only when you submit one of our forms asking us to contact you or schedule something for you — a lead event when you submit a form requesting our services (today, the demo booking request and the inquiry form on our integration and modernization page), and a schedule event when you request a rescue window (each described below). Each such server-side lead event carries the click and browser identifiers described in the booking section below (including Meta’s click ID and the browser ID from Meta’s first-party cookie), your IP address and browser type, and a one-way hashed (irreversible) version of the identifiers you entered in the form — your name and phone number, and your email address if you provided one — never the readable values, so that Meta can match the event to a person in its own systems and attribute your request to the ad that led to it. The purpose is to measure our own advertising; we never sell your information. An earlier version of this site used Meta’s WordPress plugin with its Events Enrichment feature, which could cache and hash identifiers it observed during ordinary browsing; that integration was removed on August 6, 2026. The one browser-side matching feature we use is Meta’s advanced matching, and it is active on this site: when an event fires and the Pixel detects identifiers you have typed into this site’s forms at that moment, it sends Meta a one-way hashed (irreversible) version of them — never the readable values — to improve how ad results are matched. When nothing has been typed at the moment an event fires, nothing is sent.

Because part of this transmission happens on our server rather than in your browser, blocking cookies or using a tracker blocker will not necessarily prevent it. The most direct controls available to you are to not submit personal details on this site, and to use Meta’s own ad preference settings, linked below.

Information you send us directly

If you email us, we receive your email address and whatever you put in your message. If you submit a form on this site, we receive what you enter in it, which may include your name, email address, phone number, and the details you choose to tell us about your business. We keep form submissions for up to 24 months, and we never sell them. After 24 months an automatic purge permanently removes the personal details from each stored record — the name, contact information, message, and any advertising identifiers — leaving only de-identified operational data such as the date and the type of request. Form submissions and our replies are delivered as email through Microsoft Azure Communication Services, which transmits the message on our behalf. We use what you send to answer you and to keep a record of the correspondence.

If you request a demo time through the booking module, we store the details you submit — your name, email, phone, your office address if you choose an in-person visit, your chosen time, and anything you tell us about what you are trying to fix — on our own systems, and use them to schedule, confirm, and remind you about the appointment — and, when your visit came from an ad, for the advertising measurement described in the Meta section above. We keep them for up to 24 months, and we never sell them. After 24 months an automatic purge permanently removes the personal details from each stored record — the name, contact information, addresses, notes, and any advertising identifiers — leaving only de-identified scheduling data such as dates and appointment types.

When your visit arrives from an ad, we also keep the click identifiers it carries — such as Google’s click ID or Meta’s click and browser IDs — together with your demo request, so we can tell which advertising actually leads to booked demos. They stay with the request, are never sold, and are removed by the same 24-month cleanup.

The chat assistant

This site offers a chat assistant. It is automated: when you open it yourself, you are talking to an AI, not a person, and the assistant says so. Separately, Sassan Darian — the founder of WholeFunnel AI, a real person — may open a small live-chat window with you while you are on the site; when that happens you are talking to him, and the window says so. What you type in that live window is kept only briefly (it is deleted with the presence records described below) unless you go on to submit your details. The assistant also answers questions about our technical-rescue service; the same storage, retention, and deletion described here apply.

What the assistant does with your messages. Messages you type into the chat are sent to our chat service and processed by Azure OpenAI, a Microsoft service, to generate the assistant’s replies. The chat records we keep are stored in the United States; to generate replies, Microsoft may process your messages in its data centers globally, under Microsoft’s terms. Neither we nor Microsoft uses your chat messages to train AI models.

Every conversation is stored, in full, for 12 months. We keep a record of every chat conversation on this site — the full text of what you type and what the assistant replies, along with the page it happened on and timestamps — whether or not you leave your contact details, and we keep that record for 12 months. We automatically detect and strip text that looks like a password, key, or connection string before the transcript is stored, before anything is sent to the model, and before anything reaches our logs — but that detection is automatic pattern matching, not a guarantee, so please do not paste credentials into the chat; if you already have, rotate them. Everything else you volunteer — names, numbers, business details — is kept verbatim in the stored transcript for that full period. The assistant is instructed not to collect sensitive information (passwords, payment details, government identifiers) in chat, and to steer you to email or the phone instead if you begin sharing it. We do not record your IP address or browser details in these transcripts.

If you leave your details. If you submit the contact form inside the chat, we receive your name, email address, anything you enter in the optional company/website field, your message, and the conversation transcript, and a person is notified by email so they can reply to you.

Chat analytics. We also keep a separate, reduced per-message analytics record in which email addresses and phone numbers are automatically removed before storage; those reduced records are kept for a shorter period, 90 days. To be clear about the relationship: the full, unscrubbed transcripts described above are kept longer (12 months) than these reduced records (90 days).

How deletion happens. Chat transcripts and chat-form submissions delete automatically at 12 months, and the reduced analytics records at 90 days, enforced by a scheduled purge process — deletion is a running mechanism, not manual housekeeping.

If you request a rescue window, we also store your chosen time. Your card details are collected and held by Stripe, our payment processor, on its own systems under its own terms — we never see or store your card number. A request places a hold, not a charge; the hold is released if we decline or the request expires, and it is captured only if we accept. Payment records are kept with the request on the same 24-month schedule.

Chat usage measurement. Opening the chat and sending messages are recorded as events in Google Analytics 4, like other interactions described in this policy. Chat events are not sent to Google Ads or to Meta and are not used to build advertising audiences.

Asking a person to step in. If you ask to talk to a person, the assistant collects your details as a chat-form submission (above) and a person follows up by email within one business day.

Your choices. You do not have to use the chat — every question it answers can also be sent to support@wholefunnel.ai. To ask about or request deletion of your chat data, email support@wholefunnel.ai.

Live visitor presence and owner-initiated chat. While you are actively viewing key pages of this site, your browser sends us a short presence signal every several seconds so that Sassan Darian, the founder — a real person — can see, in real time, that someone is on the site and which page they are on. The signal carries a random session identifier stored in your browser for the duration of the visit, the page you are viewing, a coarse region class derived from your device’s timezone setting, whether you are interacting with a form or the chat, and a timestamp. It does not carry your name, and we do not store your IP address or browser fingerprint with it. Signals stop when you close the tab, switch away from it, or simply stop interacting for a few minutes — and each presence record is deleted within minutes of the last signal (within about an hour if a live conversation was open), with cleanup running as part of normal site activity. Presence is not used for advertising, feeds no advertising audience, and sends nothing to Google or Meta. Visitors whose timezone indicates the EU, UK, Canada, or Australia are excluded from presence entirely.

The technical rescue service

This site offers a same-day technical rescue service for businesses at wholefunnel.ai/rescue. Two different kinds of data are involved, and they are handled differently.

The rescue request form. If you ask for help through the rescue page, we receive your name, phone number, the problem type you select, and — if you choose to provide them — your email address and a note about what broke. We store these on our own systems and use them to call you back and handle your request. Rescue requests are kept for up to 24 months and then deleted automatically by a scheduled purge process; they are never sold. Submitting the form also records the contact event described in the Meta section above and a corresponding event in Google Analytics.

Rescue engagement work. The rescue service itself — diagnosing and fixing a client’s systems — happens inside the client’s own systems, under a written scope the client approves before any access, and is governed by that written agreement rather than by this website policy. It is described here for transparency because of the tooling involved: rescue engineering work is performed with Claude, an AI engineering tool made by Anthropic, used under Anthropic’s commercial terms. Under those terms Anthropic does not train its models on this work, and data processed during a rescue is automatically deleted from Anthropic’s systems within 30 days. Anything we copy from a client’s systems for diagnosis is deleted when the engagement closes.

Text messages. If you call or text our service number, or give us your phone number in a rescue request, we may call you back and may send you text messages about your request — scheduling, status, and follow-up on that request only, never marketing lists. Reply STOP to any text from us to stop receiving texts (HELP for help); message and data rates may apply. Your phone number is used for handling your request as described above and is never sold or shared for others’ marketing.

Cookies and similar technologies

The tools above set and read cookies and use similar browser storage and identifiers to recognise a browser across pages and visits. This site also uses the functional cookies WordPress itself requires, including when an administrator signs in. Because we do not operate a consent banner, no cookie preferences are stored for you here; the controls available to you are the platform and browser controls described next.

Your choices and how to opt out

For Google advertising, Google’s My Ad Center (opens in a new tab) lets you control ad personalisation across Google services, and Google publishes an Analytics opt-out browser add-on (opens in a new tab). For Meta advertising, Meta’s ad preferences (opens in a new tab) and your Meta account settings let you control how Meta personalises advertising to you and review what businesses have sent Meta about you. In your browser, every major browser lets you block or delete cookies, and several block third-party tracking by default; blocking cookies stops most of the browser-side collection described here, though as noted above it does not stop server-side transmission.

Where your data goes

This website runs on Microsoft Azure in the United States. Data collected by the tools described here is transmitted to Google and to Meta and processed on their infrastructure under their own policies. We do not transfer this data to anyone other than the analytics, advertising, email, and AI providers named in this policy.

Server logs

Like most websites, our web server keeps standard technical logs of requests — the requesting IP address, browser type, and the page requested — which we use for security and to diagnose delivery problems. These logs are kept for a short period (no more than eight weeks) and are then overwritten; they are never sold or used for marketing.

How long it is kept

We keep email correspondence and form submissions for as long as we need them to answer you and to keep a record of the exchange. Data held by Google and by Meta is retained under those platforms’ own retention settings and policies, which we configure only within the options they offer. Chat conversations are kept on the schedule described in “The chat assistant.” Rescue requests are kept on the schedule described in “The technical rescue service.”

Children

This site is not directed to children, and we do not knowingly collect information from children.

Changes to this policy

We update this page when what runs on this site changes. The date at the top reflects the most recent update.

Questions and requests

Email support@wholefunnel.ai with any question about this policy, or any request concerning your data, and we will respond.