Bell Statistics

Privacy Policy

What we collect when you use this website, why we collect it, who else sees it, and what you can ask us to do about it.

Last updated

Bell Statistics provides advanced analytics consulting — A/B testing, marketing mix modeling, geo testing and causal inference — to businesses. This policy covers the website at bellstatistics.com: the pages you read, the forms you fill in, the consultation calendar, the newsletter, and the private proposal pages we send to clients.

It does not cover the data we handle inside a paid engagement. When a client's own data comes to us under a signed agreement we act as a processor on that client's instructions, and the agreement — not this page — governs what we may do with it.

We have tried to write this as a description of what the site actually does rather than a list of things we are permitted to do. Where something may surprise you, it has its own section: visitor identification, session recording, and the proposal pages we send to clients.

1. Who we are

Bell Statistics is the controller of the personal data described in this policy. We operate from Israel and our infrastructure runs in the United States.

2. What we collect

There are no accounts on this site and nothing to log into. Almost everything below is collected either because you typed it into a form or because your browser sent it with the request.

Three forms collect personal data: the contact form (on the contact page, in the enquiry dialog, and on our campaign landing pages), the consultation booking form, and the newsletter signup in the footer.

Each form also carries a hidden field that is never shown to you and must stay empty. If it comes back filled in, the submission is treated as automated: we record the attempt and take no further action on it.

Categories of personal data collected through bellstatistics.com.
CategoryWhat it includesWhere it comes from
Identity and contactFirst and last name, work email address, company name, job title.Typed into the contact or booking form.
What you writeThe message field on the contact form (up to 5,000 characters) and the notes field on the booking form (up to 2,000).Typed by you.
NewsletterYour email address. Nothing else is required to subscribe.The footer signup form.
SchedulingThe slot you choose, your browser's time zone, and the calendar invitation and video link created for the call.The booking form and your browser.
Campaign attributionThe referring site, the page you landed on, the page you submitted from, and any utm_source, utm_medium, utm_campaign, utm_term, utm_content, gclid, fbclid or li_fat_id present in the address.Read from the URL you arrived on and held in your browser for the session.
TechnicalYour browser's user-agent string, a two-letter country code, and a salted SHA-256 hash of your IP address.Request headers, via our hosting provider.
Analytics identifiersA Google Analytics client ID and a PostHog distinct ID, so an enquiry can be joined to the visit it came from.Cookies and storage set in your browser.

3. We do not store your IP address

Your IP address reaches our servers, as it must for any website to answer a request. It is never written to our database. Before anything is stored it is combined with a secret value and hashed with SHA-256, and only that hash is kept.

The hash cannot be reversed into an address, and without the secret it cannot be matched against a list of guesses either. What it can still do is answer the question it exists for: how many submissions came from the same source in the last hour. We also derive a two-letter country code from the request, and that is stored as it is.

4. Cookies and similar technologies

We do not currently show a cookie banner. The analytics and advertising tags below load when a page loads, without asking you first. We would rather say so plainly than imply a consent step that does not exist. If that is not acceptable to you, the controls at the end of section 13 work today and take effect immediately, and the same section explains how to ask us to delete anything already collected.

Two of the entries below are not cookies at all. They are browser storage, they never leave your device unless you submit a form, and clearing your site data removes them.

Cookies and browser storage used on bellstatistics.com.
NameSet byWhat it is forLifetime
_ga and relatedGoogle AnalyticsDistinguishes visitors and sessions. We also read this value when you submit a form, so the enquiry can be matched to the visit that produced it.Up to 2 years
Tag Manager cookiesGoogleLoads and configures the other tags on this list.Varies by tag
ph_*PostHogProduct analytics: a distinct ID, the current session, and session recording.Up to 1 year
RB2BRB2BVisitor identification — see section 6.Set by the vendor
bell_offer_viewBell StatisticsSet only on a client proposal page. Ties engagement on the page to the link that was opened. HttpOnly, so page scripts cannot read it.6 hours
__Host-bell_adminBell StatisticsA signed login session for our own staff. Never set for site visitors.12 hours
bell-theme (local storage)Bell StatisticsRemembers that you chose light or dark mode. Never sent to us.Until you clear it
bell_attr (session storage)Bell StatisticsThe campaign details you arrived with, held for this tab only. Sent to us only if you submit a form.Until the tab closes

5. Analytics, autocapture and session recording

We use PostHog for product analytics. Two things about how it is configured go further than counting page views, so they are worth stating rather than leaving to be discovered.

Autocapture records interactions — clicks, and which elements were involved — without us writing code for each one. Session recording reconstructs a playback of a visit: the pages, the scrolling, the pointer, the interactions.

Recording is constrained in three ways. Every form input is masked, so what you type is not captured as you type it. Regions marked as sensitive are excluded from capture altogether, which includes the calculator input fields and their results. And URLs sent to analytics are stripped of every query parameter except the campaign keys listed in section 2, so anything else carried in an address — an unsubscribe token, a calculator's inputs — does not travel with the event.

We also use Google Analytics 4 and Google Tag Manager for traffic measurement, and Google Ads for conversion reporting. When you submit a form we pass a SHA-256 hash of your email address to Google Ads so the conversion can be attributed. The plain address is never placed in the browser's data layer.

None of this runs on our internal admin pages.

6. Visitor identification

This is the disclosure most likely to matter to you, so it is not buried in a list.

We run a service called RB2B, which performs reverse-IP identification. It attempts to resolve an anonymous visitor — someone who has filled in no form and given us nothing — to a named individual and a work email address, by matching the network the visit came from against the vendor's own data. Where it succeeds, we learn that a particular person at a particular company looked at our site.

It runs on our public marketing pages in production only. It does not run on our admin pages, and it does not run on preview or local builds.

This is processing of personal data about you, carried out without asking you first, and we would rather name it than describe it as business intelligence. If you do not want it: the browser-level controls at the end of section 13 stop it running at all, and the same section explains how to object and how to ask us to delete anything already collected.

7. The calculators stay in your browser

Our statistical calculators are built so that the numbers you put into them never reach us. That is a property of how they are built rather than a promise about how we behave, and it is worth explaining, because people paste real data into them.

Every calculator runs entirely in your browser. No request is made to our servers when you calculate, and the pages are static files with no server-side code behind them that could receive anything. We could not see your inputs if we wanted to.

Two consequences follow. Your settings are mirrored into the page address so that a link is shareable — but pasted observations are deliberately excluded from that address, because a copy-link button that embedded someone's customer data in a URL would be a confidentiality incident rather than a feature. And because analytics only ever receive a URL stripped of everything but campaign parameters, your inputs do not reach our analytics either.

8. Client proposal pages

If we have sent you a commercial proposal as a link rather than as a PDF, this section is for you.

A proposal lives at a private address reachable only through a signed, expiring link addressed to you. It is not indexed, it is not linked from anywhere, and it cannot be reached by guessing. We record when that link is opened, and we tell you so here because the reason for hosting a proposal instead of attaching it is precisely that we can see it was read.

For each opening we store the proposal, the recipient the link was issued to, the time, the country, the browser's user-agent string and a hashed IP. While the page is open we also record which sections were read and for how long, which pricing option was clicked, and whether the page was printed. We do not store the link itself, only a fingerprint of it, so a stored record cannot be turned back into a working link.

Corporate mail systems follow links before a person does. Those automated fetches are recorded and labelled as such rather than counted as you reading the document. If you would prefer a proposal as a plain attachment with no measurement at all, ask and we will send one.

9. How we use it, and on what legal basis

We use personal data for the purposes below. The legal bases named are those we rely on under the GDPR and UK GDPR; if you are outside those regimes the purposes are the same.

  • To answer you — replying to an enquiry, holding a consultation call, and sending the confirmation, reminder, reschedule and cancellation emails that go with a booking. Basis: steps taken at your request before entering a contract, or our legitimate interest in responding to a business enquiry.
  • To run an engagement — correspondence and scheduling with clients. Basis: performance of a contract.
  • To send the newsletter. Basis: your consent, which you can withdraw at any time through the unsubscribe link in every issue or the unsubscribe page.
  • To understand how the site is used and improve it — analytics, autocapture and session recording. Basis: legitimate interests.
  • To measure and improve our marketing — campaign attribution, advertising conversion reporting, and the visitor identification described in section 6. Basis: legitimate interests.
  • To see whether a proposal was read. Basis: legitimate interests in the conduct of a commercial negotiation with your organisation.
  • To keep the site up — rate limiting, spam filtering and abuse investigation, which is what the hashed IP exists for. Basis: legitimate interests in the security of the service.
  • To meet our obligations — tax, accounting, and responding to lawful requests. Basis: legal obligation.

10. Who else processes it

We do not sell personal data in the ordinary sense of the phrase: we do not trade it for money. Some US state privacy laws define selling and sharing more broadly than that, to take in disclosures to advertising partners — section 13 explains what that means for the tags described in sections 5 and 6, and how to opt out.

The providers below process personal data on our behalf, under contract. All of them process it in the United States.

Service providers that process personal data for Bell Statistics.
ProviderWhat it does for usTheir privacy policy
VercelHosts the website and runs its server-side code. Sees every request.vercel.com
SupabaseThe database holding enquiries, bookings and newsletter subscribers.supabase.com
ResendSends our confirmation emails and the newsletter, and reports bounces and complaints.resend.com
GoogleCalendar and Meet for booked calls; Analytics and Tag Manager for measurement; Ads for conversion reporting.policies.google.com
PostHogProduct analytics, autocapture and session recording.posthog.com
UpstashRate-limit counters, keyed on the hashed IP. No names or addresses.upstash.com
RB2BThe reverse-IP visitor identification described in section 6.rb2b.com

11. Where your data goes

We operate from Israel and our infrastructure is in the United States, so personal data collected here is transferred internationally as a matter of course.

Israel has been recognised by the European Commission as providing an adequate level of protection for personal data, so a transfer from the EEA to us does not require an additional safeguard. The onward transfer to our US providers is made under the European Commission's standard contractual clauses, or under the EU–US Data Privacy Framework where the provider is certified to it.

If you would like to know which mechanism is relied on for a particular provider, ask us and we will tell you.

12. How long we keep it

We keep personal data for as long as it is needed for the purpose it was collected for, and afterwards for as long as we need it for our own records.

In practice: enquiries and bookings are kept for the life of the commercial relationship and a reasonable period after it, because a prospect who did not become a client this year often does the next. A newsletter record is kept until you unsubscribe, and then we retain the fact of the unsubscribe, because that is what stops us mailing you again. Proposal-view records are kept while the proposal is live and afterwards for our records. Analytics data is kept for the periods our providers apply, which are set out in their own policies.

We do not currently apply a fixed automatic deletion schedule to enquiry records. If you would like yours removed, ask us and we will delete it — see section 13.

13. How it is protected

No system is perfectly secure, and a policy claiming otherwise is not worth reading. What we can tell you is what is actually in place.

  • Every database table holding personal data has row-level security enabled and forced, with no access policy granted to any public role. Nothing is readable through a public API; the tables are reachable only by our own server-side code holding a service credential.
  • Your IP address is never stored — see section 3.
  • Staff access to the internal dashboard requires a password, stored only as a slow salted hash, and produces a signed session that expires after twelve hours. Removing someone's account invalidates their live sessions on the next request they make.
  • The internal dashboard loads no analytics, advertising or visitor-identification code at all, so viewing an enquiry never hands it to a third party.
  • Data is transmitted over TLS, and the public form endpoints are rate limited.

14. Your rights

Wherever you are, you can ask us for a copy of what we hold about you, ask us to correct it, or ask us to delete it. Email allon@bellstatistics.com and say what you want. We will not charge you and we will not treat you differently for asking. We aim to respond within 30 days, and we may need to ask you something first to confirm who you are.

If you are in the EEA or the UK, you also have the right to restrict or object to processing, the right to data portability, and the right to withdraw consent at any time without affecting what was done before you withdrew it. Where we rely on legitimate interests — analytics, marketing measurement and visitor identification — you can object and we will stop. You may also complain to your national supervisory authority, or to the Information Commissioner's Office in the UK.

If you are in California, you have the right to know what we collect and why, to have it deleted, to have it corrected, and to opt out of its sale or sharing. We do not sell personal data for money. The analytics and advertising tags described in sections 5 and 6 may nevertheless amount to sharing for cross-context behavioural advertising as California defines it. To opt out, email us at the address above and we will suppress you, or use the browser controls in the last paragraph of this section, which stop the tags running in the first place. We do not knowingly sell or share the personal data of anyone under 16.

If you are in Israel, you have the right under the Privacy Protection Law to review personal data held about you and to request its correction or deletion.

Controls that work without asking us. An advertising or tracker-blocking browser extension stops the analytics, advertising and visitor-identification scripts on this site from loading at all. Google publishes an opt-out add-on for Google Analytics, and most browsers offer a Global Privacy Control setting. Clearing your site data removes the cookies and browser storage listed in section 5.

15. Children

This is a business-to-business service. It is not directed at children and we do not knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, contact us and we will delete it.

16. Changes to this policy

When this policy changes we update the date at the top of the page. If a change materially affects how we use personal data we already hold, we will take reasonable steps to tell the people affected directly, rather than relying on you to re-read the page.

17. Contact us

Questions about this policy, and any request about your data, should go to allon@bellstatistics.com.

Bell Statistics, Medinat ha-Yehudim St 29, Herzliya, Israel.