Privacy
Privacy policy
What this site collects today, what the scorecard will collect when it opens, who processes it, and how to have it corrected or deleted.
Drafted 20 September 2026. Not in force.
Who is responsible for your data
RampFunnels is a trading name. The company behind it is the one named below, and it is the controller of the personal data described on this page. Under the GDPR and the UK GDPR, controller means it decides why the data is processed and how.
Controller
- Legal name
- Limelight International LLC, a limited liability company formed in the State of Wyoming, United States, trading as RampFunnels
- Registration number
- {{registration number}} Not supplied yet. It goes here when it is, and it is not guessed in the meantime.
- Registered address
- 1309 Coffeen Avenue, Ste 2379Sheridan, WY 82801United StatesThis is a registered address, not an office. There is no RampFunnels desk at it and visitors cannot be received there. Post sent to it reaches the company.
- Phone
- +1-307-218-7004
- Data protection contact
- nooruddin@sellmysaas.io
Write to the data protection contact above about anything on this page. It reaches a person, not a queue.
What this policy covers
It covers this website and the RampFunnels scorecard, and it covers the personal data of anyone who visits either, wherever they are.
The company is formed in Wyoming and the data is processed in the United States. The site is aimed at businesses in North America and in Europe, so the GDPR and the UK GDPR apply to visitors in the EEA and the UK whether or not the company has an establishment there, and US state privacy laws apply to residents of the states that have them. This policy carries all three. Where a right exists only in one of them, the section says so.
Two things it does not cover. Personal data processed inside a client engagement is governed by the contract for that engagement, not by this page. Sites you reach by clicking a link out of this one are governed by their own policies.
What is collected when you visit this site
Server logs and nothing else. There is no analytics, no tag manager and no advertising pixel on this site today.
The site is a Next.js application hosted by Vercel. Loading a page makes a request to Vercel’s servers, and Vercel records that request in a log. Those logs contain:
- the IP address the request came from
- the browser and operating system your browser reports in its user agent string
- the URL requested, and the page that referred you to it if your browser sent one
- the date and time of the request, and the response the server gave
Request logs of this kind are ordinary for any hosted website. They exist so the site can be kept available and defended against abuse. They are not used to build a profile of you and they are not combined with anything else.
The typefaces are compiled into the site at build time rather than fetched from a font service, so loading a page does not make your browser talk to a third party. The cookie policy has the full list of what the page requests, and it is short.
What is collected when you contact us
If you email the address on this page, we hold your email address, your name if you give it, and whatever you write. If you call the number, we hold no recording, because calls are not recorded.
The contact form on the site is not connected to anything yet. Nothing typed into it is transmitted or stored while that is the case, and the send button is switched off. When it is wired up, this section gets the name of the service that receives it, before the form goes live and not after.
What the scorecard will collect
The scorecard is not live. This is what it is designed to collect, so that the disclosure exists before the collection does.
A completed scorecard produces four things:
- the answers you give, which describe your business and your marketing rather than you personally
- a score and a band computed from those answers
- the contact details you submit in order to receive the report, which is normally a name, a work email address and a company name
- the report itself, which is the score and the band written up
The answers are the part worth being clear about. They are business information in almost every case, but they are attached to your contact details, so they are treated as personal data throughout this policy and they carry every right listed below.
You can take the scorecard and read your score without giving contact details, if the build allows it, and the page will say plainly at the point where it asks. No question on it asks for a special category of personal data, which means nothing about health, ethnicity, politics, religion, trade union membership, genetics, biometrics, sex life or sexual orientation.
Open item
The platform that will run the scorecard is not chosen yet
A third-party quiz platform will host the scorecard and process every answer, score and contact detail submitted to it. Which one has not been decided.
Naming it here is not optional once it exists. Articles 13 and 14 of the GDPR require the categories of recipient to be disclosed, and a reader is entitled to know whose servers their answers land on. This page carries the name, the country its infrastructure sits in and the basis for the transfer before the scorecard accepts a single response.
Why it is processed, and the lawful basis
Under the GDPR and the UK GDPR, every use of personal data needs a lawful basis. Here is each use and the basis it rests on.
- Keeping the site up
- Serving pages and keeping request logs so the site stays available and abuse can be identified. Legitimate interests, Article 6(1)(f). The interest is running a website that works, and the logs are not used for anything else.
- Answering you
- Replying to an email or a call about our services. Steps taken at your request before entering a contract, Article 6(1)(b), or legitimate interests, Article 6(1)(f), where you are writing on behalf of a company rather than for yourself.
- Producing your score
- Scoring your answers, generating the report and sending it to you. Steps taken at your request before entering a contract, Article 6(1)(b). You asked for the report by completing the scorecard, and this is how it gets made and delivered.
- Marketing email afterwards
- Sending you follow-up email about RampFunnels after you complete the scorecard. Consent, Article 6(1)(a), for recipients in the EEA and the UK. The consent is separate from the request for the report, it is never a pre-ticked box, and you can withdraw it at any time without losing the report you already have.
- Delivering an engagement
- Doing the work a client has contracted for. Performance of a contract, Article 6(1)(b), between RampFunnels and that client. Personal data belonging to the client’s own respondents is covered by that contract, where RampFunnels is a processor and the client is the controller.
- Meeting a legal obligation
- Keeping records we are required to keep, and responding to a lawful request from an authority. Legal obligation, Article 6(1)(c).
Who else processes it
A processor is a company that handles the data on our instructions. Here is every category that applies today, and what runs in it.
- Hosting and delivery
- Vercel Inc. hosts this site and serves it through its content delivery network. It processes the request logs described above, and it is the only processor with access to anything on this site today.
- The mailbox that receives mail sent to the data protection address is operated by a provider, and that provider processes the contents of your message in the ordinary course of delivering it. The provider is named here once the mail stack is confirmed.
- Quiz platform
- Not engaged yet. It will process every scorecard answer, score and submitted contact detail once the scorecard is live, and it is named here before that happens.
There is no analytics provider, no advertising network, no customer relationship system, no scheduling tool and no email marketing platform holding data from this site today, because none of them is connected to it. Each one of those is a category this page has to name before it starts running, and adding one without updating this page first is not an option that exists.
Personal data is not sold, rented or handed to anyone for their own purposes. It may be disclosed where the law requires it, or to a buyer as part of a sale of the business, in which case this page is updated before the transfer takes effect.
How long it is kept
Request logs are kept for as long as the host keeps them, under Vercel’s own retention schedule, and RampFunnels does not extend them.
Open item
Retention periods for everything else are not set
No retention period has been decided for scorecard answers, scores, reports or the contact details submitted with them, and none is stated here, because a period invented for a policy is a period nobody will keep to.
Article 13(2)(a) of the GDPR requires either the period or the criteria used to set it. This page is not complete until it carries one of the two, and the scorecard cannot lawfully collect anything while it does not.
You can have your data deleted at any time in the meantime, by writing to nooruddin@sellmysaas.io.
Where it is processed, and transfers out of the EEA and the UK
The company is in the United States and its processing happens there. If you are in the EEA or the UK, your personal data is transferred out of it as soon as you use this site, which is a restricted transfer under Chapter V of the GDPR and under the UK GDPR.
A restricted transfer is lawful when a specific safeguard is in place, such as the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Agreement or the UK Addendum, or the recipient’s certification under an adequacy framework.
Open item
The safeguard for EEA and UK transfers is not confirmed
No transfer mechanism is named on this page, because no data processing agreement has been confirmed as executed with any processor. Naming a safeguard that is not signed would be a fabrication, and a reader in the EEA or the UK is the reader most likely to check.
What has to be settled: a signed data processing agreement with the host, the same with the quiz platform once it is chosen, and the transfer clauses inside each. This page then names the mechanism and says where a copy can be requested.
Open item
Whether a representative in the EU and the UK is required
Article 27 of the GDPR and of the UK GDPR requires a controller outside the EEA or the UK to appoint a representative there, unless an exemption applies. Whether RampFunnels needs one, and who it would be, has not been determined.
If a representative is appointed, their name and address appear in this section and in the controller panel at the top of the page.
Your rights in the EEA and the UK
If the GDPR or the UK GDPR applies to you, you have the following rights over your personal data. Each one is exercised by writing to the data protection contact.
- Access
- Ask whether we hold personal data about you and, if we do, ask for a copy of it together with the information in this policy.
- Rectification
- Have inaccurate personal data corrected, and have incomplete data completed.
- Erasure
- Have your personal data deleted, where one of the grounds in Article 17 applies. Withdrawing consent to marketing email is one of them.
- Restriction
- Have processing paused while an accuracy dispute or an objection is being resolved.
- Portability
- Receive the personal data you gave us in a structured, commonly used, machine readable format, and have it sent to another controller where that is technically feasible. This covers your scorecard answers.
- Object
- Object to processing based on legitimate interests. Where you object to direct marketing, we stop, with no balancing test and no exceptions.
- Withdraw consent
- Withdraw consent at any time, for anything we process on the basis of consent. Withdrawing it does not make the processing before it unlawful, and it does not take your report away.
- Automated decisions
- Not be subject to a decision based solely on automated processing that produces a legal or similarly significant effect. The scorecard computes a score, and that score decides what you are shown next. It is not a decision of that kind: it has no legal effect, it does not decide what you are allowed to buy, and a person is involved in everything that follows it.
- Complain
- Lodge a complaint with a supervisory authority. In the UK that is the Information Commissioner’s Office. In the EEA it is the authority for the country you live or work in, or where you think the problem happened.
The GDPR and the UK GDPR give us one month from receiving a request to respond, extendable by two further months where the request is complex or where there are several. If we need to extend, we say so within the first month and we say why. Identity is verified before anything is released, which normally means replying from the address the data is held against.
Your rights in the United States
Twenty US states now have comprehensive consumer privacy laws. Three of them, Indiana, Kentucky and Rhode Island, have applied since 1 January 2026.
The rights those laws give differ in the detail, and which set you get depends on where you live. Across the states that have one, the rights are broadly these.
- Know and access
- Confirm whether personal data about you is being processed, and obtain a copy of it.
- Correct
- Have inaccurate personal data corrected.
- Delete
- Have personal data about you deleted.
- Portability
- Obtain the data you provided in a portable and, where technically feasible, readily usable format.
- Opt out
- Opt out of the sale of personal data, of sharing it for cross-context behavioural advertising, and of targeted advertising and certain profiling. Section 13 explains why there is nothing here to opt out of today.
- No retaliation
- Exercise any of these without being denied a service, charged a different price or given a lower quality of service for it.
- Appeal
- Appeal a refusal. Most of these laws require an appeal route, and a refusal from us carries one, with the reasons written out.
Requests go to the same address as everything else on this page. Most of these laws set a 45 day deadline, extendable once where the request is complex, and we work to the deadline that applies to you rather than to one of our own.
An authorised agent may make a request on your behalf where your state’s law allows it. We will ask for proof of the authorisation and for confirmation from you directly.
Selling, sharing and targeted advertising
RampFunnels does not sell personal data, does not share it for cross-context behavioural advertising, and does not use it for targeted advertising or for profiling that produces legal or similarly significant effects. There is no advertising technology on this site and no data flows to an advertising network from it.
That is why there is no “do not sell or share my personal information” link: there is nothing behind it to switch off, and a control that does nothing is worse than no control. If any of that changes, this section changes first and the mechanism goes live with the change, not after it.
Security
The site is served over HTTPS. Access to the systems that hold personal data is limited to the people who need it, and each processor is expected to meet the standard its own agreement sets.
RampFunnels holds no security certification and this page does not claim one. No transmission over the internet is completely secure, and any organisation telling you otherwise is selling something.
Children
This site and the scorecard are for people acting for a business. They are not directed at children, and personal data is not knowingly collected from anyone under 16. If you believe a child has given us personal data, write to the address above and it will be deleted.
Changes to this policy
When this policy changes, the date at the top changes with it. A change that affects what is collected, why, or who processes it is made before the change it describes takes effect, not afterwards.
The first substantive change will be the removal of the draft notice, once the open items are closed and the policy has been through legal review.
How to ask, and how to complain
Everything on this page is exercised by writing to nooruddin@sellmysaas.io. Say what you want and from which address, and you will get a reply from a person.
If you are not satisfied with the answer, you can complain to a regulator without coming back to us first. In the UK that is the Information Commissioner’s Office at ico.org.uk. In the EEA it is the supervisory authority in your country. In the United States it is normally your state attorney general.
Related: the cookie policy and the terms of use.