We use optional analytics to improve this site and marketing technology to identify business visitors for relevant outreach. You can allow all, decline optional use, or choose categories. Privacy policy

    Skip to main content

    Privacy notice

    Privacy, plainly stated

    This notice explains how GSD at Work LLC d/b/a Caritas Venture Co. collects and uses information through this website and our text-messaging program. Optional analytics and business visitor identification stay off unless you allow them.

    Last updated August 22, 2026

    At a glance

    • We use limited technical data to deliver, secure, and troubleshoot the site.
    • Analytics, session replay, and business visitor matching require your choice.
    • We honor Global Privacy Control signals by keeping visitor identification off.
    • Business visitor matching does not run on sensitive, restricted, or confirmation pages.
    • Raw fit-call, diagnostic, and case-study submissions are deleted from our website intake storage after 180 days.
    • We do not share mobile information or text-message consent data with third parties or affiliates for marketing or promotional purposes.

    01

    Information you share with us

    If you contact us, book a meeting, or submit a form, we receive the information you choose to provide. That may include your name, work email, company, role, phone number, scheduling details, and the contents of your message or response.

    We use it to respond, provide requested materials, prepare for conversations, deliver services, maintain business records, and protect our systems. Please do not submit sensitive personal information through a general website form.

    We automatically delete raw fit-call, diagnostic, and case-study submissions from our website intake storage 180 days after we receive them. That period applies only to the raw website intake copy. If an inquiry becomes an active opportunity or client relationship, relevant communications, contracts, billing, and service records may be kept separately for business, contractual, and legal purposes.

    02

    Text messaging

    If you separately opt in to our text-messaging program, we collect your mobile number, your opt-in and opt-out records, message content, and related delivery and technical metadata. We use this information to provide the conversational, customer-care, and informational texts you request, including automated and AI-assisted replies, to maintain consent and suppression records, and to secure and troubleshoot the service.

    Twilio and Vapi process this information as service providers needed to operate the messaging service. No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. All other categories in this notice exclude text messaging originator opt-in data and consent; this information will not be shared with third parties for marketing or promotional purposes.

    Message frequency varies. Message and data rates may apply. Reply STOP to cancel or HELP for help. Consent is not a condition of purchase. We keep consent, opt-out, and messaging records as reasonably needed to operate the program, honor your choices, demonstrate compliance, resolve disputes, and meet legal obligations, then delete or de-identify them when practical. See our text-messaging terms at caritas.ventures/terms/.

    03

    Site operation and functional tools

    Our hosting and security systems process basic request data needed to serve the site, such as IP address, requested URL, referrer, date and time, browser or device details, and security or diagnostic events. Netlify hosts the site.

    Sentry receives error diagnostics so we can find and repair failures. Core error monitoring can include the page, browser and device context, network details, and technical traces surrounding an error. Senja powers functional testimonial widgets and may receive the technical requests needed to display them. Read the vendors' notices at Sentry and Senja.

    04

    Optional analytics

    If you allow optional tracking, Google Analytics, PostHog, Hotjar, Ahrefs Web Analytics, and Sentry performance and replay tools help us understand traffic, navigation, campaign attribution, site speed, and usability. Depending on the tool, this can include cookie or session identifiers, pages viewed, clicks, scrolling, approximate location, referrer and campaign parameters, device information, and performance timings.

    PostHog is limited to route views and selected site actions. Its session replay, surveys, heatmaps, feature-flag polling, broad autocapture, and SDK-managed persistent browser storage are disabled. If you allow analytics, Caritas places one random pseudonymous journey identifier in first-party browser storage for a fixed period of up to 30 days. A separate visit identifier and sanitized visit source are kept only for the current browser session. We send the random identifiers to PostHog so consented page views and site actions can be measured across reloads and return visits. Sentry replay is configured to mask page text and block media. We do not use these tools to intentionally collect form contents.

    If you voluntarily submit a fit-call, diagnostic, or case-study form, we may create a separate internal link between that form record and the random journey identifier. This lets us understand which consented journeys produce real inquiries. That link expires after 30 days and is removed by a daily deletion process. We do not send the submitted name, email, company, form text, submission identifier, or the internal link to PostHog or Google Analytics. The internal link is used for conversion measurement and is not itself permission to send or personalize outreach. A browser journey can be shared by more than one person, so it is treated as attribution evidence rather than proof of identity. Learn more from Google, PostHog, Hotjar, Ahrefs, and Sentry.

    05

    Optional business visitor identification

    With your permission, we use RB2B to understand which businesses and business professionals show interest in our services. Its technology may process IP address, cookies or similar identifiers, device and browser details, page visits, timestamps, referrer, and campaign parameters to attempt a match against business data.

    A returned business record may include a person's name, employer, company domain, role or title, work contact details, business profile links, and the associated visit history. A match does not mean that you gave those details to us directly, and vendor data can be incomplete or out of date.

    After you allow marketing tools, we use a temporary daily record in your browser to count whether the configured visitor-identification script was attempted, loaded, or failed. The measurement request body contains only the provider name and outcome. Our measurement record stores daily aggregate counts, without a browser identifier, page URL, query string, session identifier, IP address, or user-agent string.

    We may use matched records in internal prospecting and outreach automation to prioritize interest, prepare relevant follow-up, measure whether outreach is useful, and suppress people who opt out. Automated tools may assist with triage and drafting. They do not make decisions that produce legal or similarly significant effects. Every outreach message provides a way to opt out.

    We configure this service not to run on sensitive, restricted, form submission, or appointment-confirmation pages. See the vendor notice for RB2B.

    06

    Your privacy choices

    Optional tools stay off until you select "Allow all" or save selected categories. You can reject them without losing access to the site. Use the "Privacy choices" link in the footer at any time to change your selection. Your saved choice lasts for up to 180 days, then we ask again. We may also ask again after a material change to these tools.

    If your browser sends a recognized Global Privacy Control signal, we treat it as a request to keep visitor identification off. While that signal is active, it takes priority over a prior marketing choice stored in that browser. You may still choose whether to allow optional analytics.

    07

    Sharing, retention, and protection

    We disclose information to service providers that host, secure, analyze, or support the site and our business communications. We may also disclose it when required by law, to protect rights and safety, or as part of a business transaction. Some providers process information outside your state or country.

    We keep information only as long as reasonably needed for the purpose described, legal obligations, security, and dispute resolution, then delete or de-identify it when practical. We run a daily deletion process for visitor-identification pilot records in our own systems once they are 30 days old. RB2B controls its current copies under its settings, contract, and privacy notice. Leadpipe controls copies collected during our prior evaluation under its settings, contract, and privacy notice until its applicable deletion or retention process completes. We also run a daily process that deletes raw fit-call, diagnostic, and case-study submissions from our website intake storage once they are 180 days old. This does not require us to delete separate opportunity, client, contractual, billing, or service records at that time. Other periods vary by record type and contractual controls. A separate 180-day period applies to the browser record of your consent choice. We use reasonable technical and organizational safeguards, but no online system is risk-free.

    The first-party journey identifier has a fixed 30-day lifetime and is cleared when analytics permission is withdrawn or expires. The form-to-journey link in our systems expires after 30 days and is removed by a daily deletion process. PostHog may retain the resulting pseudonymous analytics events for a longer period under our project and vendor settings, but those events do not contain the form identity or internal link.

    08

    Your rights and requests

    Depending on where you live, you may have rights to access, correct, delete, or receive a copy of personal information, and to object to or restrict certain uses. You can also withdraw consent and opt out of outreach at any time. We will not discriminate against you for making a privacy request.

    Email hello@caritas.ventures with "Privacy request" in the subject. Tell us what you are asking for and how we can locate the relevant record. We may need to verify your identity before completing a request.

    09

    Children and changes to this notice

    This is a business website and is not directed to children under 13. We do not knowingly collect personal information from children under 13 through it.

    We may update this notice as our practices change. We will post the new date here and provide additional notice when a change materially affects your choices. Questions are welcome at hello@caritas.ventures.