Privacy notice
Last updated 29 July 2026
This says what we do with personal data, in the order you’d actually want to know it. It’s short because we collect very little.
Cookies, and the choice you get first
Nothing that measures you loads until you say it can, with one exception we would rather write down than gloss over. Google’s tag is on the page before you answer. Until you accept it is switched to collect nothing: no cookies, nothing stored on your device, and nothing that identifies you. What it does send, even if you say no, is that a page was opened and that you declined. Everything else waits for a yes, and no is a decision we keep rather than one we ask again next week.
If you say yes, four things load. Google Analytics counts which pages get read and where people arrived from. Microsoft Clarity records how a page is used, which means your clicks, your scrolling and your mouse movement while you’re on our pages, so we can see where the site loses people. Google Ads is told when an advert we paid for led to a sale, so we can tell which advertising is worth running. the Meta pixel tells Facebook and Instagram the same thing about their adverts, and lets us show a follow-up advert to someone who has been here before. They set cookies, and some of what they collect is used for advertising, which is the part we would want to know about if we were reading this. We advertise this business, and these tools are how we find out whether that advertising paid for itself.
You can change your mind whenever you like. The Cookies link in the footer of every page brings the choice back, and withdrawing is as easy as giving it. If you withdraw, we delete the cookies that were set. The lawful basis for all of this is your consent.
We record your answer in your browser's own local storage rather than in a cookie, so the answer itself never travels back to us on every page you open.
The checkout page is separate from all of that, and it loads Stripe whether or not you accept anything, because the fields you type a card number into have to belong to Stripe rather than to us. Stripe sets what it needs to process the payment and to spot fraud. Stripe is the payment processor and handles that data as a controller in its own right; its privacy policy is at stripe.com/privacy.
Until 28 July 2026 this site measured nothing at all and this section said so. We changed it because we couldn’t tell whether anything we sent people was working, and we aren’t willing to advise anyone on their marketing measurement while refusing to do our own.
On 29 July 2026 we changed it again, and this one gave something up. We switched Google to the mode where its tag is present before you answer, and we added the tools that report a sale back to the platform that sold us the click, because we now advertise this business. The previous version of this page promised that a no meant nothing was sent to anyone. That is no longer true and we have rewritten it rather than left it standing, because a privacy notice that overstates the protection is worse than one that offers less: you have no way to check.
Who is responsible
Parallax Thinking Ltd is the data controller: registered in England and Wales under number 16344822, registered office 90 Florence Road, Poole, Dorset, BH14 9JF. For anything in this notice, email hello@parallax-thinking.com and it reaches Scott Morgan directly.
What we collect, and when
If you use the enquiry form: your name, your email address, what you tell us about where your business is, and which kind of work you were reading about. We use it to reply to you. The lawful basis is our legitimate interest in answering people who ask us to.
If you buy Parallax Search: your name, email address, your practice or business name and your website address. We use it to provide the service you have bought and to keep the records a business is required to keep. The lawful basis is performance of our contract with you, and our legal obligation for the accounting records.
If you buy the AI Visibility Audit: the same, plus the sentence you write about what your business does and where, because the audit is composed around it.
If you arrive from an advert or a campaign link and then buy, the campaign labels on that link are stored with your order so we can tell which advertising paid for itself. They describe the advert rather than you: no part of it says who you are, where you browsed before, or what you searched for. The lawful basis is our legitimate interest in knowing whether our own advertising works.
We never see your card number. Your card details, and the billing address that goes with them, go directly to Stripe and are never held by us or by this website.
Who else touches it
Stripe, which takes the payment and holds the card details. Resend, which delivers the notification email to us. Cloudflare, which hosts this site and serves it. Google, which provides the mailbox the notification lands in, and which provides Google Analytics, receiving a page count from you whatever you answer and the rest only if you agreed to it, and which runs the advertising we buy. Microsoft, which provides Clarity, only if you agreed to it. Meta, which runs the advertising we buy on Facebook and Instagram, again only if you agreed to it.
Each of these acts on our instructions, and we don’t sell personal data or share it for anyone else’s marketing. Some of them process data outside the UK, under the safeguards their own terms provide.
When we’re the processor, not the controller
Once you’re a client, the data inside your own accounts and systems stays yours. There we act as your processor, handling it on your instructions under a data processing agreement, which is available on request.
No patient-identifiable or customer-identifiable data enters the dashboard we build, from any source. It holds counts, costs and rates, never names.
How long we keep it
Enquiries: for as long as the conversation is live, and up to two years after, in case it picks back up. Ask and we’ll delete yours sooner.
Client and payment records: six years after the end of the relationship, because that’s how long a UK company is required to keep its financial records.
What you can ask us to do
You can ask for a copy of the personal data we hold about you, ask us to correct it, ask us to delete it, ask us to restrict what we do with it, ask for it in a portable form, and object to us processing it. Email us and we’ll do it, normally within a month and without charge.
If you think we have got it wrong, you can complain to the Information Commissioner’s Office at ico.org.uk or on 0303 123 1113. We’d rather you told us first so we can put it right.