Legal · privacy
Privacy policy
We run ads for a living, so we are not going to pretend we do not track anything. Here is exactly what this site collects, who we hand it to, and how to switch it off.
Last updated 13 August 2026
§ 01
Who we are
This site, ecg.agency, is operated by Damoche Capital, LLC, doing business as ECG, a creative-first growth agency (“ECG”, “we”, “us”). Our mailing address is 2875 NE 191st Street, 5th Floor, Aventura, FL 33180.
We are the controller of the personal information described here. For anything about this policy or your data, email hello@ecgagency.com.
This policy covers the website and booking a call with us. It does not cover work we do for clients on their own properties, which is governed by our contract with that client.
§ 02
What we collect
When you browse the site. We do not ask you to sign in and we do not run a database. What is collected happens through advertising and hosting infrastructure: the pages you view, the buttons you click that open our booking calendar, your IP address, your browser and device type, and the cookies and storage keys listed in section 3. If you arrived from a Meta ad, the click identifier in the link is captured too.
When you book a call. Our calendar runs on Calendly. You give it your name, email address, time zone, anything you type into the application questions, and a phone number only if you opt into text reminders. That booking record lives in Calendly and in the calendar it writes to. We do not store a separate copy.
When you email us. We keep the message and your address, because that is how email works.
We do not knowingly collect payment details, government identifiers, precise location, or any special category data through this site.
§ 04
What we send to Meta
This is the part most policies bury, so we will be blunt about it. We send Meta (Facebook and Instagram) information about what you do here, both from your browser and directly from our server. Sending it from the server means an ad blocker or tracking protection will not necessarily stop it.
Four events are reported:
- PageView — you loaded a page.
- BookingStarted — you clicked a call-to-action and the calendar opened.
- Schedule and Lead — you completed a booking.
Every event carries your IP address, browser user agent, the page URL, and the identifiers in section 3.
When you complete a booking, we also send Meta your email address, name, and phone number if you gave one — hashed with SHA-256 before they leave our server, along with the campaign parameters from the link you arrived on. Hashing means we transmit a fixed-length fingerprint rather than the address itself. Be clear about what that does and does not mean: it is not anonymisation. The entire purpose is for Meta to compare that fingerprint against its own users and identify you if you have an account. It does mean your address is not sent in readable form and cannot be read back out of the hash by anyone intercepting it.
We do this to measure which ads produce real conversations, and Meta uses it to target advertising. Under California law this counts as “sharing” for cross-context behavioural advertising. We have never sold personal information for money and do not intend to. Section 8 explains how to stop it.
§ 05
Why we use it
To run the site and keep it available and secure; to understand which ads and pages lead to booked calls; to improve our own advertising and to buy it more accurately; and to have the conversation you booked.
We do not use it to make automated decisions with legal or similarly significant effects about you.
If you are in the UK or EEA, our legal basis for analytics and advertising measurement is our legitimate interest in understanding and improving our marketing, balanced against your privacy — and your consent where local law requires it before such cookies are set. For handling a booking or an email, the basis is taking steps at your request before entering a contract. You can object to processing based on legitimate interests at any time using the contact address in section 1.
§ 07
How long we keep it
The browser identifiers in section 3 expire on the schedule listed there, or immediately when you clear your site data. Booking records stay in Calendly and our calendar until we delete them; we clear out records with no ongoing business relationship on a rolling basis. Email correspondence is kept as long as it is useful to the relationship. Once information reaches Meta or Vercel, their own retention schedules apply and we cannot shorten them for you.
§ 08
Your choices
Practical ways to stop what is described above:
- Clear or block the storage. Clearing site data for ecg.agency removes all four items in section 3. Blocking third-party cookies, or using a browser with tracking protection, stops most of the browser-side reporting.
- Adjust it at the source. If you have a Meta account, its Accounts Centre ad preferences let you disconnect activity that businesses like ours send about you, and limit how it is used for targeting.
- Do not book through the site. Email us instead and no booking event is generated.
- Ask us. Email hello@ecgagency.com and we will opt you out of advertising-related sharing and delete what we hold. You do not need an account or a reason, and we will not treat you differently for asking.
§ 09
Your rights
Depending on where you live, you may have the right to know what personal information we hold, get a copy, correct it, delete it, limit how it is used, opt out of targeted advertising and of “sale” or “sharing”, and not be discriminated against for exercising any of it.
UK and EEA residents additionally have the right to data portability, to object to processing, to withdraw consent at any time without affecting prior processing, and to complain to your supervisory authority — in the UK, the ICO.
To exercise any of these, email hello@ecgagency.com. We respond within the time the applicable law allows — 45 days under US state laws and one month under UK/EU GDPR. We may need to confirm your identity first, and an authorised agent may act for you with written permission.
§ 10
International transfers
We operate from the United States and our providers are US-based, so information you give us is processed there. If you are in the UK or EEA, that means your data leaves your jurisdiction. Meta, Calendly and Vercel each rely on the European Commission’s Standard Contractual Clauses, the UK Addendum, or the EU-US Data Privacy Framework for these transfers.
§ 11
Security
The site is served over HTTPS. Identifiers we send server-side travel over encrypted connections, and customer details are hashed before transmission to Meta. Our booking webhook rejects any request that is not cryptographically signed by Calendly. No system is perfectly secure, and we cannot guarantee absolute security of anything transmitted over the internet.
§ 12
Children
This site sells business services and is not directed at anyone under 16. We do not knowingly collect their information. If you believe a child has given us data, email us and we will delete it.
§ 13
Changes
If we change what we collect or who we send it to, we update this page and move the date at the top. Material changes get a notice on the site. This policy is governed by the laws of the State of Florida, without regard to its conflict-of-laws rules.
§ 14
Contact
hello@ecgagency.com
Damoche Capital, LLC d/b/a ECG
2875 NE 191st Street, 5th Floor
Aventura, FL 33180