Skip to content

Privacy Policy

Last updated: July 2026

Information Gathered from Visitors

In common with other websites, our web server stores log files containing the visitor's IP address, browser type, referring page, pages visited, and time of visit. These logs are used solely for security monitoring and anonymous traffic analysis.

We use Plausible Analytics, a privacy-focused analytics service that does not use cookies, does not collect personal data, and is GDPR-compliant by default.

If you consent via the cookie banner, we also use Google Analytics 4 (loaded through Google Tag Manager) to understand aggregate usage patterns. Google Analytics sets cookies (such as _ga and _ga_*) that expire after 2 years. These scripts are loaded only after you accept cookies; if you decline, no Google cookies are set.

Tracking, Profiling & Automated Identification

We believe transparency beats fine print, so here is everything this site does to understand its visitors — including the parts most sites leave out:

  • First-party page tracking: our own server records each page view with the path, referring page, IP address, browser user agent, and any campaign (UTM) parameters. This powers our traffic dashboards and abuse prevention. It never leaves our server.
  • Company (not person) identification: we look up visitor IP addresses against a locally stored MaxMind GeoLite2 database to identify the organization or networka visit came from (for example, “a visitor from Acme Corp's network”). This lookup happens on our own server, identifies companies rather than individuals, and no data is sent to MaxMind or anyone else.
  • Repeat-visit linking: we compute a short hash of IP address + browser user agent to connect repeat visits into one anonymous timeline. This record contains no name or email unless you later identify yourself (for example by signing in), at which point your visits are linked to your contact record.
  • Engagement beacons: pages report anonymous scroll depth and time-on-page so we can tell which content is actually useful.
  • Email tracking: emails we send record delivery, open, and click events so we know whether they arrived and were read.
  • AI assistant processing: conversations with Chi AI (web chat, SMS, or phone) are processed by our AI systems and stored, including call transcripts, so the assistant can answer you and we can review quality.

To object to any of this processing or have your visit and contact records purged, email data@itsupportchicago.net. Retention windows for each record type are listed under Data Retention below.

Chat Page Context

While you use the chat widget, Chi AI can see the page you are on — its address, title, and visible text — so it can answer questions about what you are looking at. While the chat panel is open, it is also told short descriptions of elements you point at or text you select (for example, “the ‘Pricing’ heading”) so you can gesture at what you mean.

Nothing is captured while the chat is closed, form values and passwords are never read, and the widget shows a “Sees this page” indicator with an off switch whenever sharing is active. Shared page context is stored with the conversation like any other chat content.

Issue Reports

If you report a problem through the chat, your report — including a short excerpt of the conversation and, when page sharing is on, a snapshot of the page you were viewing — is emailed to IT Support Chicago staff so a human can act on it. If you include a contact address, staff may use it to follow up. To review or erase a report, email data@itsupportchicago.net.

Account Data

If you create an account, we store your email address and display name (provided via Google OAuth, Microsoft OAuth, or magic link). This information is used only to authenticate you and personalize your experience.

Evaluation Data

When you use our evaluation tool, we store your company profile, weight preferences, and saved search results so you can return to them later.

Your evaluations are confidential. Your company profile, custom weights, and scored results are never shared with the vendors being ranked, never displayed publicly, never sold, and never used in our public ranking calculations. Only you can see your evaluations.

How We Use Your Data

  • To provide the evaluation and ranking service
  • To save your searches so you can return to them
  • To detect and prevent abuse (rate limiting, fraud prevention)
  • To improve the service (aggregate, anonymous usage analytics)

What We Do NOT Do

  • We do not sell your data to anyone
  • We do not share your data with vendors in our rankings
  • We do not use your data for advertising
  • We do not use tracking cookies without your explicit consent
  • We do not serve third-party advertisements
  • We do not use your data to train AI foundation models. Our AI assistant (Chi AI) processes and stores your conversations to answer you (see Tracking above), but your data is never sold to, or used to train, third-party models.

Cookies

Essential cookies: We use a single httpOnly session cookie (isc_session) for authentication and a localStorage key to remember your cookie consent preference. These are necessary for the site to function.

Analytics cookies (opt-in): If you accept cookies via the consent banner, Google Analytics sets cookies (_ga, _ga_*) to distinguish unique visitors. These expire after 2 years.

No advertising cookies: Plausible Analytics does not set cookies of any kind. We do not serve ads and never set advertising or remarketing cookies.

You may withdraw cookie consent at any time by clearing isc_cookie_consent from your browser's localStorage, or by blocking cookies via browser settings. Blocking all cookies will prevent you from signing in.

Third Parties

We share data only with services necessary to operate the site:

  • Resend: Email delivery for magic links
  • Google OAuth / Microsoft OAuth: Authentication only
  • Plausible Analytics: Anonymous, cookie-free web analytics
  • Google Analytics / Google Tag Manager: Aggregate usage analytics (loaded only after cookie consent)
  • Cloudflare: DNS and tunnel (no personal data stored)
  • AI model providers (OpenAI, Google, xAI, Anthropic): when you interact with Chi AI by web chat, SMS, or phone, your conversation content (including call transcripts) is sent to one or more of these providers via their APIs solely to generate the response. We use API terms under which providers do not use this content to train their models.
  • Twilio: SMS and voice-call transport (phone numbers and message/call content, as required to deliver the service)

None of these providers receive your data for their own marketing purposes.

SMS / Text Messaging Data

If you communicate with us via SMS or text message, your mobile phone number and message contents are used solely to respond to your inquiry. Your mobile information will not be sold, rented, or shared with third parties or affiliates for their own marketing purposes. Mobile opt-in data and consent are not shared with any third parties except service providers that help us operate our messaging program, and those providers are restricted from using your information for any other purpose.

Message frequency varies based on your interactions with us. Message and data rates may apply.

For full details on our text messaging program, see our SMS Terms & Conditions.

Persona Memory

Chi AI keeps a private, per-person memory: facts you share and your conversation history, so later conversations can pick up where you left off. Your memory is visible only to you (and to IT Support Chicago staff reviewing quality) — never to other visitors — and this site's own published rankings and data always outrank remembered facts when they conflict.

  • One memory across channels: memory is keyed to your verified mobile number, so your text and phone-call conversations with Chi AI share one memory per person.
  • SMS always remembers: texting Chi AI keeps memory for your phone number (possession of the handset is the authentication); the first reply you receive says so and names the erasure keyword.
  • Erasure by text — “FORGET”: text FORGET to +1 (872) 349-2939 and we permanently erase the stored memories, conversation history, and call transcripts for that number — and, if the number is verified on an account, that account's memory too. You get a confirmation text once the erasure has completed. FORGET is not STOP: STOP opts you out of receiving messages; FORGET erases what we remember.
  • What FORGET does not delete: SMS consent records (kept for legal compliance), the deletion-audit record proving the erasure happened, usage metadata that contains no conversation content, and server and diagnostic logs.
  • Recycled numbers: memory is keyed to the phone number itself. If a number is reassigned by a carrier, its new holder could encounter memory from the previous holder — text FORGET from the number to erase it.
  • Caller-ID caveat: voice calls recall memory by the calling number, and caller ID can be spoofed — a determined attacker who spoofs your number on a call could expose that number's memories. If this concerns you, text FORGET to erase the memory, or skip verifying your number.

You can also request erasure of remembered data at any time by emailing data@itsupportchicago.net.

Visitor Options

You may request deletion of your account and all associated data at any time by emailing data@itsupportchicago.net.

You may block cookies via your browser settings, though this will prevent you from accessing account features. You may opt out of SMS messages at any time by texting STOP.

Data Retention & Deletion

Retention is enforced by an automated weekly job with these windows:

  • Account and saved evaluation data: as long as your account exists
  • Unsaved draft evaluations: deleted after 90 days of inactivity
  • Sign-in and usage logs: 12 months
  • Page-view and engagement records: 24 months
  • Email delivery/open/click events: 24 months
  • IP-to-organization lookups: 12 months
  • Raw web-server logs: up to 90 days
  • SMS consent records: for the life of the messaging program plus four years, as required for compliance

Upon account deletion, all associated personal data is permanently removed within 30 days.

Data Portability

Signed-in users can download everything we hold about them — account profile, saved searches, draft evaluations, activity logs, and stored conversations with Chi AI — as a JSON file from /api/account/export. No request or approval needed.

Account Deletion (Right to Erasure)

Signed-in users can delete their account and its data with a request to /api/account/delete, confirmed by typing the account email. This permanently erases your saved searches, evaluations, analyses, contact record and activity history, your email correspondence with us, and your conversations and memories with Chi AI — then removes the account itself and returns an itemized count of what was erased. Phone-call records keep only operational metadata; the transcripts are erased.

Deletion retains the narrow records law or basic security requires: SMS consent records, the deletion-audit record proving the erasure happened, security logs with the account link removed, and anonymized usage telemetry. Questions or problems: data@itsupportchicago.net.

Changes to This Policy

We may update this Privacy Policy from time to time. Changes are effective when posted to this page, and the “Last updated” date above reflects the most recent revision. Your continued use of the site after changes are posted constitutes acceptance of the updated policy.

Contact

For privacy questions or data requests: data@itsupportchicago.net