ReachIRL pilot / Privacy

Privacy Policy

Effective September 30, 2026

This policy explains the information the ReachIRL pilot collects, why we use it, the providers that help us operate the site, and the choices available to you.

Who operates ReachIRL

ReachIRL is operated by Erickson Operating LLC for this U.S. pilot. References to “ReachIRL,” “we,” or “us” in this policy mean Erickson Operating LLC in connection with the pilot.

Information you provide

If you join the waitlist, we collect your name, email address, city, and, only if you provide it, a phone number. If you choose the business path, we also collect your company name and industry. If you send Feedback/Contact, we collect your message and, if you provide them, your name and email address. If you claim and choose to save a business offer, we collect the email address you enter so we can send the saved offer and, when the offer schedule allows, one reminder. We also record the page from which a submission was sent and a random request identifier used to prevent duplicate processing.

If you apply for a free advertiser pilot, we collect your contact name, work email, company or brand, website, the action you want people to take, and whether you can provide downstream conversion results. You may also provide your intended audience, preferred location, promotion or call to action, timing, and additional context. We record the landing page, referrer, and campaign-source parameters when available so we can understand how applications reached us. A pilot application is stored separately from the advertiser waitlist and does not guarantee a campaign.

If you submit an AI data project inquiry, we collect your name, email address, project description, and, if you provide them, your company, company website, requested data type, geography, approximate volume, equipment or capture setup, metadata or transcript requirements, timeline, and whether you want to discuss an NDA before sharing more detail. We also record the landing page, referrer, and campaign-source parameters when available. Please do not submit confidential, personal, or sensitive data through the inquiry form.

If you submit a ReachIRL purchase-reward claim, we collect the payout method and destination you choose, the order or receipt number, purchase channel and time, and a private receipt or order confirmation for digital claims. You may also provide a first name and email address for follow-up. We use these details only to verify the claim, prevent duplicate rewards, contact you if needed, and make or record the manual ReachIRL-funded payout. Submitting a claim does not enroll you in marketing.

If you use the Intent Graph, we collect the choices you make, the options shown, response timing, answer changes, rewards and cumulative balance, and the QR/source context for the session. If you claim a payout, we also collect your chosen Venmo or PayPal method, one email address or US mobile number that you supply for the payout, and the request status. We do not verify that submitted contact as an identity credential. We use it to send or resolve the payout, link the claim to its session, prevent duplicate payouts, maintain payout, accounting, and fraud records, and contact you if needed to resolve the payout. Claiming does not sign you up for marketing, and this flow does not require an account, password, Google sign-in, OAuth, magic link, or one-time code.

Some Intent Graph experiences may begin with unpaid screening questions and then offer selected participants a fixed paid research follow-up. If you accept, we collect one email address for that research, reward administration, duplicate prevention, and resolving the research or reward if needed. We also collect the deeper choices you make. This email does not enroll you in marketing or authorize provider outreach. After the research is complete, we may separately ask whether you want to hear from a provider about the specific category. We record your yes or no, the time, category scope, and consent-copy version. Your reward does not depend on that answer.

If you join the waitlist to earn, we keep one record for your email address across your submissions, give you a referral code, and email you about your next steps. If you choose to complete the earn intake form, we collect what you enter there: gender, shirt size, age range, ZIP code, how far you would travel, whether you would take part with friends, the brand categories and kinds of places you select (and which of them you mark as favorites), and your availability; and, only if you provide them, your racial or ethnic background, how much notice you need, the kinds of work you are open to, a headshot photo, social media handles, an approximate follower range, favorite brands and local places, clubs or communities and events you take part in, a phone number, and how you heard about us. A headshot is stored privately: it is never published publicly, it is visible to ReachIRL, and it may be shown to a business considering you for paid work. You can replace or remove it at any time from the intake form. Your racial or ethnic background is optional. We use it to make better matches, and we do not discriminate. If you tell us you are under 18 we do not keep an intake form for you; we record only that the attempt was made, so we do not contact you about paid work. If you arrive through another person's referral link, we record that they referred you and count that referral for them; we do not show them your name or email.

Information collected automatically

When you use the site, we may collect the page and QR code visited; scan time; pilot, campaign, location, participant, shirt, and creative attribution; browser, operating system, device class, in-app-browser, language, referrer, and screen or viewport details; interaction, scrolling, return-visit, session, error, and site performance information; and signals used to identify bots, rapid repeat scans, or other abuse.

If you use or open a ReachIRL share link, we record an opaque link identifier, whether the visit came from a QR route or a shared link, its referral depth, and the originating QR, campaign, shirt, location, and field run. The public link does not contain a visitor identifier, email address, or scan record identifier. Shared-link visits are stored separately from QR arrivals.

On QR routes, hosting headers may provide an approximate city, region, and country. ReachIRL does not request or intentionally collect precise GPS location, and browser geolocation permission is disabled by the site. The application does not save a raw IP address. It may briefly process an address for rate limiting and, when configured, save only a salted SHA-256 hash for abuse detection. That hash is designed not to reveal the original address. Hosting and network providers may still process IP addresses in the ordinary course of delivering and securing the service.

Analytics and session replay

We use PostHog to understand pilot engagement, site performance, and usability. PostHog session replay may record interactions such as page changes, clicks, scrolling, and layout changes so we can see how the experience works in practice. The site is configured to mask every form input, page text, and element attribute in replay. Our named analytics events report field names and form state, not the names, email addresses, company names, or messages typed into forms. These protections reduce exposure, but replay and analytics data remain pseudonymous rather than guaranteed anonymous.

Intent Graph balances, answers, and payout status use the first-party database as their source of truth. Submitted payout email addresses, research email addresses, and mobile numbers are masked in replay and are not sent to PostHog, placed in public URLs, or included in public reporting.

Why we use information

We use information to:

  • operate the waitlist, send members who joined to earn their checklist, profile, referral, and access emails, and respond to Feedback/Contact;
  • review free-pilot applications for audience fit, timing, and whether ReachIRL can create a useful campaign test;
  • assess AI data project inquiries, clarify collection briefs, and respond about feasibility or a potential pilot;
  • match members who joined to earn to paid opportunities using their intake form;
  • measure the pilot and understand QR engagement;
  • send an offer you explicitly saved and at most one reminder;
  • review purchase-reward claims, prevent duplicate payouts, make manual payouts, and maintain an auditable reward ledger;
  • operate the Intent Graph, measure completion, link a cash-out to its session and submitted payout contact, prevent duplicate campaign payouts, make or resolve manual payouts, and maintain payout, accounting, and fraud records;
  • screen for a paid research follow-up, reserve and administer a fixed research reward, prevent duplicate participation, and record a separate category-specific provider-contact choice;
  • measure direct QR engagement and downstream shared reach;
  • improve usability and diagnose technical or performance issues;
  • detect duplicate, fraudulent, bot, or automated scans; and
  • maintain and protect the site and its services.

We do not use the pilot site for cross-site advertising or ad retargeting.

Service providers and third-party collection

We disclose information to providers as needed for them to operate services for us: Vercel for hosting and infrastructure; Supabase for database storage and other protected application services; PostHog for analytics and session replay; and Resend for email delivery — Feedback/Contact messages to private operator inboxes so we can respond, earn emails (checklist, profile, referral, access) to you, and saved business offers. A notice of each earn signup is also sent to those operator inboxes. A notice containing the free-pilot application is sent independently to each founder's operator inbox after the application is saved. AI data inquiries use the same private application, founder-notification, and BizDev review infrastructure; their project type and collection fields remain explicitly identified. Purchase-reward claim details and receipt files are stored privately with Supabase. A PII-minimized notice of a digital reward claim is sent independently to each founder's operator inbox and links to an authenticated review page; the receipt, order number, and payout destination are not included in that notice. Saved-offer email is transactional and does not enroll the address in the waitlist or marketing.

Intent Graph payout email addresses or mobile numbers are stored in private Supabase tables for payout operations. They are visible only on the authenticated founder dashboard and are not included in public reporting or founder notification email; those notices contain only the amount, method, request ID, and test/live status.

Only if you explicitly choose “yes” to the separate category-specific provider-contact question may ReachIRL share your research email and relevant answers with a provider in that category so the provider may contact you. Choosing “no” means we do not make that provider-contact disclosure. Your research reward is already earned either way, and providing an email for the research or payout is not permission for provider contact.

These providers may collect or process technical information through the site in the course of hosting, delivering, securing, measuring, or supporting their services. We do not describe these providers as advertisers, and the current pilot does not sell personal information or share it for cross-context behavioral or targeted advertising.

Cookies and browser storage

QR and shared-link pages use first-party, HTTP-only cookies: a random visitor identifier, set for up to one year; a last-scan value, set for up to one day to recognize rapid repeats; and a random scan-record identifier plus QR code, set for up to one day so a share can be credited to the run that caused it. The browser also stores first-seen, last-seen, and maximum-scroll information in first-party local storage to recognize return visits. After an earn signup, or when you open the link from an earn email, an HTTP-only cookie set for up to one year identifies your earn record so your checklist and intake form open on that device; a referral link sets a 30-day HTTP-only cookie holding the referral code. PostHog uses first-party cookies and local storage for its pseudonymous analytics identifiers and session state; after an earn signup, PostHog associates your activity with a random internal identifier, not your email. ReachIRL does not use session storage in the current implementation.

Intent Graph payout claims do not use OAuth or authentication browser storage. Clearing site data does not by itself delete a payout request already stored in the first-party database.

If you start the earn intake form and leave before saving, your unsaved answers are kept in your own browser's local storage so returning later does not lose them. That draft never leaves your device, is cleared when you save the form, and expires on its own within seven days.

Do Not Track and browser signals

The site does not currently change its analytics or storage behavior in response to the legacy Do Not Track signal or Global Privacy Control. The pilot does not sell personal information or use it for targeted-advertising sharing, so there is no sale or targeted-advertising activity for Global Privacy Control to opt out of in the current implementation. You may limit cookies or local storage through browser settings, although doing so may affect analytics and repeat-visit functions.

How long we keep information

  • QR arrivals, opaque share lineage, shared-link arrivals, and behavioral or performance analytics data are kept for up to 12 months, subject to shorter provider limitations.
  • Intent Graph choices, reward/journey records, and payout records—including research email, qualification, and explicit provider-contact choice—are kept for up to 12 months after the pilot or payout resolution, unless a shorter verified request is honored or a limited longer period is reasonably necessary for payment, dispute, fraud-prevention, legal, or accounting records.
  • PostHog session replay is kept for up to 12 months or PostHog’s shorter configured or plan retention period, whichever is shorter.
  • Feedback/Contact submissions are kept for 12 months, unless longer retention is reasonably necessary to resolve an active communication or request.
  • Free-pilot applications are kept while the pilot remains operationally useful. Once an application is no longer reasonably needed for evaluation, campaign planning, or related communication, it will be deleted within 12 months, or earlier when an appropriate verified deletion request is honored.
  • Waitlist submissions, and for the earn side your earn record, intake form, referral history, and a log of which emails we sent you, are kept while the ReachIRL waitlist remains operationally useful. Once a record is no longer reasonably needed for that purpose, it will be deleted within 12 months, or earlier when an appropriate verified deletion request is honored.
  • Saved-offer email and delivery state are kept through the offer lifecycle and any reasonably necessary support period, then deleted within 12 months of the save unless an appropriate verified request is honored earlier.
  • Purchase-reward receipts and order confirmations are scheduled for deletion 30 days after submission. The associated claim and payout ledger may be kept for up to 12 months for duplicate prevention, accounting, fraud review, dispute resolution, and pilot measurement, then deleted or de-identified when no longer reasonably needed.

Limited information may be kept longer when reasonably necessary for security, fraud prevention, legal obligations, dispute resolution, or recordkeeping. Infrastructure providers may retain short-lived operational records according to their service settings.

Security

We use reasonable technical and organizational safeguards appropriate to this pilot, including server-only service keys, restricted database access, request validation, rate limiting, masked replay, and security headers. No security measure is perfect, and we cannot guarantee absolute security.

Your choices and requests

You may email reachirl@conversionsconsulting.com to request access to, correction of, or deletion of information associated with you. We may ask for information needed to verify the request and locate a matching record. We will honor appropriate verified requests, subject to information we reasonably need or are permitted to retain for security, legal, fraud-prevention, dispute, or recordkeeping purposes.

Children

ReachIRL is intended for adults participating in or using the pilot. We do not knowingly seek personal information from children. The site does not use technical age verification. If you believe a child has provided information, contact us so we can review and take appropriate action.

Changes to this policy

We may update this policy as the pilot or its services change. If we do, we will update the effective date shown at the top of this page.

Contact

Erickson Operating LLC
ReachIRL
reachirl@conversionsconsulting.com