Updated 27 September 2026. This policy covers the public lol.marketing agency website. Linked client portals and separate products provide their own privacy information.
Controller and contact
lol.marketing LLC, 30 N Gould St Ste N, Sheridan, WY 82801, USA. Contact person: Manuel Streit. For questions about processing or your rights, email hello@lol.marketing.
Website access and technical delivery
Google Firebase Hosting delivers this website. Requests involve technical connection information, including IP address, time, requested address, response status and browser/device information. This supports delivery, troubleshooting and protection against misuse.
The contact form is processed through Google Cloud Functions in us-central1 in the United States. Firebase Hosting uses globally distributed infrastructure. Processing is therefore not restricted to Germany or the European Union.
The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is reliable, secure website operation and protection against abusive access. Firebase states that Hosting retains IP data for a few months and that Functions retains IP addresses temporarily to provide the service. Other technical logs depend on their security and troubleshooting purposes and the relevant service settings.
Contact forms and email inquiries
When you contact us, we process your name, email address and message. Company and website are optional form fields. The form also sends the selected language, an applicable service context and the page path so we can understand the inquiry. We use this information to respond, ask follow-up questions and, where relevant, prepare a proposal.
The server passes the inquiry to the email service Brevo (Sendinblue SAS, France). Brevo sends a transactional notification to the responsible lol.marketing mailbox, processing the message, contact information and technical delivery data. Brevo identifies EU locations for its databases. This does not make the preceding US form processing or subsequent email communication exclusively European.
An inquiry does not subscribe you to a newsletter and does not require consent to analytics, ad performance measurement or email matching. A name, reachable email address and a description are needed to respond meaningfully to a form inquiry. You may instead contact us directly by email.
For pre-contractual or contractual requests, the legal basis is Article 6(1)(b) GDPR. If you contact us on behalf of a business or for another purpose, we rely on our legitimate interest in responding to communications under Article 6(1)(f) GDPR.
We retain inquiries and related correspondence as needed to handle them, respond to follow-up questions and, where applicable, perform a contract. We then delete them unless legal retention requirements or the establishment, exercise or defence of legal claims require further retention. Delivery logs help explain delivery status and investigate failures. Their retention is separate from correspondence in the mailbox; automatic Brevo deletion is not assumed for every existing data category.
Contact-form protection
We use an additional field not visible to ordinary visitors and a server-side limit on repeated inquiries to prevent automated abuse. A secret-keyed pseudonymous identifier is derived from the normalised email address. We also limit the total number of accepted attempts. The protection database stores only the derived identifier, counters and timestamps, without the email address in plain text and without the message. We do not evaluate IP addresses for this limit. During high request volumes, the overall limit may also apply.
The rate-limit window is 15 minutes. Protection records receive an expiry time 24 hours after the last permitted attempt. They are then removed through the database’s enabled automatic deletion feature; deletion is asynchronous rather than immediate at the expiry time. The information is used only for abuse prevention. The legal basis is Article 6(1)(f) GDPR, reflecting our interest in keeping the form available and preventing unwanted sending. If a request is temporarily limited, email contact remains available.
Your privacy preferences
You can decide separately whether to allow Analytics, Ad performance for ChatGPT ads, Meta ad measurement and Enhanced email matching. All four purposes are optional and off by default. Email matching is available only together with ChatGPT ad performance measurement. You can reject all, adjust each setting or accept all. We ask again for earlier decisions because the new Meta choice has been added.
Your selection, the version of these settings and the time of your decision are stored in your browser’s local storage as cookie-consent. The decision is valid for six months, after which we ask again. You can change it at any time through “Cookie settings” in the footer. If browser storage is blocked, the decision cannot be saved permanently.
Storing your choice enables us to apply it without asking again on each page. It is necessary for the setting you request under section 25(2)(2) of Germany’s TDDDG. Where personal data is involved, the basis is Article 6(1)(f) GDPR. You can submit an inquiry with any selection.
Google Analytics requires your consent
Google Analytics 4 loads only after you allow Analytics. Before that, and after a rejection, Google Analytics tags on this website do not send measurement data to Google (Basic Consent Mode). Analytics may process visited pages, timestamps, technical browser/device characteristics, a pseudonymous browser identifier and usage events. These include contact clicks, starting contact, an inquiry successfully submitted after provider acceptance (generate_lead), completing the marketing check, a successful headline roast or a click on the WhatsApp contact link. An attempted submission alone does not count as a successful inquiry.
We send page addresses to Google Analytics without arbitrary URL parameters. After analytics consent, only approved campaign source and medium values are retained. We retain the fixed campaign name and two creative identifiers for the ChatGPT driving-school ad, and the fixed campaign name and ten creative identifiers for the Meta driving-school ads. For referring pages, we send only the domain, without the path, query parameters or fragment. The OpenAI click identifier oppref, Meta click identifier fbclid, search terms from URL parameters, message text, names, email addresses and individual check answers are not included in the Analytics events we configure. Google advertising features and sharing user data for Google ads remain denied in the consent settings. Allowing “Ad performance” or “Meta ad measurement” does not enable Google advertising features.
Google may derive an approximate location from connection information. The website does not request the browser’s location permission for this. Google states that individual IP addresses from EU, Swiss and UK users are discarded before logging; this does not make all remaining usage information anonymous.
The legal bases are consent under Article 6(1)(a) GDPR and section 25(1) TDDDG for storing and accessing analytics identifiers. According to Google, Analytics cookies such as _ga and _ga_… have a default lifetime of up to two years, which browsers may shorten. Analytics information helps us understand website use and the path from an ad to an inquiry. The existing Analytics account is set to retain individual event data for two months and user data for 14 months; the user-data period resets after new user activity. Google’s aggregated standard reports may be retained for different periods.
You can withdraw consent for the future through “Cookie settings”. Further analytics collection then stops, and the related Analytics identifiers are removed from your browser where this website can access them. Withdrawal does not affect the lawfulness of processing before withdrawal. You can contact us to request information about or deletion of data already sent to Google.
ChatGPT ads: optional ad performance measurement
If you allow Ad performance and your form inquiry is successfully transmitted to us, our server sends a conversion event to OpenAI. Here, success means that our email provider Brevo has accepted the notification. The lead_created event contains a random event identifier, the event time and a source URL limited to this website. If you arrived through a ChatGPT ad, it may also contain the unchanged OpenAI click identifier oppref attached to the ad link. This helps OpenAI attribute the inquiry to an ad. We store this identifier on this website only after your ad performance consent and for no more than 30 days. No OpenAI advertising pixel is loaded in your browser.
Only if you also allow Enhanced email matching do we trim the email address from your successful inquiry, convert it to lower case and hash it with SHA-256 on our server. Only that hash is sent to OpenAI as an additional matching identifier. A hash does not make the address anonymous: OpenAI may match it against addresses hashed in the same way. We do not send the plain email address, names, phone numbers, message text, visitor IP addresses or browser identifiers in this conversion. Your consent under Article 6(1)(a) GDPR is the legal basis for both optional processing purposes; section 25(1) TDDDG also applies to accessing or storing the click identifier in your browser.
We use this information to measure the success of our ChatGPT ads and optimise them for confirmed inquiries. The OpenAI Conversion Terms also permit OpenAI to use conversion data for reports, creating custom audiences for the advertiser, and improving, optimising and delivering its services, among other purposes. We do not upload an audience list through this website. Under the OpenAI Ad Tools Data Processing Addendum, OpenAI and we generally act as independent controllers for this ordinary conversion processing; different roles apply to the restricted processing specifically defined there. The addendum names OpenAI Ireland Limited as the OpenAI entity processing EEA and Swiss data. Further processing outside the EEA is possible; according to the addendum, OpenAI Ireland Limited uses a valid transfer mechanism for such onward transfers.
If transmission temporarily fails, our server may queue the conversion without the plain email address for at most 24 hours and make no more than four attempts in total. After a successful transmission or cancellation, matching identifiers are removed from our queue. Deletion of the remaining minimal technical status is scheduled after 24 hours; an asynchronous database deletion rule provides backup for the regular server cleanup. The random event identifier used for a possible withdrawal remains in your browser for no more than seven days. OpenAI’s retention period after receipt depends on its terms and the specific processing; we do not claim a fixed provider retention period.
You can withdraw ad performance and email matching consent separately for the future through “Cookie settings”. Withdrawing ad performance consent removes the click identifier from your browser and cancels pending conversion transmissions. Withdrawing only email matching consent removes hashes still pending transmission. A transmission already in progress cannot reliably be stopped, and this cannot automatically retrieve data already sent to OpenAI. For access or deletion requests, contact us at the email address above. We will help identify the relevant inquiry and exercise your rights with the recipient. The inquiry form works regardless of these choices.
Meta ads: separate consent
Only if you allow Meta ad measurement do we load the Meta Pixel (“Websitedaten lol.marketing”, ID 650494788048644) from Meta Platforms and send a PageView event. Meta then receives the requested page, technical connection data and, where available, its browser and click identifiers _fbp, _fbc and fbclid. Before loading the tag, we remove arbitrary URL parameters and leave only approved campaign tags, a safe form context and a well-formed Meta click ID in the browser address. The pixel may set or read accessible Meta cookies. Without this separate consent, we do not load it. The legal bases are Article 6(1)(a) GDPR and section 25(1) TDDDG. Meta explains its data processing.
After a successful driving-school inquiry, meaning only after Brevo acknowledges acceptance, we send a Lead event with the same random event identifier through the browser pixel and, if a Meta browser identifier is available, through the Meta Conversions API. The server event contains only the event name and time, a source URL limited to known pages, the event identifier, the browser identifier _fbp or click identifier _fbc, and the browser user agent. This helps Meta match the event technically. The form name, email address, message, phone number, IP address and other form contents are not included in the Meta queue or our Meta event. Without either identifier, we omit the server transmission; a confirmed Lead can still be measured through the browser pixel. Both channels use the same ID so Meta can deduplicate them.
If transmission temporarily fails, our separate Meta queue stores the identifiers and user agent for no more than 24 hours and makes no more than four attempts in total. It removes them after success, final failure or withdrawal; the remaining minimal technical status is then deleted. The event ID for a possible withdrawal remains in your browser for no more than seven days. You can withdraw Meta ad measurement through “Cookie settings” for the future at any time. Accessible Meta cookies are then deleted and pending server events cancelled; an in-progress or completed transmission cannot be recalled this way. Meta may process data outside the EEA; information about recipients and international transfers is in Meta’s Privacy Policy. The inquiry form works without this consent.
Roast Me: optional AI headline test
Roast Me starts only when you submit your headline. Our server sends the text and your chosen response language to Google Gemini through the Gemini API. The response appears in your browser. Please do not enter confidential information or other people’s personal data. The result is an AI-generated copy suggestion, not a binding assessment. There is no sign-up, newsletter subscription or automatic follow-up message.
We process the necessary information to provide the test you request and prevent abuse, based on our legitimate interest under Article 6(1)(f) GDPR. We do not store your headline or result in our database or send them to Google Analytics. Google processes the submitted text to provide the AI response. Processing may take place outside the EEA; Google’s Gemini API terms and privacy policy apply. Provider retention depends on the applicable terms and service settings.
Only when you first submit does the browser store a random identifier under roaster_client_id, valid for 24 hours. It is used solely to limit use of the requested free test, not for advertising or analytics. Expired identifiers are replaced on the next use; you can delete the entry through your browser’s website-data settings at any time. Storage serves the provision and protection of the function you explicitly request (section 25(2)(2) TDDDG). If browser storage is blocked, the identifier remains only in memory for the current page.
The server stores only identifiers derived with a secret key, time windows, counters and expiry times. IP addresses and forwarded headers are not used for these limits. Up to five admitted attempts per browser identifier and 200 overall are allowed per 24-hour window. Admitted attempts count even if a subsequent technical error occurs; the overall limit may temporarily affect all visitors. Protection records expire at the end of their window and are removed asynchronously by the existing automatic database-deletion function.
With analytics consent, only successful completion may be counted as an event. The identifier, your input and the AI response are not included. The tool also works without analytics consent.
Contact through WhatsApp
The WhatsApp button is a normal external link. Before you click, this website does not load WhatsApp content or connect to WhatsApp. If you open the link and message us there, WhatsApp processes the data required for its service under its own privacy information. We use your message to respond to your enquiry; the purposes and legal bases described under contact enquiries apply to business enquiries. You can always use our contact form or email instead.
Marketing check and external links
The marketing check calculates its guidance entirely in the browser. Individual answers and results are not transmitted to us or an AI model. With analytics consent, completion of the check may be counted as a usage event.
Fonts and images are supplied through this website. Links to other sites open the relevant provider when you follow them, and that provider’s privacy information applies there. The new inquiry process does not embed an appointment-booking service and does not automatically decide whether to enter into a contract.
Recipients and international processing
Recipients include authorized people at lol.marketing and the hosting, function, database and email services used for these purposes. With the relevant consent, Google Analytics, OpenAI and Meta are added for the purposes described above. Disclosures may also be required by law.
lol.marketing LLC is a US company. The infrastructure and providers described above may process information outside the EEA, particularly in the United States. Google’s published processing terms contain provisions for international transfers, including applicable EU standard contractual clauses. Google also describes its use of applicable adequacy mechanisms such as the EU-US Data Privacy Framework. OpenAI’s advertising terms are linked in the ad performance section. You may request information about the recipients and transfer safeguards relevant to your data, including a copy of applicable safeguards, through our contact address.
Your rights
Subject to the relevant legal conditions, you may request access, rectification, erasure, restriction of processing and data portability. You can object to processing based on legitimate interests for reasons relating to your particular situation. Consent may be withdrawn for the future.
You may lodge a complaint with a data protection supervisory authority, particularly where you normally live, work or believe an infringement occurred. The European Commission provides an explanation of these rights. To contact us, begin with an email to the address above. We may request suitable additional information if needed to identify the relevant records.
Sources and further reading
- Datenschutz-Grundverordnung / GDPR
- § 25 TDDDG
- Firebase: Privacy and Security
- Firebase Data Processing and Security Terms
- Google Cloud Data Processing Addendum
- Google: Data transfer frameworks
- Brevo: Privacy policy
- Brevo: Data storage location
- Brevo: Data processing agreement
- Google Analytics: Cookie usage
- Google Analytics: EU, Switzerland and UK data handling
- Google Analytics: Data retention
- Google: Basic Consent Mode
- OpenAI: Conversions API
- OpenAI: Conversion Terms
- OpenAI: Ad Tools Data Processing Addendum
- European Commission: Your data protection rights