Last updated: 27 August 2026
GTM Layer LLC (we, us, our) is a revenue operations consultancy registered in the United States at 30 N Gould St, Sheridan, Wyoming 82801.
This notice explains what personal data we hold, why we hold it, who we share it with, how long we keep it, and what you can ask us to do about it. It covers four things: the gtmlayer.com website, the Revenue Leak Scan app for HubSpot, the research database we use to identify businesses that may need our services, and the work we do for our clients.
We are registered with the UK Information Commissioner's Office, registration number ZC219430.
Contact us about anything in this notice at privacy@gtmlayer.com.
We value your privacy and your rights as a data subject and have therefore appointed Prighter Group with its local partners as our privacy representative and your point of contact for the following regions:
• European Union (EU)
• United Kingdom (UK)
Prighter gives you an easy way to exercise your privacy-related rights (e.g. requests to access or erase personal data). If you want to contact us via our representative, Prighter, or make use of your data subject rights, please visit the following website: https://app.prighter.com/portal/17412690523
Data protection law splits responsibility in two, and which half applies changes who you should contact.
Where we decide what to hold and why, we are the controller. That covers this website, the Revenue Leak Scan app, our marketing, our newsletter and our research database. This notice covers all of it, and requests come to us.
Where we deliver services to a client, we act on that client's instructions as a processor. If your data is in a client's CRM and we are working on that CRM, the client decides what is held and why, their own privacy notice governs it, and a request about it should go to them. If you send such a request to us we will pass it on to the client promptly and tell you we have done so, but we cannot action it ourselves.
If you have contacted us, or we work with your company. Your name, business email address, phone number if you gave us one, job title, employer, and a record of our correspondence and meetings. You gave us this directly.
If you have never contacted us. We maintain a research database of people in roles that may need our services. It holds your name, job title, employer, business email address, and links to public professional profiles. We did not get this from you. We collect it from public professional profiles, company websites, public registers, and third-party providers of business contact information. We record where each record came from. For records added before August 2026 we can tell you the categories of source, and in many cases the specific provider, but our records do not always identify a single supplier.
If you have been on a call with us. We record client and prospect calls and keep both the recording and a written transcript. We say so at the start of the call, and you can ask us not to record.
If you use the Revenue Leak Scan app. Your HubSpot portal ID, the email address of the person who installed the app, encrypted access tokens, the report we generate for you, and a record of when each scan ran. The section below sets out exactly what the app does and does not do with your CRM.
If you subscribe to our newsletter. Your name and email address.
We do not knowingly collect special category data, meaning information about health, race or ethnic origin, religion, political opinions, trade union membership, genetics, biometrics, sex life or sexual orientation. We do not seek criminal offence data.
• Identifying and contacting businesses that may need our services. Legitimate interests, being our interest in finding customers for a business-to-business service, balanced against your interest in not being contacted inappropriately. We contact people only in a professional capacity, about their work, and never in a personal one.
• Providing services to a client. Performance of a contract, or legitimate interests where you are our client's employee rather than our counterparty.
• Running the Revenue Leak Scan on your HubSpot portal. Your consent, given when you install the app and withdrawn by uninstalling it.
• Recording and transcribing meetings. Legitimate interests, being an accurate record of what was discussed and agreed.
• Sending the newsletter. Your consent, which you can withdraw at any time. • Keeping accounting and tax records. Legal obligation.
• Keeping a record of people who have asked us not to contact them. Legal obligation, because we cannot honour that request unless we remember it.
Where we rely on legitimate interests we have carried out and recorded a balancing assessment. You can ask us for a summary of it.
What we access: When you install the app, you grant it read-only access to your HubSpot portal via OAuth: deals, contacts, companies, owners, pipelines and property metadata, plus leads where your portal uses that object. The app has no write permissions of any kind. It cannot create, change or delete anything in your CRM, and we will never ask you to widen its access for the free scan.
What we do with it: Each scan pulls those records solely to compute your report. The pull, the analysis and the report generation all happen inside one isolated, temporary environment that exists only for the duration of that scan.
What we never store: Your raw CRM records are never stored. Each scan reads them into an isolated, temporary environment that exists only for that run, computes your report, and the environment is destroyed when the run ends, on success and on failure alike. Nothing is written to a database, a backup or long-term storage, so there is nothing left to delete. What we do keep is listed below.
What we keep: Three things. The computed report and its underlying findings, which can reference records in your CRM by name, because naming them is what makes the report useful. The connection itself, meaning your portal ID, the email address of the person who installed the app, and OAuth tokens. And run records, meaning when scans ran, whether they succeeded, and how many API calls they used. That is the complete list.
How tokens are stored: OAuth tokens are encrypted at rest using AES-256-GCM. The encryption key is held separately from the database, so a copy of the database on its own cannot decrypt a token. When you uninstall, your tokens are deleted.
The monthly re-scan: The app re-runs your scan roughly every 28 days and emails you what has changed. Same access, same no-storage promise, every run.
Your report: Reports are stored privately and served through a link unique to your portal. After you uninstall, your existing report link keeps working, because the report is yours. Email us if you would prefer it deleted.
Uninstalling: Remove the app at any time from HubSpot Settings, under Integrations and Connected Apps. Uninstalling deletes your tokens and stops all future scans. You can also email us and we will disconnect and remove the app from our side.
We use service providers who process personal data on our behalf, covering cloud infrastructure and databases, CRM, data enrichment, meeting recording and transcription, email delivery, accounting, and our privacy representative and their hosting provider. For the Revenue Leak Scan specifically these are Supabase (database and report storage), Fly.io (the isolated compute that runs each scan) and Resend (report email delivery), all processing in the United States. Scans read from HubSpot's APIs under HubSpot's own terms.
We keep a current list of every provider that handles personal data for us, and we will send it to you on request.
We do not sell your personal data, and we do not share it for cross-context behavioural advertising. We do not use your data, or your CRM's data, to train models.
We are a United States company and our infrastructure is in the United States. If you are in the United Kingdom or the European Economic Area, your data is transferred outside your country when we hold it.
For those transfers we rely on the UK International Data Transfer Addendum and the European Commission's standard contractual clauses, incorporated into our agreements with the providers who process data for us. We are not certified under the EU-US Data Privacy Framework. You can ask us for details of the safeguards that apply to your data and we will tell you.
These are ceilings rather than schedules. They are the longest we will hold each kind of record.
• Research records on people we have never engaged with: 12 months from when we last verified the record.
• Records where there is an active commercial relationship, meaning you have replied, met us or booked with us: 3 years from last contact.
• A record that you have asked us not to contact you: kept permanently, minimal details only.
• Client contracts and deliverables: 7 years from the end of the engagement.
• Accounting and financial records: 7 years from the end of the financial year.
• Meeting recordings and transcripts: Kept for as long as we are trading, because a recording is our own record of what was discussed and agreed, and can be evidence in a live matter. We review them periodically rather than deleting on a fixed schedule.
• Email correspondence: 24 months from last activity, longer where a thread evidences contract terms.
• Revenue Leak Scan connection data: deleted with your tokens when you uninstall.
The one row with no discretion in it is the suppression record. If you ask us not to contact you, we keep a minimal permanent record of that request, holding no more than we need to recognise you and stay away. It is the only way to be certain we do not contact you again by mistake, and deleting it would guarantee the opposite.
You do not have to wait for a period to run out. Ask us to delete your data and we will, whatever the list above says.
You can ask us to:
• tell you what we hold about you, and give you a copy
• correct it if it is wrong or incomplete
• delete it
• stop using it for marketing, which we will always do, immediately and without asking why
• restrict or object to how we use it
• transfer it to you or to someone else in a portable format
• withdraw your consent, where consent is what we rely on
We provide you with an easy way to submit us privacy related request like a request to access or erase your personal data. If you want to make use of your data subject rights, please visit our Trust Center: https://app.prighter.com/portal/17412690523
You can also email privacy@gtmlayer.com directly.
What happens next. We will respond within one month of receiving your request. If your request is genuinely complex we may extend that by up to two further months, and if we do we will tell you inside the first month and explain why. There is no charge.
We will not ask you to prove your identity unless we have real doubt about who you are, and if we do ask, we will ask for the least we can work with. Asking someone for a passport to prove they control a business email address is itself a data protection problem, and we are not going to do it.
A request to delete your data, or to object to how we use it, needs no reason and no explanation from you.
If you are unhappy with how we have handled your personal data, tell us at privacy@gtmlayer.com and put complaint in the subject line. We will acknowledge your complaint within 30 days of receiving it, as required by the Data (Use and Access) Act 2025, and tell you what we intend to do about it.
You do not have to complain to us first. If you are in the United Kingdom you can go straight to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113. If you are in the European Economic Area you can complain to your national supervisory authority, and Prighter can direct you to the right one.
The comprehensive state privacy laws, in California, Virginia, Colorado, Connecticut, Texas, Oregon, Montana and elsewhere, apply to businesses above a set size. We are a two-person company and we sit below every one of those thresholds, so those laws do not currently place obligations on us.
We would rather not use that as a reason to treat you differently. Ask us the same things anyone else can ask, and we will do the same things about them: tell you what we hold about you, correct it, delete it, or stop contacting you. Email privacy@gtmlayer.com.
We do not sell personal data and we do not use it for targeted advertising, so there is nothing there for you to opt out of.
The website sets six cookies, and this is the complete list.
• _ga and _ga_SYHDNHDRFX: Google Analytics, which tells us how many people visit and which pages they read. • hubspotutk: identifies your browser to our CRM, so that if you later fill in a form we can connect the two. • __hstc, __hssc and __hssrc: HubSpot's analytics, doing much the same job as Google's.
We also use Cloudflare Turnstile to keep automated traffic off our forms. That one is necessary for the site to work rather than optional.
None of the six is necessary. They are there because we want to understand which kinds of business find our work relevant, and we do not use them for advertising. We do not run a tool that identifies individual visitors, and we do not sell or share any of it.
A consent banner is live on gtmlayer.com as of 27 August 2026. Non-essential cookies are held back until you accept them, by category, and you can change or withdraw your choice at any time through Cookies settings. One honest caveat while we finish the wiring: Google Analytics is not yet connected to the banner and can set its cookie before consent; we are closing that gap now and will update this section when it is done.
If we contact you cold by email, that email will tell you how to stop, and it will carry our postal address. Our cold emails deliberately contain no links, so the way to opt out is to reply and say so. One word is enough. We action those replies ourselves and add you to the suppression record described above, and you will not hear from us again.
Our services are sold to businesses. They are not directed at children, and we do not knowingly collect data about anyone under 18.
If this notice changes in a way that matters, we will update this page and the date at the top of it. The commitments about read-only access to your CRM, and about never storing your raw CRM data, are load-bearing parts of how the product is built rather than preferences, so do not expect those to move.