Effective date: August 20, 2026. This Privacy Policy is the notice at collection for visitors to https://keyforecasts.com and related hosts we operate for this brand (including keyforecasts-la.web.app).
Controller: DTLA Professional Services, LLC, doing business as Key Forecasts, 770 S Grand Ave, Los Angeles, CA 90017, United States. Phone: (213) 444-2224. Privacy requests: use the contact form or call (213) 444-2224. We do not publish a staff inbox on this website.
Scope
This policy covers the Key Forecasts marketing website, the strategy-session form, and the systems that deliver those pages (Firebase Hosting and a Cloud Function). It does not cover sister products listed on Our Apps (PayXT, Trackkr, and others). Those products have their own sites and policies. It also does not cover a paid controller engagement; client work is governed by a written agreement and any separate confidentiality terms.
The site is intended for business owners and operators in Los Angeles, California, who are considering financial reporting, analysis, or cash-flow forecasting. It is not directed at children.
Information we collect
You provide
If you submit the strategy-session form, we receive:
- Name
- Email address
- Phone number (optional, if you enter it)
- Approximate annual revenue (if you enter it)
- The service you selected (reporting, analysis, forecasting, fractional controller, or not sure)
- The message you write about the business
Do not send Social Security numbers, bank logins, full card numbers, medical details, or other highly sensitive data through the form. If we need that class of information later, it will be under a client agreement, not this public form.
If you call us, we collect whatever you say that we need in order to call back and discuss the work. We do not operate a recorded-call system on this website.
Collected automatically
- IP address, approximate location derived from IP, date and time
- Browser type, device type, operating system, language, screen size as reported by the browser
- Pages viewed, referring URL, and click or scroll events that measurement tags record
- Whether JavaScript is enabled (the Google Tag Manager noscript iframe is a fallback)
Security and anti-abuse
- Google reCAPTCHA Enterprise on the contact form (score-based, action name CONTACT). Google receives the token, your IP, and device/browser signals to judge whether the submission is automated. See Google Privacy Policy and Google Terms.
- A hidden honeypot field. If it is filled, we treat the submission as spam and do not email it.
- A short-lived signed challenge (issued-at time, nonce, HMAC) so the form cannot be replayed easily. Timing checks reject submissions that are too fast or too old.
- In-memory rate limiting by IP (currently more than eight posts per hour are rejected).
What we do not collect on this site
- Account passwords (there is no customer login)
- Payment card data (this site does not process payments)
- Precise GPS location
- Biometric identifiers
- Inputs from the on-page cash snapshot, cash runway simulator, and job-costing analyzer. Those calculators run in your browser and are not submitted to our servers unless you copy the figures into the contact form yourself.
How we use information
- To reply to strategy-session requests, usually within one business day
- To call or email you about the inquiry you sent (not a purchased marketing list)
- To keep the form and site usable: bot blocking, rate limits, error diagnosis
- To measure traffic and content performance through Google Tag Manager container GTM-NB5KMLPJ (pages, devices, campaigns, and similar events as configured in that container)
- To comply with law, enforce our terms, and protect the practice and other people
- To improve the public site (which pages help, which forms fail)
We do not use contact-form contents to train public generative-AI models. Public pages (guides, service copy, this policy) may be crawled by search engines and AI bots because our robots.txt allows them. That is page content, not your private form submission.
Google Tag Manager and measurement
We load Google Tag Manager (GTM-NB5KMLPJ) in the head of every page, with a noscript iframe immediately after the opening body tag. GTM is a tag-management layer. It can load Google Analytics, Google Ads conversion or remarketing tags, and other tags we place in the container. Those tags may set first-party and third-party cookies, read the page URL, and send device and usage data to Google.
We do not list every cookie name here because tags in the container can change. The Cookie policy describes the categories we use and the cookies Google products commonly set. Google’s own processing is described at policies.google.com/privacy and business.safety.google/privacy.
You can opt out of Google Analytics with the Google Analytics opt-out browser add-on, limit ad personalization at adssettings.google.com, and use industry opt-outs such as aboutads.info and networkadvertising.org. Browser controls that block third-party cookies will also reduce what GTM tags can store.
Who we share information with
We do not sell personal information, and we do not rent our inquiry list. We share information with service providers who process it on our instructions:
| Provider | Role | Data involved |
|---|---|---|
| Google LLC (Firebase Hosting, Cloud Functions, logging, Secret Manager, reCAPTCHA Enterprise, Tag Manager, and any Analytics or Ads tags in GTM) | Hosting, form backend, security, measurement | Page requests, IPs, form payloads in transit to our function, reCAPTCHA signals, analytics events |
| FormSubmit (formsubmit.co) | Delivers the contact-form message to our inbox | Name, email, phone, revenue, need, message |
| Our email and phone providers | So we can reply | The inquiry and our reply |
We may also disclose information if required by law, to respond to lawful process, or if we transfer the practice (merger, sale of assets). We will not post your inquiry publicly.
Outbound links (LinkedIn, Facebook, Instagram, X, TikTok, GitHub, and sister apps) send you to those companies. Their cookies and policies apply after you leave.
Retention
- Strategy-session inquiries: kept as long as needed to respond, follow up, and keep ordinary business records, then deleted or archived on a shorter cycle if you ask us to delete and we have no legal duty to keep them. A typical working window is up to 24 months unless a client relationship starts.
- In-memory rate-limit data: about one hour.
- HMAC challenges: only until they expire (minutes, not more than 30 minutes).
- Firebase / Google Cloud request logs: per Google Cloud’s logging retention for the project.
- Google Analytics / Ads data: per the retention and ads settings configured in those Google products.
Security
Transport is HTTPS. Hosting sends Strict-Transport-Security. The contact function sanitizes fields, rejects empty or malformed email, uses reCAPTCHA Enterprise (fail closed below a 0.5 score), a honeypot, timing checks, and IP rate limits. Inbox and signing secrets live in Google Secret Manager, not in the public JavaScript. No method is perfect. Do not put secrets in the public form.
California privacy (CCPA / CPRA)
If you are a California resident, you have the right to know, access, correct, and delete personal information; to opt out of sale or sharing for cross-context behavioral advertising; to limit use of sensitive personal information; and not to be discriminated against for exercising those rights.
We do not sell personal information for money. We do not share personal information for cross-context behavioral advertising except to the extent Google measurement or ads tags in our Tag Manager container use identifiers for Google’s advertising or analytics products. Use the Google and industry opt-outs above, and browser cookie controls, to limit that. We do not currently honor the Global Privacy Control (GPC) signal in code; if you send GPC, still use those opt-outs. We do not use or disclose sensitive personal information for purposes that require a “limit the use” right beyond what is needed to provide the form and secure the site.
Categories collected in the last 12 months, if you used the site or form:
- Identifiers (name, email, phone, IP)
- Commercial or business information you type (revenue range, what you need help with)
- Internet or electronic activity (pages, device, referral)
- Approximate geolocation from IP
- Professional or employment-related information if you include it in the message
- Inferences only in the narrow sense of a reCAPTCHA risk score, which we use to accept or reject a post and do not store as a marketing profile
Sources: you, your browser, Google (GTM, reCAPTCHA, hosting logs). Business purposes: as listed under “How we use information.” We do not use the form to build a third-party advertising audience of inquirers.
To exercise rights, submit the contact form with the subject of your request or call (213) 444-2224. We will verify using the email or phone in the request. An authorized agent may submit a request with proof of authority. Shine-the-light (Cal. Civ. Code § 1798.83): we do not disclose personal information to third parties for their own direct marketing.
Other U.S. state privacy laws
If you live in a state with a consumer privacy statute (for example Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana), you may have similar rights to access, delete, and opt out of targeted advertising or sale. Use the same contact methods. We will respond as those laws require when they apply to us.
International visitors
The site is hosted in the United States (Google Cloud / Firebase, including us-central1 for the contact function). If you visit from the EEA, UK, or elsewhere, your information is processed in the United States. We rely on our legitimate interests in operating a public business website and responding to inquiries, and on steps you take when you submit the form. You may object or request deletion through the contact form. This site is not designed as an EU consumer storefront.
Children
The site is for adults considering professional finance work. We do not knowingly collect information from children under 16. If you believe a child submitted the form, contact us and we will delete it.
Do not send unsolicited financial records
Emailing or uploading full general ledgers, payroll files, or tax returns through the public form is at your own risk. Wait for a client channel if the file is sensitive.
Changes
We will update the effective date when this policy changes. Material changes to how we use personal information will be posted on this page. Continued use of the site after the new date means you accept the updated policy for subsequent visits.