Privacy
Where your details go.
Asking for a deep audit means handing over four things about your business. This page says what happens to each of them, in the same plain words as the rest of the site, and it was written by reading the code rather than a template.
Nothing is sold, and nothing goes to an advertising network. There is no list to be put on.
Marketing 8 Fortune Pty Ltd · ABN 76 601 038 715 · Sydney NSW · Last reviewed 6 August 2026
What we hold
The whole list.
Four things get typed in, three more arrive alongside them, and one is thrown away on the spot. That is everything.
Your web address, your name, your email and your phone. Those four, asked once, on the audit form. Kept so a person can read the request and write back to you.
The page you sent it from, the site that linked you to us if there was one, and any campaign tag on the link. It tells us which pages are doing their job and nothing about you personally.
Scrambled into a one-way code the moment it arrives, and only the code is stored. It counts requests from one place in a day so the form cannot be sent thousands of times by a bot. The address itself is never written down, and the code cannot be turned back into it.
This changed on 6 August 2026, and it used to say none. The public pages now run Google Analytics, which sets two cookies in your browser: one that gives your browser a random number so a second visit is not counted as a new person, and one that measures how long a visit lasted. They tell us which pages get read and which get closed. They carry no name, no email and nothing you typed. There is still no advertising tag and no remarketing pixel, and nothing here follows you onto another website. View the page source and check.
Analytics is switched off on the sign-in page and on every page of the client area. What a client reads once they are signed in, their audit, their proposal, their monthly reports, is nobody else’s business, so none of it reaches Google. That is set in the code rather than in a setting somebody could flip by accident.
Existing clients can sign in to a private area to read their audit, their documents and their monthly reports. Signing in sets one cookie, holding your session and nothing else, so the area knows it is you. It is HttpOnly and Secure, cannot be read by a script, is set only after you sign in, and is cleared the moment you sign out.
There is no second form, no newsletter sign-up, no chat widget and no data bought from anywhere else. If a field is not in the list above, it is not held.
Who else sees it
Four providers.
Taking your request, storing it and getting an answer back to you uses three outside services. Counting how many people read a page uses a fourth. Nobody else is involved: a person does the audit itself, using their own tools, so your details never go to a search-data company. Here is exactly what each one receives.
Vercel
Hosts this site and runs the code behind the form. Your four details pass through it on the way to the database. The function handling them runs in Sydney rather than overseas.
Supabase
Holds the database your record sits in: the four details you typed, how you got here, and the one-way code standing in for your IP address. It opens only to our own credentials. For an existing client, Supabase also runs sign-in: it is who checks the emailed link and issues the one session cookie described above.
Resend
Carries the audit-request emails: the alert to our own inbox, which contains all four details so the person answering has what they need, and the confirmation that goes back to your own address. For an existing client signing in, Resend is also who delivers the sign-in link, sent by Supabase.
Added 6 August 2026. Google Analytics counts visits to the public pages. It receives the address of the page you are on, the site that sent you, roughly which city you are in worked out from your IP address, and what browser you use. It does not receive your name, your email, your phone number or anything you typed into the form, and it is switched off on the sign-in page and everywhere inside the client area.
Your record is stored in Australia. The database sits in Sydney and the code that writes to it runs in Sydney. Two things leave the country. The alert email goes through Resend, a United States company, so the four details inside that message travel overseas. And the analytics described above go to Google, also a United States company, though what Google gets is which page was read rather than who read it. Australian Privacy Principle 8 says you are entitled to know both before you hand anything over, so there they are.
Nothing is sold, rented or swapped. No advertising network, no data broker, no list. Analytics tells us which pages get read. It is not used to follow you, and it is not connected to any advertising account.
No one else is added quietly. Google is the fourth provider and it was named here in the same release that switched it on, which is the promise this line has always made. A fifth gets the same treatment.
Your side of it
Ask, and it’s yours.
Ask for a copy of everything held about you and you get it. Ask for something corrected and it is corrected. Ask for it deleted and the record goes: your details, the audit findings, the lot. An email comes back confirming it is done.
One exception, for clients rather than enquirers. Once an invoice has been issued, it and the records behind it are kept for as long as tax law requires business records to be kept, even if you ask for the rest of your account deleted. Everything else about you, including the enquiry that started it, is deleted on request the same as above.
Email info@marketing8fortune.com or ring 02 8188 3747. Same person either way, and it takes a couple of days at most.
Nothing is kept without a reason. A record stays while a request is open or work is running. There is no automatic purge behind the scenes, so asking is what triggers deletion. Asking is free.
Under 18s are not the audience. This is a service sold to business owners, and nothing here is aimed at children.
If we have handled this badly, say so. Tell us first. If that gets nowhere, the Office of the Australian Information Commissioner takes complaints at oaic.gov.au.