Privacy

Privacy Policy

Local Wrangler is a lead-tracking and revenue-attribution platform. This policy explains what data we collect, how we use it, and the choices you have. It covers both the people who use Local Wrangler (our customers) and the visitors to our customers' websites.

Last updated: August 10, 2026

Overview

We try to collect as little as we need to do one job well: showing a business where its leads come from. Our website tracking is designed to be privacy-first by default. It sets no cookies on your visitors and does not track people across other websites.

Local Wrangler is operated by Service Scalers. Throughout this policy, "we", "us", and "Local Wrangler" refer to the service and the company that runs it.

Who is responsible for what

There are two relationships to keep separate:

  • For our customers' account data (the people who sign up and log in), we decide how that data is handled, so we act as the controller.
  • For the visitor and lead data that a customer collects through Local Wrangler on their own website, the customer decides why and how it is used. We handle it on their behalf, so for that data we act as a processor and the customer is the controller.

If you are a visitor to a business that uses Local Wrangler and you want your data accessed or deleted, contact that business first, since they control it.

Account data we collect

When you create and use a Local Wrangler account, we collect:

  • Your name, email address, and password credentials.
  • Your organization details, team members you invite, and the roles you assign them.
  • The websites and phone numbers you connect for tracking, and the integrations you connect.
  • Billing information when you subscribe to a paid plan. Card details are handled by our payment provider; we do not store full card numbers.
  • Basic usage and diagnostic information so the product works and stays secure, such as log records and error reports.

Visitor data the tracker collects

When you add the Local Wrangler tracking snippet to your site, it records the following about your visitors so you can attribute leads:

  • Pages viewed, page titles, referrer, and time spent on a page.
  • Scroll depth, clicks on contact links (phone, email, chat), and similar engagement signals.
  • Traffic source and campaign details taken from the URL, such as UTM parameters and advertising click identifiers. These include gclid, gbraid and wbraid from Google, fbclid from Facebook, and msclkid from Microsoft.
  • Approximate location (country, region, city). To work this out the IP address is shortened first (the last part is removed) and only the shortened form is sent to the location provider, so it sees a broad network range rather than a single address. The full address is not stored with the visit.
  • Browser, operating system, and device type.
  • The details a visitor types into your forms, or shares on a tracked call or chat, such as name, email, phone, and message. This is the lead information you asked for.

Call recordings and chat transcripts are captured only for the channels you turn on, and they belong to your organization.

Calls and chats you record: if you turn on recording for a tracking number, we store the recording and produce a written transcript of it. To do that we send the audio to a speech to text provider, and we then send the transcript to an AI provider that returns a short summary, a suggested category, and topic tags for the business. The same applies to a chat transcript when chat is connected. Recording is off unless the business turns it on for a specific number.

One of those categories can act on its own. When a transcript reads clearly as a robocall or a sales solicitation, the enquiry is automatically marked as not genuine, without anyone at the business reading it first. This works the same way for a recorded phone call and for a chat conversation. That is the only category that changes anything by itself. Everything else the AI suggests is a label the business can act on or ignore.

Five things limit this. The business is alerted about the enquiry before any of this runs, so it is never kept from them at the moment it arrives. Nothing is deleted or hidden: the enquiry stays in the business's list, the change is recorded along with the reason for it, and the business can undo it at any time. If the business has already set a status, theirs is the one that stands, including when they set it while this was still running. When the AI is not confident, it leaves the enquiry alone rather than guessing. And when the conversation itself shows the person is a current or former customer, the enquiry is never marked down, whatever else it looks like. That last safeguard reads the conversation, not our record of who has bought before, so it depends on the person saying so.

Cookies and first-party tracking

On visitors' sites: the tracking snippet sets no cookies. It does not use third-party cookies and does not read or write a cookie to identify a person. Visits are grouped in two ways. The browser stores a random first-party identifier, kept for up to 30 days, along with the traffic source the visit arrived from and a small counter of how many times that browser has visited. None of this is shared with other websites. Separately, our servers calculate a value from the visitor's network address and browser details combined with a secret that we change every day. That calculation is one way, it is never shared, and because the tracking key of the individual site is part of it, the same person visiting two different businesses produces two different values, which we do not link. We delete each day's secret when it is more than 7 days old, and never keep one beyond 8 days, after which the value cannot be traced back to a network address, other than in the backups described under Data retention. Until then we treat it as personal data rather than as anonymous data.

Rules about storing information on a visitor's device differ by country, and in some places they cover browser storage as well as cookies. What notice or consent your own site needs is your decision to make for the places your visitors are in.

On the Local Wrangler app: when you log in to your dashboard, we use strictly necessary cookies and similar browser storage to keep you signed in and remember your preferences. These are essential to running the app you chose to use.

On the customer portal: if a business sends you a link to follow your job, that page asks you to confirm your job number and phone number before it shows you anything. Once you have, it sets one cookie for that job so you do not have to confirm them again on every screen. It lasts up to 12 hours, or until the link itself expires, whichever comes first. It holds no details about you: only a version tag, an expiry, and a signature proving it came from us. It is not used for tracking or advertising.

Global Privacy Control: when a visitor's browser sends a Global Privacy Control (GPC) signal, the tracker treats it as an opt out of sharing for advertising. It stops capturing advertising click identifiers and does not forward lead data to a site's advertising tools, while still recording the basic, cookieless measurement the business needs.

How we use data

  • To provide the tracking, attribution, and reporting features you use.
  • To create and secure your account, and to support your team.
  • To process payments and manage subscriptions.
  • To keep the service reliable and safe, including preventing abuse, spam, and fraud.
  • To stop automated and abusive submissions, which includes automatically judging whether a submission is genuine.
  • To communicate with you about your account, important changes, and support requests.
  • To improve the product, using aggregated or non-identifying information where possible.

We do not sell personal data, and we do not use one customer's visitor or lead data to serve another customer.

Submissions we do not accept

Not every submission becomes a lead. Some are stopped because they look automated, because they carry no way to reply, or because they were sent from a site we do not recognise. We keep a short record of these so a business can see that something was blocked and judge whether it should have been. That record holds the time, the page, the form, and which kinds of detail were present, for example that an email address and a phone number were filled in. It does not hold the details themselves.

Where a submission is stopped because our checks judged it to be automated, we hold the submission itself so that a person at the business can look at it and release it if the judgement was wrong. These checks are automatic and they are not always right, which is why the submission is held for review rather than discarded.

A submission that contains a password, a card number or similar sensitive details is never stored, in any form, and it is never held for review. It is discarded the moment it arrives, and the record we keep of it is the same short record described above, with none of what was typed.

Sharing and service providers

We share data only as needed to run the service and only with providers bound to protect it. These fall into a few categories:

  • Cloud hosting and database providers that store and serve the platform.
  • A payment provider that processes subscriptions and billing.
  • Communication providers used to send transactional email, power tracked calls, and power tracked chat for the channels you enable.
  • A location provider that turns a shortened network address into an approximate country, region, and city.
  • Speech to text and AI providers that produce transcripts and summaries for the recorded calls and chats you turn on.
  • Providers that help us measure performance and diagnose errors so the product stays reliable.

We may also share data to comply with the law, enforce our terms, or protect the rights and safety of our users and the public. If the business changes hands, data may transfer as part of that transaction, and this policy will continue to apply to it.

Data retention

We keep your account data for as long as your account is open. What happens when you close it is described under Your rights and choices below.

We keep the visitor and lead data your organization collects for as long as your organization uses Local Wrangler, so your reporting history stays intact. If a Service Scalers connection is removed, your lead and tracking history is preserved, not deleted.

Some data is short lived by design and is removed automatically by a clean-up that runs once a day. The times below are the longest any of it is kept:

  • The daily secret used to recognise a returning visit is deleted when it is more than 7 days old, and is never kept beyond 8 days. After that, the visit records it produced can no longer be traced back to a device.
  • Location lookups are kept for at most 31 days.
  • The temporary link between a visitor and a tracking phone number or a chat widget is deleted within 91 days of it expiring. The lead it produced keeps its own record of where it came from.
  • Search Console figures are kept for at most 8 days.
  • The list of who is on a site right now is cleared hourly instead, and an entry is never kept beyond about two hours.

We take a backup of the database every day so we can recover from a failure. A backup is a snapshot of everything at that moment, so data that has since been deleted can still exist inside one until that backup ages out. Backups are kept for a limited period and are used only to restore the service after a failure.

We keep records for longer where the law requires it, for example billing and tax records.

Security

We protect data with measures appropriate to its sensitivity, including encryption in transit, access controls scoped to each organization, hashed credentials, encryption at rest for the third-party keys you connect, and verification of the provider signature on webhooks that deliver calls, chats, and form submissions. The tracking snippet is public by nature, since it runs in your visitors' browsers, so submissions it sends are checked against the site they claim to come from and are rate limited rather than signed. No system is perfectly secure, but we work to reduce risk and respond quickly to issues.

Your rights and choices

If you have a Local Wrangler account. You can ask us to give you a copy of your personal data, correct it, or delete it. To do that, contact us using the details below. Depending on where you live you may also have the right to object to or restrict some processing, and to be told what we hold and why. We will not treat you differently for exercising any of these rights.

Closing your account. You can close your account from your account settings. When you do, we remove your name and email address, delete your profile picture, delete any invitations still waiting for you, and delete your sign-in. The picture is removed straight away, and any copy still held in the cache that serves images clears within an hour. A record that the account existed stays in place so that the work attached to it, such as which account recorded a lead, does not break. That record no longer contains your name or contact details.

You cannot close an account while you still own a company in Local Wrangler, because that company and the people in it depend on it. Contact us and we will hand it over or close it with you.

Closing your account does not delete your company's data. That data belongs to the company and other people may be relying on it.

If there is personal data of yours that closing your account does not reach, contact us and we will remove it.

If you are a visitor to a business that uses Local Wrangler. That business decides what happens to your data, so contact them first. Two things are in your own hands. You can clear what your browser stores for that site, which separates your future visits from your past ones; visits already recorded are not changed by it, and they stay linked to the value our servers calculate, which you cannot clear yourself. That value stops being traceable to a device after about a week, as described above. And if you turn on Global Privacy Control in your browser, we stop collecting advertising click identifiers and stop passing lead details to the site's advertising tools, automatically and with nothing for you to ask for.

International data

We may process and store data in countries other than where you live. When we do, we take steps to ensure it remains protected to a standard consistent with this policy and applicable law.

Children

Local Wrangler is a business tool and is not directed to children. We do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact us and we will remove it.

Changes to this policy

We may update this policy as the product and the law evolve. When we make material changes, we will update the date at the top and, where appropriate, notify you. Continuing to use Local Wrangler after a change means you accept the updated policy.

Contact

Questions about this policy or your data can be raised through your Local Wrangler dashboard or your account team. For contractual terms on how we process data on your behalf, ask us about a data processing agreement.

Privacy laws differ by country and by your role as a business. This page describes our practices and how the tracking behaves technically. It is not legal advice, and you remain responsible for your own privacy notice and the lawful basis for analytics on your site.