Legal
Privacy Policy
What we collect when you visit this site, request a simulation or receive a report, why we collect it, who processes it for us, and how to make us delete it.
Last updated 10 October 2026
1. Who we are and what this covers
Robles Consulting LLC (“Robles Consulting”, “RC”, “we”, “us”) is an IT consulting firm registered in Texas, United States. We run Visitor Simulator and this site, which you can reach at simulator.rc-frame.work and at sim.roblesconsultingllc.com.
For the purposes of the EU and UK General Data Protection Regulation, we are the data controller for the personal data described in this policy. Our contact details are:
Robles Consulting LLC100 Plaza Pl, Ste 300, PMB 58
Northlake, TX 76226
USA
privacy@roblesconsultingllc.com
This policy covers the pages of this site, the request form, the emails we exchange about your request, and the simulations we run and the reports we send you. The staff panel at sim.rc-frame.work is for RC staff only.
2. What we collect
When you visit this site
- Request data. Cloudflare, which serves this site, processes request data, including your IP address and browser details, to deliver pages and protect against attacks.
- Google Analytics. It sets cookies only if you accept analytics, and it stops completely if you reject them. If you are in the European Economic Area, the UK or Switzerland, it does not load at all until you accept. Elsewhere, until you choose, it counts visits without cookies. See section 9 and our Cookie Policy.
This site has no third-party fonts, no social media widgets and no advertising pixels. Its one form is the request form.
When you request a simulation
- Your name, your email address and, if you give it, your business name.
- The website address you want tested, and what you choose: the goals, the number of visitors, the devices and any extras.
- What you write: your own goals, a description of your typical visitors and any notes.
- The estimated price the form showed you, when you sent the request, and which of this site's two addresses you used.
- To stop the form being abused, a one-way keyed hash of your IP address. We do not store the IP address itself.
Our team receives an email with your request, so we can reply to you.
When you type your website's address
To show you a preview and check that the site can be reached, our server fetches the home page at that address, once when you type it and once when you send the request. We keep only a short note of what we found with your request, such as whether the site answered and whether bot protection stopped us. The preview's pictures, such as the site's icon, load in your browser straight from that website, without telling it which page you came from.
When we run a simulation for you
Simulated visitors browse the website you named, the way any visitor would. We record the pages they reached, what they did on each one, screenshots of those pages and the report. Screenshots show whatever the website shows to the public, which can include personal data the website itself publishes, such as staff names. When a simulated visitor tries a form, it uses made-up details, and the form is never actually sent.
AI models play the visitors and write the report, so the content and screenshots of the tested pages are processed by them. The models run on Cloudflare Workers AI by default; for some runs we may use another AI provider, and the page content is then sent to that provider. Your name, email address, business name and notes are never sent to an AI model. The description of your typical visitors is, because it shapes the visitors.
When you contact us
If you email us or reply to one of our emails, we keep the correspondence for as long as we need it to deal with the matter.
What we never collect here
We do not ask for special-category data (such as health, biometric, political or religious information). We do not buy personal data from data brokers, and we do not build advertising profiles.
3. Why we use it, and our legal basis
Where the GDPR applies, we rely on the following bases. Where it does not, we still limit ourselves to these purposes.
| Purpose | Data used | Legal basis |
|---|---|---|
| Deliver this site and keep it secure | Request data, including IP address | Legitimate interests in running a secure, working site |
| Estimate visits in total before you make a cookie choice, outside the EEA, the UK and Switzerland | Cookieless Google Analytics measurements | Legitimate interests in understanding how the site is used |
| Understand returning visits and which pages are useful | Google Analytics events and cookies | Your consent, which you can withdraw at any time |
| Reply to your request, confirm the price and run the simulation you ask for | Your request and contact details | Steps you ask us to take before a contract, and performance of that contract |
| Stop bots and floods from using the request form | Hashed IP address, the time the form was opened and sent | Legitimate interests in the security of our systems |
| Meet legal, tax and accounting obligations | Billing records and correspondence about the service | Compliance with a legal obligation |
We do not make automated decisions about you that have legal or similarly significant effects. We do not use your data to train AI models. We send marketing email only if you ask for it; replies about your request are not marketing.
4. Who we share it with
We do not sell your personal data, and we do not share it for cross-context behavioural advertising. A small number of service providers process data on our instructions, under contract:
| Provider | What it does | What it sees |
|---|---|---|
| Cloudflare | Hosting, security, the database and storage behind requests, simulations and reports, email sending, and the AI models that run on Workers AI | Request data including IP address; your request and contact details; the tested pages, screenshots and reports |
| Website analytics (Google Analytics 4), with cookies only if you accept; outside the EEA, the UK and Switzerland, cookieless until you choose | Page views, IP address and browser details and, with your consent, a randomly generated visitor identifier | |
| Other AI providers | Only when we choose one instead of Workers AI for a run: playing the visitors and writing the report | The content and screenshots of the tested website's pages, and the description of your typical visitors |
Beyond these providers, we disclose personal data only where the law requires it (for example, a valid legal request), where we need to establish or defend a legal claim, or as part of a merger or sale of the business. If a sale means your data would become subject to a different policy, we will tell you before that happens.
5. International transfers
We are established in the United States, and most of the providers above are based in the US. If you are in the European Economic Area, the United Kingdom or Switzerland, your personal data is transferred outside your home jurisdiction when you use this site.
For these transfers, our agreements with providers include the European Commission’s Standard Contractual Clauses, with the UK International Data Transfer Addendum where it applies. Where a provider is certified under the EU-US Data Privacy Framework, we may rely on that instead. You can ask us which safeguards apply to a specific provider.
6. How long we keep it
- Requests: deleted automatically two years after we receive them. Requests we mark as spam are deleted after 30 days.
- Simulations and reports, including screenshots: deleted automatically 90 days after the simulation. A report link stops working when the report is deleted, when the link expires or when we withdraw it.
- Billing records: as long as tax and accounting law requires.
- Correspondence: we review and remove what we no longer need within 24 months of our last contact with you.
- Google Analytics data: up to 14 months. After that, Google keeps only aggregated reports.
- Your cookie choice: stored in your own browser and never sent to us. We ask again after 12 months.
You can ask us to delete your data sooner (see below). We will do so unless the law requires us to keep it.
7. Your rights
If the EU or UK GDPR applies to you, you have the right to:
- know what we hold about you and get a copy of it;
- have inaccurate data corrected;
- have your data deleted;
- restrict how we use it;
- object to processing that we base on legitimate interests;
- receive your data in a portable format;
- withdraw consent at any time. Withdrawing is as easy as giving consent: use Cookie settings in the footer of any page.
To use any of these rights, email privacy@roblesconsultingllc.com. We will respond within one month. We may ask you to confirm your identity before we act, and we do not charge for a reasonable request.
If you are unhappy with how we have handled your data, you can complain to your data protection authority: in the EU, the supervisory authority where you live or work; in the UK, the Information Commissioner’s Office. We would appreciate the chance to put it right first.
8. US state privacy rights
If you live in California, Colorado, Connecticut, Texas, Virginia or another state with a comprehensive privacy law, you may have the right to know what personal information we have collected about you, to have it corrected or deleted, to receive a copy of it, and not to be discriminated against for using those rights.
We do not sell personal information, and we do not share it for cross-context behavioural advertising or targeted advertising. There is nothing to opt out of on that front, but we honour Global Privacy Control signals anyway.
To make a request, email privacy@roblesconsultingllc.com. You may use an authorised agent; we will ask for proof that they are authorised.
9. Cookies and analytics
Google Analytics sets cookies only if you accept analytics. If you are in the European Economic Area, the UK or Switzerland, it does not load at all until you accept. Elsewhere, until you choose, it runs with its cookies switched off and sends cookieless measurements that Google uses to estimate total visits. If you accept, it also sets cookies holding a randomly generated identifier.
The page address Google receives keeps only utm_ campaign tags from the query string, and the referring address is cut down to the referring site’s name. Google receives your IP address and browser details with each request and uses them to estimate your approximate location; Google Analytics 4 does not store IP addresses. Advertising features, Google signals and ad personalisation are switched off. Rejecting analytics stops Google Analytics completely.
If your browser sends a Global Privacy Control signal, we treat it as a refusal and do not ask, unless you opt in yourself. Report links never run analytics. Our Cookie Policy lists every cookie and storage entry and lets you change your choice.
10. Security
This site is served over HTTPS with a strict content security policy. Requests, simulations and reports are visible only to RC staff, who sign in through Cloudflare Access. Report links are long random addresses that can expire and can be withdrawn at any time, and search engines are told not to index them.
No system is perfect. If you think you have found a security issue, please email privacy@roblesconsultingllc.com and we will look at it promptly. If a breach affects your personal data and puts you at risk, we will notify you and the relevant regulator as the law requires.
11. Children
This site is for businesses and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you think a child has sent us personal data, contact us and we will delete it.
12. Changes to this policy
If we change how we handle personal data, we will update this page and the “last updated” date above. If a change materially affects you, we will tell you directly as well. If a change needs your consent, we will ask for it again rather than assume it.
Contact
Have a question about this policy, or want us to delete what we hold about you? Email privacy@roblesconsultingllc.com and we will reply within one month, usually much sooner.