Security and compliance FAQ
Security and compliance FAQ
This FAQ covers common security, privacy, and compliance questions for Pipeline On.
It is general product guidance, not legal advice. Ask your legal, privacy, or web team how these rules apply to your business and location.
What does Pipeline On do?
Pipeline On adds an ID tag to your website so eligible visits can be measured and, where available, recovered into homeowner lead profiles.
Recovered profiles can include contact, address, page journey, source, property, and follow-up delivery details depending on what is available.
Do we need a privacy policy update?
Usually, yes.
Your privacy policy should explain that your website uses cookies, pixels, scripts, and similar technologies for analytics, advertising measurement, visitor identification, attribution, and follow-up marketing.
See Update your privacy policy for Pipeline On.
Do we need a cookie banner?
It depends on your visitors, location, business, legal obligations, and how your website already handles consent.
Some websites can run tracking under existing disclosures and opt-out links. Others should use a consent banner or privacy choices flow before non-essential tracking runs.
See Do you need a cookie banner for Pipeline On?.
Can a cookie banner reduce recovered leads?
Yes.
If your banner blocks Pipeline On until the visitor accepts tracking, fewer visitors will be eligible for recovery. That can be the right compliance tradeoff, but it will reduce volume.
See Why your cookie banner can reduce recovered leads.
What opt-out language should we use?
Use language that matches your actual site, business, location, and privacy program.
Many U.S. businesses use a footer or privacy link such as:
- Do Not Sell or Share My Personal Information.
- Your Privacy Choices.
- Privacy Choices.
See Example privacy and cookie wording for Pipeline On.
Does Pipeline On honor service-area and account limits?
Pipeline On supports service-area settings so recovered leads can be filtered and follow-up can avoid obvious out-of-area noise.
Free audits also have domain rules. A free audit is limited to one domain per account, and the same domain cannot be reused across different free-audit accounts.
These limits protect the product from abuse and keep audit data tied to the correct business.
Who can see recovered leads?
Pipeline On account access is scoped to the organization and sites connected to that account.
Your team should only invite users who need access to recovered lead information.
Support may access account information when needed to troubleshoot, maintain the service, or respond to a support request.
What data can appear in a lead?
A recovered lead can include:
- Name.
- Email.
- Phone, when available.
- Address and location fields.
- Website domain.
- Source page and referrer.
- First seen and recovered timestamps.
- Page journey.
- Property links and property facts, when available.
- Follow-up delivery status.
Some fields can be blank. Phone is optional.
What data goes to Zapier?
When Zapier is enabled, Pipeline On sends a versioned lead payload to your saved Zapier Catch Hook URL.
The payload can include name, email, phone when available, address fields, site details, source URL, source path, referrer, first seen time, and recovered time.
Make sure the destination CRM or workflow is appropriate for this type of recovered lead data.
Should every recovered lead go straight into the CRM?
Not always.
For many teams, the best setup is:
- Hot leads go to the main CRM workflow.
- Lower-confidence or incomplete leads go to a review queue.
- Missing-phone leads are handled without breaking the Zap.
- Out-of-area leads are filtered or archived.
- Source page and Pipeline On source are saved in notes.
This keeps recovered visitor data useful without overwhelming the office.
How should we handle deletion or opt-out requests?
If a visitor or customer sends a privacy, deletion, suppression, or opt-out request that involves Pipeline On data, contact support with the relevant email, phone, or address details.
Do not put sensitive personal details in screenshots or public tickets when a support message with the necessary identifiers is enough.
Does Pipeline On replace legal compliance tools?
No.
Pipeline On does not replace:
- Your privacy policy.
- Your cookie banner or consent manager.
- Your legal review.
- Your CRM data governance.
- Your email or SMS compliance process.
- Your internal access controls.
Pipeline On is one part of your website and follow-up stack.
What should we check before launch?
Before using recovered leads, confirm:
- The ID tag is installed on the live website.
- The privacy policy has appropriate tracking and follow-up language.
- Cookie banner or consent behavior matches your policy.
- Opt-out or privacy choice links are present where required.
- Your team understands which recovered leads should be contacted.
- Zapier or CRM routing is tested with blank optional fields.
- Service area and high-intent settings are configured.
- Only appropriate users have account access.
If you are not sure whether your setup is compliant, ask your legal or privacy adviser before turning on automated follow-up.