Privacy notice
What this site does with what it can see
Version 2026-08-10 · in effect from 10 August 2026
Two things on this site touch your data: optional analytics, which is off until you accept it, and the early-access form on the landing page, which is closed. Everything else — the maps, both workspaces, every figure — runs without recording anything about you at all.
The short version
Analytics is optional, off until you accept, and counts page addresses — nothing you type, upload, open or configure.
Refusing costs nothing. Every page, both workspaces and every figure work exactly the same either way, and nothing on this site is behind the choice.
Whichever you choose, the answer lasts six months (182 days) and then you are asked again. So do the analytics cookies, if you accepted.
Who is responsible
- Controller
- Federico Berti
- Address
- Via Ponte Pietra 4, 37121 Verona, Italia
- Privacy contact
- federicberti@gmail.com
An individual, not a company. There is no VAT number, business registration, data protection officer or representative to name, because none exists.
Before you accept analytics
This is also what is true after you refuse, after you withdraw, and on any visit where the stored choice cannot be read. Each line describes the document your browser actually receives, and each one is checked on every build.
- No Google script is loaded, and the page's HTML contains no Google address and no inline analytics snippet to load one from.
- No connection of any kind is made to Google. Not a page view, not an event, not a consent signal, not an empty request that would confirm a visit.
- No analytics cookie exists, because the only thing that creates one has not run.
- No identifier is generated, stored or derived — there is nothing to link one visit to another.
After you accept analytics
- The Google tag is fetched
- from googletagmanager.com, once, and configured for a single Google Analytics property (G-HMZLWLJF4H). Fetching it tells Google your browser asked for a file, which necessarily includes your network address — that is how any request on the internet works, and it is the first thing consent is actually about.
- One page view is sent for the page you are on
- and one more each time you move to a different page. Opening a panel, moving a slider, changing a filter or switching a workspace's mode is not a page view and sends nothing.
- A page view carries the address, a title and where you came from
- and each of the three has its query string and its # fragment cut off before it is assembled. What travels is exportexportexport.com plus a path — /scenario-lab, never /scenario-lab followed by the code, the costs and the markets you were looking at.
- Google records what any web service records in the act of being contacted
- your network address, your browser's own description of itself, an approximate location derived from the address, and the cookies below. Google states that for visitors in the EU, Switzerland and the UK it collects through servers in those regions and discards the address after deriving a coarse location rather than logging it.
- Advertising is switched off in the configuration, not merely unused
- Google signals, advertising personalisation and advertising identifiers are all explicitly disabled by this site's own tag settings, and Google is additionally told to restrict how it processes what it receives.
What never travels, accepted or not
This list is long because it is specific. Most of it lives in the address bar of a shared workspace link, which is exactly why the query string and the # fragment are cut off before an address is ever assembled.
- Company names, and anything typed into the product
- SKUs, costs, prices, margins and profit figures
- Notes, questionnaire answers and assessment responses
- Product Shape attributes, scenario values and Decision Set contents
- Selected markets, shortlists and comparisons
- Customs codes under examination
- Search text and anything typed into a field
- Query strings and # fragments, from any address, ever
- Email addresses, and anything from the early-access form
- Session identifiers, user identifiers and any identifier this site could set
Cookies, once it has run
_ga- distinguishes one browser from another, which is what makes a count a count — six months (182 days), configured — not the two-year default.
_ga_<property>- keeps the state of a single visit, so a sequence of pages is one visit and not five — six months (182 days), configured — not the two-year default.
How your choice is remembered
Your answer is kept in local storage in your own browser, under a single key. It holds four things and nothing else — no identifier, no history, nothing that could be used to recognise you.
- Whether you accepted or refused
- the choice itself, as one of two words
- When you chose
- so it is possible to say what was in force at any moment
- Which version of this notice you were shown
- so a material change to it means you are asked again rather than assumed to agree
- The record's own format version (currently 1)
- so a record this site can no longer read is treated as no choice at all, not as a yes
Nothing records when the choice runs out. It is worked out from the timestamp each time the record is read — six months (182 days) after you chose — so there is no expiry date sitting in the browser that a later visit could push forward.
A cookie would be sent to this site's server on every request, so remembering the choice in one would mean transmitting it repeatedly in order to record that you asked for less. Local storage stays where it is.
It is specific to one browser on one device. There is no account, so a choice made on a laptop is not known to a phone — and inventing a way to link them would be the opposite of what the choice is for.
Clearing your browser's site data removes it, and you are asked again on the next visit.
On what basis, and how to stop it
Basis: your consent. Nothing loads until you press Accept. The two actions are the same size and the same colour, neither is preselected, and refusing is a single press that is remembered. You can change your mind at any time through Privacy choices, in the footer of every page.
Withdrawing does all of this, immediately:
- The tag is told immediately to stop storing anything, and it stops: no analytics cookie is written again.
- The analytics cookies this page can reach are deleted.
- The stored choice becomes a refusal, so the next visit loads nothing at all.
- The page then reloads. That is deliberate and it is the part that finishes the job: a script cannot be removed from a page once it is in it, so the page is replaced. Without the reload the tag stays present and keeps answering its own automatic events with a request to Google — one that carries no cookie and says consent was denied, but a request all the same.
- What was already sent while you had accepted cannot be recalled from this browser — it is with Google, and removing it there is a request to the controller, who can ask Google to delete it.
Who receives it, for how long, and where it goes
Google Ireland Limited — Google Analytics 4, acting as processor. Google's own data processing terms state that Google is a processor of the personal data a customer sends through these services. It acts on the controller's instructions; it is not a second controller deciding for itself what to do with your visit. No other recipient. Nothing is sold, and nothing is shared with anyone else.
How long
- Your choice is kept for six months (182 days) from the moment you make it, and then it lapses: analytics goes off and you are asked again. Visiting in the meantime does not extend it — the clock runs from the decision, not from your last visit. You are also asked again, straight away, whenever this notice changes materially.
- The two analytics cookies are configured to last six months (182 days) at most — 15,724,800 seconds, rather than the two years Google would otherwise use — and are set not to renew themselves on each visit. Refusing, withdrawing, or letting the six months lapse deletes the ones this site can reach, immediately.
- Google is set to keep event-level data for two months, the shortest period it offers. Google documents that this setting governs explorations and funnel reports, and that it does not apply to the standard aggregated reports, whose totals remain available afterwards.
Two months is the controller's decision and it is recorded as such. It is a setting inside Google's own interface that no code in this site can read back, so this notice states what was chosen rather than asserting it is already in force; the outstanding list below says which of the two it is today.
Where
Google states that data from visitors in the EU, Switzerland and the UK is collected through domains and servers in those regions, and that the network address is used to derive an approximate location and then discarded rather than logged. Processing after that point can involve Google infrastructure outside the EEA, including in the United States.
Google's published processor terms provide for the European Commission's Standard Contractual Clauses where no other transfer solution applies, and rely on the EU–US Data Privacy Framework for transfers to certified Google entities in the United States.
That is a description of what Google publishes, not an assurance about it. This site's controller is not in a position to audit Google's infrastructure, and does not claim to have.
Where these statements come from
Everything above about Google’s own behaviour is taken from Google’s current published documentation, listed here so it can be checked rather than taken on trust.
- Google Analytics 4 cookie usage
- gtag.js configuration reference
- Tag platform: manage privacy settings
- Google Ads Data Processing Terms
- Google Analytics data retention
- EU, Switzerland or UK-focused data and privacy in Google Analytics
- How Google Analytics safeguards data
- How Google uses information from sites or apps that use its services
The early-access form is closed, and collects nothing
The early-access list has not opened. The form is not rendered on the landing page, the server refuses submissions, and no request can be recorded — including by anyone who tries to reach the endpoint directly. What follows describes what will happen when it does open.
What the form collects
Everything in this list comes from the form itself — there is no hidden field beyond the three described at the end of it, and nothing is gathered from anywhere else.
- Email addressrequired
- the only way to reply to the request, and the identifier that keeps a repeat submission from becoming a second record
- First namerequired
- so a reply can address you rather than your inbox
- Companyoptional
- context for the request
- Roleoptional
- who is in the room when an export decision is made — chosen from 6 options
- Product categoryrequired
- whether the pilot can say anything useful about your product — chosen from 18 options
- The export decision you are trying to makerequired
- free text, up to 600 characters, used to understand what the product is being asked for
- When you agreed to this notice, and which version of itrequired
- so it is possible to say what you actually agreed to
- Whether you separately opted in to product updatesoptional
- recorded only if you tick it; it is a separate box and never a condition of joining
- The page you submitted from, the referring website's hostname, and campaign tags if the link carried themoptional
- to tell where interest is coming from
What the form deliberately does not collect
These are design decisions, not omissions, and each one is enforced in the code rather than promised in prose.
- No IP address — not stored whole, not stored truncated, not stored hashed. The waitlist table has no column for one.
- No device or browser fingerprint, and no bot-detection or advertising script, at any time, whatever anyone has consented to.
- No telephone number, revenue figure, headcount, or any special-category data.
- The referring page's path is discarded; only its hostname is kept.
- Nothing from this form ever reaches the analytics described above — the two are separate systems that never see each other's data.
To stop one script filling the database, the server counts recent submissions in memory for 10 minutes, keyed by a value derived from the network address and a random secret that changes every time the server restarts. It cannot be turned back into an address, cannot be matched against one, and is never written to the database or a log — nothing about it is stored.
Why the form’s answers are handled, and on what basis
Purpose. To decide who is invited into a limited pilot, in what order, and to reply to the request. It is not used to profile anyone, is not combined with data from anywhere else, is not sold, and is not shared with anyone beyond the two providers named below.
Basis: your consent. You are asked for it in a ticked box that is not pre-ticked, it is recorded with the moment you gave it and the version of this notice you were shown, and you can withdraw it at any time.
Agreeing to have your request handled is separate from agreeing to product updates. The second box is optional, unticked, and joining the list never depends on it.
How long a request is kept
24 months from the date of the request — long enough to run a pilot and invite people from the queue in order, short enough that a request nobody acted on does not sit in a database indefinitely. That is a decision, not a legal requirement, and it is stated as one. Erasure happens sooner if you ask for it — there is no waiting period.
A request moves through a small number of states, and never more than one at a time: waiting, invited, activated, declined, withdrawn. Every request starts at waiting.
Who else is involved
- Supabase — hosts the database the request is stored in.
- Vercel — hosts and serves this website, and handles the request in transit.
Nobody else receives what the form would collect. Where the database physically sits, and therefore whether that data would leave the European Economic Area, is listed below as still to be established — the list is closed, so nothing is waiting on the answer.
The early-access list additionally requires its own configured mailbox before it may open. It has none, which is one of the four independent reasons the form is not rendered and the server refuses every submission.
What you can ask for
- See it
- ask for a copy of what is held about you
- Correct it
- ask for anything inaccurate to be changed
- Delete it
- ask for the record to be removed; it will be
- Withdraw consent
- at any time, without giving a reason
- Object or restrict
- ask that it stop being used while a question about it is resolved
- Take it with you
- ask for it in a machine-readable form
Write to federicberti@gmail.com. For anything held by Google under an analytics consent, the same address is the route: the request is passed on as an instruction to delete it.
If the answer is unsatisfactory. You can complain to a supervisory authority. The controller is established in Italy, so that is the Garante per la protezione dei dati personali; if you live elsewhere in the European Economic Area you may also complain to your own, and you do not need this notice’s permission to do it.
What this notice cannot yet tell you
These are stated openly rather than filled in with plausible text. Each one names the single thing that would settle it.
- Whether the two-month setting is switched on inside Google, today
- somebody opening the property's own administration screen and looking. Two months is decided and is stated above as the decision; nothing in this site's code can read the setting back, so until it has been seen on screen this notice distinguishes the choice from the fact. The same applies to the advertising and enhanced-measurement switches that the tag's own configuration already disables from this side.
- Whether the analytics cookies still expire on time months from now
- time, and another look. On the deployed site both cookies were observed expiring in exactly 182 days, marked Secure, and the expiry did not move across six page views — so the six months and the instruction not to renew are doing what this notice says. What has not been watched yet is the same cookie across separate visits on separate days, which is the case a renewal would show up in, so the claim is stated as configured and observed rather than as proven over a lifetime.
- Where the early-access database will physically sit
- the Supabase project's region, which is chosen when the project is created. Stated here once it is known, because it determines whether data leaves the EEA. The list is closed until then, so nothing is waiting on the answer.