Public Website Privacy
Website Measurement & Analytics Choices
This supplement explains the deliberately limited measurement design for the public Yampa Basin Services Group website. It does not expand the collection or permitted use of customer service-request information.
Optional Google Analytics
Google Analytics is optional. The Google script is not requested and no Google Analytics measurement is sent until a visitor affirmatively chooses Allow optional analytics. Choosing to continue without analytics does not restrict the website or its public request paths.
If allowed, the site sends the canonical site origin plus an approved public pathname. When the separately controlled campaign feature is enabled, it may also send the exact pre-registered campaign labels described below. Raw browser URLs, query strings, fragments, and uncontrolled referrers are removed. The implementation does not send form entries, names, phone numbers, email addresses, VINs, property addresses, request descriptions, uploaded-file information, customer or company identifiers, internal Operations routes, advertising click IDs, or a user ID.
Google may process ordinary technical information associated with the permitted page-view request, such as browser or device details, timestamp, network information, and approximate location. Google Analytics may set first-party _ga cookies only after permission is granted. Advertising storage, advertising user data, advertising personalization, Google Signals, and targeted advertising are disabled by this implementation.
The site stores only the fixed choice granted or denied under a versioned preference key in the visitor's browser. After a choice, the persistent Analytics choices button can reopen the panel. Continuing without analytics withdraws permission, disables later measurement, and asks the browser to expire first-party Google Analytics cookies that this site can remove.
Limited Campaign Attribution
A public campaign link may contain a code-owned, pre-registered source, medium, campaign, and placement code. The site considers those codes only after the visitor makes the same affirmative optional-analytics choice, the separate campaign-attribution setting is enabled, the browser is not marked as staff or test traffic, and the landing page is an exact canonical public route. It then keeps only an exact approved combination for the current browser tab. It discards unknown or duplicated values, search terms, advertising click IDs, full landing URLs, full referrer URLs, and arbitrary query parameters. An approved external referrer is reduced to its origin, such as https://www.google.com, without a path or query.
Campaign attribution is not a visitor profile. After permission, the exact registered source, medium, campaign, and placement codes may be sent to Google Analytics as standard campaign labels on an explicit public-page-view event so that event can be grouped by the outreach registration it carries. Arbitrary query values, landing paths, advertising click identifiers, and full referrers are not used as campaign labels. The same limited record may also leave the browser as part of a customer-submitted request through an approved direct intake path. It is not added to a prepared email fallback. If browser session storage is unavailable, the service-request path continues without attribution.
Release & Test Controls
Analytics is fail-closed: it requires a valid production measurement identifier, an explicit analytics setting, the production hosting context, and the visitor's permission. Campaign attribution additionally requires its own explicit enablement setting. Both remain absent on local builds, automated tests, deploy previews, branch previews, protected Operations routes, APIs, and the release-hold route. Staff and controlled-test browsers can also be excluded locally so internal visits do not become customer-performance evidence.
Google Analytics Enhanced Measurement, Google Signals, advertising personalization, and any advertising link must remain off until a separate reviewed release changes this contract. The production data-retention setting must be recorded and reviewed before analytics is enabled. No measurement result should be treated as proof that a request was received, qualified, accepted, completed, or paid.
Provider Information
Review Google's own data practices in the Google Privacy Policy. Questions about this site's measurement design can use the contact method listed in the main privacy notice without including sensitive service-request information.