01
Who we are
Kimura Worldwide LLC is a Google and Meta ads agency based in
Orange County, California. In this policy, "we", "us" and "our"
mean Kimura Worldwide LLC. "You" means anyone who visits this
website.
This policy covers kimuraworldwide.com and the
pages, tools and forms on it. It does not cover the advertising
accounts we manage for clients, which are the client's own
property and are covered separately in
section 10.
02
What we collect
Three kinds of information, and they are worth keeping separate.
What you hand us on purpose
- Your name, email address, phone number, company name and website, when you fill in a form.
- Whatever you write in a message field.
- Your email address, if you subscribe to the Built Right newsletter.
- The figures you type into a calculator or diagnostic tool on this site, if you choose to send them with a request.
What your browser sends automatically
- Your IP address, which gives an approximate city, not a street.
- Your browser, operating system and screen size.
- The pages you opened, in what order, and how long you stayed.
- The page or ad that sent you here, including click identifiers such as Google's
gclid.
What our tools record, if you accept cookies
- Analytics events, such as a form being submitted.
- A replay of your session: cursor movement, clicks and scrolling. See section 3.
The same list, in the categories California uses
The lists above are how a person would describe this. California's
privacy law has its own category names, and a policy has to answer
in those too, so here is the same information mapped across.
Everything above goes to the companies named in
section 5 and nobody else.
What we never collect on this site: payment
card numbers, bank details, social security or government ID
numbers, health information, or precise GPS location. This site
takes no payments. If you become a client, billing is handled
elsewhere and we never see a full card number.
03
Cookies, analytics and session recording
Start with the part most policies leave out. We
use Microsoft Clarity, which records a replay of your visit:
where the cursor moved, what you clicked, how far you scrolled,
and the page as it appeared to you. We watch these to find the
places where the site is confusing. Clarity is configured to mask
text entered into form fields, and we do not use it to work out
who you are.
None of this loads until you accept cookies. On
a first visit the banner appears and nothing below runs until you
choose. Choose "Accept essential" and the only things that load
are the ones needed to serve the page.
What actually runs, once you accept
You can also clear or block cookies in your browser settings at
any time. Blocking them will not break this site, and nothing on
it is gated behind accepting them.
Do Not Track and Global Privacy Control
These are two different signals and we treat them differently, so
both are worth stating plainly.
-
Global Privacy Control is a legally recognised
opt-out signal. We honour it. If your browser
sends it, we treat that as you opting out of any sharing for
advertising, exactly as if you had emailed us.
-
Do Not Track is an older browser setting that
was never given an agreed meaning, and no common standard for
obeying it exists. We do not respond to it, and
California law requires us to say so rather than imply
otherwise. Use the cookie banner or Global Privacy Control
instead, both of which do work.
04
How we use it
- To answer you when you write in.
- To deliver the work, if you become a client.
- To send the Built Right newsletter, if you asked for it.
- To measure which ads and pages produce inquiries, so we stop paying for the ones that do not.
- To find and fix the parts of the site people get stuck on.
- To keep records, and to comply with the law when we have to.
We do not upload your email address or phone number to
Google or Meta as a customer list, and we do not build
advertising audiences out of the people who write to us.
Anonymous site visitors may be added to a remarketing audience
if you accepted advertising cookies. Someone who sends us a
message is not.
05
Who we share it with
Six companies, named. Each one gets only what it needs to do its
job, and none of them may use your information for their own
purposes.
Beyond those six, we will hand over information in only two
situations: when the law requires it, such as a subpoena or a
court order, and if the business is ever sold or merged, in which
case whoever buys it inherits this policy. We will not
hand your information to anyone else without asking you
first.
06
We do not sell your information
We have never sold personal information, we do not sell
it now, and we did not sell any in the last twelve months.
Nobody pays us for it.
Here is the caveat, because leaving it out would be the
convenient version. California law defines "sharing" broadly
enough that letting an advertising cookie load can count as
sharing personal information for cross-context behavioural
advertising, even when no money changes hands. We use Google Ads
cookies for exactly that purpose. So rather than argue about the
definition, we give you the switch:
- Choose Accept essential on the cookie banner and no advertising cookie loads.
- Or turn on Global Privacy Control in your browser. We treat that signal as a valid opt-out.
- Or email us and ask, using the address in section 17.
We do not knowingly sell or share the personal information of
anyone under sixteen.
07
Your California rights
If you live in California, the CCPA as amended by the CPRA gives
you these rights. You can use them whether or not you are a
client, and using them costs nothing.
- Know. Ask what personal information we hold about you, where we got it, why we have it and who we gave it to.
- Access. Get a copy of it.
- Delete. Tell us to delete it, subject to the records we are legally required to keep.
- Correct. Tell us to fix it if it is wrong.
- Opt out. Tell us to stop any sharing for advertising, as described in section 6.
- No retaliation. We will not deny you service, change your price or give you a worse version of anything because you exercised a right.
How to use them
Email [email protected]
with what you want. We will ask a question or two to confirm you
are who you say you are, which is a protection for you rather than
an obstacle. We respond within 45 days. If a
request is genuinely complicated we may take another 45, and if we
do, we will tell you before the first 45 are up rather than after.
An authorised agent may make a request for you. We will ask for
written proof that you authorised them.
We do not collect the categories California calls sensitive
personal information, so there is nothing here to limit.
Shine the Light
California's "Shine the Light" law lets you ask once a year which
personal information a business shared with other companies for
those companies' own direct marketing. Our answer is
none. We have never done it and we do not do it, so
there is no list to send you.
08
If you live in another US state
We work with businesses across the country, and a dozen states now
have privacy laws of their own. Rather than list each one and
argue about which applies to you, we do the simple thing:
Whatever state you live in, you get the rights in
section 7. Ask us for a copy
of what we hold, a correction or a deletion, and we will do it.
We are not going to check your address first.
That covers residents of Virginia, Colorado, Connecticut, Utah,
Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire,
New Jersey and anywhere else that passes a similar law after this
was written.
Nevada lets residents opt out of the sale of
certain personal information. We do not sell it, to anyone, so
there is nothing to opt out of. Email us anyway if you want that
confirmed in writing.
If your state gives you a right to appeal a decision we make about
a request, and you think we got one wrong, reply to our answer and
say so. A person will look at it again.
09
If you are in the UK or EU
We are a United States business and we do not market to, or offer
services in, the United Kingdom or the European Economic Area. If
you visit this site from either, your information is processed in
the United States.
If the UK GDPR or the EU GDPR applies to you, you have the right
to access, correct, delete, restrict or object to our use of your
information, and to receive a copy in a portable format. Write to
the address in section 17 and we will
handle the request the same way we handle a California one.
10
Client ad account data
This clause is about clients rather than visitors, and no standard
privacy policy covers it, so it is written out here.
When you hire us, you give us access to your Google Ads, Meta and
analytics accounts. We see the data in them, including
performance figures, spend, and any lead information your own
forms capture.
That data stays yours. We act on your
instructions with it and nothing else. We do not merge it into
our own marketing, we do not use one client's data to work on
another client's account, and we do not sell or publish it.
When an engagement ends, access is handed back or removed. If we
publish a case study we ask first, and the company is blinded
unless you tell us in writing that we may name you.
11
Email and text messages
If you subscribe to Built Right you get the newsletter, and every
issue carries an unsubscribe link that works immediately. If you
send us an inquiry you get a reply, and you are not added to the
newsletter for having written in.
We do not send marketing text messages from this website. If you
become a client and we agree to use text for account
communication, that is set up separately and you can stop it by
replying STOP.
12
How long we keep it
The seven years on client records is how long tax and contract
records have to be kept. Ask us to delete something sooner and we
will, apart from anything we are required by law to hold on to.
13
How we protect it
The site runs over an encrypted connection. Access to the systems
holding your information is limited to the people who need it,
and every account that can reach client data uses two-factor
authentication.
No website can promise perfect security and we are not
going to. If a breach ever affects your information we
will tell you and the relevant authorities within the time the
law allows, rather than waiting to see whether anyone notices.
14
Children
This site is for businesses and is not directed at children. We
do not knowingly collect personal information from anyone under
sixteen. If you believe a child has given us information, write to
us and we will delete it.
15
Links to other sites
We link out to other websites, including Google's and Microsoft's
privacy controls in section 3. Once you
follow a link you are on someone else's site under someone else's
policy, and this one no longer applies.
16
Changes to this policy
When we change this policy we change the "last updated" date at
the top of the page. If a change is significant, such as adding a
tool that collects something new, we will say so on the site
rather than quietly updating the date.
17
How to reach us
Questions about this policy, or any request under
section 7 or
section 9, go to one place:
A real person reads that inbox and you will get a real reply.
Effective 4 September 2026. Last updated 4 September 2026.
This policy replaces all previous versions.