Privacy policy
Last updated:
Before you run ads: replace every [BUSINESS NAME], [ADDRESS] and [SUPPORT EMAIL] below with your real details. Meta rejects ads whose landing page has no working privacy policy and contact route, and this page is otherwise complete.
This policy explains what [BUSINESS NAME] ("we", "us") collects when you visit this site or buy the Camera Confident course, why we collect it, and what you can ask us to do with it.
Who we are
[BUSINESS NAME], [ADDRESS]. Questions about this policy or your data: [SUPPORT EMAIL].
What we collect
- Your email address, when you buy the course or ask for a new access link. We need it to deliver the course and to send your receipt.
- Payment details are entered directly into Stripe's payment form and are never sent to or stored on our servers. We receive only the outcome of the payment, the amount, and the last four digits and brand of the card.
- Marketing attribution — if you arrived from an ad, the campaign parameters in the link (utm_source, utm_medium, utm_campaign, utm_content, utm_term and Meta's fbclid) are attached to your order so we know which ad brought you.
- Course progress — which lessons you have completed is stored in your own browser (localStorage) on the device you study on. It is not sent to us.
- Standard server logs kept by our host, Cloudflare, including IP address, for security and abuse prevention.
What we don't collect
We do not ask for your name, address, phone number or date of birth. We do not collect card numbers. We do not sell or rent your data to anyone, ever.
Why we're allowed to use it
- To perform our contract with you — delivering the course you paid for, and supporting it.
- Our legitimate interests — keeping the site secure, preventing fraud, and understanding which ads work.
- Legal obligation — keeping transaction records for tax and accounting.
- Your consent — where required, for advertising cookies and any marketing email beyond your purchase.
Who else processes your data
- Stripe — payment processing. stripe.com/privacy
- Resend — sending your access and receipt emails. resend.com/legal/privacy-policy
- Cloudflare — hosting, and the storage that holds your order record. cloudflare.com/privacypolicy
- Meta — if the Meta Pixel is active on this site, it reports page views and purchases back to Meta for ad measurement. facebook.com/privacy/policy
Each of these is a processor acting on our instructions, except Meta and Stripe, which are also independent controllers of the data they collect.
Cookies
We set one cookie of our own: a signed sign-in cookie that keeps the course open after you follow your access link. It is strictly necessary — without it you would have to click your email link on every page. Stripe sets its own cookies inside its payment form for fraud prevention. If the Meta Pixel is enabled it sets advertising cookies.
How long we keep it
Order records — your email, the payment reference and the amount — are kept for as long as you have access to the course, and for at least the period our tax obligations require. Rate-limiting records expire within minutes. You can ask us to delete your data at any time, though deleting your order record ends your access to the course.
Your rights
Depending on where you live you can ask us to give you a copy of your data, correct it, delete it, restrict how we use it, or object to that use. Email [SUPPORT EMAIL] and we will respond within 30 days. If you are in the UK or EU and you are not satisfied, you can complain to your national data protection authority.
Children
This course is sold to adults. We do not knowingly collect data from anyone under 16.
Changes
If we change this policy we update the date at the top. Material changes are emailed to anyone who has bought the course.