Legal

Privacy Policy

Last updated: February 2026

This is the privacy policy for Courtney Johnson ("we," "us," "our"). It covers what personal data we collect, why, and what happens with it.

Contact us:



, ,

What We Collect

When You Create an Account or Purchase

  • Name, email address, phone number
  • Billing address (street, city, state, postcode, country)
  • Payment method, tokenized by Stripe or PayPal. We never see or store your card number.

When You Visit Any Page

Our analytics system automatically records:

  • IP address and country (derived from a local geolocation database, no data leaves our servers)
  • Device type, browser, and user agent
  • Page URL and referrer domain
  • UTM parameters (source, medium, campaign, term, content)
  • Ad click identifiers (fbclid, gclid)
  • A device fingerprint: a SHA-256 hash combining your browser's characteristics with your HTTP request headers. This provides core site functionality (like deadline timers and session continuity) and helps measure marketing performance. It isn't a cookie and isn't shared with third parties.
  • Bot and threat detection signals (user agent pattern matching, threat score)

When You Submit a Form

  • Email address

When You Purchase, Accept an Upsell, or Request a Refund

  • Order ID, amount, currency, and products involved

Device Fingerprinting and Profile Merging

We run a custom analytics system that records pageviews, optins, purchases, upsells, and refunds.

Fingerprinting: We create a unique hash from your browser's characteristics (screen size, installed fonts, language) and your HTTP request headers, producing a single SHA-256 hash. This fingerprint provides core site functionality like deadline timers and consistent session continuity across visits. It also protects the business from bot traffic and helps measure which marketing channels drive sales. Fingerprint data is not shared with third parties.

Profile merging: When you provide your email through an optin form or at checkout, we link all anonymous visitor records associated with that email into one profile. This connects your browsing history across devices and browsers so we can attribute your purchase to the right marketing source.

Opting out of fingerprinting: Fingerprinting doesn't use cookies and can't be disabled through browser cookie settings. You can object to fingerprint-based processing by contacting us at . If you object, we'll stop using your fingerprint for analytics, though anonymized data already collected is retained. Your other rights (access, erasure, portability) apply to fingerprint data.

Cookies

  • visitor_id — First-party, 7 days. Visitor identification (UUID) for analytics.
  • attribution — First-party, 7 days. UTM parameters, referrer, and landing URL for marketing attribution.
  • _fbp, _fbc — Third-party, varies. Meta/Facebook conversion tracking.
  • Clarity cookies — Third-party, varies. Session recording and heatmaps.
  • Stripe/PayPal cookies — Third-party, varies. Payment processing and fraud prevention.
  • WordPress session — First-party, session. Logged-in user session.

We ask for your consent before setting analytics or advertising cookies. You can change your preferences at any time through the cookie settings link in our website footer.

For details on managing cookies, see our Cookie Policy.

Third-Party Processors

We share data with these services to run our business:

  • Stripe — Payment tokens, billing info, email. Payment processing.
  • PayPal — Billing info, amounts, email. Payment processing.
  • Postmark (Wildbit) — Email addresses, email content. Email delivery (order confirmations, login codes, marketing newsletters).
  • Amazon Web Services (S3) — Uploaded media files. File storage.
  • Microsoft Clarity — Session recordings, clicks, scrolls, device info. Heatmaps and behavior analytics.
  • Meta/Facebook — Names, email, phone, address, purchase amounts, visitor ID, click IDs, country (all PII hashed with SHA-256 before transmission). Conversion tracking and ad optimization via Meta Conversions API (server-to-server). Meta processes this data as an independent controller under its own Privacy Policy.
  • Hetzner — Site and customer data as needed. Server hosting and infrastructure.
  • Ubicloud — All database records (customer data, orders, analytics). Managed database hosting.

Note on geolocation: We use the MaxMind GeoLite2 database, which runs locally on our servers. No visitor data is sent to MaxMind.

How We Use Your Data

  • Process purchases and deliver digital products — Contractual necessity
  • Operate your account and provide customer support — Contractual necessity
  • Send transactional emails (order confirmations, login codes, account notifications) — Contractual necessity
  • Measure marketing performance (which channels and campaigns drive purchases) — Legitimate interest
  • Improve our website (heatmaps and session recordings help us fix usability problems) — Legitimate interest
  • Optimize advertising (conversion data sent server-to-server to Meta via the Conversions API, helping us reach people who benefit from our products) — Consent
  • Provide site functionality (device recognition for features like deadline timers, session continuity) — Contractual necessity
  • Detect fraud and bots (threat scoring protects our checkout and analytics) — Legitimate interest
  • Retain financial records (orders, invoices, tax documentation) — Legal obligation

You can object to processing based on legitimate interest at any time by contacting us at . We'll stop unless we can demonstrate compelling grounds that override your interests.

How Long We Keep It

  • Financial records (orders, invoices) — 10 years. Applicable tax and accounting law.
  • Analytics (IP, fingerprint, visitor events) — 13 months, then anonymized. Sufficient to measure annual marketing cycles.
  • Marketing email addresses — Until unsubscribe + 30 days on suppression list. Compliance.
  • Inactive subscribers (no engagement) — 2 years, then deleted. Storage limitation principle.
  • Server logs — 3 days. GDPR guidance.
  • Aggregated/anonymous statistics — Indefinitely. No personal data remains.

Your Rights

Under the GDPR

You have the right to:

  • Access your personal data (request a copy of everything we hold)
  • Rectification of inaccurate data
  • Erasure of your data ("right to be forgotten")
  • Restrict processing to limit how we use your data
  • Data portability to receive your data in a machine-readable format
  • Object to processing based on legitimate interest
  • Withdraw consent you've previously given, at any time
  • Complain to your local data protection authority

California Residents (CCPA)

You also have the right to:

  • Know what personal information we collect, use, and share
  • Correct inaccurate personal information we hold about you
  • Delete your personal information
  • Opt out of the sale or sharing of your personal information
  • Non-discrimination for exercising your privacy rights

We don't sell personal information. We share data with Meta for ad optimization, which constitutes "sharing" under the CCPA. You can opt out using the "Do Not Sell or Share My Personal Information" link on our website, or by contacting us at .

How to Exercise Your Rights

Email with your request. Under GDPR, we respond within one month (extendable by two months for complex requests, with prior notice). Under CCPA, we respond within 45 days (extendable by an additional 45 days with notice). We may ask you to verify your identity first.

Children

Our services aren't directed to anyone under 18. We don't knowingly collect data from minors. If you believe we have, contact us and we'll delete it.

Changes to This Policy

We may update this policy from time to time. We'll post the updated version here and update the date at the top. For material changes, we'll notify you by email or a prominent notice on our website.