Privacy Policy
Last updated: July 10, 2026
What we collect
We collect only the data needed for the requested workflow:
- Lead email and consent record — when you request a free template or choose to save a tool result. We record the source, requested asset, consent-copy version, consent timestamp (when applicable), and campaign parameters.
- Purchase details — Stripe processes checkout and records buyer, payment, billing and tax information. We use the Checkout Session ID only to verify access to a purchased download.
- Aggregate analytics — we use a self-hosted Umami Analytics instance to understand page and referrer patterns. The checkout success page and private download endpoints do not load analytics.
We do not store quiz answers, disclosure-generator text, IP addresses in the lead sheet, or payment-card details.
Purposes and consent
- To provide the requested template, tool or purchased file.
- To maintain a minimal operational record of the request.
- To send marketing updates only where the separate checkbox was selected. The checkbox is unticked by default.
- To understand aggregate site usage.
Buyer emails held by Stripe are not automatically added to the marketing list.
Processors and storage
- Stripe — hosted payment processing, receipts and purchase records.
- Google Sheets / Google Apps Script — restricted lead record after the connected account and webhook are configured.
- Cloudflare Pages and R2 — website hosting, server-side purchase verification and private file storage.
- Umami — aggregate website analytics.
Retention and rights
We retain records only for the operational, legal and accounting periods that apply. You may request access, correction, deletion, restriction or objection where GDPR provides those rights. Marketing consent can be withdrawn at any time.
Contact privacy@readyforaiact.com. If you are dissatisfied, you may also contact the data-protection authority in your country.
Security
Paid ZIP files are stored privately. A completed Stripe session is re-verified before each download. A Checkout Session ID acts as a bearer credential, so do not share the success-page URL.