1.Who is responsible
[Your full legal name or registered company name] is the data controller for the personal data described in this policy. That means we decide why and how it is processed.
- Controller
- [Your legal name]
- Address
- [Street, postcode, city, country]
- Privacy contact
- privacy@massunlocked.com
- Data protection officer
- [Not appointed — not required for our scale of processing]
2.What this covers
This policy explains what we do with personal data when you visit massunlocked.com, buy the guide, email us, or see one of our ads.
It does not cover other websites we link to. Those have their own policies.
3.What we collect
3.1 What you give us
- Order details — your name, email address, billing country, and the details of what you bought and when.
- Correspondence — anything you write to us by email or through the contact form, including the content of refund and guarantee claims.
- Marketing preferences — whether you signed up for emails, and whether you later unsubscribed.
3.2 What we collect automatically
- Technical data — IP address, browser type and version, device type, operating system, language, and approximate location derived from the IP address.
- Usage data — which pages you visited, when, how long for, what you clicked, where you arrived from, and whether you reached the checkout.
- Advertising identifiers — cookies and similar identifiers set by advertising platforms, described in sections 6 and 7.
3.3 What we deliberately do not collect
We do not ask for, and you should not send us, information about your health, your body weight, your medical history or your diagnoses. Health data is a special category under data protection law and we have no need for it.
Our guarantee in particular requires no weight, no photographs and no medical information. If you send us health details anyway, we will only use them to answer you, and we will delete them once your query is closed.
4.Why, and our legal basis
Under the UK and EU GDPR we must have a lawful basis for each purpose:
| What we do | Data used | Legal basis |
|---|---|---|
| Take your order, deliver the guide, send your receipt | Order details | Performance of a contract |
| Answer your emails and support requests | Correspondence, order details | Performance of a contract, or our legitimate interest in running a business properly |
| Process refunds and guarantee claims | Order details, correspondence | Performance of a contract; legal obligation where a statutory right applies |
| Keep accounting and tax records | Order details, invoices | Legal obligation |
| Detect and prevent fraud, chargeback abuse and repeated refund abuse | Order details, technical data | Legitimate interest in protecting the business |
| Understand how the site is used and improve it | Usage and technical data | Consent, where analytics cookies are used |
| Advertise on Meta and other platforms, and measure whether ads work | Advertising identifiers, usage data, hashed email | Consent |
| Send marketing emails | Email address, marketing preferences | Consent, or soft opt-in for our own similar products to existing customers |
| Defend or bring legal claims | Whatever is relevant | Legitimate interest in establishing or defending legal claims |
Where we rely on legitimate interests, we have considered whether our interest is overridden by your rights, and you can object at any time — see section 12.
5.Payment information
Payments are handled by Lemon Squeezy, LLC, which acts as merchant of record for the sale.
We never see or store your full card number, expiry date or security code. Those go directly to the payment provider, which is certified to the PCI DSS security standard and acts as its own controller for the payment data it holds.
We receive only confirmation of payment, the last four digits of the card or the payment reference, the amount, the currency and the billing country.
Lemon Squeezy's own privacy policy is at lemonsqueezy.com/privacy. Lemon Squeezy is based in the United States, so paying for the guide involves a transfer of your payment data outside the UK and EEA — see section 10 on international transfers.
6.Cookies and tracking
Cookies are small files stored on your device. Similar technologies include pixels, local storage and device fingerprinting. We group them as follows:
| Category | What it does | Consent needed |
|---|---|---|
| Strictly necessary | Runs the checkout, keeps your session, remembers your cookie choice | No |
| Analytics | Tells us which pages are read and where people drop off | Yes |
| Advertising | Measures ad performance and builds audiences — see section 7 | Yes |
You need a real consent banner. In the EU and the UK, analytics and advertising cookies may only be set after the visitor has actively agreed. That means: nothing non-essential fires on page load, refusing is as easy as accepting, no pre-ticked boxes, and the choice can be withdrawn later.
The Meta Pixel in section 7 is an advertising cookie. If you install it so that it fires the moment the page opens, this policy becomes untrue and you are in breach from your first visitor. Wire the Pixel to fire only on consent.
You can also block or delete cookies in your browser settings, though the checkout may stop working if you block the strictly necessary ones.
7.Meta Pixel and advertising
We advertise on Meta's platforms (Facebook and Instagram). To measure whether those ads work, we use the Meta Pixel, a small piece of code that reports back to Meta when someone visits this site or completes a purchase.
Through the Pixel, Meta may receive your IP address, information about your browser and device, which pages you viewed, and whether you bought. Where we use Meta's Conversions API or advanced matching, a hashed (scrambled) version of your email address may also be sent so Meta can match the purchase to an ad view.
Meta uses this to report on our ads, to build audiences of people who resemble our customers, and for its own purposes as set out in its own policies. For some of this processing, we and Meta are joint controllers, and a summary of that arrangement is published by Meta.
- Meta's privacy policy: facebook.com/privacy/policy
- Your Meta ad settings: facebook.com/adpreferences
- Off-Facebook activity: facebook.com/off_facebook_activity
We only load the Pixel after you consent to advertising cookies, and you can withdraw that consent at any time through our cookie settings.
We do not tell Meta, or any other advertising platform, anything about your health, your body or your weight.
[If you also use TikTok, Google Ads or another platform, describe it here in the same way — or delete this line.]
8.Marketing emails
If you consented, or if you bought from us and we are contacting you about our own similar products, we may email you.
Every marketing email has a one-click unsubscribe link. You can also email us and ask to be removed. Unsubscribing is immediate and free, and it does not affect your access to something you already bought or your right to claim the guarantee.
We will always send you service messages — your receipt, your download link, a reply to your question — because those are part of the contract, not marketing.
9.Who we share data with
We do not sell your personal data. We share it only with service providers who help us run the business, and only as far as they need it:
| Recipient | Purpose | Who |
|---|---|---|
| Payment processor | Taking payment, issuing refunds, collecting sales tax and VAT as merchant of record | Lemon Squeezy, LLC |
| Email platform | Sending receipts, delivery links, marketing | [your email tool] |
| Hosting and file delivery | Serving the site and the download | [your host] |
| Analytics | Understanding site usage | [your analytics tool, or "none"] |
| Advertising platforms | Running and measuring ads | Meta Platforms [+ others] |
| Professional advisers | Accounting, tax, legal | As needed |
We may also disclose data where the law requires it, to enforce our Terms, or to protect our rights or someone's safety. If the business is sold or transferred, customer data may pass to the buyer, who must continue to protect it under this policy.
10.International transfers
Some of our providers are based outside the EEA and the UK, mainly in the United States. When personal data is transferred there, we rely on a lawful transfer mechanism — usually the European Commission's Standard Contractual Clauses, the UK Addendum, or the provider's certification under the EU–US Data Privacy Framework.
Ask us and we will tell you which mechanism applies to a given provider.
11.How long we keep it
| Data | Kept for | Why |
|---|---|---|
| Order and invoice records | [7] years | Tax and accounting law |
| Guarantee-claim correspondence | [3] years after the claim closes | Defending a possible dispute |
| General support emails | [2] years | Continuity of support |
| Marketing list membership | Until you unsubscribe, then a suppression record indefinitely | To make sure we do not email you again |
| Analytics and advertising data | [14] months, or the platform's own default | Measuring campaigns |
When a period ends we delete the data or anonymise it so it can no longer identify you.
12.Your rights
If the UK or EU GDPR applies to you, you have the right to:
- Be informed — which is what this document is for.
- Access — get a copy of the personal data we hold about you.
- Rectification — have inaccurate data corrected.
- Erasure — have data deleted, where we have no overriding reason to keep it. Note that we must keep invoice records for tax purposes even if you ask us to erase everything else.
- Restriction — ask us to pause processing while a dispute is resolved.
- Portability — receive the data you gave us in a machine-readable format.
- Object — to processing based on legitimate interests, and absolutely to direct marketing, at any time.
- Withdraw consent — at any time, without affecting anything done before you withdrew it.
To exercise any of these, email privacy@massunlocked.com. We will respond within one month. We may ask you to confirm your identity first, and we will not charge you unless a request is manifestly excessive.
If you are in California or another US state with similar law, you may have comparable rights to know, delete, correct and opt out of the sale or sharing of personal information. We do not sell personal information. Use the same address to make a request.
13.Security
We use HTTPS across the site, restrict access to order data to people who need it, use reputable providers, and keep accounts protected by strong, unique passwords and two-factor authentication where available.
No system is perfectly secure, and we cannot guarantee that data sent over the internet is safe in transit. If a breach occurs that is likely to put your rights at risk, we will notify the relevant supervisory authority within 72 hours and tell you without undue delay.
14.Children
This site and product are for adults aged 18 and over. We do not knowingly collect data from children. If you believe a child has given us personal data, contact us and we will delete it.
15.Automated decisions
We do not make decisions producing legal or similarly significant effects about you by automated means alone. Fraud checks by our payment processor may be partly automated; a refused payment can always be queried with us or with the processor directly.
16.Changes to this policy
We may update this policy. The date at the top shows the current version. If a change materially affects how we use your data, we will tell you by email or with a notice on the site before it takes effect.
17.Complaints
Please tell us first — email privacy@massunlocked.com and we will try to put it right.
You also have the right to complain to a data protection authority. If you are in the EEA, that is the authority in the country where you live, work, or where you think the problem occurred. In your case the lead authority is [your national data protection authority]. In the UK it is the Information Commissioner's Office at ico.org.uk.
18.Contact us
Privacy questions: privacy@massunlocked.com
Everything else: contact page