Privacy Policy
Effective date: 13 July 2026
I run Meta ads for a living, so I know exactly how tracking works and what it collects. Which means I'm not going to write you a privacy policy full of fog.
Here's what's actually happening on this site.
Who's responsible for this
Me. Benjamin Boman, an individual sole trader. Not a company, not a faceless entity. One person.
Under UK and EU GDPR, that makes me the data controller for this website and for any marketing emails I send.
Anything privacy related, send it here:
https://benjaminboman.typeform.com/to/jFFsSqiz
I'll come back to you inside a month. Realistically it'll be a lot faster than that.
What this policy covers, and what it doesn't
This covers leadads.guide and my email list.
It does not cover the checkout. Here's why that matters.
leadads.guide is sold through Gumroad, and Gumroad is the merchant of record. So when you buy, you're actually transacting with Gumroad, not with me. They take the payment, they handle the tax, they issue the receipt, and they host the course you're buying.
What that means for your data: Gumroad collects and controls your payment info, billing details, and tax data. They're their own controller for that, under their own policy:
https://gumroad.com/privacy
I never see your card details. They don't touch my systems at any point.
The course files themselves are also hosted by Gumroad, in the US. Your access runs through their platform.
What I actually collect
Stuff you hand me directly:
- Your email address, if you opt in to the list
- Whatever you write in the contact form (name, email, message)
Stuff Gumroad passes to me after you buy:
- Name
- Country
- Your purchase and refund record
Stuff that gets picked up automatically when you land on the site:
- IP address
- Device, browser, operating system
- Which pages you looked at, where you came from, how long you stayed
- Click IDs in the URL, like
fbclidandgclid - Event data fired through Google Tag Manager
Cookies and tracking, the honest version
I use Google Tag Manager to fire tags on this site. Here's every one of them and what it does.
| Type | What it is | What it's for | How long it sticks around |
|---|---|---|---|
| Essential | Consent cookie | Remembers what you chose on the banner | 6 to 12 months |
| Analytics | Google Analytics 4 (_ga, _ga_*) | Tells me how many people hit the page and what they did | Up to 2 years |
| Advertising | Meta Pixel (_fbp, _fbc) | Measures whether my ads work, and builds retargeting and lookalike audiences | Up to 90 days |
| Essential | Gumroad cookies | Checkout and course access | Set by Gumroad |
On consent: if you're in the EEA or UK, the analytics and advertising tags are blocked by default. Nothing fires until you actively say yes on the banner. I manage this through Google Consent Mode v2.
Changed your mind? Cookie settings link is in the footer. Withdraw consent any time.
Essential cookies run regardless. The site doesn't work without them.
One thing worth knowing: even when you deny consent, Google Consent Mode still sends anonymous, aggregated signals to Google. No identifiers, nothing that points back to you. But I'd rather tell you it happens than let you find out later.
The Meta Pixel, since I'd be a hypocrite not to explain this properly
I teach people to run Meta lead ads. So yes, obviously, I run the Meta Pixel on this site. I may also use the Conversions API.
What that means in practice: certain events, including page views, purchases, and hashed identifiers like your email, get shared with Meta Platforms, Inc.
For that collection and transmission, Meta and I are joint controllers under Meta's Controller Addendum. What Meta then does with that data on their side is governed by Meta's own policy:
https://www.facebook.com/privacy/policy
If you want to limit what Meta does with it, go into your Meta ad preferences and your off-Facebook activity settings. That's the lever that actually works, not anything I can do on my end.
Why I'm using your data, and what lets me
| What I'm doing | Legal basis |
|---|---|
| Giving you access to the course, and supporting you | Contract |
| Handling refunds | Contract / legal obligation |
| Sending you service and transactional emails | Contract |
| Sending you marketing emails and the newsletter | Consent |
| Analytics | Consent (cookies) |
| Advertising, retargeting, audience building | Consent (cookies) |
| Security and fraud prevention | Legitimate interests |
| Keeping business records | Legal obligation |
If you withdraw consent, that's fine, and it takes effect going forward.
Who else touches your data
Every third party I use, and why:
- Gumroad (US): checkout, payment, tax, refunds, course hosting
- Meta Platforms (US): ad measurement and retargeting
- Google (US): Tag Manager and Analytics 4
- Resend (US): sending my emails
- Typeform: the contact form
That's the full list. I don't sell your data to brokers, and I'm not in the business of doing that.
Worth flagging, though: running the Meta Pixel probably counts as "sharing" under a few US state laws, even though no money changes hands. See the US section below.
Data leaving your country
My service providers are almost all based in the US, and I'm based outside the EEA and UK. So if you're in the EEA or UK, your data is going to cross borders.
Those transfers rely on the safeguards those providers have in place, including EU to US and UK to US Data Privacy Framework certifications, and Standard Contractual Clauses where they apply.
How long I keep it
- Email list: until you unsubscribe, then you're out
- Contact form messages: up to 24 months
- Analytics: 14 months, which is the GA4 retention setting I've got it on
- Advertising cookies: as per the table above
- Purchase records: Gumroad holds these, on their own retention and tax schedule
Your rights, if you're in the EEA or UK
You can ask me to:
- Show you what I hold on you
- Fix anything that's wrong
- Delete it
- Restrict what I do with it
- Hand it over in a portable format
- Stop processing where I'm relying on legitimate interests
- Withdraw your consent, any time
And you can complain to your supervisory authority. In the UK that's the ICO, at ico.org.uk.
Use the contact form.
On the EU representative question. GDPR says some non-EU controllers need to appoint a formal EU representative. I haven't appointed one, and I want to be upfront about the reasoning rather than just going quiet on it.
This is one guy selling one $97 digital product. Processing of EEA residents' data is occasional. There's no special category data, no criminal conviction data, nothing sensitive. It's website analytics, ad measurement, and a small email list. The processing is unlikely to result in a risk to anyone's rights and freedoms, which is the test. So I'm relying on the derogation in Article 27(2)(a).
If the scale or nature of what I'm doing changes, I'll revisit that. That's the honest position.
Your rights, if you're in the US
Depending on which state you're in, you can:
- Find out what I've collected on you
- Delete it
- Correct it
- Opt out of the "sale" or "sharing" of it
- Opt out of targeted advertising
- Not be treated worse for asking
Do Not Sell or Share My Personal Information. Here's the deal: the Meta Pixel on this site likely counts as "sharing" for cross-context behavioural advertising under CCPA/CPRA, and as "targeted advertising" under other state laws. I'm not selling anything to anyone, but the definition is broad and it catches this.
To opt out: hit the cookie settings link in the footer and decline advertising cookies. That's the mechanism.
Global Privacy Control. If your browser sends a GPC signal, I treat it as a valid opt-out. No extra step needed on your side.
I only email people who asked to be emailed. Every email has an unsubscribe link, and it works immediately. No "are you sure?" gauntlet.
Kids
This is a product for business owners and marketing people. It's not aimed at anyone under 18, and I don't knowingly collect data from anyone under 18.
Security
I use HTTPS, sensible access controls, and reputable providers. That's a genuine effort, not a shrug.
But I'm not going to tell you it's impossible to breach, because nobody can honestly say that about anything on the internet. If there's ever a breach that's likely to put your rights at risk, I'll notify the relevant authority and, where required, you.
Automated decisions
I don't run any automated decision-making or profiling that produces legal or similarly significant effects on you. No algorithm is deciding anything about you here.
Changes
If this policy changes, the effective date at the top changes with it. If it's a material change, I'll email you about it.
Contact
Everything privacy related goes here:
https://benjaminboman.typeform.com/to/jFFsSqiz