Lead Ads Guide Lead Ads Guide

Privacy Policy

Effective date: 13 July 2026

I run Meta ads for a living, so I know exactly how tracking works and what it collects. Which means I'm not going to write you a privacy policy full of fog.

Here's what's actually happening on this site.

Who's responsible for this

Me. Benjamin Boman, an individual sole trader. Not a company, not a faceless entity. One person.

Under UK and EU GDPR, that makes me the data controller for this website and for any marketing emails I send.

Anything privacy related, send it here:
https://benjaminboman.typeform.com/to/jFFsSqiz

I'll come back to you inside a month. Realistically it'll be a lot faster than that.

What this policy covers, and what it doesn't

This covers leadads.guide and my email list.

It does not cover the checkout. Here's why that matters.

leadads.guide is sold through Gumroad, and Gumroad is the merchant of record. So when you buy, you're actually transacting with Gumroad, not with me. They take the payment, they handle the tax, they issue the receipt, and they host the course you're buying.

What that means for your data: Gumroad collects and controls your payment info, billing details, and tax data. They're their own controller for that, under their own policy:
https://gumroad.com/privacy

I never see your card details. They don't touch my systems at any point.

The course files themselves are also hosted by Gumroad, in the US. Your access runs through their platform.

What I actually collect

Stuff you hand me directly:

  • Your email address, if you opt in to the list
  • Whatever you write in the contact form (name, email, message)

Stuff Gumroad passes to me after you buy:

  • Name
  • Email
  • Country
  • Your purchase and refund record

Stuff that gets picked up automatically when you land on the site:

  • IP address
  • Device, browser, operating system
  • Which pages you looked at, where you came from, how long you stayed
  • Click IDs in the URL, like fbclid and gclid
  • Event data fired through Google Tag Manager

Cookies and tracking, the honest version

I use Google Tag Manager to fire tags on this site. Here's every one of them and what it does.

TypeWhat it isWhat it's forHow long it sticks around
EssentialConsent cookieRemembers what you chose on the banner6 to 12 months
AnalyticsGoogle Analytics 4 (_ga, _ga_*)Tells me how many people hit the page and what they didUp to 2 years
AdvertisingMeta Pixel (_fbp, _fbc)Measures whether my ads work, and builds retargeting and lookalike audiencesUp to 90 days
EssentialGumroad cookiesCheckout and course accessSet by Gumroad

On consent: if you're in the EEA or UK, the analytics and advertising tags are blocked by default. Nothing fires until you actively say yes on the banner. I manage this through Google Consent Mode v2.

Changed your mind? Cookie settings link is in the footer. Withdraw consent any time.

Essential cookies run regardless. The site doesn't work without them.

One thing worth knowing: even when you deny consent, Google Consent Mode still sends anonymous, aggregated signals to Google. No identifiers, nothing that points back to you. But I'd rather tell you it happens than let you find out later.

The Meta Pixel, since I'd be a hypocrite not to explain this properly

I teach people to run Meta lead ads. So yes, obviously, I run the Meta Pixel on this site. I may also use the Conversions API.

What that means in practice: certain events, including page views, purchases, and hashed identifiers like your email, get shared with Meta Platforms, Inc.

For that collection and transmission, Meta and I are joint controllers under Meta's Controller Addendum. What Meta then does with that data on their side is governed by Meta's own policy:
https://www.facebook.com/privacy/policy

If you want to limit what Meta does with it, go into your Meta ad preferences and your off-Facebook activity settings. That's the lever that actually works, not anything I can do on my end.

Why I'm using your data, and what lets me

What I'm doingLegal basis
Giving you access to the course, and supporting youContract
Handling refundsContract / legal obligation
Sending you service and transactional emailsContract
Sending you marketing emails and the newsletterConsent
AnalyticsConsent (cookies)
Advertising, retargeting, audience buildingConsent (cookies)
Security and fraud preventionLegitimate interests
Keeping business recordsLegal obligation

If you withdraw consent, that's fine, and it takes effect going forward.

Who else touches your data

Every third party I use, and why:

  • Gumroad (US): checkout, payment, tax, refunds, course hosting
  • Meta Platforms (US): ad measurement and retargeting
  • Google (US): Tag Manager and Analytics 4
  • Resend (US): sending my emails
  • Typeform: the contact form

That's the full list. I don't sell your data to brokers, and I'm not in the business of doing that.

Worth flagging, though: running the Meta Pixel probably counts as "sharing" under a few US state laws, even though no money changes hands. See the US section below.

Data leaving your country

My service providers are almost all based in the US, and I'm based outside the EEA and UK. So if you're in the EEA or UK, your data is going to cross borders.

Those transfers rely on the safeguards those providers have in place, including EU to US and UK to US Data Privacy Framework certifications, and Standard Contractual Clauses where they apply.

How long I keep it

  • Email list: until you unsubscribe, then you're out
  • Contact form messages: up to 24 months
  • Analytics: 14 months, which is the GA4 retention setting I've got it on
  • Advertising cookies: as per the table above
  • Purchase records: Gumroad holds these, on their own retention and tax schedule

Your rights, if you're in the EEA or UK

You can ask me to:

  • Show you what I hold on you
  • Fix anything that's wrong
  • Delete it
  • Restrict what I do with it
  • Hand it over in a portable format
  • Stop processing where I'm relying on legitimate interests
  • Withdraw your consent, any time

And you can complain to your supervisory authority. In the UK that's the ICO, at ico.org.uk.

Use the contact form.

On the EU representative question. GDPR says some non-EU controllers need to appoint a formal EU representative. I haven't appointed one, and I want to be upfront about the reasoning rather than just going quiet on it.

This is one guy selling one $97 digital product. Processing of EEA residents' data is occasional. There's no special category data, no criminal conviction data, nothing sensitive. It's website analytics, ad measurement, and a small email list. The processing is unlikely to result in a risk to anyone's rights and freedoms, which is the test. So I'm relying on the derogation in Article 27(2)(a).

If the scale or nature of what I'm doing changes, I'll revisit that. That's the honest position.

Your rights, if you're in the US

Depending on which state you're in, you can:

  • Find out what I've collected on you
  • Delete it
  • Correct it
  • Opt out of the "sale" or "sharing" of it
  • Opt out of targeted advertising
  • Not be treated worse for asking

Do Not Sell or Share My Personal Information. Here's the deal: the Meta Pixel on this site likely counts as "sharing" for cross-context behavioural advertising under CCPA/CPRA, and as "targeted advertising" under other state laws. I'm not selling anything to anyone, but the definition is broad and it catches this.

To opt out: hit the cookie settings link in the footer and decline advertising cookies. That's the mechanism.

Global Privacy Control. If your browser sends a GPC signal, I treat it as a valid opt-out. No extra step needed on your side.

Email

I only email people who asked to be emailed. Every email has an unsubscribe link, and it works immediately. No "are you sure?" gauntlet.

Kids

This is a product for business owners and marketing people. It's not aimed at anyone under 18, and I don't knowingly collect data from anyone under 18.

Security

I use HTTPS, sensible access controls, and reputable providers. That's a genuine effort, not a shrug.

But I'm not going to tell you it's impossible to breach, because nobody can honestly say that about anything on the internet. If there's ever a breach that's likely to put your rights at risk, I'll notify the relevant authority and, where required, you.

Automated decisions

I don't run any automated decision-making or profiling that produces legal or similarly significant effects on you. No algorithm is deciding anything about you here.

Changes

If this policy changes, the effective date at the top changes with it. If it's a material change, I'll email you about it.

Contact

Everything privacy related goes here:
https://benjaminboman.typeform.com/to/jFFsSqiz

← Back to the guide