Definitions
- Personal Data – any information relating to an identified or identifiable natural person.
- Processing – any operation performed on Personal Data, whether or not by automated means.
- Data Subject – a natural person whose Personal Data is being processed.
- Child – a natural person under 16 years of age (13 in the US for COPPA purposes).
- Client Portal – the authenticated area of our site where clients review concepts, proposals, worksheets, and invoices.
- Services – our website, client portal, and any marketing, design, development, hosting, or strategy services we provide.
Data protection principles we follow
- Lawful, fair, transparent. We only process data when we have a lawful basis and we tell you what we're doing.
- Purpose-limited. We use data only for the purpose it was collected.
- Minimal. We collect only what we need to do the work.
- Time-limited. We don't keep data longer than needed.
- Accurate. We do our best to keep data accurate and up to date.
- Secure. We protect data with reasonable administrative, technical, and physical safeguards.
What rights do you have
- Right to information – know whether and how your Personal Data is processed.
- Right to access – request a copy of the Personal Data we hold about you.
- Right to rectification – ask us to correct inaccurate or incomplete data.
- Right to erasure – ask us to delete your Personal Data ("right to be forgotten").
- Right to restrict processing – ask us to pause certain processing.
- Right to object – object to processing based on legitimate interests or direct marketing.
- Right to object to automated decision-making – including profiling that has a legal or significant effect on you.
- Right to data portability – receive your data in a machine-readable format.
- Right to withdraw consent – at any time, where processing is based on consent.
- Right to lodge a complaint – with a supervisory authority in your jurisdiction.
To exercise any of these rights, email jason@waypointmkt.group. We respond to most requests within 30 days.
What Personal Data we gather
Information you provide
Name, business/organization name, email, phone (optional), billing and shipping address at checkout, project notes, files you upload (logos, brand assets, photos), account credentials for the client portal, and any information you send us by email or through forms.
Information collected automatically
IP address, device and browser info, referring URL, pages viewed, time on page, and interactions with our marketing emails (opens and clicks). Cart contents and session state are stored in your browser and, for logged-in users, associated with your account.
Information from partners
When you check out or sign in with a third party (for example Stripe for payments or Google for sign-in), we receive limited information from that provider — such as your name, email, transaction status, and account identifier — to complete the request.
Publicly available information
When we prepare a proposal or concept, we may look at your public website, social profiles, or listings to understand your brand and competitors. We don't scrape private data.
How we use your Personal Data
To perform our contract with you
- Deliver services you requested (proposals, concepts, websites, marketing, hosting).
- Process payments and invoices through Stripe.
- Provide and secure your client portal account.
- Send transactional emails (receipts, proposal shares, worksheet invites, password resets).
On the basis of legitimate interest
- Prevent fraud and abuse; keep systems secure.
- Understand which pages, packs, and campaigns work so we can improve them.
- Follow up on proposals we've sent and reach out about relevant services.
- Compile anonymized case studies and portfolio references.
With your consent
- Send marketing emails, newsletters, and drip sequences.
- Use non-essential cookies (analytics beyond what's strictly necessary).
- Feature your logo, project, or testimonial in our public marketing.
To comply with law
We keep the records we're legally required to keep (tax, accounting, contracts) and respond to lawful requests from authorities.
AI and automated tools
We use AI tools to help draft copy, generate design concepts, research competitors, and summarize client briefs. We do not submit customer chat transcripts, unsolicited contact lists, or marketing data to third-party AI vendors for model training. When we use AI as part of a deliverable, a human at Waypoint reviews the output before it reaches you.
Who else has access to your data
We do not sell your Personal Data. We share it only with vendors that help us run the business, and only for the purpose they were hired for. Our current processing partners include:
- Stripe – payments and subscription billing.
- Supabase / cloud hosting – database, authentication, and file storage for the site and client portal.
- Lovable – the platform we use to build, host, and iterate on the site itself.
- Resend (or a comparable transactional email provider) – delivery of receipts, proposals, and drip emails.
- Google – Google sign-in and Google Workspace (email, calendar, docs).
- Calendly – scheduling calls with our team.
- AI providers (e.g., OpenAI, Anthropic, Google) – used through vetted APIs to assist with drafting and research; we do not opt in to training on business data.
- Analytics – privacy-respecting web analytics to understand traffic. We do not run third-party ad-network tracking.
We may disclose Personal Data to third parties or public officials when legally required, or to protect our rights, users, or the public. In the event of a merger, acquisition, or sale of assets, your data may transfer to the successor entity subject to this policy.
How we secure your data
We use HTTPS for all data in transit, encrypted storage for data at rest, role-based access controls, and row-level security policies on our database so that customer data isn't exposed across accounts. Payment card data never touches our servers — Stripe handles it. Only the Waypoint team members who need access to a given piece of information have access to it.
Even with these safeguards, no system is perfect. If we discover a breach that affects your Personal Data, we'll notify affected users and the appropriate authorities as required by law.
If you have a client portal account, please keep your credentials confidential and use a strong, unique password.
Cookies and other technologies
Cookies are small text files stored in your browser. We use them to keep you signed in, remember cart contents, and understand site usage. You can control cookies at the browser level; disabling them may break parts of the site (like login and checkout).
- Necessary – required for login, checkout, cart, and security. Always on.
- Functional – remember preferences (e.g., your ministry/business audience selection).
- Analytics – help us understand which pages and packs are useful.
- Email tracking pixels & link redirects – used only in emails we send to you, so we can see whether a message was received and which links were useful.
We do not use advertising cookies or third-party ad networks on waypointmkt.group. If that ever changes, we'll update this policy and give you a way to opt out.
Retention
- Order, invoice, and contract records: as long as needed for tax and accounting (typically up to 7 years).
- Client portal data (concepts, proposals, worksheets, uploaded assets): for the life of the account plus a reasonable grace period after closure.
- Marketing email lists: until you unsubscribe or ask us to delete you.
- Web analytics: aggregated and anonymized where possible; raw event data pruned regularly.
Children
Our services are not directed to children under 16. We don't knowingly collect Personal Data from children. If you believe a child has provided us data, contact us and we will delete it.
International users
Waypoint Marketing is based in the United States and our infrastructure is hosted with US-based providers. If you access our services from outside the US, your Personal Data will be transferred to and processed in the United States, which may have different data-protection laws than your jurisdiction.
US state privacy rights (California, Virginia, Colorado, and others)
If you're a resident of a US state with a comprehensive privacy law, you have the rights described above (access, correction, deletion, portability, and the right to opt out of the "sale" or "sharing" of Personal Data for cross-context behavioral advertising). We do not sell your Personal Data as those terms are defined under California, Virginia, Colorado, Connecticut, or Utah law. To exercise your rights, email jason@waypointmkt.group. We will not discriminate against you for exercising them.
Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be announced on this page and, where appropriate, by email. Continued use of the services after an update means you accept the revised policy.
Contact
Waypoint Marketing
Email: jason@waypointmkt.group
See also our Terms & Conditions and our Trust & Security page.