Legal
Privacy Policy
Who We Are
This website is operated by Laurel Robbins, an online educator and entrepreneur. References to “we,” “us,” or “our” throughout this policy refer to Laurel Robbins and her business.
This policy applies to:
- laurelrobbins.com and all subpages
- Email communications sent from this business
- Products and courses sold through this site
- Any forms, sign-ups, or contact submissions on this site
What We Collect
We only collect what we actually need. Here’s a plain-language breakdown:
| Type of data | Examples | When collected |
|---|---|---|
| Contact information | Name, email address | When you sign up, purchase, or contact us |
| Purchase data | Products bought, transaction IDs | When you make a purchase |
| Payment data | Card details (processed by Stripe — we never see or store your full card number) | At checkout |
| Usage data | Pages visited, time on site, device type, browser | Automatically via analytics tools |
| Communications | Messages you send us, replies to emails | When you reach out directly |
We do not sell your data. Ever. To anyone. Full stop.
How We Use Your Information
We use your information only for the following purposes:
- To deliver the products or services you purchased
- To send you content you’ve explicitly opted into (email list, course updates)
- To respond to your questions or support requests
- To process and manage payments securely
- To improve the website and understand what’s useful to visitors
- To comply with our legal obligations
We rely on the following legal bases for processing your data under GDPR:
- Contract performance — to fulfil a purchase you’ve made
- Legitimate interests — to improve our site and communicate with customers
- Consent — for marketing emails (you can withdraw this at any time)
- Legal obligation — for tax, accounting, or compliance requirements
Cookies & Tracking
This site uses cookies — small text files stored on your device — to make the site work properly and to understand how it’s being used.
| Cookie type | Purpose | Can you opt out? |
|---|---|---|
| Essential | Required for the site to function (e.g. login, cart) | No — site won’t work without these |
| Analytics | Understanding traffic and page performance (Google Analytics) | Yes — via cookie banner or browser settings |
| Marketing | Tracking conversions, retargeting ads (e.g. Meta Pixel) | Yes — via cookie banner |
You can manage or withdraw cookie consent at any time via your browser settings. Disabling non-essential cookies won’t affect your ability to use the site.
Third-Party Services
We use a small number of trusted third-party tools to run this business. Each has its own privacy policy and handles data according to GDPR-compliant standards.
- Stripe — payment processing. Your card data goes directly to Stripe; we never handle it. Stripe Privacy Policy ↗
- ConvertKit / Kit — email marketing and list management. When you join our email list, your name and email are stored here. Kit Privacy Policy ↗
- Google Analytics — anonymous website usage data to understand what content is helpful. Google Privacy Policy ↗
- WordPress / WooCommerce — website platform and order management
- Zoom — for live calls and sessions (if applicable to your purchase)
We do not allow any third party to use your data for their own marketing purposes.
How Long We Keep Your Data
We keep your data only as long as needed:
- Purchase records — retained for 7 years for accounting and legal compliance
- Email subscribers — kept until you unsubscribe or ask us to delete your record
- Contact form enquiries — retained for up to 2 years
- Analytics data — anonymised and aggregated; no personal data is stored long-term
You can ask us to delete your personal data at any time (subject to legal retention obligations). See Your Rights below.
Your Rights
If you’re in the EU, UK, or a jurisdiction with similar data protection laws, you have the following rights regarding your personal data:
- Right to access — request a copy of the data we hold about you
- Right to correction — ask us to fix inaccurate or incomplete data
- Right to erasure — ask us to delete your personal data (“right to be forgotten”)
- Right to restrict processing — ask us to limit how we use your data
- Right to data portability — receive your data in a portable format
- Right to object — object to processing based on legitimate interests or for marketing
- Right to withdraw consent — unsubscribe or withdraw consent at any time without penalty
To exercise any of these rights, email us at hello@laurelrobbins.com. We’ll respond within 30 days and won’t make it complicated.
You also have the right to lodge a complaint with your national data protection authority if you believe your data has been mishandled.
Data Security
We take reasonable and appropriate steps to protect your personal data from unauthorised access, loss, or disclosure. These include:
- SSL/HTTPS encryption on all pages of this site
- Payments processed entirely by Stripe (PCI-DSS compliant)
- Limited access to personal data — only accessed when necessary
- Use of reputable, GDPR-compliant third-party services
No system is 100% secure, and we cannot guarantee absolute security. If you believe your data has been compromised, please contact us immediately.
Children’s Privacy
This website and its products are intended for adults aged 18 and over. We do not knowingly collect personal data from children under 16.
If you believe a child has provided us with personal information, please contact us and we will delete it promptly.
Changes to This Policy
We may update this policy from time to time. When we do, we’ll update the “last updated” date at the top of this page. If any changes are significant, we’ll let you know via email (if you’re on our list) or with a notice on the site.
Continuing to use this site after any changes means you accept the updated policy.
Contact Us
Questions about this policy or how your data is handled? Just reach out — we’re human here and happy to help.
Get in touch
You can contact us any time about privacy, data requests, or general questions.
We aim to respond to all data-related requests within 30 days, as required by GDPR.