Privacy

Privacy Policy

Public legal and informational pages should feel clear and lightweight, not like another landing-page hero.

Page content

Last Updated: January 1, 2025

Your privacy matters. This Privacy Policy explains how Holistically Simple ("we," "us," "our") collects, uses, protects, and shares your personal information when you use our Private Membership Association (PMA) platform and services.

1. Information We Collect

The organization gathers data through direct user submission, automatic collection processes, and external sources.

1.1 Information You Provide Directly

Users may submit account details including names, email addresses, phone numbers, and business information. Payment data is processed securely through third-party vendors. Profile information encompasses photos, biographies, business descriptions, and location details. Business data may include customer contact lists, CRM information, marketing campaigns, and pipeline details. Communication data consists of platform messages, support tickets, and community posts. Assessment data involves responses to strategic questionnaires and onboarding forms.

1.2 Information We Collect Automatically

The platform automatically captures usage data such as pages viewed and navigation patterns. Device information includes IP addresses, browser types, and operating systems. Location data reflects general geographic information derived from IP addresses, not precise GPS coordinates. The service employs cookies and similar tracking technologies. Performance data encompasses load times and technical diagnostics.

1.3 Information From Third-Party Sources

Data may be imported from connected services including email providers and CRM tools. Public profile information from social media accounts may be incorporated. Transaction confirmation and payment status information comes from payment processors like Stripe.

2. How We Use Your Information

  • Platform Services — Access to CRM, marketing automation, website builder, and community features
  • Account Management — Account creation, payment processing, subscription handling, identity verification
  • Communication — Transactional emails, platform updates, support responses, community notifications
  • Personalization — Customized experiences, resource recommendations, peer group matching
  • Analytics & Improvement — Usage pattern analysis, feature improvement, performance optimization, A/B testing
  • Security & Fraud Prevention — Fraud detection, unauthorized access prevention, threat identification
  • Legal Compliance — Meeting legal obligations, responding to legal requests, enforcing terms
  • Marketing (with consent) — Promotional emails, product updates, educational content (users may opt out)

3. How We Share Your Information

We do NOT sell your personal information.

3.1 Service Providers

Data is shared with trusted vendors providing hosting, payment processing, email services, analytics, and customer support. All service providers are contractually required to protect your data and use it only for the specified purposes.

3.2 Community Members (Limited Sharing)

Profile information including names and business details are visible to community members. Community posts and comments are visible to other members. However, your business contact data (CRM, customer lists) is NOT shared with other members.

3.3 Business Transfers

If Holistically Simple is acquired or merged, information may transfer to the new entity with user notification.

3.4 Legal Requirements

Information may be disclosed if required by law, court order, or government request to protect rights and property or enforce agreements.

3.5 With Your Consent

Data sharing occurs when users explicitly authorize third-party connections or integrations.

4. Data Retention

Active accounts retain data during membership. Canceled accounts retain information for 90 days before deletion. Payment and transaction data retained for 7 years (tax and legal compliance). Support communications and community posts remain indefinitely unless deletion is requested. Backup system data is deleted within 90 days of removal from active systems.

5. Your Privacy Rights

Users may possess rights including data access, correction, deletion, portability, use restriction, and marketing objection depending on location.

To exercise your rights, contact:

We will respond to your request within 30 days. Identity verification may be required to protect your privacy.

6. Data Security

Technical Safeguards — TLS/SSL encryption for data in transit, role-based access controls, two-factor authentication options, continuous threat monitoring, encrypted backups

Organizational Safeguards — Employee privacy training, confidentiality agreements, regular security audits, incident response procedures

No system is 100% secure. While we use best practices to protect your data, we cannot guarantee absolute security.

7. Children's Privacy

Our services are NOT intended for individuals under 18 years of age. We do not knowingly collect personal information from children under 18. Discovered child data is deleted immediately.

8. Cookies & Tracking Technologies

Essential Cookies — Enable platform functionality and security

Preference Cookies — Remember user settings and preferences

Analytics Cookies — Track usage patterns using Google Analytics and similar tools

Marketing Cookies — Deliver relevant advertising and measure campaign effectiveness

Users can control cookies through browser settings or Google Analytics opt-out tools. Disabling essential cookies may affect platform functionality.

9. International Data Transfers

Holistically Simple is based in the United States. Data may be transferred and processed in the U.S. or other countries where service providers operate. Users consent to such transfers by using the services.

10. California Privacy Rights (CCPA)

California residents possess additional rights including disclosure requests, deletion rights, and sale opt-out capabilities. We do NOT sell data. Users cannot face discrimination for exercising these rights.

Contact: privacy@holisticallysimple.com

11. European Privacy Rights (GDPR)

EEA, UK, and Switzerland residents possess GDPR protections. Data processing bases include consent, contract performance, legal obligation, and legitimate interests. Users may lodge complaints with local data protection authorities.

Data Protection Officer: dpo@holisticallysimple.com

12. Third-Party Links

The platform contains links to external services. We are NOT responsible for the privacy practices of these external sites.

13. Changes to This Privacy Policy

Updates may occur to reflect practice changes or legal requirements. Material changes trigger email notifications and platform notifications. Continued use of our services after changes take effect constitutes acceptance of the updated policy.

14. Contact Us