Privacy Policy
This Privacy Policy describes how Noah Ratzan Consulting, LLC (“I,” “me,” or “my”), a Connecticut limited liability company, collects, uses, and protects personal information when you use noahratzan.com, submit an application, attend a consultation, or book a session. I am the data controller for the processing described below.
Contact for privacy matters: noah@noahratzan.com.
1. Information I Collect
I collect the following categories of personal information:
- Application / lead data — name, email, a short description of your project and goals, technical context (languages, frameworks, prior AI-tool experience), how you heard about me, and any fields you voluntarily fill on the application form. Collected when you submit an application through this site. (An intake endpoint that could accept applications from another site I operate or partner with exists in the code but is switched off, and no application is accepted through it. Applications that arrived through it before it was switched off, if any, are retained under the same rules as any other application, including a snapshot of what was entered on the other site.)
- Attribution data — the campaign parameters in the link you arrived through, the website that referred you, and the first page you landed on. Recorded in two first-party cookies (see §8) only after you accept analytics — nothing attribution-related is written to your browser before you answer the banner — and, if you then apply or book, saved on your record. Withdrawing analytics consent deletes the cookies and clears the saved fields (see §6).
- Account and profile data — if you are promoted to customer status, an account is created for you. There is no password: you sign in with a one-time link sent to your email address, or with Google sign-in, so whoever controls your mailbox can sign in as you. Stored fields are a display name, email address, time zone, and your recorded analytics-consent choice. If you book through a booking link I have sent you, a minimal record (your email and the name you give) is created even if you never sign in.
- Customer session data — goals you record in your customer dashboard, pre-session prep notes, tech stack declarations, and session journal entries (post-session reflections). These are collected and stored only for active customers.
- Booking data — session date, time, duration, product type (e.g. “Build 60”), and any notes you submit during booking.
- Payment data — processed by Stripe at time of booking. I do not receive or store your full card number; Stripe provides a tokenized reference, charge ID, amount, and status. I retain those metadata records for tax, accounting, and refund purposes.
- Session notes and screenshots — I take selective time-stamped screenshots at meaningful technical or pedagogical moments during a session and compile written notes; both are shared with you as a post-session summary. I do not record sessions as audio or video, apart from research conversations booked through a research booking link (see Terms §15). I apply per-screenshot crop-and-redact discipline before saving to minimize incidental personally-identifying information. Stored in Google Workspace (Google Drive). Retention is described in §5 below; see also Terms §15.
- Analytics events — a first-party log of page views, interactions, and product-use events (e.g. application submitted, session booked) keyed to your account or to a pseudonymous session identifier for anonymous visitors. Your IP address is never stored with an analytics event in readable form — it is converted to a one-way salted hash at the moment the event is recorded, and only that hash is kept; your browser's user-agent string is stored alongside it. Until you answer the analytics banner, these events are held provisionally on my server and deleted unless you accept (see §3 and §8). Events that record something you deliberately completed — an application submitted, a consultation booked, a payment confirmed — are kept as part of that transaction record regardless of your analytics choice. Two events carry content you typed or clicked: the site search records your search query, and an outbound-link click records the destination address. If you accept analytics, events are also sent to PostHog (see §4); if you do not, PostHog receives nothing.
- Email records — for each lifecycle email I send you (booking confirmations, prep reminders, receipts, optional re-engagement emails): the address, subject, workflow, timestamp, and whether it was accepted for delivery or failed, plus any bounce the mail provider reports back. I do not use open pixels or click tracking, so I cannot tell whether you opened an email or clicked a link in it. If your address hard-bounces or reports spam, I record it on a suppression list so I stop mailing you; that list has no expiry, because it is the record that prevents further email.
- Testimonial data — if you choose to submit a testimonial, I collect your quote and an attribution (name, and an affiliation if you give one), plus whether you agree to it being displayed on noahratzan.com. Nothing is published without that explicit consent, and if I ever want to use it anywhere else — social media, a written case study — I will ask you separately, in writing.
- Anti-abuse data — your IP address, your browser's user-agent string, and the result of the Cloudflare Turnstile challenge on the application form, used only for rate limiting and bot mitigation. Your IP address is sent to Cloudflare to run that check. It is also held briefly in raw form inside the rate-limit counters, which expire within minutes and are deleted nightly.
- Audit log data — a timestamped entry is written when I access your account, approve an application, or edit your data, and also when you sign in to one of the tools hosted on this site or book a consultation. These entries record your IP address in full. Retained for up to seven (7) years for compliance and dispute-resolution purposes.
- My own notes about you — when I review an application, decide fit after a consultation, run a session, or plan your learning, I write notes and decisions in your record. These are my working notes and are not shown to you in the app, but they are your personal data: you can ask for a copy under §6. They follow the record they are written on — removed when a declined application is scrubbed, deleted with your account, and kept with booking records where those are retained (§5).
- Other features on this site — if you ask for edit access to a community listing or leave a comment on one, I store your account email, what you wrote, and the outcome of the request.
If you record your own session — with my prior agreement, using your own app on your own device (see Terms §15) — that recording is yours. I never receive, store, or otherwise process it, and I am not the data controller or processor for it under this Policy.
2. How I Use Your Information
I use your information for the following purposes:
- Deliver the service — reviewing your application, scheduling a free consultation, operating the booking flow, conducting paid sessions, processing payments, issuing refunds, and sending necessary transactional emails.
- Assess fit — reviewing applications to decide whether to invite you to a consultation and subsequently promote you to customer status.
- Improve the service — reviewing analytics events to understand funnel performance, identify friction, and prioritize improvements. Provisional events from visitors who have not yet answered the analytics banner are visible in my own dashboard for the short window before they are kept or deleted (§3); they are not shared with anyone.
- Security and anti-abuse — rate-limiting, fraud detection, and audit logging.
- Communications — sending transactional emails (booking confirmation, receipts, prep, cancellations) you cannot opt out of while you have an active booking, and — with your opt-in — occasional re-engagement emails, each with a clear unsubscribe link.
- Legal and accounting — retaining payment and invoice records to comply with tax, accounting, and dispute obligations.
I do not sell your personal information. I do not use your data to train AI models, and the AI providers listed in §4 process it only to return a result to you. I do not share your data with advertising networks.
3. Legal Bases for Processing (EU / UK / EEA)
If you are in the EU, UK, EEA, or Switzerland, I process your personal information on one of the following lawful bases under the GDPR / UK GDPR:
- Performance of a contract (Art. 6(1)(b)): operating the booking flow, delivering paid sessions, and processing payments you have authorized.
- Legitimate interests (Art. 6(1)(f)): reviewing applications to assess fit, operating rate limits and audit logs for security, and briefly holding first-party analytics events while you decide whether to accept them. That last one works like this: when you first arrive, the record of your visit is held provisionally, on my server only — nothing is stored on your device. If you accept analytics, that record is kept and your visit history is complete from arrival. If you decline, nothing further is recorded, and anything held provisionally is deleted. If you never answer, provisional records are deleted automatically — they become eligible for deletion after thirty minutes and are removed by a sweep that runs every thirty minutes, so within about an hour. The result is that I retain the same analytics data I would retain under a pure opt-in. Separate from this, events that record a transaction you deliberately completed — a submitted application, a booked consultation, a confirmed payment — are kept as part of that record whatever your analytics choice (§1). I have assessed these interests against your rights and freedoms and consider them appropriate given the small scale of processing, the minimization measures applied (IP hashing on analytics records, short retention), and your ability to object.
- Consent (Art. 6(1)(a)): testimonials, optional re-engagement emails, optional cookies, research conversation recordings (see Terms §15), and third-party analytics — PostHog receives nothing, and its library is not even loaded, until you accept analytics. (Session notes and screenshots are processed under contract performance.)
- Legal obligation (Art. 6(1)(c)): retaining payment and invoice records for the periods required by Connecticut tax and accounting law.
You may withdraw consent at any time — analytics consent from the “Analytics” control in the footer of every page (§6, §8), and any other consent by emailing noah@noahratzan.com. Withdrawal does not affect the lawfulness of processing performed before withdrawal.
4. Sharing and Third-Party Processors
I rely on the following third-party processors, each subject to its own privacy policy. Each provider is bound by its own published terms and privacy commitments; where a provider's standard terms include a data processing addendum, that addendum governs my use of the service. I have not separately negotiated data processing agreements.
- Stripe, Inc. (United States) — payment processing, invoicing. Receives name, email, billing address, and card details directly. stripe.com/privacy
- Google LLC (United States) — Google sign-in (authentication), Google Calendar (scheduling), Google Meet (video call hosting), Google Drive (session notes and screenshot storage), Google Cloud Storage (research conversation recordings), and Google Workspace (my business email; lifecycle email is sent through Google Apps Script under the same account — no separate third-party email vendor processes customer mail). policies.google.com/privacy
- PostHog, Inc. (United States) — product analytics. PostHog receives nothing at all until you accept analytics: its library is not loaded, and no event is sent. If you accept, it receives page views and interaction events; it sets first-party cookies only — never third-party cookies — and cross-subdomain tracking is disabled, so its identifier does not follow you onto other sites of mine. PostHog receives your IP address at the moment an event arrives, which it uses to derive an approximate location; I do not send the address as an event property. Once you sign in, your events are identified to PostHog by an internal account identifier, with your email address attached as a profile property. If you later withdraw consent, I stop sending events and delete the analytics data I hold; data PostHog already received cannot be recalled from them (§6, §8). posthog.com/privacy
- Cloudflare, Inc. (United States) — DNS and edge network layer, and Turnstile bot mitigation on the application form. Receives your IP address to run the Turnstile check. cloudflare.com/privacypolicy
- Vercel Inc. (United States) — website hosting, edge infrastructure, Vercel Web Analytics (aggregate page-view counts), and Speed Insights (page-performance measurements) — the last two run on every page regardless of your analytics choice. vercel.com/legal/privacy-policy
- GitHub, Inc. (United States) — stores the nightly database backups described in §5, in a private repository only I can read. Those backups are copies of the whole database, so they contain the same personal information the database does. docs.github.com/…/github-general-privacy-statement
- Supabase, Inc. (United States) — database for site content, user accounts, and analytics events. supabase.com/privacy
- OpenAI, L.L.C. (United States) — powers the search and question-answering features on this site. Receives the text of questions you ask and the immediately preceding turns of that conversation, in order to generate an answer for you. Your data is not used to train models. openai.com/policies/privacy-policy
- Perplexity AI, Inc. (United States) — provides web-grounded answers when you use the web search option in question-answering. Receives your question text. perplexity.ai/hub/legal/privacy-policy
- Functional Software, Inc. (dba Sentry) (United States) — error monitoring. Receives technical reports when something fails on the server, which may incidentally include details of the request you made. sentry.io/privacy
- Mapbox, Inc. (United States) — map tiles and styles on the maps this site displays, including maps on pages that do not require signing in. Receives your IP address and the map areas you look at. mapbox.com/legal/privacy
I do not share your personal data with third parties other than these processors, except (a) with your explicit consent (e.g. a published testimonial), (b) if required by law, court order, or regulator, or (c) in the unlikely event of a business transfer, in which case you would be notified in advance.
5. Data Retention
Retention periods vary by data category:
- Declined or dormant applications — up to ninety (90) days from when you applied, then automatically scrubbed: your name, email, free-text answers, the intake snapshot, any marketing-attribution fields, and any notes I wrote are removed, and an anonymized row is kept for funnel analytics. This applies to applications marked declined, not a fit, or dormant. Applications I decline outright are deleted in full at the point of decline, together with the consultation booking, consent record, and email history attached to them.
- Active customer profile, goals, journal, tech stack — retained while your account exists. You can delete your account yourself from your account privacy page (see §6): nothing is deleted for fourteen (14) days after you ask, and signing back in and cancelling within that window keeps everything; after the window, the deletion runs automatically. Deleting your account removes your profile details, goals, session journals, tech stack, learning plans and progress, notification preferences, the analytics activity tied to your account, your testimonials (published ones are taken down), and the sign-in itself. Booking and payment records, the audit log, and any do-not-email suppression entry are retained on the grounds described in this section.
- Session notes and screenshots — up to twelve (12) months from the session date. I delete these by hand; you may ask me to delete them sooner at any time. See Terms §15.
- Research conversation recordings — up to twelve (12) months from the session date, then deleted automatically. Only research conversations booked through a research booking link are recorded, only with your agreement, and you can delete the recording at any time from the manage link in your confirmation email. See Terms §15.
- Booking and payment records — retained for seven (7) years as required by Connecticut tax and accounting law. Deletion requests for these records may be refused on legal-obligation grounds.
- Analytics events — provisional events from visitors who never accepted analytics are deleted within about an hour (§3). Retained events are kept up to twenty-four (24) months, then aggregated to non-personal daily summaries and the per-event rows deleted.
- Email records — up to eighteen (18) months from last send, then deleted — except a hard-bounce or spam-complaint suppression entry, which is kept without expiry because it is the record that stops me emailing you (§1).
- Site feedback — up to twenty-four (24) months from submission, then deleted.
- Testimonials — retained while your consent stands. You may withdraw consent to publication at any time, at which point the testimonial is removed from public display; you may also ask me to delete it entirely, and deleting your account deletes it.
- Audit log — up to seven (7) years, enforced by a nightly deletion job.
- Anti-abuse data — up to ninety (90) days.
- Backups — I take a full backup of the database every night and store it in a private repository on GitHub (see §4); backups are kept for up to three (3) months, with older copies pruned automatically on a tapering schedule. I am replacing this with encrypted backups that separate customer data from site content and delete themselves sooner; until that is in place, the description here is what actually happens. My database provider also keeps a rolling seven (7) day recovery window. Data you ask me to delete is removed from the live system immediately and ages out of backups as they are pruned; I do not restore deleted records from a backup except to recover from a system failure.
6. Your Rights
Depending on where you live, you have some or all of the following rights regarding your personal data:
- Access — request a copy of the personal data I hold about you.
- Correction / rectification — request correction of inaccurate data.
- Deletion / erasure — request deletion of data that is not required to be retained on legal or contractual grounds. If you have a customer account, you can delete it yourself from your account privacy page: nothing is deleted for fourteen (14) days, signing back in and cancelling within that window keeps everything, and after the window the deletion runs automatically (§5). You can also request deletion by email at any time.
- Portability — request a copy of certain data in a machine-readable format.
- Restriction — request that I pause processing while a concern is resolved.
- Objection — object to processing based on legitimate interests (I will honor the objection unless I have a compelling overriding basis).
- Withdraw consent — withdraw consent for testimonials or marketing emails at any time, and withdraw analytics consent at any time from the “Analytics” control in the footer of every page. Withdrawing analytics consent deletes the attribution cookies this site set, stops all analytics collection and transmission, deletes the analytics events I can identify as yours, and clears any marketing-attribution fields copied onto your inquiry record. One honest limit: I cannot retract data PostHog has already received — withdrawing means I stop sending and delete what I hold, not that nothing was ever collected.
- Session notes and screenshots — request earlier deletion of notes or screenshots from your session (see Terms §15).
- Do-not-sell / do-not-share (CCPA) and opt-out signals — I do not sell or share personal information for cross-context behavioral advertising. If your browser sends an opt-out preference signal such as Global Privacy Control, I honor it as a refusal of optional analytics — on the page and on my server (§8).
- Non-discrimination — I will not discriminate against you for exercising any right under applicable privacy law.
To exercise any right, email noah@noahratzan.com. I will acknowledge within 7 days and respond substantively within 30 days (or as required by applicable law). I may need to verify your identity before fulfilling certain requests.
If you are in the EU, UK, or EEA, you also have the right to lodge a complaint with your national data protection authority; you are encouraged to contact me first so I can address your concern directly.
7. International Data Transfers
Noah Ratzan Consulting, LLC is based in the United States, and several of my processors are too: Stripe, Google, PostHog, Cloudflare, Vercel, Supabase, GitHub, OpenAI, Perplexity, Sentry, and Mapbox (each described in §4). If you are located in the EU, UK, EEA, or another jurisdiction with data-transfer restrictions, your personal data may be transferred to and processed in the United States. Where required, such transfers are made under the Standard Contractual Clauses (SCCs) adopted by the European Commission (and the UK equivalent) or under another lawful transfer mechanism made available by the processor.
8. Cookies and Similar Technologies
Your choice about analytics. When you first visit, a banner asks whether you consent to analytics. You can change your answer at any time using the “Analytics: on / Analytics: off” control at the bottom of every page. If your browser sends a Global Privacy Control (GPC) signal, I treat that as a refusal: nothing optional loads, the banner is not shown, and the footer control is hidden. Until you answer the banner, nothing about your visit is stored in your browser, and anything recorded on my server is provisional and deleted within about an hour unless you accept (§3). If you accept analytics and later change your mind, I stop sending events to PostHog and delete the analytics data I hold; data PostHog already received before you withdrew cannot be recalled from them.
Cookies I set. No optional cookie is set before you answer the banner.
| Cookie | What it is for | How long | Category |
|---|---|---|---|
sb-…-auth-token (and related sign-in cookies) | Keeps you signed in | 7 days, refreshed as you use the site | Strictly necessary |
nrz_consent | Remembers your analytics choice | 1 year | Strictly necessary |
nrz_first_touch | The campaign link, referring site, and page you first arrived on | 90 days | Optional (analytics) — set only after you accept |
nrz_last_touch | The same, for your most recent arrival | Until you close the browser | Optional (analytics) — set only after you accept |
ph_…_posthog | PostHog's identifier for your browser, on this domain only | 1 year | Optional (analytics) — set only after you accept |
nrc_internal_device | Marks my own browser so my visits are excluded from visitor counts; only ever issued to me | 1 year | Strictly necessary |
I do not use advertising cookies, and no cookie I set is readable by any other website.
Browser storage. I also use your browser's local storage. Your analytics choice is stored there as well as in a cookie, so clearing cookies alone does not reset it. If you accept analytics, PostHog stores its identifiers there too; withdrawing consent clears them. If you are signed in as an administrator, some interface preferences are stored locally as well. None of this leaves your browser except as described in §4.
Embedded content from other companies. Some pages load content served by third parties, which may set their own cookies when it loads: Stripe (the payment form, including its fraud-check frame), Cloudflare Turnstile (the bot check on the application form), Mapbox (maps), and video players (YouTube, Vimeo, Loom — nothing is loaded until you click play). Their own privacy policies govern what they store.
If you prefer, you can disable cookies entirely in your browser; sign-in will not work without them.
9. Security
I use industry-standard security practices: HTTPS everywhere, encrypted database connections, encrypted OAuth tokens, scoped admin access with two-factor authentication, rate limiting on high-risk endpoints, and audit logging of administrative actions. No system is perfectly secure; I cannot guarantee absolute security but I take reasonable precautions. In the event of a security incident that affects your personal data, I will notify you and, where required, the applicable regulator, within the timeframes required by law.
10. Children's Privacy
My services are directed to adult professionals, researchers, and practitioners. I do not knowingly collect personal information from individuals under the age of 16. If you believe a minor has submitted data, please email noah@noahratzan.com and I will delete it promptly.
11. Governing Law
This Privacy Policy is governed by the laws of the State of Connecticut, USA. For any questions or concerns about this policy, contact noah@noahratzan.com.
12. Changes to This Policy
I may update this policy as services evolve. Changes take effect when posted at this URL, and the “Last updated” date below reflects the most recent revision. I do not currently send change notifications; the version posted here is the authoritative one, and the date below is the record of when it last changed.
Last updated: September 2, 2026