PRIVACY POLICY

Effective Date: May 22, 2026

This Privacy Policy describes how Greg Rubbert ("I," "me," or "my"), operating gregrubbert.com (the "Site"), collects, uses, and protects information when you visit the Site, make a purchase, receive an invoice, submit a contact form, or sign up for email communications. Payments are handled through two processors depending on context: Paddle for store purchases, and Squarespace Payments for invoices. Both are described in detail below.

1. Information Collected

The following categories of information may be collected when you use this Site:

a) Information you provide directly:

  • Name and email address submitted through the contact form

  • Name and email address submitted when signing up for the newsletter

  • Any message content or details included in contact form submissions

b) Store purchase data (processed by Paddle):

  • Billing address and payment details — collected and stored solely by Paddle

  • Order history and transaction records

c) Invoice payment data (processed by Squarespace Payments):

  • Name, email address, phone number, and billing address provided when paying an invoice

  • Payment details — processed by Stripe on behalf of Squarespace Payments

  • Invoice details such as line items and payment history

As you complete invoice checkout, this Site may auto-complete your billing address by sharing what you type with the Google Places API, which returns address suggestions to improve your checkout experience.

d) Information collected automatically by Squarespace:

  • Browser type, network, and device information

  • Web pages you visited prior to arriving at this Site

  • Web pages you viewed while on this Site

  • Your IP address

  • Clicks, internal links, pages visited, scrolling, searches, and timestamps

2. How I Use Your Information

Information collected is used to:

  • Fulfill store orders and deliver digital products you purchase

  • Send and collect payment for invoices

  • Respond to contact form submissions and provide customer support

  • Send transactional emails related to your purchase or account activity

  • Send newsletter communications you have opted into

  • Understand how visitors use this Site and improve it over time

  • Comply with applicable legal and tax obligations

3. Cookies

This Site uses cookies and similar technologies — small files that download to your device when you visit a website. Two categories are used:

  • Necessary and required cookies: Always active. These allow Squarespace, this Site's hosting platform, to securely serve the Site to you.

  • Analytics and performance cookies: Used to understand site traffic and activity. These are only placed after you acknowledge the cookie consent banner displayed on the Site.

You can view details about the specific cookies Squarespace uses at squarespace.com/privacy. You may also adjust cookie preferences through your browser settings at any time.

4. Store Purchases — Paddle

Digital product purchases made through the Site's store are processed by Paddle (paddle.com), who acts as the Merchant of Record for those transactions. When you complete a store purchase, you are transacting directly with Paddle. Your payment information is collected, stored, and secured solely by Paddle and is subject to Paddle's Privacy Policy at paddle.com/legal/privacy. I do not store or have access to your full payment details.

As Merchant of Record, Paddle handles applicable sales tax, VAT/GST collection, and compliance with consumer transaction laws across jurisdictions on my behalf.

5. Invoice Payments — Squarespace Payments

Invoice payments are processed through Squarespace Payments, a native payment solution provided by Squarespace. I provide your contact and invoice information to Squarespace so they can deliver invoicing services on my behalf. Squarespace Payments uses the following third-party service providers, which also receive your personal information and process it under their own privacy policies:

  • Stripe — payment processing services. Privacy policy: stripe.com/privacy

  • Sift — fraud monitoring and detection services. Privacy policy: sift.com/service-privacy

I do not store your full payment card details.

6. Transactional Emails

I may send you emails related to your order or account activity. For example, you may receive an email confirming a purchase, notifying you that an invoice has been sent or paid, or providing access to a digital product. These transactional emails are necessary to our relationship and it is not possible to unsubscribe from them. I provide your contact information to Squarespace so they can send these emails on my behalf.

7. Contact Form

When you submit information through the contact form on this Site, I collect the data you enter — typically your name, email address, and message — in order to respond to your inquiry. This information is provided to and stored by Squarespace as part of their website hosting services. I retain contact form submissions for up to two years, or longer if an ongoing business relationship requires it.

8. Email Newsletter

If you sign up for the newsletter, I collect your name and email address to send you updates and communications. I provide this information to Squarespace, my email marketing provider, so they can send these emails on my behalf and help me manage my relationship with you. You can unsubscribe at any time by clicking the unsubscribe link at the bottom of any newsletter email. I will not send you marketing emails without your consent.

9. Squarespace Hosting and Analytics

This Site is hosted by Squarespace. Squarespace collects personal data about visitors to run this website and to protect and improve its platform and services. This includes browser, network, and device information, IP addresses, and browsing behavior on this Site. I provide this information to Squarespace, our website hosting provider, so they can provide website services to us. You can read more about how Squarespace uses your data in their Privacy Policy at squarespace.com/privacy.

10. Fonts

This Site uses font files served by Google Fonts and Adobe Fonts to display text. To render fonts properly, these services may receive information about your browser, network, device, and IP address. This is a standard part of how web fonts are delivered.

11. Sharing of Information

I do not sell or rent your personal information. Information may be shared with:

  • Paddle — for store payment processing, order fulfillment, and commerce compliance

  • Squarespace — for website hosting, analytics, invoicing, email campaigns, and form storage

  • Stripe — for invoice payment processing via Squarespace Payments

  • Sift — for fraud monitoring via Squarespace Payments

  • Google Places API — for billing address auto-complete during invoice checkout

  • Google Fonts / Adobe Fonts — for font rendering (browser, device, and IP data only)

  • Legal or regulatory authorities — if required by applicable law or to protect my legal rights

12. Data Security

I take reasonable technical and organizational precautions to protect personal information from unauthorized access, disclosure, alteration, or destruction. No method of internet transmission or electronic storage is completely secure, and I cannot guarantee absolute security. Paddle, Squarespace, Stripe, and Sift each maintain their own security programs for data they process on their respective platforms.

13. Data Retention

I retain contact form submissions and direct communications for up to two years unless a longer period is required by law or an ongoing business relationship warrants it. Newsletter subscriber data is retained until you unsubscribe. Transaction records held by Paddle and Squarespace Payments are retained according to their respective data retention policies.

14. International Visitors — GDPR (EU/UK)

If you are located in the European Union or United Kingdom, the General Data Protection Regulation (GDPR) or UK GDPR may apply to the processing of your personal data. The legal bases I rely on for processing are:

  • Contract performance — to process purchases, deliver products, and fulfill invoices

  • Legitimate interests — to operate and improve this Site and respond to inquiries

  • Consent — to send newsletter communications you have opted into

  • Legal obligation — to comply with applicable laws and tax requirements

As an EU or UK visitor, you have the following rights regarding your personal data:

  • Right to access — request a copy of the data held about you

  • Right to rectification — request correction of inaccurate data

  • Right to erasure — request deletion of your data in certain circumstances

  • Right to restriction — request that processing of your data be limited

  • Right to data portability — receive your data in a structured, machine-readable format

  • Right to object — object to processing based on legitimate interests

  • Right to withdraw consent — for newsletter communications, unsubscribe at any time

To exercise any of these rights, contact me at info@gregrubbert.com. For data held by Paddle, contact Paddle directly at paddle.com. For data held by Squarespace or its sub-processors (Stripe, Sift), refer to squarespace.com/privacy.

Regarding the EU right of withdrawal: For digital products made available immediately upon purchase, buyers acknowledge at checkout that the right of withdrawal is waived once delivery begins. Paddle manages this consent process as part of the store purchase flow.

15. California Visitors — Privacy Rights

Although this is a small independent business and may not meet the formal thresholds that trigger mandatory CCPA/CPRA obligations, I am committed to transparency. As a matter of good practice, California visitors may:

  • Request to know what personal information I have collected about them

  • Request deletion of personal information I hold directly

  • Be informed that I do not sell or share personal information with third parties for their own marketing purposes

To make any such request, contact me at info@gregrubbert.com.

16. Children's Privacy

This Site is not directed to children under the age of 13. I do not knowingly collect personal information from children. If you believe a child has submitted personal information through this Site, please contact me and I will promptly remove it.

17. Changes to This Policy

I may update this Privacy Policy from time to time to reflect changes in practices or applicable law. Updated versions will be posted on this page with a revised effective date. For significant changes, I will make reasonable efforts to provide notice. Continued use of the Site after the effective date of any update constitutes your acknowledgment of the revised policy.

18. Contact

For questions, concerns, or to exercise your privacy rights, contact me at: info@gregrubbert.com