Privacy Policy
Privacy Policy
Last Updated: March 27, 2026
Effective Date: January 2025
Company: LifePreneur, LLC
Address: 6100 W Gila Springs Pl, Suite 25, Chandler, AZ 85226
Contact: support@lifepreneur.com
1. OVERVIEW
This Privacy Policy explains how LifePreneur, LLC ("Company," "we," "us," or "our") collects, uses, stores, and protects personal information when you access or use the LifePreneur Platform and any associated services ("Platform" or "Service").
By using our website at lifepreneur.com, purchasing a subscription or any product, or accessing our Discord community, you acknowledge that you have read and understood this Privacy Policy.
Our Commitment: We are committed to protecting your privacy and complying with applicable data protection laws, including the General Data Protection Regulation (GDPR) and California Consumer Privacy Act (CCPA).
2. INFORMATION WE COLLECT
We collect different types of personal data depending on how you interact with our Platform. We distinguish between Essential Data (required to provide the Service) and Optional Data (collected only with your consent).
Essential Data (Always Collected)
Required to provide you with access to the Program and fulfill our contract with you:
Account & Identity Information
- Full name
- Email address
- Password (encrypted, never stored in plain text)
- Account creation date
- User ID (randomly generated)
Payment Information
- Billing name and email
- Payment method details (processed and stored securely by Stripe)
- Transaction history and purchase records
- Subscription status and plan type
- Refund and cancellation records
Discord Community Access
- Discord username and user ID
- Discord profile information (avatar, display name)
- Server join date and role assignments
- Community participation status
- User-generated content posted in community channels (messages, reactions)
Affiliate Program Data (If You Use a Referral Link or Become an Affiliate)
- Referral source and affiliate code
- Referrer information (who referred you)
- Conversion data (if you purchase via affiliate link)
- Affiliate dashboard access (if you become an affiliate)
- PayPal email address (for affiliate payouts)
- Earnings and commission records
Technical & Security Data
- IP address (for security and fraud prevention)
- Browser type and version
- Device type (desktop, mobile, tablet)
- Operating system
- Session data and authentication tokens
- CSRF protection tokens
- Login history and security events
- Geographic location (country/region level, not precise GPS)
Support & Communication Records
- Support ticket history and correspondence
- Email communications regarding your account
- Feedback and survey responses (if provided voluntarily)
Optional Data (Collected Only With Your Consent)
We will ask for your explicit consent before collecting or using:
Analytics Data
- Page views and navigation patterns
- Time spent on pages
- Feature usage statistics
- Traffic source information
- Anonymous usage metrics (via Vercel Analytics)
Marketing & Advertising Data (Future Use Only)
- Ad campaign interactions (not currently active)
- Marketing preferences
- Behavioral data for targeted advertising (requires future consent)
Important: You can withdraw consent for optional data collection at any time without affecting your access to the Program.
Data We Do NOT Collect
We do not collect:
- Social Security numbers or government ID numbers
- Precise geolocation data (GPS coordinates)
- Biometric data
- Health or medical information
- Political or religious beliefs
- Trade union membership
- Data from children under 18 (see Section 12)
3. LEGAL BASIS FOR PROCESSING (GDPR)
Under GDPR Article 6, we process your personal data based on the following legal grounds:
| Data Type | Legal Basis | GDPR Article |
|---|---|---|
| Account & identity information | Contract performance | Article 6(1)(b) |
| Payment information | Contract performance | Article 6(1)(b) |
| Discord access data | Contract performance | Article 6(1)(b) |
| Affiliate tracking | Legitimate business interest | Article 6(1)(f) |
| Security & fraud prevention | Legitimate business interest | Article 6(1)(f) |
| Support communications | Contract performance | Article 6(1)(b) |
| Marketing emails (promotional) | Consent | Article 6(1)(a) |
| Optional analytics | Consent | Article 6(1)(a) |
| Legal compliance | Legal obligation | Article 6(1)(c) |
Legitimate Interest: Where we rely on legitimate interests, we have balanced our business needs against your privacy rights and determined that processing is necessary and proportionate.
4. HOW WE COLLECT INFORMATION
We collect information through various methods:
Direct Collection
- Account Registration: When you create an account (after purchasing)
- Purchase Process: When you complete a payment via Stripe
- Discord OAuth: When you connect your Discord account
- Affiliate Sign-up: When you join our affiliate program via Rewardful
- Contact Forms: When you submit a support request or contact us
- Onboarding: When you complete the onboarding questionnaire
Automatic Collection
- Cookies: See our Cookie Policy for complete details
- Session Tracking: Authentication tokens to keep you logged in
- Security Monitoring: IP addresses and login patterns to prevent fraud
- Analytics: Anonymous usage data (with your consent)
Third-Party Sources
- Stripe: Payment verification and subscription status
- Discord: Profile information when you authorize OAuth access
- Rewardful: Affiliate referral attribution data
5. HOW WE USE YOUR INFORMATION
We use your personal data for the following purposes:
Essential Service Delivery
To provide and maintain your access to the Program:
- Create and manage your account
- Process payments and subscriptions
- Verify your identity and authenticate logins
- Grant access to Discord community
- Deliver training materials and Platform features
- Process refunds and cancellations
- Provide customer support
Legal Basis: Contract performance (GDPR Article 6(1)(b))
Security & Fraud Prevention
To protect our Platform and users:
- Detect and prevent fraudulent purchases
- Monitor for unauthorized access attempts
- Enforce our Terms of Service
- Prevent abuse or misuse of the Platform
- Maintain system security and integrity
Legal Basis: Legitimate business interest (GDPR Article 6(1)(f))
Affiliate Program Management
To fairly compensate creators who refer new members:
- Track referral sources via Rewardful
- Attribute purchases to affiliates
- Process affiliate payouts via PayPal
- Provide affiliate performance dashboards
- Manage affiliate relationships
Legal Basis: Legitimate business interest (GDPR Article 6(1)(f))
Communication & Support
To keep you informed and help you succeed:
- Send transactional emails (login, purchase confirmation, receipts)
- Provide customer support responses
- Send important Platform updates and announcements
- Deliver training reminders and access instructions
- Notify you of security or account issues
Legal Basis: Contract performance (GDPR Article 6(1)(b))
Optional Uses (Require Your Consent)
Marketing Communications:
- Promotional offers and new features
- Educational content and tips
- Event announcements
- Affiliate opportunities
Analytics & Improvement:
- Understand how users interact with the Platform
- Identify popular features and content
- Improve user experience and performance
- Develop new features based on usage patterns
Legal Basis: Consent (GDPR Article 6(1)(a)) - Can be withdrawn at any time
Legal Compliance
To meet our legal obligations:
- Respond to legal requests and court orders
- Comply with tax and financial regulations
- Maintain records for audit purposes
- Protect our legal rights
Legal Basis: Legal obligation (GDPR Article 6(1)(c))
6. DATA SHARING & THIRD-PARTY SERVICES
We share your information only with trusted service providers necessary to deliver the Program. We never sell your personal data to third parties.
For a complete list of all third-party services that may process your data, see our Subprocessors page.
Essential Third-Party Services
Payment Processing
Stripe
- Purpose: Process customer payments and manage subscriptions
- Data Shared: Name, email, payment method, transaction details
- Privacy Policy: stripe.com/privacy
- Location: United States (GDPR-compliant)
- Control: Required for payment processing (cannot opt out)
PayPal
- Purpose: Process affiliate commission payouts only (not customer payments)
- Data Shared: Email address, payout amount, affiliate earnings
- Privacy Policy: paypal.com/privacy
- Control: Required only if you become an affiliate
Authentication & Security
Better Auth
- Purpose: Secure authentication and session management
- Data Shared: Email, encrypted password, session tokens
- Type: Open-source, self-hosted (data stays on our servers)
- Privacy Policy: better-auth.com
- Control: Required for account access (cannot opt out)
Community Access
Discord
- Purpose: Provide access to private community server
- Data Shared: Discord username, user ID, profile information, community messages
- Privacy Policy: discord.com/privacy
- Location: United States
- Control: Required to access community features
- Important: Messages you post in Discord are subject to Discord's privacy policy and community moderation
Affiliate Program
Rewardful
- Purpose: Track referrals and manage affiliate program
- Data Shared: Referral codes, conversion data, affiliate IDs
- Privacy Policy: getrewardful.com/privacy
- Location: United States
- Control: Only active if you use an affiliate link or become an affiliate
- Cookies: See our Cookie Policy for Rewardful cookie details
Database & Hosting
Vercel
- Purpose: Host our Platform and provide infrastructure
- Data Shared: All data you provide (stored securely on our servers)
- Privacy Policy: vercel.com/legal/privacy-policy
- Location: United States (GDPR-compliant)
PostgreSQL Database
- Purpose: Store your account, subscription, and Platform data
- Type: Self-managed database with encrypted backups
- Location: Secure servers with access controls
File Storage
AWS S3 / Cloudflare R2
- Purpose: Store user avatars, testimonial images, and uploaded files
- Data Shared: Files you upload (profile pictures, etc.)
- Privacy Policy: AWS Privacy / Cloudflare Privacy
- Location: Secure S3-compatible storage with encryption
Email Services
Multiple Providers Available (Resend, Postmark, Mailgun, Plunk)
- Purpose: Send transactional and marketing emails
- Data Shared: Email address, name, email content
- Control: You can unsubscribe from marketing emails; transactional emails are required
Optional Third-Party Services (Require Your Consent)
Analytics
Vercel Analytics
- Purpose: Privacy-friendly anonymous usage statistics
- Data Shared: Page URLs, referrer, browser type, geographic region (country/city)
- Type: Server-side tracking (no cookies in your browser)
- Privacy Policy: vercel.com/docs/analytics/privacy-policy
- Privacy-Friendly: Does not collect IP addresses, user identifiers, or cross-site tracking
- Control: You can opt out via our cookie banner
- Default: Disabled until you consent
Future Third-Party Services (Not Currently Active)
We may add these services in the future. We will notify you and request fresh consent before activation:
- Google Analytics: Website analytics
- Meta (Facebook) Pixel: Advertising and retargeting
- TikTok Pixel: Advertising and tracking
- Google Ads: Paid advertising campaigns
Important: Check the "Last Updated" date at the top of this policy. If we add new tracking services, we will update this policy and notify you via email or Platform announcement.
7. INTERNATIONAL DATA TRANSFERS
Primary Location: Our servers and most third-party services are located in the United States.
For EU/UK Users:
If you access the Platform from the European Union or United Kingdom, your personal data will be transferred to and processed in the United States, which may have different data protection laws than your country.
Safeguards We Use:
- Standard Contractual Clauses (SCCs): We use EU-approved Standard Contractual Clauses with third-party processors
- GDPR Compliance: All third-party services are selected for GDPR compliance
- Encryption: Data is encrypted in transit (TLS/SSL) and at rest
- Access Controls: Limited access to personal data on a need-to-know basis
- Data Protection Agreements: Written agreements with all processors
Your Rights: EU/UK users retain all GDPR rights regardless of where data is processed (see Section 10).
8. DATA RETENTION
We retain your personal information only as long as necessary to fulfill the purposes described in this Privacy Policy or as required by law.
Retention Periods
| Data Type | Retention Period | Reason |
|---|---|---|
| Account information | Duration of account + 7 years | Legal/tax compliance, dispute resolution |
| Payment records | 7 years after transaction | Tax regulations, financial audits |
| Subscription history | Duration of subscription + 7 years | Billing disputes, legal compliance |
| Discord community data | Duration of membership | Community management |
| Support tickets | 3 years after resolution | Customer service quality |
| Session cookies | 30 days or until logout | Authentication |
| Affiliate data | 7 years after last payout | Tax compliance, commission disputes |
| Analytics data (aggregated) | Indefinitely | Business intelligence (cannot identify you) |
| Analytics data (raw) | 90 days | Privacy protection |
| Marketing consent records | Until consent withdrawn + 3 years | Compliance proof |
| Deleted account data | 30-90 days (backup retention) | Recovery period, then permanently deleted |
Account Deletion
When you delete your account or request data deletion:
- Your account is immediately deactivated
- Personal data is removed from active systems within 30 days
- Backup systems are purged within 90 days
- We may retain anonymized/aggregated data that cannot identify you
- We retain certain records for legal compliance (e.g., tax records for 7 years)
9. SECURITY MEASURES
We implement industry-standard technical and organizational safeguards to protect your personal data:
Technical Protections
- Encryption in Transit: All data transmitted via TLS 1.3 encryption (HTTPS)
- Encryption at Rest: Database and file storage encrypted
- Password Security: Passwords are hashed using bcrypt (never stored in plain text)
- Session Security: HttpOnly, Secure cookies in production
- CSRF Protection: Tokens protect against cross-site request forgery
- SQL Injection Prevention: Parameterized queries via Prisma ORM
- Regular Security Updates: Dependencies and infrastructure kept current
Organizational Protections
- Access Controls: Limited employee/contractor access on need-to-know basis
- Authentication: Multi-factor authentication for admin accounts
- Logging & Monitoring: Security events logged and monitored
- Incident Response Plan: Procedures for security breach response
- Vendor Security: All third-party services vetted for security practices
- Regular Audits: Periodic security reviews and vulnerability assessments
Limitations
Important: No online system is 100% secure. While we implement reasonable safeguards, we cannot guarantee absolute security. You acknowledge that you share information at your own risk.
Your Responsibility:
- Use a strong, unique password
- Enable two-factor authentication (if available)
- Do not share your login credentials
- Log out on shared devices
- Report suspicious activity immediately to support@lifepreneur.com
10. YOUR PRIVACY RIGHTS
You have important rights regarding your personal data. These rights vary depending on your location.
Rights for All Users
Access: Request a copy of the personal data we hold about you
Correction: Request correction of inaccurate or incomplete data
Deletion: Request deletion of your personal data (subject to legal retention requirements)
Object: Object to certain types of processing (e.g., marketing)
Withdraw Consent: Withdraw consent for optional data processing at any time (no penalties)
Contact Us: Exercise any of these rights by emailing support@lifepreneur.com
Additional Rights for EU/UK Users (GDPR)
Data Portability: Receive your data in machine-readable format (JSON/CSV)
Restriction: Request restriction of processing in certain circumstances
Automated Decision-Making: We do not use automated decision-making or profiling
Supervisory Authority: Right to lodge a complaint with your local Data Protection Authority
No Discrimination: Exercising your rights will not result in discriminatory treatment
Additional Rights for California Users (CCPA)
Know: Know what personal information is collected, used, and shared
Delete: Request deletion of personal information (with exceptions)
Opt-Out: Opt-out of sale of personal information (we do not sell your data)
Non-Discrimination: Equal service and pricing regardless of privacy choices
Authorized Agent: Designate an authorized agent to make requests on your behalf
How to Exercise Your Rights
Email: support@lifepreneur.com with "Privacy Request" in subject line
Include:
- Your full name and email address associated with your account
- Specific request (access, deletion, correction, etc.)
- Verification information (we may ask security questions to confirm identity)
Response Time:
- GDPR requests: 30 days
- CCPA requests: 45 days
- We will notify you if we need additional time
Verification: We may request additional information to verify your identity before processing requests (to protect your privacy).
Limitations on Rights
We may deny or limit requests if:
- Required by law to retain data (e.g., tax records)
- Necessary to complete transactions or provide services
- For security and fraud prevention
- To defend legal claims
- We cannot verify your identity
11. COOKIES & TRACKING TECHNOLOGIES
We use cookies and similar tracking technologies to provide and improve the Platform.
For complete details, please see our Cookie Policy, which explains:
- What cookies we use (essential and optional)
- How to manage cookie preferences
- Third-party tracking services
- Analytics and advertising cookies (future use)
Summary:
Essential Cookies (Always Active):
- Authentication tokens (Better Auth session cookies)
- CSRF protection tokens
- Language preferences
- Affiliate tracking (Rewardful)
Optional Cookies (Require Consent):
- Vercel Analytics (privacy-friendly, no browser cookies)
Your Control: Manage cookie preferences via our cookie banner or browser settings. Disabling essential cookies will prevent you from logging in.
12. CHILDREN'S PRIVACY
The Platform is not intended for individuals under 18 years old. We do not knowingly collect personal information from children or minors.
If you are under 18: Do not use the Platform, create an account, or provide any personal information.
For Parents/Guardians: If you believe a minor under 18 has provided us with personal information, contact us immediately at support@lifepreneur.com. We will delete such information promptly.
Age Verification: By using the Platform, you represent that you are at least 18 years old.
13. MARKETING COMMUNICATIONS & CONSENT
We send different types of emails, and you have control over what you receive.
Transactional Emails (Cannot Opt Out)
These are essential to provide the Service:
- Purchase confirmations and receipts
- Account creation and login notifications
- Password reset requests
- Subscription status changes (renewals, cancellations, payment failures)
- Discord invite links
- Security alerts
- Customer support responses
- Terms/Policy updates
Legal Basis: Contract performance (GDPR Article 6(1)(b))
Marketing Emails (Can Opt Out)
Promotional content requires your consent:
- New feature announcements
- Educational content and tips
- Special offers or promotions
- Affiliate program opportunities
- Event invitations
- Community updates
Legal Basis: Consent (GDPR Article 6(1)(a))
How to Opt Out:
- Click "Unsubscribe" link in any marketing email
- Email support@lifepreneur.com with "Unsubscribe" in subject
- Update preferences in your account settings (when available)
Important: Opting out of marketing emails does NOT opt you out of transactional emails (which are required to provide the Service).
Double Opt-In (EU Users)
For EU users, we use double opt-in for marketing consent:
- You provide your email and consent to marketing
- We send a confirmation email
- You click the confirmation link to verify
This ensures explicit, verifiable consent as required by GDPR.
14. THIRD-PARTY LINKS & EXTERNAL WEBSITES
Our Platform may contain links to external websites or services that we do not control:
- Payment processors (Stripe checkout pages)
- Discord community servers
- Affiliate partner websites
- Educational resources and tools
- Social media platforms
Important: This Privacy Policy does not apply to third-party websites. Each external service has its own privacy policy and data practices.
Your Responsibility: Review the privacy policies of any third-party services you use. We are not responsible for the privacy practices, content, or security of external websites.
Discord Community: When you join our Discord server, your activity there is subject to Discord's Privacy Policy and our community guidelines.
15. BUSINESS TRANSFERS
If LifePreneur, LLC is involved in a merger, acquisition, asset sale, or bankruptcy:
- Your personal data may be transferred as part of that transaction
- We will notify you via email and/or Platform announcement before any transfer
- The acquiring entity will be bound by this Privacy Policy (or you will be given the opportunity to consent to a new policy)
- You will have the right to delete your account before any transfer
16. FUTURE SERVICES & PLANNED INTEGRATIONS
As we improve the Platform, we may implement additional services or tracking technologies.
Planned Future Integrations
Marketing & Advertising (Not Currently Active):
- Google Ads (paid advertising)
- Meta (Facebook) Pixel (retargeting and advertising)
- TikTok Pixel (advertising and analytics)
- Additional marketing automation tools
Enhanced Analytics (Not Currently Active):
- Google Analytics (website analytics)
- Heatmaps and session recording tools
- A/B testing platforms
Important Commitments:
- Notice Before Activation: We will update this Privacy Policy BEFORE implementing any new tracking or data collection services
- Fresh Consent Required: For material changes that require consent, we will:
- Update the "Last Updated" date at the top
- Notify you via email or Platform announcement
- Request fresh consent via our cookie banner (where applicable)
- Give you the opportunity to opt out
- No Retroactive Consent: We will not retroactively apply new tracking to past data without explicit consent
- Transparency: The updated policy will clearly identify what new services are being added and why
Stay Informed: We recommend reviewing this Privacy Policy periodically to stay informed of any changes.
17. UPDATES TO THIS PRIVACY POLICY
We may update this Privacy Policy at any time to reflect:
- Changes in our data practices or technology stack
- New features or services
- Legal or regulatory requirements
- User feedback and privacy best practices
- Changes in third-party service providers
When We Update This Policy
The "Last Updated" date at the top will change to reflect the most recent revision.
For Minor Changes (e.g., clarifications, contact information updates):
- Changes become effective immediately upon posting
- Continued use of the Platform constitutes acceptance
For Material Changes (e.g., new data collection, tracking technologies, sharing practices):
- We will notify you via email or prominent Platform notice
- For changes requiring consent, we will request fresh consent before implementation
- You will have the opportunity to review changes before they take effect
- If you do not agree, you may delete your account
Your Responsibility: We recommend reviewing this Privacy Policy periodically (check the "Last Updated" date).
Archive: Previous versions of this policy are available upon request by emailing support@lifepreneur.com.
18. CONTACT INFORMATION & DATA PROTECTION
For questions, concerns, or requests regarding your privacy, personal data, or this Privacy Policy, please contact:
LifePreneur, LLC
6100 W Gila Springs Pl, Suite 25
Chandler, AZ 85226
United States
Email: support@lifepreneur.com
Website: https://lifepreneur.com
For Privacy-Specific Inquiries: Use subject line "Privacy Request" or "GDPR Request"
Privacy Officer: For GDPR-related inquiries, you may request to speak with our designated privacy officer.
Response Time: We aim to respond to all privacy inquiries within 3 business days, though formal data requests may take up to 30-45 days depending on jurisdiction and complexity.
For EU/UK Users
Data Protection Authority: If you believe your data protection rights have been violated, you have the right to lodge a complaint with your local supervisory authority:
- EU: Find your Data Protection Authority at edpb.europa.eu
- UK: Information Commissioner's Office (ICO) at ico.org.uk
We encourage you to contact us first so we can address your concerns directly.
For California Users
California Privacy Rights: Email support@lifepreneur.com with "CCPA Request" in subject line
Authorized Agent: If using an authorized agent, provide written authorization and proof of identity
This Privacy Policy is designed to comply with GDPR, CCPA, and other applicable privacy regulations.
Transparency Commitment: We believe in clear, honest communication about how we handle your data. If you have questions or concerns about any part of this policy, please reach out—we're here to help.
Last reviewed and verified accurate: March 27, 2026