Who is responsible
The data controller is Zion Boggan, operating The Governed Agent Lab. Contact: support@zionclickcreate.com.
What we actually collect
| Data | Why |
|---|---|
| Email address | Your account identity, receipts, and announcements. For Blueprint buyers it is the immutable checkout email that opens the private workspace. |
| Payment references | Card data goes only to Stripe's hosted checkout. We store Stripe's payment and customer references, never card numbers. We see your name, email, and the card issuer country, which sets your membership tier. |
| Blueprint application answers | Business contact details, the problem you want mapped, and the numbers behind it (inquiry volume, response time, average sale, costs). Used to decide fit, book the call, and deliver the work. |
| Usage on owned platforms | Community activity on Skool, workspace sign-ins, and funnel events (application, call booked, payment, onboarding). Used to run the service and keep an audit record of access decisions. |
| Newsletter subscription | If you opt in, your email goes to Beehiiv for delivery. Unsubscribe links are in every issue. |
What we never do
- We do not sell, rent, or trade your personal data. To anyone, for any price. There is no exception to write here because there is no exception.
- We do not run ad-network tracking. No Google Analytics, no Meta pixel, no TikTok pixel, no session recording, no fingerprinting.
- We do not buy audiences. No lookalike uploads, no list purchases, no scraping your profile.
- We do not send your data to models for training. Client materials submitted in the Blueprint application stay out of any AI training pipeline.
Who processes data with us
- Stripe: hosted checkout, payment records, receipts, and the customer billing portal. Card data stays on Stripe's pages under their terms.
- Skool: community hosting and membership billing for the Lab.
- Cloudflare: page serving, database, event queue, and one-time-code access control for the Blueprint path.
- Beehiiv: newsletter delivery, only if you subscribe.
Each has its own privacy notice for the parts they operate. We hand them the minimum needed to provide their function.
How long we keep things
Application and payment records are kept while the relationship is active and for any longer period tax, fraud-prevention, or dispute rules require. Access audit records follow the same rule. Server logs rotate within 90 days.
Your rights
Wherever you live, you get at least this baseline:
- Access: ask what we hold about you and get a copy.
- Correction: fix anything wrong.
- Deletion: ask us to delete your data. Records we must legally keep (tax, fraud prevention) are kept as long as required and no longer.
- Portability: get your data in a machine-readable format.
- Sale opt-out (CCPA): trivially satisfied, since we do not sell data. You are permanently opted out by default.
- Non-discrimination (CCPA): exercising these rights never changes your price or access tier.
To use any right, email the mailbox below from the address on the account. We respond within 30 days.
Security
The Blueprint purchase path runs approval-gated checkout, stores the public application token only as a one-way hash, and keeps admin surfaces behind separate access controls. Payment integrity is enforced server-side: the browser cannot set a price. No system is perfect, but the design principle is simple: collect little, expose less, log everything that touches access.
Contact
Privacy questions and rights requests: support@zionclickcreate.com. Never send card details or copies of identity documents by email unless we ask for them in a support thread.