Blacksheep Mind

Privacy Policy

Last updated:

This policy explains what personal information BlacksheepMind collects, why we collect it, who we share it with, and the choices and rights you have. BlacksheepMind is run by [LEGAL ENTITY NAME] (“we,” “us”), which is the controller of your personal information. It applies to visitors and customers worldwide, and includes extra information for people in the European Economic Area (EEA), the United Kingdom and California.

1. Who we are

[LEGAL ENTITY NAME], [REGISTERED ADDRESS]. You can reach us about anything in this policy at [CONTACT EMAIL].

EU representative: [EU REPRESENTATIVE NAME AND ADDRESS, IF REQUIRED]. UK representative: [UK REPRESENTATIVE NAME AND ADDRESS, IF REQUIRED].

2. Information we collect

Account information: your name, email address and password. Passwords are stored only as a secure one-way hash, never in readable form.

Order information: what you bought, the price, currency and date, your country, an optional phone number, any discount code used, and payment references from Stripe. Stripe collects your card or wallet details directly; we never see or store your full card number.

Coaching information: if you book coaching, your contact details and anything you choose to share with us while scheduling and during sessions.

Reading and account activity: your reading progress (including the furthest page you have reached in each book), notes and highlights, reading streaks, reviews and email preferences.

Technical and security information: sign-in sessions, IP address, approximate country (detected from your IP address by our network provider), browser and device type. We use this to keep accounts secure, limit concurrent sign-ins and prevent fraud.

Marketing and referral information: how you first found us (for example, campaign tags in a link and the referring website), and, if you arrived through a partner’s link, which partner referred you.

Partner information: if you join BlacksheepMind Partners, your partner profile, referral statistics, commission records, and the payout details you give us (such as a PayPal email address or bank account details).

Messages: anything you send us by email, such as support or refund requests.

3. How we use your information and our legal bases

To provide what you bought (contract): creating and running your account, processing payments, giving you access to books in the reader, saving your progress, scheduling and delivering coaching, sending receipts and essential account emails such as sign-in links and password resets, and handling refunds.

To run and protect the store (legitimate interests): preventing fraud, account sharing and abuse; keeping the site secure; understanding which campaigns and partners bring customers; measuring our advertising; running the Partners program; sending customers emails about similar books and offers (which you can turn off at any time); and improving our books and features. We balance these interests against your rights, and you can object at any time (see section 9).

With your consent: placing advertising pixels and non-essential cookies in your browser and sharing hashed identifiers with advertising platforms (see section 4), and, where the law requires consent, sending you marketing emails. You can withdraw your consent at any time; this does not affect anything we did before you withdrew it.

To meet legal obligations (legal obligation): keeping tax and accounting records, responding to lawful requests from authorities, and handling payment disputes.

4. Cookies and advertising measurement

Essential cookies are always used because the site cannot work without them. They keep you signed in, remember your cookie choice and your light or dark theme, and protect checkout from tampering.

We also set two first-party cookies for our own reporting, each lasting up to 30 days: one remembers how you first arrived (campaign tags and the referring site), and one remembers which partner referred you so that partner can be credited for your purchase. We do not share these cookies with advertising platforms.

Advertising pixels from Meta (Facebook and Instagram) and TikTok load in your browser only after you choose “Accept” on our cookie banner. If you choose “Decline,” these pixels never load, and the site still works fully.

When you accept, we also send key events (such as viewing a book, starting checkout and completing a purchase) directly from our server to Meta and TikTok, together with hashed (scrambled) versions of identifiers such as your email address and phone number, so the platforms can match the events to their users and measure our ads.

If you decline, we still send a limited version of those key events from our server, without your email, phone, name or other hashed identifiers. These events include technical information such as your IP address and browser type, the page involved, the purchase value and currency, and any ad-click ID that came with your visit. We do this on the basis of our legitimate interest in measuring our advertising and preventing fraud.

To change your choice, clear the cookies for blacksheepmind.com in your browser and the banner will appear again, or contact us. You can also manage ad preferences in your Meta and TikTok account settings.

5. Who we share information with

We do not sell your personal information. We share it only with service providers who help us run BlacksheepMind and who may use it only on our instructions:

Stripe (payment processing and fraud prevention); Cloudflare (email delivery, network, security and country detection);[HOSTING PROVIDER AND SERVER LOCATION] (hosting our servers and database); and the video-call and messaging tools we use to schedule and hold coaching sessions.

Meta and TikTok receive advertising measurement data as described in section 4. For some of this data they act as independent controllers under their own privacy policies.

PayPal and banks receive the details needed to pay partner commissions.

We may also disclose information if the law requires it, to protect our rights or the safety of others, or to a buyer or successor if our business is sold or reorganized, in which case this policy will continue to protect your information.

6. International transfers

We serve customers worldwide, and our service providers process data in several countries, including the United States. When we transfer personal information out of the EEA, the UK or Switzerland to a country without an adequacy decision, we rely on recognized safeguards such as the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum, or on the provider’s certification under the EU-U.S. Data Privacy Framework and its UK and Swiss extensions. You can ask us for more details.

7. How long we keep information

We keep your account information for as long as your account is open. Sign-in sessions expire after 30 days.

When you delete your account, we delete your personal information and your access to your purchases ends immediately. Financial records (orders, payments, refunds and partner commissions) are kept in anonymized form, with your identity removed, for as long as tax and accounting laws require.

We may keep limited information for longer where we need it to resolve a dispute, prevent fraud or comply with the law.

8. How we protect information

We use encryption in transit (HTTPS), hash passwords with a modern algorithm (Argon2id), limit each account to 3 active sign-in sessions, and restrict internal access to people who need it. No system is perfectly secure, but we work to protect your information and will notify you and the authorities of a data breach where the law requires.

9. Your rights

Depending on where you live, you may have the right to: access your personal information and get a copy of it; correct it; delete it; restrict or object to how we use it, including objecting to processing based on legitimate interests and to direct marketing; receive it in a portable format; and withdraw consent at any time. People in the EEA and UK have these rights under the GDPR and UK GDPR.

Many of these you can do yourself: download a copy of your data at /account/data, change your email preferences in Account › Settings, or delete your account in Account › Settings.

For anything else, email us at [CONTACT EMAIL]. We may need to verify your identity before acting on a request, and we will reply within one month (or sooner if your local law requires). We will not treat you differently for using your rights.

If you are in the EEA or UK and are unhappy with how we have handled your information, you have the right to complain to your local data protection authority (in the UK, the Information Commissioner’s Office). We would appreciate the chance to sort it out with you first.

10. Notice for California residents

This section applies to California residents under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA).

In the last 12 months we collected these categories of personal information: identifiers (such as name, email address, IP address and account ID); customer records and commercial information (such as purchases and phone number, if given); internet and electronic activity (such as reading progress and interactions with our site); approximate geolocation (country); and account login credentials. We collect them from you, from your device, and from Stripe. We use them for the purposes in section 3, and keep them for the periods in section 7.

We disclose these categories to the service providers listed in section 5 for business purposes. We do not sell personal information, and we have no actual knowledge of selling or sharing the personal information of consumers under 16. When you accept advertising cookies, the pixels and server events described in section 4 may count as “sharing” for cross-context behavioral advertising. You can opt out of this at any time by choosing “Decline” on our cookie banner, or by clearing our cookies and choosing it again. We use account login credentials only to provide and secure your account.

You have the right to know what personal information we collect, use and disclose; to delete it; to correct it; to opt out of its sharing; and not to be discriminated against for using these rights. To make a request, use the self-service tools in section 9 or email [CONTACT EMAIL]. You may use an authorized agent; we may ask for proof of their authority and verify your identity.

11. Marketing emails

We may email you about new books, reading reminders and offers. Where the law requires your prior consent for this, we only send these emails if you have given it. Every marketing email has an unsubscribe link, and you can turn them off at any time in Account › Settings. We will still send essential emails about your account and purchases.

12. Children

BlacksheepMind is not directed at children, and you must be at least 16 to create an account. We do not knowingly collect personal information from anyone under 16. If you believe a child has given us personal information, contact us at [CONTACT EMAIL] and we will delete it.

13. Changes to this policy

We will post any changes on this page with a new “Last updated” date. If a change materially affects how we use your information, we will tell you by email or on the site before it takes effect.

14. Contact

Questions or requests about your privacy: [CONTACT EMAIL]. Postal address: [LEGAL ENTITY NAME], [REGISTERED ADDRESS].

We use cookies to measure ads and improve your experience. You can accept or decline tracking.