Effective Date: August 28, 2025
Welcome to Funnel of the Week (“we,” “us,” “our”). We are committed to protecting your personal information and your right to privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you participate in our online membership community (the “Services”).
By using our Services, you agree to the collection and use of information in accordance with this policy.
Table of Contents
Information We Collect
How and Why We Use Your Information
Sharing Your Information with Third Parties
User-Generated Content, Profiles, and Member Interactions
Data Security and Retention
Your Data Protection Rights
Children’s Privacy
International Data Transfers
Changes to This Privacy Policy
How to Contact Us
We collect personal information that you provide to us directly and information that is automatically collected when you use our Services.
2.1. Information You Provide to Us
We collect personal information that you voluntarily provide when you register for an account, pay for a membership, participate in community activities, or contact us. This includes:
Account Information: Your first and last name, email address.
Payment Information: To process your subscription, we collect payment data, such as a credit card number and security code. All payment data is processed by our secure payment processor (Lemon Squeezy), and we do not store your full payment instrument number on our servers.
Profile Information: You may choose to provide optional information for your member profile, such as a profile picture, biography, or location. This information is provided at your discretion.
User-Generated Content: We collect the content you create and share within the community, including posts, comments, and direct messages.
Communications: If you contact us directly for support, we may receive your name, email address, and the contents of your message.
2.2. Information We Collect Automatically
When you use our Services, we automatically gather certain information about your device and usage:
Log and Usage Data: This includes your IP address, browser type, operating system, pages visited, links clicked, and the dates and times of your access.
Cookies and Tracking Technologies: We use cookies and similar technologies to operate the platform and analyze usage.
We use your personal information for a variety of business purposes, each with a corresponding lawful basis under GDPR for our members in the EU/EEA.
| Purpose | Lawful Basis (under GDPR) |
| To create and manage your account and facilitate your paid membership. | Performance of a contract |
| To process your payments for the membership subscription. | Performance of a contract |
| To provide core community features, such as displaying your profile and content. | Performance of a contract |
| To send you administrative information, such as policy updates. | Legitimate interests; Performance of a contract |
| To improve our Services by analyzing usage data to enhance features. | Legitimate interests |
| To protect our Services by monitoring for and preventing fraudulent activity. | Legitimate interests |
| To send you marketing communications, such as our newsletter. | Consent |
| To respond to your inquiries and provide customer support. | Legitimate interests |
| To comply with legal obligations, such as responding to a court order. | Legal obligation |
We do not sell your personal information. We may share your information only in the following situations:
Service Providers: We share information with third-party vendors who perform services on our behalf, such as payment processing (Lemon Squeezy), data analysis (Google Analytics), email delivery (Beehiiv), and community hosting (Circle). These providers are obligated to protect your data and cannot use it for any other purpose.
Legal Requirements: We may disclose your information where we are legally required to do so to comply with applicable law or a valid legal process.
Business Transfers: We may share or transfer your information in connection with a merger, sale of company assets, or acquisition of our business.
User-Generated Content (UGC): You retain ownership of the content you post to the community. By posting, you grant us a non-exclusive, worldwide, royalty-free license to display and distribute your content as necessary to operate the community. Our Community Guidelines govern what content is acceptable, and we reserve the right to moderate and remove content that violates our policies.
Public Profiles and Privacy by Default: Your username and optional profile information may be visible to other members. We provide you with granular settings to control this visibility. By default, your new account is set to the most privacy-protective options.
Member-to-Member Communications: Our Services allow you to communicate with other members via direct messaging. Please be aware that these messages are not end-to-end encrypted. Our administrative and moderation teams may access the content of direct messages to investigate a safety concern.
Content After Account Deletion: If you delete your account, we may anonymize your content by removing your username and profile link, attributing it to an “Deleted Member” to maintain the integrity of community discussions.
Security: We have implemented appropriate technical and organizational security measures, including data encryption and internal access controls, to protect your personal information. However, no method of transmission over the internet is 100% secure. We also have a formal data breach response plan in place to manage any potential incidents effectively.
Retention: We will only keep your personal information for as long as it is necessary for the purposes set out in this policy, unless a longer retention period is required by law. Generally, we will keep your information for as long as you have an active account with us.
You have certain rights regarding your personal information under applicable data protection laws. These include the right to:
Access your personal data.
Correct inaccurate data.
Delete your personal data (the “right to be forgotten”).
Object to our processing of your data.
Data portability (receive your data in a machine-readable format).
Withdraw consent at any time.
To exercise any of these rights, please contact us at [email protected].
7.1. For Residents of the European Economic Area (EEA) and UK
If you are a resident in the EEA or UK, you have the rights detailed above under the GDPR. Our lawful bases for processing are described in Section 3. You also have the right to lodge a complaint with your local data protection supervisory authority.
7.2. For Residents of California
If you are a resident of California, you have specific rights under the CCPA/CPRA, including the Right to Know, Delete, and Correct your personal information. We do not “sell” or “share” your personal information as defined by the CCPA/CPRA. To make a request, please contact us via email.
Our Services are not intended for use by children under the age of 16, and we do not knowingly collect personal information from them. If we become aware that we have collected such information, we will delete it as soon as possible.
Your information may be transferred to and maintained on computers located outside of your country, where data protection laws may differ. If you are in the EEA or UK, your data may be transferred to the United States. We use legal safeguards like Standard Contractual Clauses to ensure your data is treated securely and in accordance with this policy.
We may update this privacy policy from time to time. The updated version will be indicated by a revised “Effective Date.” If we make material changes, we will notify you by email and/or a prominent notice on our website before the change becomes effective.
If you have questions, comments, or wish to exercise your privacy rights, you may contact our Data Protection Officer (DPO) at: