Legal
Privacy Policy.
This Privacy Policy explains what rolandfrasier.com (the “Site”) collects when you visit, why, who helps us run the Site, how long we keep things, and how to see, fix or delete what we hold about you. It is written in plain English on purpose. If anything here is unclear, ask and a person will answer.
This Privacy Policy is part of our website Terms of Use. We may update this page from time to time. When we do, the effective date at the bottom changes, the new version applies from that date, and if the change matters to you we ask for your consent again where the law requires it.
1. Who we are
The Site is run by Scalable.co, LLC, 4330 Gaines Ranch Loop, Suite 120, Austin, TX 78735. In privacy law terms we are the “controller” of the information described here. You can reach us about privacy through the form on our Privacy choices page or by email at roland@digitalmarketer.com.
2. What we collect
- What you give us. Your name, email address, phone number, company, website, and whatever you write in a form. You give this to us when you subscribe to the newsletter, request a free guide, ask about working with Roland, invite him to speak, or send us a privacy request.
- What we collect automatically, from everyone. Which pages are visited, the link that brought the visit here (for example a link in an Instagram message or a YouTube description), the country and region the visit comes from, and the type of device. We do not store IP addresses. Without your permission this is a plain count: no cookie, no id, nothing that follows you from one visit to the next.
- With your permission: a visitor id. If you allow analytics cookies we also keep a random visitor id and a short one way hash of your browser’s name (not of your address), so that a return visit counts as the same person and we can connect the post you came from to the form you later filled in. With the same permission, PostHog also records the clicks you make and a replay of your visit (what the page showed and where you clicked). Anything you type into a form is hidden from the replay.
- Instagram messages you start. When you comment a keyword on one of Roland’s Instagram posts and reply to the automatic message, ManyChat passes us your Instagram handle, your first name, the keyword, and the email address you type into that conversation.
3. Why we use it, and the legal basis
- To do what you asked (reply to your inquiry, open the guide, deal with your privacy request): because it is needed to act on your request.
- To send you the newsletter, Off the Org Chart: your consent, which you can withdraw with the unsubscribe link in any issue.
- To see which posts, videos and messages bring people here, using cookies: your consent in the European Union, the European Economic Area, the United Kingdom, Switzerland, California and Quebec. Elsewhere our legitimate interest in understanding our own audience, with a way to turn it off on the Privacy choices page.
- To send you, once, a short follow up email that fits the pages you read here: only if you gave us your email and allowed analytics cookies, on the same consent, which you can withdraw with the unsubscribe link in that email.
- To count visits without cookies and keep the Site secure: our legitimate interest in running the Site.
- To keep a record of your privacy choices and requests: our legal obligation to show that we asked and that we answered.
We do not use your information for advertising on other sites. We do not sell it, and we do not share it for anyone else’s marketing.
4. Cookies and storage
A cookie is a small text file stored in your browser. None of ours are used for advertising. The Site stores nothing beyond the first group until you have said yes, if you are somewhere that requires a yes.
Always on, because the Site needs them to respect what you asked:
- rf_consent: remembers your answer on the privacy bar or the Privacy choices page, and which version of this policy you answered. It holds no id. Lasts 180 days.
- rf_dealstack, rf_newsletter: set only after you ask for a guide, so this browser is not asked for your email again. Last 180 days.
- Your light or dark theme choice is kept in your browser’s local storage and never leaves your device.
Only with your permission (analytics and attribution):
- rf_vid: a random visitor id so a return visit counts as the same person. Lasts 400 days.
- rf_first: the first link that brought you here. Set once, lasts 90 days.
- rf_last: the most recent link that brought you here. Lasts 90 days.
- rf_attr_js: a copy of rf_last that our analytics can read, without any messaging id. Lasts 90 days.
- ph_… (PostHog): one cookie plus matching entries in your browser’s local storage, holding a random analytics id and the current session. Lasts 365 days.
When analytics cookies are off, page views are still counted, in two ways that store nothing in your browser: our own record keeps the page, the link, the country and the device with no id at all, and PostHog counts the visit with a hash computed on its own servers that changes every day and cannot be turned back into you.
You can change your answer anytime on the Privacy choices page. Turning analytics off deletes the cookies above and PostHog’s storage from your browser. You can also clear or block cookies in your browser settings; the Site still works without them, though a guide you unlocked may ask for your email again.
If your browser sends a Global Privacy Control signal we treat it as a no, everywhere, without asking.
5. Who helps us run the Site
We work with a small number of companies. Each one sees only what it needs to do its job, and each has agreed in writing to protect it.
- Vercel hosts the Site and serves every page. Its servers see your IP address to deliver the page and to tell us the country a visit comes from; we do not store the address.
- Supabase stores the forms you submit, the leads you create, the visit counts, the link clicks and the record of your privacy choices, in the United States.
- PostHog gives us analytics, hosted in the United States and loaded through our own domain. Without your permission it only counts page views. With your permission it also records clicks and a replay of your visit with everything you type hidden, and when you give us your email it is attached to your PostHog record so we can see which pages led you to sign up. It never sees your Instagram handle.
- Beehiiv sends Off the Org Chart, the follow up email that carries a guide you requested, and at most one short follow up email that fits the pages you read here. The newsletter is published by The Scalable Company, and we pass your email to it only when you ask for the newsletter or a guide.
- ManyChat, working through Meta’s Instagram platform, powers the automatic replies and direct messages you receive when you comment a keyword on one of Roland’s posts. Meta’s own privacy policy applies to Instagram itself.
- Google (YouTube) and Spotify provide the video and podcast players. They load only after you press play, and YouTube runs in its privacy enhanced mode. Video thumbnails are served from our own servers, so reading a page sends nothing to Google.
- Calendly provides a booking calendar, only if we switch it on. It is off today. If it is on, your name and email are passed to Calendly so the booking form is filled in, and Calendly’s own notice applies.
- Google (Gmail) carries the email that tells our team a form was submitted.
We may also share information when the law requires it, for example in response to a court order, or to protect the Site and the people who use it.
6. Where your information goes
We are in the United States and so are the companies above. If you are in the European Union, the European Economic Area, the United Kingdom or Switzerland, your information is transferred to the United States. We rely on the Standard Contractual Clauses approved by the European Commission, with the United Kingdom addendum where it applies, and on the safeguards each company describes in its own agreements. You can ask us for a copy of the clauses that apply.
7. How long we keep it
- Visit counts, tracked link clicks and Instagram message events: 400 days, then deleted.
- Instagram comment text, used to match a message to the post it came from: 90 days, then deleted.
- The record of your privacy choice: 25 months, so we can show that we asked.
- Consulting and speaking inquiries, guide requests and newsletter sign up records: 3 years from the date you sent them, or sooner if you ask.
- Your newsletter subscription itself: until you unsubscribe, which you can do from any issue.
- Privacy requests: 2 years after we complete them, as our record that we answered.
- Backups kept by our providers age out on their own schedules, usually within weeks.
8. Your rights in the EU, the EEA, the UK and Switzerland
You can ask us for a copy of what we hold about you, ask us to correct it, ask us to delete it, ask us to limit how we use it, receive it in a portable form, and object to our use of it where we rely on legitimate interest. You can withdraw consent at any time on the Privacy choices page or with the unsubscribe link in any newsletter, without affecting what happened before. You also have the right to complain to your data protection authority, for example the Information Commissioner’s Office in the United Kingdom, though we would rather hear from you first.
9. Your rights in California and other US states
Depending on where you live you may have the right to know what personal information we collect and how we use and share it, to receive a copy, to correct it, to delete it, and not to be treated differently for using these rights. The categories we collect are the ones listed in section 2, for the purposes in section 3, shared only with the companies in section 5. We do not sell your personal information, and we do not share it for cross context behavioral advertising. We do not collect sensitive personal information, and we do not knowingly collect anything from anyone under 16. You may use an authorized agent to make a request; we will ask the agent for proof that you allowed it. We answer within 45 days, and tell you if we need longer.
10. Global Privacy Control
If your browser or an extension sends the Global Privacy Control signal, we honor it automatically in every region: analytics cookies stay off and no privacy bar is shown.
11. How to make a request
Use the form on the Privacy choices page, or email roland@digitalmarketer.com. Before we act we reply to the email address you used, so we know the request is really from you. We complete requests within 30 days. Deleting your record with us removes it from Supabase, from PostHog where a record exists, and from our newsletter list. It does not reach into your Instagram or Meta account, which you control through those apps.
12. Security
Information travels to us over an encrypted connection and is stored with providers who publish their own security practices. Access is limited to the people who run the Site. No system on the internet is perfectly secure, so please do not send us anything you would not want stored, such as financial account details.
13. Other sites
The Site links to other companies’ websites, including the free tools built by companies Roland co founded and the newsletter’s own site, offtheorgchart.com. Once you leave rolandfrasier.com their privacy policy applies, not this one. Please read it before you enter your details there.
14. Children
The Site is written for business owners and is not directed at anyone under 18. We do not knowingly collect information from children, and if we learn that we have, we delete it.
15. Changes
When this policy changes we update the date below. A change that affects what we do with your information is announced on the Site, and in the regions that require it we ask for your consent again.
Questions about this policy go to roland@digitalmarketer.com.