Privacy Policy
Last Updated: 14 August 2026 (updated data controller details, added Beehiiv newsletter processing)
Introduction
This Privacy Policy applies to runsitself.co ("we", "us", "our") and governs the collection, use, and protection of personal data in relation to our website and digital products.
We are committed to protecting your privacy and handling your personal data in accordance with the EU General Data Protection Regulation (GDPR), Regulation (EU) 2016/679.
This Privacy Policy should be read in conjunction with our Terms of Service.
Data Controller Details:
- Name: WZLOT sp. z o.o. (operating the RunItself brand)
- Registered office: ul. Fryderyka Szopena 35C/164W, 35-055 Rzeszów, Poland
- Registration: KRS 0001244989, District Court in Rzeszów, XII Commercial Division of the National Court Register
- Jurisdiction: Poland (EU)
- Email: info@maciejmarek.com
- Website: runsitself.co
1. Information We Collect
1.1 Information You Provide to Us
We collect and process the following personal data when you purchase our products or engage our services:
Contact Information:
- Full name
- Business name and trading details (if applicable)
- Email address
- Billing address
Commercial Information:
- Information you voluntarily provide about your business when filling in our AI Board onboarding questionnaire (agency name, team size, clients, pain points)
- Questions or topics submitted during Diagnostic Calls, Wiring Service sessions, or Discovery Calls
Communication Data:
- Correspondence via email
- Support tickets and queries
- Meeting notes from paid calls (where consent is provided)
Important — Context files stay with you: The shared-context.md you complete as part of AI Board in a Box lives in YOUR account on Claude.ai / ChatGPT / Gemini. We do NOT have access to those files. We only see what you explicitly email us.
1.2 Information We Collect Automatically
Website Usage Data:
- IP address (anonymised by Cloudflare)
- Browser type and version
- Pages visited and time spent
- Referring website addresses
- UTM parameters (when you arrive from an ad or external link)
We use Cloudflare Analytics (privacy-focused, no cookies) for baseline traffic monitoring.
Marketing Tracking (only with your consent):
- Meta Pixel (browser-side) — tracks page views, content views, and purchases when you interact with our site after clicking a Meta/Facebook/Instagram ad
- Meta Conversions API (CAPI) (server-side) — sends purchase events from our Stripe webhook to Meta for ad attribution accuracy
- Hashed identifiers sent to Meta: email (SHA-256), IP address, user agent, click ID (fbclid)
- Purpose: measure ad campaign performance, optimise ad spend, build retargeting audiences
Meta Pixel and CAPI are only activated if you give consent via our cookie banner. You can withdraw consent at any time by clearing your browser data or using the “Cookie Settings” link in our footer (when available).
1.3 Information from Third Parties
We may receive data from:
- Stripe (payment confirmations, customer email, transaction metadata)
- Cal.com (booking confirmations, scheduled call details)
- Email service providers (delivery confirmations, bounces)
2. Legal Basis for Processing
We process your personal data under the following GDPR legal bases:
Contract Performance (Article 6(1)(b)): Processing necessary to fulfill your order, deliver digital products, conduct paid calls, and provide services.
Legitimate Interests (Article 6(1)(f)):
- Improving our products and website functionality
- Sending service-related updates to existing customers
- Fraud prevention and security
- Business development based on aggregated purchase patterns
Consent (Article 6(1)(a)):
- Marketing communications (newsletter — you can unsubscribe any time)
- Sharing testimonials or case studies (always with explicit opt-in)
Legal Obligation (Article 6(1)(c)):
- Tax and accounting compliance (Polish tax law requires 7-year retention of invoices)
- Response to lawful requests from authorities
3. How We Use Your Information
Product Delivery:
- Sending download links for purchased products (AI Board, bumps, bundles)
- Scheduling and conducting paid calls (Diagnostic Call, Wiring Service, Discovery Call)
- Providing customer support
Business Operations:
- Processing payments via Stripe
- Issuing invoices
- Maintaining customer records
Marketing and Communications:
- Sending the 5 mandatory post-purchase onboarding emails (essential for product use)
- Adding customers to our weekly newsletter (opt-out via unsubscribe link in every email)
- Sharing product updates
4. Data Sharing and Disclosure
We share your personal data only with the following categories of recipients:
Essential Service Providers (always):
- Stripe (payment processing) — stripe.com/privacy
- Stripe Tax (EU VAT calculation and OSS compliance)
- Google Workspace (email delivery via info@maciejmarek.com, file hosting via Google Drive, calendar bookings via Google Calendar Appointment Schedules)
- Beehiiv (newsletter subscription and delivery; your email address is stored with Beehiiv when you sign up for the newsletter) — beehiiv.com/privacy
- Cloudflare (DNS, DDoS protection)
- SEO Host (Apache hosting for runsitself.co)
- Anthropic / OpenAI / Google — only if you upload your shared-context.md to their platforms (you control this)
Marketing Providers (only with your consent via cookie banner):
- Meta Platforms (Facebook, Instagram) — Meta Pixel (browser) and Conversions API (server) for ad attribution and audience building. Privacy: facebook.com/privacy/policy
We ensure all third parties respect the security of your personal data and treat it in accordance with GDPR.
We do not sell or rent your personal data. When we share with marketing providers (Meta), it is for the limited purpose of measuring ad performance and is governed by Data Processing Agreements + Standard Contractual Clauses.
5. International Data Transfers
We primarily process data within the EU. Where we transfer data outside the EU/EEA (e.g., to US-based services like Stripe, Cloudflare, Anthropic), we rely on:
- Standard Contractual Clauses approved by the European Commission
- Adequacy decisions where applicable
- Data Processing Agreements with each provider
6. Data Retention
- Active Customer Data: Duration of business relationship plus 7 years (Polish tax law)
- Prospective Customer Data: Up to 3 years from last contact
- Newsletter Subscribers: Until you unsubscribe or request deletion
- Call Recordings (paid sessions, where consent given): 90 days unless you request permanent retention
- Website Analytics: 6 months (Cloudflare aggregated, IP anonymised)
7. Your Data Protection Rights (GDPR)
Under GDPR, you have the following rights:
- Right of Access (Article 15): Request a copy of the personal data we hold about you
- Right to Rectification (Article 16): Request correction of inaccurate data
- Right to Erasure (Article 17): Request deletion (subject to legal retention obligations)
- Right to Restrict Processing (Article 18): Request we limit how we use your data
- Right to Data Portability (Article 20): Request your data in a structured, machine-readable format
- Right to Object (Article 21): Object to processing based on legitimate interests or for marketing
- Right to Withdraw Consent: Where processing is based on consent, you can withdraw it at any time
To exercise any of these rights, email info@maciejmarek.com. We aim to respond within 30 days.
You also have the right to lodge a complaint with the Polish Personal Data Protection Office (UODO) at uodo.gov.pl.
8. Cookies and Tracking Technologies
8.1 Strictly Necessary (always on, no consent required)
- Cloudflare — security/DDoS protection cookies (cannot be disabled without breaking the site)
- Stripe Checkout — set only during payment processing, essential for purchase
- Cookie consent state — stores your consent choice in
localStorage so we don't ask twice
8.2 Marketing Cookies (opt-in only, default OFF)
The following cookies/tracking activate only after you click “Accept” on our cookie banner:
- Meta Pixel (
_fbp, _fbc) — Facebook/Instagram tracking for ad attribution. Set by connect.facebook.net. Lifetime: 90 days.
- Meta Click ID (
fbclid URL parameter) — captured when you arrive from a Meta ad, sent to our server-side CAPI for attribution.
If you click “Reject” or close the banner without choosing, no marketing cookies are set. You can still browse, purchase, and use our services normally — only ad attribution is disabled.
8.3 What we do NOT use
- Google Analytics
- Cross-site advertising retargeting beyond Meta
- Third-party data brokers
- Behavioural profiling for purposes other than ad measurement
8.4 Withdraw consent at any time
To withdraw consent: clear your browser's site data for runsitself.co (in browser settings → Privacy → Cookies → search runsitself.co → Clear). On your next visit, the banner will reappear and you can choose again. Alternatively, email us at info@maciejmarek.com and we'll log a deletion request with Meta.
9. Data Security
We implement appropriate technical and organisational measures to protect your personal data:
Technical Measures:
- SSL/TLS encryption for all data transmission (Cloudflare-managed)
- Encrypted data storage (Google Workspace + Stripe)
- Secure authentication (2FA on all admin accounts)
- Regular security updates
Organisational Measures:
- Access on a need-to-know basis
- No staff or contractors with access to customer data without signed NDA
- Incident response procedure documented
10. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy, please contact us:
Email: info@maciejmarek.com
We aim to respond to all enquiries within 5 working days.