Skip to main content

Privacy Policy

Privacy Policy for formidably.com.

Last updated: 15 May 2026 Effective date: 15 May 2026

1. Who We Are

formidably.com is operated by Formidably Ltd, a company registered in England and Wales. We are the data controller for personal data processed through formidably.com. Contact us at: contact form (or by writing to: Formidably Ltd, Unit A Crescent Trade Park, Redditch B98 9DZ).

ICO registration: ZB685467

2. Scope of This Policy

This policy covers personal data collected and processed through the formidably.com website, including its course platform, community, blog, and email list. It does not cover formidably.life or Formidably Mobile, which have their own policies.

3. The Data We Collect and Why

3.1 Account Data

When you create an account, we collect your name and email address. Your password is stored as a hashed credential via Supabase Auth. We use this data to authenticate your sessions and give you access to courses and community you have purchased or joined.

3.2 Course Purchases

When you purchase a course, we collect your name, email address, and billing country. Payment is processed by Stripe; we do not store your card details. We store a Stripe payment intent ID and your enrollment record (which course you purchased and when). Course access is permanent; your enrollment record is retained for as long as your account exists and for 7 years afterwards for financial record-keeping purposes.

If you provide a VAT number (for B2B purchases), we pass it to Stripe for tax purposes and retain it with your payment record.

If you arrived via an affiliate link, we record the affiliate identifier alongside your enrollment. This allows us to calculate commission for the affiliate. The affiliate does not receive your personal details.

3.3 Course Video Delivery

Course video content is delivered via Cloudflare Stream. When you watch a video, Cloudflare processes your IP address and device information to serve the video. Cloudflare acts as a data processor under a data processing agreement.

3.4 Community

If you participate in the formidably.com community, your display name and any content you post (posts, replies) are visible to other community members. You can delete your own posts at any time. We retain deleted post records for moderation and audit purposes for 90 days.

3.5 Analytics Cookies

We use Google Tag Manager (GTM) to manage tracking tags on our websites. GTM itself is only loaded after you consent to analytics or marketing cookies. We have implemented Google Consent Mode v2, which defaults all consent signals to denied. The signals analytics_storage, ad_storage, ad_user_data, and ad_personalization are only set to granted after you give the relevant consent.

With your consent to analytics cookies, we load Google Analytics 4 (GA4). GA4 collects information about your visit such as pages viewed, time on site, referring website, and general location (country/city level, not precise). This data is aggregated and used only to improve our websites and content. GA4 is operated by Google LLC; data may be transferred to the United States under the EU-US Data Privacy Framework.

Legal basis: consent (UK GDPR Article 6(1)(a)). If you decline analytics cookies, GA4 does not run. If you decline both analytics and marketing cookies, GTM does not load for your session. You can change your choice at any time via the cookie settings link in our footer. You can also opt out globally via the Google Analytics Opt-out Browser Add-on (tools.google.com/dlpage/gaoptout).

3.6 Marketing and Retargeting Cookies

With your consent to marketing cookies, we load advertising pixels to support retargeting campaigns. We use:

  • Meta Pixel (Facebook/Instagram): measures the effectiveness of our advertising on Meta platforms by tracking actions taken on our website after clicking a Meta ad. Operated by Meta Platforms, Inc. Data may be transferred to the United States under Standard Contractual Clauses.
  • Pinterest Tag: measures conversions and enables retargeting on Pinterest. Operated by Pinterest, Inc. Data may be transferred to the United States under Standard Contractual Clauses.

Neither the Meta Pixel nor the Pinterest Tag fires unless you have consented to marketing cookies. We do not use these pixels to build profiles about you outside the context of our own advertising campaigns. You can opt out of Meta's data use for advertising at facebook.com/settings, and Pinterest's at pinterest.com/settings/privacy.

Legal basis: consent (UK GDPR Article 6(1)(a)). You can withdraw consent at any time via the cookie settings link in our footer.

3.7 Email List and Newsletter

Across our websites, we offer the opportunity to join our email list. When you sign up you provide your name (optional) and email address, and tick a consent checkbox confirming you agree to receive Formidably updates by email. We also use gated downloads: if you request a free resource, you provide your name and email address, and optionally consent to receive further emails from us.

We collect and store: name (where provided), email address, the date and source of your signup, and your consent record. Your consent record is retained permanently so we can demonstrate lawful processing.

Legal basis: consent (UK GDPR Article 6(1)(a)). You can unsubscribe at any time via the link in any email we send, or by contacting contact form. Unsubscribing does not delete your account or affect your access to products you have purchased.

We use Resend to send emails. Resend processes your email address on our behalf under a data processing agreement.

3.8 Contact Enquiries

If you contact us through our contact form, we retain that correspondence for up to 2 years for customer service purposes.

3.9 Usage and Technical Data

We collect basic technical data to operate the service: IP addresses (retained for 30 days), browser and device type, and error logs. This data is used for security and debugging only.

4. Legal Bases for Processing (UK GDPR)

  • Contract: account data, course enrollments, community access are necessary to provide the service you have purchased.
  • Consent: email newsletter and marketing communications, analytics cookies, and marketing/retargeting cookies.
  • Legitimate interests: security logs and affiliate tracking (to fulfil commission obligations).
  • Legal obligation: financial records (7-year retention).

5. How We Share Your Data

We do not sell personal data. Processors:

ProcessorPurposeLocation
SupabaseDatabase and authenticationEU (AWS eu-west-1)
StripePayment processingUS (SCCs in place)
ResendTransactional and marketing emailUS (SCCs in place)
CloudflareCDN, DDoS protection, Stream video deliveryGlobal (adequacy/SCCs)
Google LLCGoogle Tag Manager and Google Analytics, with analytics cookies only after consentUS (Data Privacy Framework)
Meta Platforms, Inc.Meta Pixel advertising measurement and retargeting, with marketing cookies only after consentUS (SCCs in place)
Pinterest, Inc.Pinterest Tag advertising measurement and retargeting, with marketing cookies only after consentUS (SCCs in place)

6. Data Retention

  • Account and profile data: deleted within 30 days of account closure.
  • Course enrollment records: retained for 7 years after purchase to meet financial record-keeping obligations. Your course access ends on account closure but the purchase record is kept.
  • Community posts: visible until deleted by you; deleted post records purged after 90 days.
  • Email list: retained until you unsubscribe or request deletion.
  • Consent records: retained permanently as evidence of lawful processing.
  • Payment records (Stripe): retained for 7 years.
  • Security logs: retained for 90 days.
  • Affiliate conversion records: retained for 7 years.

7. Cookies

We use strictly necessary cookies to operate the site, maintain secure sessions, and remember your cookie choices. We use analytics cookies only with analytics consent and marketing cookies only with marketing consent.

Our marketing cookies support Meta Pixel and Pinterest Tag for advertising measurement and retargeting. Neither tag fires unless you have consented to marketing cookies.

You can accept all, reject all, or manage choices through the cookie banner, and you can change your choice later using Cookie settings in the footer. See our Cookie Policy for the full cookie table.

8. Your Rights Under UK GDPR

You have the right to access, correct, erase, restrict, or port your personal data, and to withdraw consent where processing is consent-based. Contact contact form. We will respond within one calendar month. You may also complain to the ICO at ico.org.uk.

9. Children

formidably.com is intended for adults aged 18 and over. We do not knowingly collect data from children. If you believe a child has created an account, contact contact form and we will delete it.

10. International Transfers

Some processors are based in the United States. Transfers are protected by Standard Contractual Clauses or the EU-US Data Privacy Framework as applicable. Details available on request.

11. Changes to This Policy

We will notify you of material changes by email or site notice at least 14 days before they take effect.

12. Contact

Formidably Ltd

Contact: contact form

Website: formidably.com

ICO registration: ZB685467

Registered in England and Wales. Governing law: England and Wales.