Privacy Policy
Last updated: April 8, 2026
1. Introduction
The Attraction Builder ("the Platform"), operated by Jen Cote in New Liskeard, Ontario, Canada, respects your privacy and is committed to protecting your personal information. This Privacy Policy explains how we collect, use, store, and protect your data when you use our Platform.
2. Information We Collect
Information you provide directly:
- Name and email address (account registration)
- Worksheet responses and training data (course participation)
- Payment information (processed securely by Stripe — we do not store card details)
- Communications with us (support emails, feedback)
Information collected automatically:
- Device and browser information
- IP address and general location
- Pages visited and features used within the Platform
- Login timestamps and session data
3. How We Use Your Information
We use your information to:
- Provide and maintain your account and subscription
- Deliver training content and personalized marketing materials
- Process AI-generated content based on your worksheet responses
- Process payments and manage billing
- Send important account notifications (billing, security, service changes)
- Improve the Platform and develop new features
- Respond to your questions and support requests
4. AI Processing
Your worksheet responses are processed by AI (Anthropic Claude) to generate personalized marketing materials. This processing occurs in real-time when you use the AI drafting feature. Your responses are sent to the AI service for processing and are not stored by the AI provider beyond the immediate request. The generated content is stored in your account on our platform.
5. Third-Party Services
We use the following third-party services to operate the Platform:
- Supabase — Database hosting and user authentication
- Vercel — Website hosting and deployment
- Stripe — Payment processing (see Stripe's privacy policy at stripe.com/privacy)
- PayPal — Payment processing (see PayPal's privacy policy at paypal.com/privacy)
- Anthropic — AI content generation
- Meta Platforms (Instagram/Facebook) — Social media automation (optional, member-initiated)
- Twilio — SMS messaging (optional, member-initiated)
- Resend — Transactional and marketing email delivery
Each of these providers has their own privacy policies governing how they handle data. We only share the minimum information necessary for each service to function.
5A. Instagram & Facebook Integration
The Platform offers optional social media automation features that integrate with Instagram and Facebook (operated by Meta Platforms, Inc.). These features are entirely opt-in — you choose whether to connect your social media accounts.
Data we access when you connect Instagram or Facebook:
- Your Instagram Business or Facebook Page profile information (name, profile picture, page ID)
- Comments on your posts (to detect keyword triggers you configure)
- Direct messages sent to your business account (to enable automated responses you configure)
- Basic information about users who interact with your content (name, profile ID — only when they initiate contact)
How we use Instagram and Facebook data:
- To send automated direct messages in response to keyword triggers you create
- To reply to comments on your posts as part of automations you configure
- To display conversations in your unified messaging inbox within the Platform
- To deliver lead magnets and free resources you offer through your social content
What we do NOT do with Instagram and Facebook data:
- We do NOT sell or share social media data with third parties
- We do NOT use social media data for advertising or ad targeting
- We do NOT access private personal messages unrelated to your business account
- We do NOT store social media data beyond what is needed for the automation features
- We do NOT transfer social media data to data brokers or analytics companies
Data retention for social media data:
Conversation data from Instagram and Facebook is stored for as long as your account is active and the social channel is connected. When you disconnect a social media account, associated conversation data is retained for 30 days then permanently deleted. You can request immediate deletion at any time by contacting us.
Revoking access:
You can disconnect your Instagram or Facebook account at any time from your Platform settings (Settings → Connected Channels). You can also revoke access directly from your Instagram or Facebook settings under Apps and Websites. Upon disconnection, we stop accessing your social media data immediately.
Data deletion requests:
To request deletion of all data associated with your Instagram or Facebook account, you can: (1) disconnect the channel in your Platform settings, (2) email us at info@theattractionbuilder.com requesting data deletion, or (3) use the data deletion callback URL provided in our Meta Developer App settings. You can check the status of a deletion request at theattractionbuilder.com/data-deletion.
6. Data Storage and Security
Your data is stored securely on servers operated by our hosting providers (Supabase and Vercel). We implement industry-standard security measures including:
- Encrypted data transmission (HTTPS/TLS)
- Row-level security on database tables
- Secure authentication with encrypted passwords
- Payment data handled entirely by Stripe (PCI-DSS compliant)
7. Data Retention
We retain your account data and worksheet responses for as long as your account is active. If you cancel your subscription, your data is retained for 90 days in case you choose to resubscribe. After 90 days, you may request deletion of your data. Payment records are retained as required by Canadian tax law.
8. Your Rights
Under Canadian privacy law (PIPEDA), you have the right to:
- Access the personal information we hold about you
- Request correction of inaccurate information
- Request deletion of your personal information
- Withdraw consent for data processing
- Receive a copy of your data in a portable format
To exercise any of these rights, contact us at info@theattractionbuilder.com
9. Cookies
The Platform uses essential cookies for authentication and session management. These cookies are necessary for the Platform to function and cannot be disabled. We do not use advertising or tracking cookies.
10. Marketing Communications
We may send you occasional emails about Platform updates, new features, or educational content. You can unsubscribe from marketing emails at any time using the unsubscribe link in any email. We will always send essential account notifications (billing changes, security alerts, terms updates) regardless of your marketing preferences.
11. Children's Privacy
The Platform is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes via email. The "Last updated" date at the top of this page indicates when the policy was last revised.
13. Contact
For questions about this Privacy Policy or your personal data, contact us at info@theattractionbuilder.com