1. Who we are
This site is operated by Jonathan Fordyce trading as TFC Health (“TFC”, “we”, “us”). We are the data controller for the personal data described below.
If you have any questions about this policy or how we handle your data, email tfchealthmedia@gmail.com.
2. What we collect
- Analytics data — pages you visit, how long you stay, what you click, your country, your device type, your browser. Collected via Vercel Analytics (always on, anonymised, cookieless) and Google Analytics 4 (only with your consent).
- Purchase data — if you buy our guide, Stripe collects your name, email, billing address, and card details. Stripe processes these on our behalf. We never see or store your card details.
- Email — if you buy our guide, we send a small number of transactional emails (receipt, download link, brief onboarding). We do not currently run a marketing newsletter.
- Support correspondence — if you email us, we keep a record of the conversation so we can help you and learn from common questions.
3. Legal basis
We rely on the following lawful bases under UK GDPR:
- Contract — processing your purchase and delivering the guide you bought.
- Consent — the Google Analytics 4 cookies and tracking only fire after you click “Accept” on the cookie banner. You can withdraw consent at any time using “Privacy settings” in the footer.
- Legitimate interest — running cookieless analytics (Vercel Analytics) to understand site performance, and responding to your support emails.
- Legal obligation — keeping records of purchases for tax and accounting law.
4. Third parties we use
We use a small set of trusted services to run the site. Each has its own privacy policy:
- Stripe — payment processing. stripe.com/privacy
- Vercel — hosting, edge network, analytics, file storage (the guide PDF lives in Vercel Blob). vercel.com/legal/privacy-policy
- Google Analytics — user-consent-gated audience and conversion analytics. policies.google.com/privacy
- Resend — transactional email delivery. resend.com/legal/privacy-policy
Some of these providers are based in the United States. Transfers happen under the UK extension to the EU-US Data Privacy Framework or the UK International Data Transfer Agreement, with standard contractual clauses where applicable.
5. Cookies and analytics
We use as few cookies as possible. None for advertising. None for tracking you across other websites.
- Strictly necessary — small data points needed to make the site work (e.g. your cookie-banner choice). Always on.
- Analytics (consent required) — Google Analytics 4. Off by default. Only fires after you click “Accept” on the banner. We use Google Consent Mode v2 to make sure no analytics cookies are set until you say yes.
- Cookieless analytics — Vercel Analytics. No cookies, no fingerprinting, no cross-site identifiers. Always on.
Change your mind any time using “Privacy settings” at the bottom of any page.
6. How long we keep your data
- Purchase records: 7 years (UK tax law).
- Email correspondence: until it is no longer relevant, typically 2 years.
- Analytics data in Google Analytics 4: 14 months (the GA4 default; user-level data deleted after that).
- Analytics data in Vercel Analytics: 90 days.
7. Your rights
Under UK GDPR you have the right to:
- Ask what data we hold about you
- Ask us to correct inaccurate data
- Ask us to delete your data (subject to legal retention)
- Ask for your data in a portable format
- Object to or restrict our processing
- Withdraw consent for analytics any time
- Complain to the ICO if you think we have got it wrong
Email tfchealthmedia@gmail.com to exercise any of these rights. We will reply within 30 days.
8. Children
This site is not directed at people under 16 and we do not knowingly collect data from children.
9. Changes to this policy
If we make a material change we will update the “Last updated” date at the top of this page and, where appropriate, re-prompt you for cookie consent.