Privacy
Shaz Method (https://shazmethod.com) is a marketing-automation practice. This policy explains what we collect when you apply, book a diagnostic, email us, or pay for setup or a retainer through a payment gateway.
Last updated: 19 September 2026
Who this covers
This policy applies to visitors of this site, people who submit the application form or email us, and clients who pay for the one-time GoHighLevel setup or a monthly retainer. This is a static marketing site. We do not run a public login or account dashboard here.
What we collect
Depending on how you reach us, we may collect:
- Application form. Name, email, phone, business name, website, role, industry, how leads arrive, approximate volume, whether you already use GoHighLevel, first-reply time, which plan you think you need, whether you run ads, ad budget, and free-text notes.
- Meeting slot. The diagnostic date, time, and timezone you pick on the apply form so we can confirm a 20-minute call.
- Email and messages. Whatever you send to hello@shazmethod.com or shaz@shazmethod.com, including attachments you choose to include.
- Business context. Offer, funnel, tools, and pipeline details you share so we can diagnose the leak and — only after a written yes — build in your GoHighLevel account.
- Technical data. Standard server and browser logs (IP address, user agent, pages viewed) needed to operate and secure the site.
- Payment records. Amount, currency, product (setup or retainer), order or subscription reference, payment status, and billing contact. See payment data below.
Payment data and card details
Checkout is handled by a PCI-DSS compliant payment gateway — currently expected to be Dodo Payments, or a successor PCI-DSS gateway (for example another Stripe-like processor). The gateway collects card numbers, expiry, CVC, and other sensitive payment credentials on its own hosted checkout or iframe.
We do not store full card numbers, CVC codes, or raw bank-account credentials on this site or on our own servers. We may receive tokens, last-four digits, card brand, billing name and email, and a success or failure status so we can start work or retry a failed charge.
International cards and wallets are processed by the gateway. Currency conversion, 3-D Secure, and fraud checks happen under that provider’s rules. Your bank or card network may apply its own fees.
How we use information
- Reply to applications and schedule the free diagnostic
- Decide whether the method is the right tool, then confirm a written yes before work
- Implement and operate the method in your GoHighLevel account after you engage us
- Process setup and retainer invoices through the payment gateway
- Send transactional mail: booking confirmations, invoices, pause or cancellation notices
- Prevent fraud, chargebacks we did not earn, and abuse of the site
- Comply with tax, accounting, and other legal obligations
We do not sell personal information or rent it as a mailing list.
Legal bases (where applicable)
We process data to take steps toward a contract (your application and any paid work), to perform that contract, to pursue legitimate interests in running a secure practice, and where the law requires a record. Where a specific use needs consent, we will ask for it.
Processors and subprocessors
We use vendors who process data on our instructions. Typical categories:
- Payment providers. Dodo Payments, or a successor PCI-DSS gateway, plus the card networks and banks behind a checkout. They process payment credentials and billing details under their own privacy terms.
- Hosting and delivery. The infrastructure that serves this static site (currently AWS Amplify or an equivalent host/CDN).
- Forms and email. If a form endpoint is configured, that provider receives the application payload. Otherwise the form opens a draft to hello@shazmethod.com. Mail hosts then store the thread.
- GoHighLevel. After a yes, work happens in your GHL account. HighLevel and its carriers process contacts, SMS, and email under their terms — not as a database we own.
- Professional advisers. Accountants or counsel when needed to keep books or handle a dispute.
Authorities may receive information when required by applicable law. We do not share your file with unrelated marketers.
Cookies and checkout
This marketing site is mostly static and does not currently load a third-party analytics pixel. The host or CDN may set essential cookies or logs for security and delivery.
When you pay, the gateway’s checkout may set cookies or local storage for session continuity, fraud prevention, and 3-D Secure. Those cookies are controlled by Dodo Payments or the successor gateway, not by a dashboard on this site. You can block non-essential cookies in your browser; checkout may then fail and you will need another way to pay.
If we later add limited first-party analytics, we will name the tool here. Until then, assume only essential site and checkout cookies.
Retention
Application and meeting details are kept long enough to run the diagnostic and, if we work together, to deliver the engagement. If we do not proceed, we keep a short record of the enquiry so we do not re-ask the same questions, then delete or anonymise when it is no longer useful.
Payment, invoice, and tax records are kept for the period required by Indian accounting and tax rules (typically several years), and as long as needed to resolve chargebacks or other disputes. Gateway logs live with the processor under its retention schedule.
Security
The site is served over HTTPS. Card data is collected by a PCI-DSS gateway, not typed into a form we host. Access to enquiry and billing mail is limited to people who need it to do the work. No method of transmission or storage is completely secure.
International transfers
The practice is operated from India and serves clients worldwide. Hosting, email, and payment processors may store or process data in other countries. We use vendors that offer contractual and security safeguards appropriate to this kind of work.
Your rights
Subject to law and records we must keep, you may ask us to access, correct, or delete personal data we hold, or to restrict how we use it. Email shaz@shazmethod.com with enough detail to find your file (the email you applied with, and a payment reference if you have one).
You can also ask your card issuer about a charge, but please write to us first so we can refund an unused prepaid month or fix a duplicate charge without a dispute. See the Terms for refunds and chargebacks.
Children
The site and the method are for business operators. We do not knowingly collect personal data from anyone under 18. If you believe a minor submitted an application, contact shaz@shazmethod.com and we will delete it.
Changes
We may update this policy when products, processors, or the law change. The date at the top will move when we do. Material changes that affect paying clients will also be flagged by email where we have an address on file.
Contact
Privacy, billing, and payment questions: shaz@shazmethod.com.
New applications and general questions still go to hello@shazmethod.com — that address is what the apply form opens. Also see Terms.