Privacy policy
Privacy Policy
This Privacy Policy explains how Gray Shadow Consulting collects, uses, discloses, retains, and protects personal information and describes the choices available to you.
Effective July 25, 2026
Privacy Policy
Effective date: July 25, 2026. Policy version: GSC-LEGAL-2026-07-25-v1.1. Last updated: July 25, 2026.
Gray Shadow Consulting is a sole proprietorship based in California. Gray Shadow Consulting is also referred to as “GSC,” “we,” “us,” or “our.” This Privacy Policy describes the personal information we collect, the sources from which we collect it, why we use it, when we disclose it, how long we intend to retain it, and the choices available to you.
This policy applies to grayshadowconsulting.com, communications with GSC, and GSC products, memberships, and services that link to this policy. It does not replace a separate privacy notice presented for a specific service, and it does not govern a third party’s independent practices.
Who we are
Gray Shadow Consulting is the sole proprietorship identified in this policy. Our office and public notice address is 750 North San Vicente Blvd, Suite 800, West Hollywood, CA 90069. Our public contact information is info@grayshadowconsulting.com and 323-813-5689.
Information we collect
Contact and inquiry information. When you contact us by email or telephone, we may collect your name, email address, telephone number, organization, the content of your message, and any information you choose to provide.
Account, order, and membership information. When you purchase or access an offer through Whop or another expressly identified checkout provider, we may receive your name, email address, account identifier, order and membership identifiers, product or plan, price, transaction status, renewal and cancellation status, access history, refund or dispute information, and support communications.
Payment information. Payment credentials are collected and processed by Whop and its payment partners. GSC does not intend to receive or store your full payment-card number or card security code. We may receive limited billing information such as billing name, billing address, payment method type, transaction amount, and the last digits or tokenized identifier needed to administer an order.
Website and device information. When you use the website, we and our service providers may collect IP address, browser and device type, operating system, language, referring and exit pages, pages and links viewed, dates and times, approximate location derived from IP address, cookie or device identifiers, and information about interactions with the site.
Communications and marketing information. We may keep records of service, support, legal, refund, and marketing communications, along with your subscription, consent, and opt-out preferences.
Derived information. We may infer general interests, engagement, or likely preferences from the information above. We do not intend to create sensitive profiles or make decisions that produce legal or similarly significant effects through automated processing.
Sensitive information. Please do not send government identification numbers, full payment credentials, medical records, precise geolocation, or other sensitive information unless we specifically request it through an appropriate secure process. GSC does not intend to collect sensitive personal information through the public website.
Sources of information
We collect information directly from you, automatically from your browser or device, from Whop and other service providers used to deliver an offer, and from people or organizations that lawfully refer or engage us. We may combine information from these sources when reasonably necessary for the purposes described below.
How we use information
We use personal information to operate and secure the website; respond to inquiries; create and administer accounts, orders, memberships, access, and support; process cancellations, refunds, and disputes; deliver products and services; communicate transactional or service information; send marketing communications when permitted; understand and improve site and offer performance; detect fraud, abuse, and security incidents; keep records; enforce agreements; comply with law; and establish, exercise, or defend legal claims.
Where a law requires a specific legal basis, our basis may be performance of a contract, steps requested before entering a contract, compliance with a legal obligation, our legitimate interests when those interests are not overridden by your rights, or consent. You may withdraw consent for future processing where consent is the basis, without affecting processing already completed.
Cookies, analytics, and advertising technology
The website uses Cloudflare for hosting, delivery, security, and related technical services. Its presentation fonts are served as local website assets rather than requested by the visitor’s browser from Google Fonts. The intended release configuration also uses Google Tag Manager to manage approved measurement technology, Google Analytics 4 for audience and site-use measurement, and may use Google conversion-linking and X/Twitter technology for attribution or remarketing when those uses are enabled and lawfully configured. Hotjar is not part of the approved release configuration and is not enabled in the current production Google Tag Manager container.
These services may use cookies, pixels, tags, local storage, or similar identifiers and may receive website and device information. Some providers may combine information from this site with information from other sites or services under their own terms and privacy policies.
The planned release control keeps the Google Tag Manager container and its nonessential analytics and advertising technology unloaded unless you affirmatively allow the combined nonessential category. You may use “Privacy choices” in the website footer to allow or withdraw that choice. Withdrawing a prior choice stops future container loading and removes known first-party measurement cookies where the browser permits. Essential page delivery, security, accessibility, and storage of the privacy choice remain available.
Do Not Track signals are not interpreted consistently across the industry, and the website does not treat a general Do Not Track signal as a universal opt-out. The website detects a recognized Global Privacy Control signal exposed by the browser and keeps the combined nonessential measurement and advertising category off while that signal remains active. The website interface does not permit an active GPC signal to be overridden.
When we disclose information
We may disclose personal information to vendors and service providers that support hosting, security, analytics, communications, customer support, checkout, payment processing, order administration, membership access, accounting, professional advice, and related business operations. Current or planned categories include Cloudflare; Google services used through Google Tag Manager; X/Twitter when enabled; Whop and its payment partners; and professional advisors when needed.
We may also disclose information when you direct us to; to complete a transaction or provide a requested service; in connection with a merger, financing, reorganization, sale, or transfer of all or part of the business, subject to appropriate protections; to comply with law, court order, or legal process; or when reasonably necessary to protect rights, safety, property, users, or the integrity of our services.
GSC does not sell personal information for money. Certain disclosures involving analytics or advertising technology may be defined as a “sale,” “sharing,” or “targeted advertising” under some privacy laws even when no money is exchanged. Where such a law applies, we will provide the required notice and opt-out method and will not knowingly sell or share personal information of consumers under 16 without the required authorization.
Retention
We intend to retain personal information only as long as reasonably necessary for the purpose collected and for legal, accounting, security, and dispute obligations. Subject to any longer period required by law, the schedule is: inquiries and routine support records for up to 24 months after the last substantive interaction; customer, order, access, refund, dispute, tax, acceptance, and consent records for up to seven years after the transaction or relationship ends; subscription consent records for at least three years or one year after termination, whichever is longer; and identifiable GA4 event and user data for no more than 14 months, with the retention period not refreshed by later activity. Cloudflare account audit logs are retained by Cloudflare for 18 months. Other provider, delivery, security, and backup records are kept for the shortest documented period compatible with the operational purpose, provider controls, legal duties, active disputes, and documented legal holds. Approved deletion is applied to active systems and propagated to providers where supported; protected backup copies expire through the verified backup rotation rather than being restored for ordinary use.
Marketing contact information may be retained until you unsubscribe or we determine it is no longer useful, after which we may keep a minimal suppression record so we can honor the opt-out. We may retain information longer when reasonably necessary for an active dispute, legal hold, investigation, fraud prevention, or another documented legal requirement. We review this schedule against actual system settings and deletion procedures and update this policy when material practices change.
Your choices and privacy rights
You may unsubscribe from marketing email through the link in the message or by contacting us. Transactional, account, security, and legal communications are not marketing and may continue when needed.
Depending on your location and subject to legal thresholds and exceptions, you may have the right to know or access personal information; obtain a portable copy; correct inaccurate information; delete information; restrict or object to certain processing; opt out of sale, sharing, targeted advertising, or certain profiling; withdraw consent; and appeal a denied request. You also have the right not to receive discriminatory treatment for exercising a privacy right.
To make a request, email info@grayshadowconsulting.com with the subject “Privacy Request,” or write to the postal address below. Describe the right you wish to exercise and the account or interaction involved. Do not send a password, full payment-card number, or government identification document by ordinary email.
We will verify a request in a manner proportionate to the sensitivity of the information, which may include confirming control of the relevant email address or asking for transaction details already associated with the account. An authorized agent may submit a request where permitted by law, but we may require proof of authority and direct confirmation from the consumer. We will respond within the time required by applicable law and explain any denial and available appeal process.
California privacy laws may provide additional rights when their applicability thresholds are met. GSC has not treated threshold applicability as established merely because it operates a commercial website. Whether or not a particular statute applies, we intend to evaluate good-faith access, correction, deletion, and opt-out requests using the process above, subject to identity verification, security, legal retention duties, and other lawful exceptions.
Security
We use administrative, technical, and physical safeguards designed to protect personal information in light of its nature and the risks involved. These measures may include access controls, provider due diligence, secure transmission, account protection, data minimization, backups, monitoring, and incident response. No security measure or Internet transmission is completely secure, and we cannot guarantee absolute security. If you believe information associated with GSC has been compromised, contact us promptly at info@grayshadowconsulting.com.
Children
The website, products, and services are intended for adults age 18 or older. They are not directed to children under 13, and GSC does not knowingly collect personal information from children under 13. If you believe a child has provided personal information, contact us so we can investigate and delete it when appropriate.
International use
GSC is based in the United States. If you access the site from another country, your information may be processed in the United States and other locations where our service providers operate. Those locations may have different data-protection laws. Where applicable law requires it, we will use an appropriate transfer mechanism or other safeguard.
Third-party services and links
Whop, payment providers, social networks, analytics providers, and linked websites operate under their own terms and privacy notices. GSC is not responsible for a third party’s independent practices. Review the notice presented by the relevant provider before giving it information.
Changes to this policy
We may update this policy prospectively to reflect legal, operational, or technical changes. The posted policy will identify its effective date. For a material change, we will provide additional notice when reasonably appropriate, such as a prominent website notice or an email to an address associated with an active account. We will obtain consent before applying a change retroactively when the law requires it.
Contact us
Email: info@grayshadowconsulting.com
Phone: 323-813-5689
Mail: Gray Shadow Consulting, 750 North San Vicente Blvd, Suite 800, West Hollywood, CA 90069