Privacy Policy
I may change this policy from time to time by updating this page; therefore, you should check this page occasionally to ensure you agree with any changes. This policy, version 2.0, is effective from January 19, 2026.
Overview
As a writing coach, I love offering lots of helpful input and free training as well as some paid options that can help writers. Content on my website and social media platforms—and some services—are available to anyone who shows up and wants to read and interact. To operate this business and provide you with services, I sometimes collect or process information about you here on this website and in other apps, software, and systems. To give you an overview, I may gather one or more of the following:
- Information you provide directly, such as completing an online form, survey, leaving a comment, scheduling a consultation, signing up for a course or membership, or sending a message through the website.
- Information automatically sent by your browser when you visit my website, such as your device’s technical address (IP address) and details about your browser.
- Information about how you use my website or services, such as which pages you visit and how often.
This privacy policy explains what information I collect and how that data is used and protected.
My commitment to data privacy
I am committed to maintaining the security and privacy of any information (“personal data”) you provide. I use systems designed to request the minimum amount of information necessary to provide my services efficiently. I retain personal data only for as long as necessary to fulfill the purposes for which it was collected and to satisfy legal, accounting, or reporting requirements. I intend to comply to the fullest extent possible with applicable data protection regulations, including the European Union’s General Data Protection Regulation (GDPR), UK GDPR, and the ePrivacy Directive, where applicable.
I follow generally accepted industry standards, including appropriate administrative, physical, and technical safeguards, to protect personal data. However, no method of transmission over the Internet or method of electronic storage is 100 percent secure. I strive to use commercially acceptable means to protect your personal information and data, but I cannot guarantee absolute security or confidentiality.
Who am I?
When you use my services or interact with my content via my website, “Ann Kroeker, Writing Coach,” and other points of contact (such as social media or scheduling programs), I act as the Data Controller. For privacy inquiries, see the Contact section.
What is “personal data”?
“Personal data” is any information that allows me to identify you personally. Most often this would be your name and email address, but occasionally you might provide a phone number or postal address. Any request for information will be clear and for the purpose of delivering information and services, so you know why I’m asking for it. Where applicable, I’ll seek your consent before collecting it, although consent may not be the only lawful basis for processing.
Lawful bases for processing
- Consent: newsletter sign-ups, marketing emails, and non-essential cookies (e.g., analytics).
- Contract: delivering coaching services, course/community access, and support.
- Legitimate interests: site security, fraud prevention, diagnostics, and essential service communications.
- Legal obligation: tax/accounting retention requirements.
With whom do I share data?
To support my work and processes, I rely on third-party companies (Data Processors) to help fulfill tasks:
- Service providers who provide IT, hosting, and system administration and communication services
- Professional advisers such as lawyers, bankers, accountants, auditors, and insurers
- Financial transaction processors (that process your payments)
- Email service providers
- Government bodies that require me to report processing activities
I expect all third parties to respect the security of your personal data and treat it in accordance with the law. Each has its own privacy policies and terms. When you are directed to a third-party service from my site or while working with me, please review their terms and privacy policies. If you cannot agree to a third party’s terms or privacy policy, I may be unable to fulfill a service.
My website and emails may contain links to other websites of interest. Once you use these links to leave my site or click through from an email, I do not control those other websites. I cannot be responsible for the protection and privacy of any information you provide while visiting such sites, which are not governed by this privacy statement. Review the privacy policies and terms applicable to any website you visit.
Third-party processors
To operate this business, I use reputable suppliers who process personal data on my behalf, including (see Vendor Details appendix for links and specifics):
- SiteGround (website hosting)
- WordPress with the Astra theme and selected plugins (content management and site features)
- Kit (formerly ConvertKit) and Encharge (email communications and newsletters)
- Heartbeat.chat (course/community hosting; user accounts, messages, participation data)
- Google Analytics and Google reCAPTCHA (site analytics and abuse prevention)
- Google Forms and Google Fonts (forms and typography)
- Formaloo (forms)
- TidyCal (appointment scheduling)
- Stripe (payment processing; I never collect, store, or have access to full card numbers or CVVs/CVCs)
- Albato (integrations/automation to pass data between services)
- Google Drive and Notion (document storage for client work)
We use integrations (e.g., Albato) to securely pass data between services you use with us (such as tagging enrollments in Encharge after you sign up in Heartbeat.chat, or TidyCal linked to Zoom to create meeting links when scheduling), strictly for operational and communication purposes.
Each provider has its own privacy notice; see the Vendor Details appendix for links and specifics.
Your rights
When you have directly provided personal information to me (such as by completing an online form or contacting me), you have rights regarding the personal data I hold:
- Access: confirm whether I hold personal data about you and receive a copy.
- Rectification: correct incomplete or inaccurate information.
- Erasure: request deletion of data (“right to be forgotten”), subject to legal obligations.
- Objection and restriction: object to certain processing or request restriction while your objection is considered.
- Consent: withdraw consent at any time where processing is based on consent.
- Portability: request transfer of your data to another controller.
When personal data is collected automatically (such as via your Internet browser, server logs, or cookies), you may object to the legal basis upon which I collect this data, and I have an obligation to consider and respond.
I may make your personal data anonymous (so you can no longer be identified) for research or statistical purposes. I may use anonymous information indefinitely without further notice.
In most circumstances, you can exercise these rights without paying a fee. I may charge a reasonable fee or refuse a request if it is clearly unfounded, repetitive, or excessive.
I may need to request specific information to help confirm your identity and ensure your right to access your personal data (or exercise other rights). This security measure ensures personal data is not disclosed to anyone without the right to receive it. I may contact you to ask for further information to speed up our response, and may enlist trusted professionals or relevant third-party service providers to assist with the process.
I aim to respond to legitimate requests within one month. If your request is complex or you have made multiple requests, it may take longer; I will notify you if that’s the case.
Types of data collected on this website
The types of data collected may change in quantity and method if I enable new functionality (for example, a new plugin). Significant changes will be noted in an updated version of this privacy policy.
General WordPress and website information
This is a WordPress website hosted by SiteGround, each of which has its own privacy policy. Using this website may result in information being collected via functionality provided through WordPress and other website methods.
Website contact forms
When you complete one of the contact forms on the website, I ask for personal information such as your name, email address, and other contact details. This is required to respond to your request. If you do not use or submit an online form, no data is collected in that regard.
Some forms relate to my email list, and the information you provide will add you to the list. I currently use two email service providers: Kit (formerly ConvertKit) and Encharge. Form information is collected on the website, and I manage that communication through Kit and Encharge. These are two of my primary data processors, and your rights apply to the information they store on my behalf. See Vendor Details for more information.
Comments
I currently have comments enabled on annkroeker.com. When you leave a comment, you will be asked to supply some information—usually your name, email address, and website. WordPress may set a cookie in connection with the comment form to remember your details and make it easier to comment next time. This information is stored within WordPress and used to manage comments and respond to you.
Most of the information you supply in a comment form is displayed to the public, including the comment itself. Please review what is displayed prior to leaving a comment, understanding it is not private and can be viewed by anyone online, including friends and family, the media, investigators, and prospective employers.
Technical data (such as IP address)
Server logs
When you visit the site, my systems collect technical information including IP address, device/browser details, and pages visited. Under GDPR/UK GDPR, IP addresses are personal data. I process this data for security, fraud prevention, diagnostics, and to maintain the site (lawful basis: legitimate interests).
Cookies Policy
Cookies are used by most websites because they help deliver and improve online services. I use cookies on annkroeker.com to better serve visitors—for example, to analyze how people use the site and to improve speed, performance, and security. Cookies can also be essential to provide certain functionality.
Cookies are small data files placed on your browser or device that can include identifiers considered personal data under GDPR/UK GDPR (for example, online identifiers and IP address). They allow me to tell when a page has been visited or a button clicked, but I do not use them to identify you by name without additional information.
You can opt out of cookies, but if you disable or refuse them, some parts of this website may not function properly. For example, WordPress may use a cookie to remember a commenter’s name and/or email address, and some embedded services may set necessary cookies to operate.
Types of cookies include:
- Session cookies: expire at the end of your browser session to link your actions during that session.
- Persistent cookies: stored on your device between sessions to remember preferences or actions.
- First-party cookies: set by the site you are visiting.
- Third-party cookies: set by a site separate from the one you are visiting.
You can influence how cookies are used on your device or block them. Most browsers (Chrome, Safari, Edge, Firefox) allow you to set preferences for allowing or blocking cookies or removing cookies already set.
Non-essential cookies (such as analytics) are only set with your consent via the cookie banner. You can change your preferences at any time. Essential cookies required for site functionality will always be set. See Vendor Details for more information about specific services.
Client communications
One-to-One and Group Communication takes place mostly via Zoom and occasionally through Voxer (Pro) and through the Heartbeat.chat direct messaging, voice notes, and live chat rooms (video and audio).
- Voxer Pro: We occasionally use Voxer Pro for asynchronous voice and text messaging with clients. Messages are handled as business communications and are not used for marketing without consent.
- Zoom (including recorded to cloud or local):
- I record certain 1:1 and group calls with participants’ consent. Zoom displays a recording indicator; we also give a verbal notice. If you do not wish to be recorded, please leave the call or request a non‑recorded alternative.
- Recordings are hosted on Loom and may be embedded in Heartbeat.chat for members/clients who have access rights.
- Zoom cloud copies are deleted after download. Local copies are temporary and kept only until upload to Loom per our retention schedule.
How your data is protected
I take the security of personal data seriously and work to protect it in several ways:
- Access control: access to personal data is strictly limited in line with my policy detailed in the “With whom do I share data?” section. Access to this website and Data Processors is limited to very few people, and when another person has access, it is controlled by individual user accounts where a strong password policy is enforced.
- Selection of third-party service providers: I use a limited number of third-party service providers (Data Processors), some of which are essential for hosting environments and cloud services. I choose reputable providers who comply with laws and regulations and uphold strict privacy practices.
Courses and Community
If you enroll in a course or join the community hosted on Heartbeat.chat, Heartbeat will process your account details (name, email), activity, messages/posts, and course progress to deliver the service (lawful basis: contract). Heartbeat may set cookies required for login and session management.
- Data categories: account profile (name, email), enrollment status, course progress, posts/comments/messages, timestamps, and moderation actions.
- Purpose: deliver course/community features, manage access, provide support, and maintain platform security and integrity.
- Cookies/trackers: session cookies for authentication and feature functionality; any non-essential cookies are controlled via Heartbeat’s own settings and notices.
- Payments: if any payments for courses are processed, they are handled via Stripe; card details are processed directly by Stripe and are not stored on my servers.
- Retention: course/community data is kept while your account remains active and for up to 24 months after inactivity, unless you request deletion sooner.
- Your choices: you can edit or delete your posts within the platform and request account deletion at any time via my privacy contact or Heartbeat’s support.
See Vendor Details for more information about Heartbeat.
Payments
- Provider: Stripe
- What’s processed: name, email, billing address, transaction details; card numbers are processed by Stripe and are not stored on my servers.
- Important clarification: I do not collect, store, or have access to full payment card numbers or CVVs/CVCs at any time. Card information entered at checkout is transmitted directly to Stripe.
- Purpose and legal basis: process payments, issue refunds, and prevent fraud (contract; legitimate interests; legal obligations).
- Your choices: you can request copies of receipts and ask me to correct invoice details; for card data, see Stripe’s privacy policy.
See Vendor Details for Stripe’s privacy policy link and transfer safeguards.
Meeting recordings
- We record certain 1:1 and group calls with participants’ consent. Zoom displays a recording indicator; we also give a verbal notice. If you do not wish to be recorded, please leave the call or request a non‑recorded alternative.
- Recordings are hosted on Loom and may be embedded in Heartbeat.chat for members/clients who have access rights.
- Zoom cloud copies are deleted after download. Local copies are temporary and kept only until upload to Loom per our retention schedule.
International transfers
Some processors are located outside your region. Where data is transferred internationally, I rely on applicable safeguards, such as adequacy decisions (e.g., EU–US Data Privacy Framework), Standard Contractual Clauses (SCCs), vendor security measures, and data minimization appropriate to the service. See Vendor Details for vendor-specific notes.
Data retention
- Inquiry/contact emails: up to 12 months
- Client records and invoices: 6 years (for tax/accounting)
- Newsletter data: until you unsubscribe, plus up to 12 months for suppression
- Course/community data (Heartbeat): while your account is active and up to 24 months after inactivity unless you request deletion
- Website server logs and security logs: typically 90 days to 12 months, unless required longer for security or legal reasons
Google Analytics
I use Google Analytics 4 to understand site usage. Analytics cookies/identifiers are only set with your consent via the cookie banner. I do not use GA for advertising or profiling. For details, see “How Google uses information from sites or apps that use our services” and GA’s opt-out tools. See Vendor Details for links.
Other Google services
This site may use:
- Google reCAPTCHA for abuse prevention on forms
- Google Forms for applications/surveys
- Google Fonts for typography
These services may connect to Google servers and set necessary cookies or collect technical data to deliver the features. See Vendor Details for more information.
Contact
Privacy contact: privacy@annkroeker.com
Business address: P.O. Box 614, Westfield, IN 46074
If you have concerns, you may also lodge a complaint with your local data protection authority.
Updates to this policy
I may update this policy from time to time. Material changes will be noted on this page with a new version and “Effective date” at the top. Your continued use of the site after changes are posted indicates acceptance of the updated policy.
Effective date
Version 2.0 — Effective January 19, 2026
—
Vendor Details
For each core processor, the following applies. If a cross‑border transfer occurs, I rely on applicable safeguards (e.g., EU–US Data Privacy Framework, Standard Contractual Clauses).
- SiteGround
- Data: IPs, server logs, hosting metadata
- Purpose: site hosting, security, diagnostics
- Retention: server/security logs typically 90–12 months
- Transfers: may include international transfers with safeguards
- Policy: https://www.siteground.com/privacy.htm
- WordPress.org / Astra
- Data: functional cookies, plugin/theme telemetry (where applicable)
- Purpose: content management and site features
- Retention: per plugin/theme needs; configuration‑dependent
- Transfers: may include international transfers with safeguards
- Policies: https://wordpress.org/about/privacy/ | https://brainstormforce.com/privacy-policy/
- Kit (ConvertKit) / Encharge
- Data: name, email, subscription status, campaign interactions
- Purpose: email communications and automation
- Retention: while subscribed; suppression up to ~12 months after unsubscribe
- Transfers: international transfers with safeguards (e.g., SCCs)
- Policies: https://convertkit.com/privacy | https://encharge.io/privacy-policy/
- Heartbeat.chat
- Data: account profile (name, email), enrollment status, course progress, posts/comments/messages, timestamps, moderation actions
- Purpose: deliver course/community features, manage access, provide support, and maintain platform security/integrity
- Payments: if payments occur via Heartbeat, they are processed by Stripe; card details are transmitted directly to Stripe and are not stored on my servers or Heartbeat’s.
- Retention: while active; up to 24 months after inactivity unless deleted sooner
- Transfers: may include international transfers with safeguards (e.g., SCCs)
- Policy: https://www.heartbeat.chat/privacy
- Google Analytics / reCAPTCHA / Forms / Fonts / Drive
- Data: online identifiers (including IP), device/browser info, usage events, consent state; reCAPTCHA risk scores; form responses; font delivery logs; stored docs and file metadata
- Purpose: site analytics (GA4), abuse prevention (reCAPTCHA), forms/applications (Forms), typography (Fonts), document storage and collaboration (Drive)
- Retention: GA4 configurable (commonly 2–26 months depending on settings); reCAPTCHA transient; Forms per form lifecycle; Fonts minimal/transient; Drive per document lifecycle and engagement needs
- Transfers: international transfers with safeguards (e.g., SCCs; vendor DPF participation where applicable)
- Policies: https://policies.google.com/privacy?hl=en | Partner sites: https://policies.google.com/technologies/partner-sites
- TidyCal
- Data: name, email, scheduling details, time zone
- Purpose: appointment scheduling and notifications
- Payments: for paid bookings, TidyCal uses Stripe as its payment processor; payment data necessary for the transaction is shared with Stripe. I do not collect, store, or have access to full card numbers or CVVs/CVCs.
- Retention: per booking lifecycle and legal requirements
- Transfers: may include international transfers with safeguards
- Policy: https://tidycal.com/privacy
- Stripe
- Data: name, email, billing details, transaction metadata (e.g., card brand, last four digits, transaction IDs, outcome/failure codes); fraud signals
- Important clarification: payments are processed directly by Stripe. I do not collect, store, or have access to full payment card numbers or CVVs/CVCs at any time.
- Purpose: payments, refunds, invoicing, fraud prevention; processes payments for TidyCal bookings, Heartbeat.chat enrollments (where applicable), and my one‑to‑one coaching (and related services).
- Purpose: payments, refunds, invoicing, fraud prevention
- Access: I can access my Stripe account to view transaction metadata and payout reports, but never full card numbers.
- Retention: per legal and accounting requirements
- Transfers: international transfers with safeguards; Stripe maintains PCI DSS compliance for card processing
- Policy: https://stripe.com/privacy
- Notion
- Data: documents, notes, project artifacts, collaboration metadata
- Purpose: client work organization and document management
- Retention: while engaged; archived per engagement needs
- Transfers: international transfers with safeguards (e.g., SCCs)
- Policy: https://www.notion.so/legal/privacy
- Zoom
- Role: Processor (video conferencing; optional recording)
- Data processed: meeting metadata (host, participants, time, IP/device info), audio/video, chat messages, and if enabled, transcripts/closed captions.
- Purpose: conduct 1:1 and group meetings; provide recording where requested; security and abuse prevention.
- Lawful bases: contract (provide services); legitimate interests (service integrity/security); consent (being recorded).
- Retention: cloud copies are deleted after download; local originals retained temporarily until successful upload to Loom, then deleted per the schedule below.
- Location/transfers: processing may occur in the United States and other regions. Transfers safeguarded via Zoom’s DPA (SCCs and, where applicable, EU‑U.S./UK‑U.S. Data Privacy Framework participation).
- Security/compliance: encryption in transit; optional E2EE; admin controls and audit logs.
- Key links: Privacy (explore.zoom.us/privacy), Trust & Security (explore.zoom.us/trust), DPA (explore.zoom.us/trust/data-processing-addendum)
- Loom
- Role: Processor (video hosting/streaming; embed delivery)
- Data processed: uploaded videos and thumbnails; audio/video of participants; titles/descriptions; viewer playback events (plays, watch time), IP address, device/browser info; limited cookies for embeds.
- Purpose: host and stream client/member replays; measure playback and reliability; secure access.
- Lawful bases: contract; legitimate interests (service quality, security); consent (recording participation; non‑essential cookies/analytics in EU/UK).
- Retention: recordings of group calls and client 1:1 calls are kept in our Loom account for replays; group calls are retained for membership replays indefinitely; playback analytics per Loom’s policy. Earlier deletion of personal one-to-one replays available upon request.
- Location/transfers: processing may occur in the United States and other regions. Transfers safeguarded via Loom’s DPA (SCCs and, where applicable, EU‑U.S./UK‑U.S. Data Privacy Framework participation).
- Security/compliance: encryption in transit/at rest; access controls.
- Key links: Privacy (loom.com/privacy), DPA (loom.com/dpa), Security (loom.com/security)
- Voxer Pro
- Role: Processor (client communications via voice notes, text messages, and attachments)
- Data processed: message content (voice notes, texts, images/files), timestamps, participant identifiers, display name/profile info, IP address, device/app version, push notification tokens, and diagnostics/analytics collected by the app.
- Purpose: facilitate client communications; ensure service reliability and security; deliver notifications.
- Lawful bases: contract (provide services to clients); legitimate interests (service quality, security). Consent may apply where local law requires for audio messaging.
- Retention: messages retained per our retention schedule (see below). We delete conversation threads on request where feasible and not legally required to retain.
- Location/transfers: processing may occur in the United States and other regions. Cross-border transfers safeguarded under the vendor’s agreements (e.g., SCCs and, where applicable, participation in EU‑U.S./UK‑U.S. Data Privacy Framework). See Voxer’s current policies for details.
- Security/compliance: encryption in transit; access controls; administrative safeguards described by the vendor.
- Key links: Privacy Policy (voxer.com/privacy), Terms (voxer.com/terms). For data processing terms/DPA, see vendor documentation or contact support.
- Albato
- Role: Processor (integrations/automation; routes data between services you use with us)
- Data processed: event payloads and fields passed through from source to destination (e.g., name, email, course enrollment details, tags), workflow metadata, timestamps, IP/device info associated with webhook/API calls, error logs.
- Purpose: execute automations; synchronize records (e.g., enrollment → tag in Encharge); reliability and security monitoring.
- Lawful bases: contract (provide services); legitimate interests (operate our systems efficiently and accurately).
- Retention: workflow logs retained per Albato’s policy; we minimize data within tasks and do not store payloads longer than necessary. We periodically purge non-essential logs; operational copies retained up to 12 months for troubleshooting, then deleted/anonymized.
- Location/transfers: processing may occur in the United States and other regions; cross‑border transfers safeguarded under the vendor’s DPA (e.g., SCCs and, where applicable, EU‑U.S./UK‑U.S. Data Privacy Framework).
- Security/compliance: encryption in transit; API keys and access controls; audit/history for workflows.
- Key links: Privacy Policy and DPA are available on Albato’s site.
- Formaloo
- Role: Processor (forms, data collection, and intake questionnaires)
- Data processed: Contact Information (Name, Email), Inquiry Details (Coaching type request, detailed description of coaching challenges/needs), Metadata (IP address approximations, submission timestamps).
- Purpose: Lead generation; direct contact initiation; initial needs assessment for service matching; system security and anti-spam measures.
- Lawful bases: Contract (necessary to respond to pre-contractual requests); legitimate interests (processing necessary to manage and respond to incoming inquiries efficiently).
- Retention: Data is retained as long as necessary to fulfill the purpose of the inquiry (e.g., while actively in sales or intake) or as long as the associated client/lead record is active in the CRM/file system, typically up to 24 months of inactivity before archival/deletion, subject to internal data governance schedules.
- Location/transfers: Data centers located in Toronto, Canada; Tallinn, Estonia; and London, UK. Transfers outside the EEA/UK are governed by Formaloo’s Privacy Policy and DPA, relying on established safeguards (e.g., SCCs or equivalent mechanisms) where applicable for EU/UK data.
- Security/compliance: Encryption in transit (HTTPS/TLS); role-based access controls; security monitoring; compliance with relevant data protection standards as outlined in their policy.
- Key links: Privacy Policy: https://www.formaloo.com/privacy-policy
- Retention schedule
- Zoom cloud copies: delete immediately after download (target within 24 hours).
- Local Zoom originals: delete within 7 days after successful upload to Loom.
- Meeting metadata/logs: retain 12 months for security/audit, then archive or anonymize.
- Voxer Pro messages: retain up to 12 months for client communications continuity, then delete or export and archive minimally (metadata only) if needed for contractual records; earlier deletion on request when feasible.
Last edited: January 19, 2026
