Section 01
Who We Are
Wellthpath ("we," "our," or "us") is a personal finance education brand producing digital spreadsheet tools and educational content for individuals in the United States. Wellthpath is operated by its founders and is based in Norway.
Our products include the Budget Starter (free), Budget Planner Pro, Side Hustle Profit Tracker, Freelancer Tax Vault, and Home & Debt Command Centre, distributed via Kajabi.
Website
Section 02
Scope of This Policy
This Privacy Policy applies to:
- Our website(s), including Kajabi-hosted landing pages and checkout pages
- Our email marketing communications managed via Kajabi
- Our social media presence on Instagram and TikTok
- Our digital products delivered electronically
- Our ManyChat comment-automation flows on Instagram
This Policy does not apply to third-party websites or platforms we link to.
Section 03
Personal Data We Collect
Data you provide directly
- Name and email address when you opt in or purchase a product
- Payment information — processed by Stripe; we do not store card numbers
- Any information you share via direct messages, emails, or contact forms
Data collected automatically
- IP address and approximate geographic location
- Browser type, operating system, and device type
- Pages visited, time on page, and referral source via cookies
- Email open and click events tracked by Kajabi
Data from third-party platforms
- Instagram — if you comment or DM us, Instagram shares your public profile with us and ManyChat
- TikTok — interactions are also subject to TikTok's own privacy policy
- Kajabi — manages our email list, product delivery, and purchase records as our data processor
- Stripe — processes payments as an independent data controller under PCI-DSS
Section 04
How We Use Your Data
- To deliver the digital products you purchase
- To send email communications you have opted into
- To respond to your questions and support requests
- To analyse how our website and content perform
- To comply with our legal obligations
- To detect and prevent fraud or abuse
We do not use your personal data for profiling, automated decision-making, or targeted advertising. We do not sell your personal data. We do not share your data with advertisers.
Section 05
Legal Basis for Processing (GDPR)
For individuals in the EEA or UK, our legal bases for processing are:
- Contract performance — processing your purchase and delivering your product (Art. 6(1)(b))
- Legitimate interests — analysing website traffic and improving content (Art. 6(1)(f))
- Consent — sending marketing emails and placing non-essential cookies (Art. 6(1)(a))
- Legal obligation — retaining transaction records for tax compliance (Art. 6(1)(c))
Section 06
Cookies & Tracking
Strictly necessary
Required for the website to function. Cannot be disabled. Includes session management tokens set by Kajabi.
Analytics cookies
We may use tools such as Google Analytics to understand how visitors use our site. These collect anonymised data and are only placed with your consent.
Marketing / Pixel cookies
If we run paid campaigns (Meta Pixel, TikTok Pixel), these track conversions and are only placed with consent. As of the effective date, we do not run paid advertising.
You can manage your cookie preferences at any time using the banner on this site, or via your browser settings.
Section 07
Data Sharing & Processors
We share personal data only with trusted third-party processors bound by data processing agreements.
| Processor | Purpose | Location |
|---|---|---|
| Kajabi | Email marketing, product delivery | United States |
| Stripe | Payment processing | United States |
| ManyChat | Instagram DM automation | United States |
| Meta / Instagram | Social media platform | United States |
| Google Analytics | Website analytics (consent required) | United States |
We do not sell, rent, or trade your personal data. We never share your data with third parties for their own marketing purposes.
Section 08
International Data Transfers
Wellthpath is operated from Norway (EEA). Our products are primarily sold to US customers. Our service providers are US-based.
Where we transfer personal data from the EEA to the US, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission. Our major processors maintain SCCs as part of their standard terms.
Section 09
How Long We Keep Your Data
- Email subscriber data — kept while you're subscribed; deleted within 30 days of unsubscribe
- Purchase records — kept for 7 years (Norwegian Bokføringsloven + US tax requirements)
- Customer support communications — kept for 3 years
- Analytics data — retained in anonymised form per our provider's default settings
- Cookie consent records — kept for 12 months from the date of consent
Section 10
Your Privacy Rights
GDPR rights — EEA & UK residents
Access
Obtain a copy of your personal data.
Rectification
Correct inaccurate data.
Erasure
Request deletion of your data.
Restriction
Limit how we use your data.
Portability
Receive your data in a portable format.
Object
Object to legitimate-interest processing.
To lodge a complaint: Datatilsynet (Norway) — datatilsynet.no
CCPA / CPRA rights — California residents
- Right to know what personal information we collect, use, and disclose
- Right to delete personal information we have collected
- Right to correct inaccurate personal information
- Right to opt out of the sale or sharing of personal information
- Right to non-discrimination for exercising your privacy rights
Wellthpath does not sell or share personal information for cross-context behavioural advertising. We respond to California requests within 45 days.
Section 11
Email & CAN-SPAM
- Every marketing email includes a clear, functional unsubscribe link
- We process unsubscribe requests within 10 business days
- We do not use deceptive subject lines or sender information
- Our emails clearly identify Wellthpath as the sender
To unsubscribe, click the link at the bottom of any Wellthpath email, or email [email protected] with "Unsubscribe" in the subject line.
Section 12
Children's Privacy
Our products are directed at adults aged 18 and over. We do not knowingly collect personal data from children under 13 (or under 16 where GDPR applies). If we become aware of such data, we will delete it immediately.
Section 13
Security
- HTTPS encryption on all pages
- Password-protected access to Kajabi and Stripe accounts
- Use of SOC 2-compliant service providers where available
No transmission over the internet is completely secure. In the event of a breach likely to cause risk to your rights, we will notify you and the relevant supervisory authority as required by law.
Section 14
Changes to This Policy
We may update this Privacy Policy from time to time. We will update the "Last Updated" date and, where changes are material, notify you by email or via a prominent notice on our website.
Section 15
Contact & Data Requests
To exercise your rights or ask a question about this policy:
Response time
30 days (45 for CCPA)
EEA / Norway
California