Privacy Notice

Last updated: September 18, 2026

This notice explains how Jeffrey Normore ("we", "us") collects and uses personal data when you read the blog, create an account or subscribe to Lean Nonprofits. We keep collection to what the service actually needs, we do not sell your data, and you can ask us to delete it at any time.

Who is responsible

Jeffrey Normore is the data controller for the information described here, meaning we decide why and how it is processed. You can reach us at jeffreynormore@gmail.com.

What we collect and why

Contact and account data

Your name and email address, which you give us when you create an account. We use them to create your account, send you secure sign-in links, tell you when your subscription is about to renew or has been cancelled, and answer your messages. The legal basis is the contract we have with you when you subscribe.

Subscription data

Your plan (monthly or yearly), whether your subscription is active, and the dates of your billing period. We store the fact that you are a subscriber so the site knows which guides to unlock for you. Card numbers and other payment details are held by our Merchant of Record, Paddle, not by us.

Reading and progress data

Which guides you open, how far through each guide you get, and when you mark one complete. This powers the progress markers you see in the library and lets us resume a guide where you left off. It is processed on the basis of our legitimate interest in making the service useful.

Support messages

Anything you email us about, including the email address you write from. We use it to help you and to keep a record of what we told you.

Technical and usage data

Your IP address, approximate country, browser and device type, and which pages you visit. We use this to keep the site secure, to spot abuse, and to understand which guides and articles are actually being read so we know what to write next.

Where payment data lives

Paddle.com is the Merchant of Record for all orders. Paddle collects and processes the payment information needed to take your money, issue invoices, calculate and remit sales tax, and handle refunds. We receive confirmation that you paid and the details needed to manage your subscription, not your card number.

Who we share it with

  • Paddle, our Merchant of Record, for payment, subscription management, tax compliance and invoicing.
  • Our hosting and database provider, which stores accounts, subscriptions and progress on our behalf.
  • Our email delivery provider, which sends sign-in links and subscription notices on our behalf.
  • Our analytics provider, which reports visitor and page-view totals so we can see what is being read.
  • Professional advisers, such as our accountant or a lawyer, where they need to see it to advise us.
  • Authorities or courts, where we are legally required to disclose it.

These providers process data only for the purpose we engaged them for. We do not sell personal data, and we do not share it for advertising.

How long we keep it

Account, subscription and progress data is kept while you are a subscriber and for a short period afterwards in case you come back. Billing records are kept for as long as tax law requires. Support messages are kept for about two years. When data is no longer needed, we delete or anonymise it.

Your rights

You can ask us at any time to:

  • confirm what we hold about you and give you a copy;
  • correct anything that is wrong;
  • delete your account and the data attached to it;
  • give you your data in a portable format;
  • stop using your data for anything based on consent or legitimate interests.

Email jeffreynormore@gmail.com and we will handle it, normally within 30 days. If you are in the European Union or United Kingdom you also have the right to complain to your data protection authority; outside those regions you have the equivalent right to complain to your national privacy regulator. Deleting your account ends access to the guide library and any unused subscription time.

How we protect it

Data is stored on infrastructure that requires authentication to reach, transferred over encrypted connections, and access is limited to what is needed to run the service. Sign-in uses single-use email links rather than passwords, so there is no password database to leak. No system is perfectly secure, and we will tell you promptly if we become aware of a breach that affects you.

Cookies

We use strictly necessary storage to keep you signed in and to remember which guides you have opened. Aggregate usage analytics help us understand what is read. We do not run advertising or cross-site tracking cookies, and there is nothing to opt into or out of beyond the essentials.

Children and international transfers

The service is for professionals running organisations and is not directed at children. Some of our providers operate outside your country, so your data may be processed elsewhere; we rely on the safeguards those providers put in place for such transfers.

Questions

Any question about this notice, or about how we handle your data, can go to jeffreynormore@gmail.com. You can also read our Terms & Conditions and Refund Policy.