1. Who we are
Inner Work Co ("we", "us", "our") is a digital products business based in the United Kingdom. We create and sell personal development workbooks, journals, and toolkits as digital downloads.
If you have any questions about this policy or your data, contact us at theinnerwork.cohq@gmail.com.
2. What data we collect
We collect the minimum amount of personal data needed to deliver our products and communicate with you.
| Data | When | Why |
|---|---|---|
| Email address | You sign up for our mailing list or purchase a product | To deliver products and send email communications |
| First name | You provide it when signing up | To personalise emails |
| Payment information | You make a purchase | To process your payment (handled entirely by Stripe) |
| Usage data | You browse our website | To understand how the site is used and improve it |
We do not collect sensitive personal data such as health information, political opinions, or biometric data.
3. How we store your data
When you submit your email address through our website, it is collected via a Google Apps Script endpoint and stored in a private Google Sheet. This sheet is accessible only to the Inner Work Co team.
Google Workspace is hosted on Google's infrastructure, which maintains ISO 27001, SOC 2/3, and GDPR compliance certifications. Your data is encrypted in transit (TLS) and at rest.
We do not store your payment card details. All payment processing is handled securely by Stripe, which is PCI-DSS Level 1 certified.
4. Email communications
When you sign up to our mailing list or make a purchase, we may send you:
- Product delivery emails (download links, receipts)
- Educational content related to personal development
- Product announcements and offers
- Occasional surveys or feedback requests
Every marketing email includes an unsubscribe link at the bottom. Click it and you will be removed from our mailing list within 48 hours. Transactional emails (order confirmations, download links) will still be sent as needed to fulfil purchases.
You can also unsubscribe at any time by emailing theinnerwork.cohq@gmail.com with the subject line "Unsubscribe".
5. Third-party services
We use a small number of trusted third-party services to operate our business. Each has its own privacy policy governing how they handle data:
Stripe
Processes payments securely. We never see or store your full card number. Stripe Privacy Policy
Google Analytics
Collects anonymised usage data (pages visited, time on site, device type) to help us understand how visitors use the site. We use IP anonymisation where available. Google Privacy Policy
Meta Pixel (Facebook/Instagram)
Tracks conversions from our advertising campaigns. This pixel may collect data about your browsing activity to serve relevant ads. You can opt out via your Facebook ad preferences or browser settings. Meta Privacy Policy
Google Workspace (Apps Script + Sheets)
Stores email subscriber data in a private spreadsheet. Google Workspace Terms
We do not sell, rent, or trade your personal data with any third party for marketing purposes.
6. Cookies
Our website uses a small number of cookies:
| Cookie | Purpose | Duration |
|---|---|---|
| Google Analytics | Measures site traffic and usage patterns | Up to 2 years |
| Meta Pixel | Tracks ad conversions and retargeting | Up to 90 days |
| Essential | Basic site functionality (e.g. form submissions) | Session |
You can disable cookies in your browser settings at any time. Disabling analytics or advertising cookies will not affect your ability to use the website or access purchased products.
7. Your rights under GDPR
Under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, you have the following rights:
Right of access
Request a copy of all personal data we hold about you.
Right to rectification
Ask us to correct any inaccurate or incomplete data.
Right to erasure
Request that we delete all your personal data. We will comply unless we have a legal obligation to retain it.
Right to data portability
Request your data in a structured, machine-readable format (e.g. CSV).
Right to restrict processing
Ask us to limit how we use your data in certain circumstances.
Right to object
Object to processing based on legitimate interests or direct marketing at any time.
To exercise any of these rights, email us at theinnerwork.cohq@gmail.com. We will respond within 30 days.
If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK's supervisory authority for data protection.
8. Legal basis for processing
We process your data under the following legal bases:
- Contract: To fulfil purchases and deliver digital products you have bought.
- Consent: When you sign up to our mailing list. You can withdraw consent at any time by unsubscribing.
- Legitimate interests: To analyse website usage and improve our products and services, where this does not override your rights.
9. Data retention
We retain your data only as long as necessary:
- Email subscribers: Until you unsubscribe or request deletion.
- Purchase records: For 6 years after the transaction, as required by UK tax law (HMRC).
- Analytics data: Retained by Google Analytics for up to 26 months, then automatically deleted.
When data is no longer needed, it is permanently deleted from our systems.
10. Children's privacy
Our products and services are not directed at individuals under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
11. Changes to this policy
We may update this privacy policy from time to time to reflect changes in our practices or legal requirements. When we do, we will update the "Last updated" date at the top of this page. For significant changes, we will notify subscribers by email.
12. Contact us
If you have any questions about this privacy policy, your personal data, or want to exercise any of your rights, get in touch:
Inner Work Co
Email: theinnerwork.cohq@gmail.com
We aim to respond to all enquiries within 5 working days and to all data rights requests within 30 days.