Privacy Policy
Last updated: June 30, 2026
This Privacy Policy explains how HowTheyGotUsers ("HowTheyGotUsers", "we", "us" or "our") collects, uses, shares and protects personal information when you visit howtheygotusers.com (the "Site") or use our subscription service (the "Service"). We have written it in plain English so you can understand exactly what we do with your data.
If you have any questions, or want to exercise your privacy rights, contact us at hello@howtheygotusers.com.
1. Who we are & the scope of this policy
HowTheyGotUsers is a paid subscription web app: a searchable library of original, plain-English write-ups summarizing real user-acquisition and marketing tactics that founders have discussed in public interviews, podcasts and articles, with links out to those public sources. It is an educational reference product.
The business is operated by an independent solo founder trading as "HowTheyGotUsers". For legal and data-protection purposes, the data controller responsible for your personal information is:
- [Company legal name / address]
- Email: hello@howtheygotusers.com
This policy applies to personal information we process about visitors, account holders and subscribers. It does not apply to the third-party public websites we link to from our write-ups, those sites have their own privacy policies, and we encourage you to read them.
This Privacy Policy should be read together with our Terms of Service and our Refund Policy.
2. Information we collect
Account information
You sign in using Supabase authentication, via Google sign-in or an email magic link. When you create an account we receive and store:
- Your email address;
- Your name and, where Google provides it, your basic profile information (such as your profile name) when you choose Google sign-in;
- An internal user identifier and your subscription status (for example, active, cancelled, or expired).
We do not store passwords. Authentication is handled by Supabase and, for Google sign-in, by Google. You can revoke Google access at any time through your Google account settings.
Subscription & billing information
Payments are processed by Dodo Payments, which acts as the merchant of record (the authorized reseller and seller of record) for your subscription. Dodo runs the checkout, charges your card, and handles taxes and VAT. This means:
- You provide your payment card and billing details directly to Dodo at checkout.
- We do not receive or store your full card number, CVC or other full payment-card data.
- We receive only limited billing-related information from Dodo needed to manage your subscription, for example confirmation that a payment succeeded or failed, your subscription plan and renewal status, the country used for tax purposes, and the email associated with the purchase.
Dodo processes your payment information under its own privacy policy as merchant of record.
Usage & log data
When you use the Service, our hosting and infrastructure providers automatically collect technical information, including:
- IP address and approximate location derived from it;
- Browser type, device and operating system information;
- Pages and tactics you view, search queries within the library, referring pages, and timestamps;
- Diagnostic and error logs used to keep the Service secure and working.
Cookies & session tokens
We use essential cookies and session tokens to keep you logged in and to operate the Service securely. See Cookies & similar technologies below for details.
Communications
If you email us, we keep your message and contact details so we can respond and maintain a record of support requests.
3. How we use your information
We use personal information to:
- Provide the Service, create and authenticate your account, grant access to the tactics library, and remember your session;
- Manage your subscription, activate, renew, cancel and confirm your subscription, and reconcile billing status received from Dodo;
- Send transactional email, such as magic-link sign-in emails, payment and renewal confirmations, cancellation confirmations, and important account or security notices, delivered through Resend;
- Support you, respond to questions, requests and complaints;
- Maintain, secure and improve the Service, monitor performance, debug errors, prevent fraud and abuse, and understand which content is useful in aggregate;
- Comply with law, meet our legal, tax and accounting obligations and enforce our Terms of Service.
We do not use your information for third-party advertising, and we do not sell your personal information.
4. Legal bases for processing (GDPR / UK GDPR)
If you are in the European Economic Area or the United Kingdom, we rely on the following legal bases under the GDPR and UK GDPR:
- Performance of a contract, to create your account, provide the Service, manage your subscription, and send transactional emails that are part of the Service you signed up for;
- Legitimate interests, to secure and improve the Service, prevent fraud and abuse, keep logs, and run our business efficiently. We balance these interests against your rights and freedoms;
- Consent, where consent is required (for example, any optional communications). You can withdraw consent at any time without affecting processing already carried out;
- Legal obligation, to comply with tax, accounting and other legal requirements.
5. Cookies & similar technologies
We keep our use of cookies minimal. We rely primarily on essential cookies and session tokens that are strictly necessary to:
- Authenticate you and keep you signed in (Supabase session tokens);
- Maintain security, including protecting against cross-site request forgery and abuse;
- Remember basic preferences needed for the Service to function.
Because these cookies are strictly necessary to deliver a service you have requested, they do not require consent. We do not use advertising cookies. Some of our infrastructure providers may set their own strictly-necessary cookies to operate hosting and security. You can block or delete cookies in your browser settings, but the Service (including sign-in) may not work properly if you do.
6. Sharing & sub-processors
We do not sell your personal information and we do not share it for cross-context behavioural advertising. We share personal information only with service providers ("sub-processors") who help us run the Service, and only as needed for them to perform their role. Each is bound by contractual confidentiality and data-protection obligations.
- Vercel, website and application hosting and content delivery. Processes log and usage data needed to serve the Site.
- Supabase, authentication and identity. Stores your account email, name and authentication/session data.
- Dodo Payments, payments and billing, acting as the merchant of record. Processes your payment and billing information and handles taxes/VAT.
- Resend, transactional email delivery. Processes your email address and the contents of transactional messages (such as sign-in links and billing confirmations).
We may also disclose personal information where required to comply with law, respond to lawful requests from authorities, enforce our Terms of Service, protect our rights, property or safety, or in connection with a merger, acquisition or sale of assets (in which case we will require the recipient to honour this policy or notify you).
7. International data transfers
We and our sub-processors may process and store personal information in countries outside your own, including the United States. Where we transfer personal information out of the EEA or UK, we rely on appropriate safeguards recognised under the GDPR and UK GDPR, typically the European Commission's Standard Contractual Clauses (and the UK Addendum where applicable), or another lawful transfer mechanism. You may contact us for more information about the safeguards we use.
8. Data retention
We keep personal information only for as long as we need it:
- Account information, for as long as your account exists. If you delete your account or ask us to delete your data, we remove or anonymise it within a reasonable period, except where we must retain it (see below).
- Billing & transaction records, retained by us and/or by Dodo as merchant of record for as long as required to meet tax, accounting and legal obligations (commonly several years).
- Usage & log data, retained for a limited period for security, debugging and analytics, then deleted or aggregated.
- Support communications, retained for as long as needed to handle your request and keep a reasonable record.
9. Security
We take reasonable technical and organisational measures to protect your personal information, including encryption in transit (HTTPS), reliance on reputable infrastructure providers, restricted access on a need-to-know basis, and not storing passwords or full payment-card data ourselves. No method of transmission or storage is completely secure, so we cannot guarantee absolute security. If a data breach affects your personal information and the law requires it, we will notify you and the relevant authorities.
10. Your privacy rights
GDPR / UK GDPR (EEA & UK)
If you are in the EEA or UK, you have the right to:
- Access the personal information we hold about you;
- Rectify inaccurate or incomplete information;
- Erase your information ("right to be forgotten"), subject to legal retention requirements;
- Restrict or object to certain processing, including processing based on legitimate interests;
- Data portability, receive your information in a structured, commonly used, machine-readable format;
- Withdraw consent at any time where processing is based on consent;
- Lodge a complaint with your local data protection authority.
California (CCPA/CPRA)
If you are a California resident, you have the right to know what personal information we collect and how we use and disclose it, to request access to and deletion of your personal information, to correct inaccurate information, and to not be discriminated against for exercising your rights. We do not sell or share your personal information for cross-context behavioural advertising, so there is no "Do Not Sell or Share My Personal Information" action to take, but you may still contact us with any request.
To exercise any of these rights, email hello@howtheygotusers.com. We will verify your request (for example, by confirming control of your account email) and respond within the timeframes required by law. You may use an authorised agent where the law permits. We will not charge you for a request unless it is manifestly unfounded or excessive.
11. Children's privacy
The Service is intended for business and professional users and is not directed to children. We do not knowingly collect personal information from anyone under 16 years of age. If you believe a child has provided us with personal information, contact us at hello@howtheygotusers.com and we will delete it.
12. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices, our sub-processors, or the law. When we make material changes, we will update the "Last updated" date above and, where appropriate, notify you by email or through the Service. Your continued use of the Service after an update means you accept the revised policy.
13. How to contact us & exercise your rights
For any privacy question, or to exercise any of the rights described above, contact us:
- Email: hello@howtheygotusers.com
- Data controller: [Company legal name / address]
This Privacy Policy is governed by the laws of [Governing law jurisdiction], without prejudice to mandatory data-protection rights you have under local law. You can also visit our contact page, review our Terms of Service, or read our Refund Policy.