Privacy Policy
Effective Date: May 9, 2026
Jolliffe’s (“we,” “us,” or “our”) respects your privacy and is committed to protecting your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit this website, create an account, purchase digital products or memberships, subscribe to communications, or otherwise interact with our services.
For the purposes of the UK General Data Protection Regulation (UK GDPR), Jolliffe’s operates as the Data Controller for the personal data processed through this website.
By using this website, you acknowledge the practices described in this Privacy Policy.
1. Information We Collect and Disclose
Information Automatically Collected
When you visit this website, certain information is automatically collected to operate the site securely, improve performance, understand visitor activity, and protect against fraud or misuse. This may include:
Browser type and version
Device type and operating system
IP address
Network and connection information
Referral URLs and search terms
Pages visited and navigation paths
Clicks, scrolling behavior, and timestamps
Site interactions and form activity
Cookie identifiers and analytics data
Information You Voluntarily Provide
We collect information you voluntarily provide when you:
Purchase digital products or memberships
Create an account
Subscribe to newsletters or marketing emails
Submit inquiries or webforms
Request support or correspondence
Complete transactions or invoicing
This information may include: Name, email address, phone number, billing address, order history, invoice and transaction details, account credentials, and any information submitted through forms or correspondence.
California Statutory Disclosures (Past 12 Months)
Pursuant to California privacy laws (including the CCPA/CPRA), the table below outlines the statutory categories of Personal Information we have collected, the sources of collection, and the categories of third-party service providers to whom we have disclosed this information for a business purpose over the preceding 12 months:
CCPA / CPRA Statutory Data CategorySpecific Elements CollectedSource of DataPurpose of Collection & DisclosureCategories of RecipientsA. IdentifiersName, Email, Phone, Billing Address, IP Address, Account CredentialsDirect input by user; browser automated telemetryAccount creation, checkout fulfillment, identity validation, marketingSquarespace, Stripe, Sift, Zapier, GoogleB. Commercial InformationOrder History, Invoice Details, Transaction History, Digital Access TiersDirect input by user during checkout transactionsPayment processing, tax tracking, content delivery, financial auditingSquarespace, Stripe, SiftC. Internet / Electronic Network ActivityBrowser Type, OS, Navigational Paths, Clicks, Google Analytics DataBrowser automated telemetry; cookiesFraud monitoring, cybersecurity defense, interface optimizationSquarespace, Google Analytics, SiftD. Geolocation DataIP-derived country/regional location metadataBrowser automated telemetryRegional VAT tax calculations, localized currency routingSquarespace, Stripe, Google Places API
2. Legal Bases for Processing (UK GDPR)
For residents of the United Kingdom and other jurisdictions recognizing similar legal frameworks, we process personal data under one or more of the following lawful bases:
Performance of a Contract
We process personal information as necessary to:
Fulfill purchases
Provide access to digital memberships or gated content
Manage customer accounts
Process transactions
Deliver customer support
Consent
We rely on consent to:
Send marketing communications
Deploy non-essential analytics or advertising cookies
Process optional form submissions where consent is requested
You may withdraw consent at any time.
Legitimate Interests
We process certain information where reasonably necessary for our legitimate business interests, including:
Maintaining website security
Preventing fraud or unauthorized access
Monitoring account misuse or concurrent logins
Improving website functionality and performance
Maintaining operational integrity
3. Cookies and Tracking Technologies
This website uses cookies and similar technologies to operate properly, analyze performance, and improve user experience.
Essential Cookies
Certain cookies are required for the website to function securely and properly. These cookies cannot be disabled through our systems.
Analytics and Performance Cookies
We may use analytics technologies, including Squarespace Analytics and Google Analytics, to understand website traffic and visitor behavior. Non-essential analytics and performance cookies are not deployed unless you affirmatively consent through our cookie banner or consent management tools where required by law.
You may withdraw or modify your cookie preferences at any time through your browser settings or applicable cookie controls.
Third-Party Fonts and Embedded Content
This website may load fonts, scripts, or embedded resources from third-party providers, including Google Fonts and Adobe Fonts. When these resources load, those providers may receive technical information such as your IP address, browser details, device information, and page activity.
4. How We Use Personal Information
We may use your information to:
Operate and maintain this website
Process transactions and memberships
Provide customer service and support
Send transactional communications
Send marketing communications where permitted
Detect fraud or unauthorized activity
Improve website functionality and visitor experience
Comply with legal obligations
Enforce our terms, policies, and intellectual property rights
5. How We Share Personal Information
We share personal information only with trusted service providers and infrastructure partners necessary to operate our business and services.
Website Hosting and Commerce Infrastructure
We utilize Squarespace as our website platform, ecommerce infrastructure provider, membership hosting provider, and analytics provider.
Payment Processing and Fraud Prevention
Payment transactions are processed through Squarespace Payments and associated financial infrastructure providers, including:
Stripe, for payment processing, invoicing, and tax-related transaction services
Sift, for fraud detection and transaction monitoring
We do not directly store full payment card information on our servers.
Address Verification and Form Automation
Information entered during checkout or webform submissions may be processed through trusted infrastructure providers, including:
Google Places API, for address verification and auto-completion
Zapier, for secure workflow automation and data routing
Legal and Operational Disclosures
We may disclose personal information where reasonably necessary to:
Comply with applicable law or legal process
Respond to lawful governmental requests
Protect our rights, users, systems, or intellectual property
Prevent fraud, abuse, or security threats
6. International Data Transfers
Because some of our service providers operate internationally, your personal information may be transferred to, stored in, or processed in countries outside your jurisdiction of residence (such as the United States). Where required under applicable law, including UK GDPR, we rely upon recognized legal safeguards for international data transfers, including Standard Contractual Clauses (SCCs) or comparable approved transfer mechanisms to guarantee your data receives an equivalent level of protection.
7. Marketing and Communications
Marketing Emails
Where permitted by law or based upon your consent, we may send promotional communications relating to updates, products, journal content, or announcements. You may unsubscribe from marketing communications at any time by using the unsubscribe link included in such emails.
Transactional and Operational Communications
We may send service-related communications necessary to administer purchases, memberships, accounts, password resets, invoices, or transactional confirmations. These communications are considered operational and may continue even if you opt out of marketing messages.
8. Data Retention
We retain personal information only for as long as reasonably necessary to fulfill the purposes described in this Privacy Policy, including operational, contractual, security, legal, accounting, tax, dispute-resolution, and regulatory obligations.
Retention periods may vary depending on transaction history, fraud prevention requirements, legal compliance obligations, customer support records, marketing consent records, and security needs. When personal information is no longer reasonably necessary, we will delete, anonymize, or securely dispose of it where practicable.
9. Your Privacy Rights
Depending on your jurisdiction, including the United Kingdom, California, and certain US states, you may have legal rights regarding your personal information. These rights may include:
The right to know what personal information we collect
The right to access personal information
The right to correct inaccurate information
The right to request deletion of personal information
The right to receive a portable copy of certain information
The right to withdraw consent
The right to opt out of certain data-sharing practices
The right to non-discrimination for exercising privacy rights
California Statutory Declarations
Authorized Agents: California residents may designate an authorized agent to submit requests on their behalf where permitted by law.
No Sale or Share of Data: We do not sell personal information or share personal information for cross-context behavioral advertising as those terms are defined under applicable California privacy laws.
Sensitive Personal Information: We do not use or disclose sensitive personal information for purposes requiring a right to limit under California law.
How to Submit a Request
To exercise privacy rights or submit a privacy-related request, please contact us at: inquiries@jolliffes.co.
In compliance with UK GDPR mandates, we will formally respond to verified consumer rights requests within one calendar month of receipt. For complex requests originating from California residents, we will respond within 45 days as permitted by the CCPA/CPRA.
10. Children’s Privacy
This website and services are not directed toward children under the age of 13, and we do not knowingly collect personal information from children. If we become aware that personal information has been collected from a child in violation of applicable law, we will take reasonable steps to delete such information.
11. Third-Party Privacy Policies
Our third-party service providers maintain their own independent privacy policies and practices. Additional information may be found at their official corporate privacy desks:
Squarespace Privacy Policy
Stripe Privacy Policy
Sift Privacy Policy
Google Privacy & Terms
We are not responsible for the privacy practices of third-party websites or services.
12. Changes to This Privacy Policy
We may update or revise this Privacy Policy from time to time to reflect operational, legal, or regulatory changes. Any updates will be reflected by revising the “Effective Date” at the top of this page. Continued use of this website after changes become effective constitutes acceptance of the revised Privacy Policy.
13. Contact Information and Grievances
If you have questions regarding this Privacy Policy, your personal information, or your privacy rights, please contact us at: inquiries@jolliffes.co.
UK Regulatory Escalation
If you are a UK resident and believe your data has been processed unlawfully, you have the right to lodge a formal complaint with the UK data protection authority, the Information Commissioner’s Office (ICO), via their website tracking system at https://ico.org.uk. We request that you attempt to resolve any grievance with our internal support team at our contact email address prior to escalating.
