Privacy Policy
Effective 7 October 2026.
Last updated: 7 October 2026.
The short version
We collect what you give us and what your browser sends, we use it to sell to you and deliver what you bought, and we share it only with the companies that run our payments, email, CRM, database, hosting and advertising. If you connect a business system to our scan we read it and never write to it. Email us and we will delete you.
1. What we collect
What you give us: your name, email address, an optional mobile number, business name, and what you tell us in an assessment, a form or a call. If you buy, our payment processor collects your card details. We never see or store a full card number.
Your mobile number: on our sign-up, assessment, workshop and order forms the number is optional, and we keep it for calls and texts only if you tick the one box agreeing to calls and texts. If you type it and do not tick that box, we do not store it. When you place an order, the number you give stays on that order as the contact for it. If you book a call on our booking calendar, which runs on GoHighLevel, its form may also ask for your number so we can reach you about that call.
On the SCORE workshop page: your quiz answers, the business answers you choose to give (company, website, team size, revenue range, where your time goes, the first job you would hand off, and the tools you use), and your name and email address. That page does not ask for a phone number. We also keep a record of whether you ticked the box for tips and workshop news, the exact words you were shown and when, a scrambled one-way version (a hash) of your IP address, your browser details and the address of the page. This is stored in our database and used to send your roadmap.
What comes automatically: your IP address, browser and device, the pages you visit here, and how you arrived. This comes from cookies and similar tags, including an advertising tag described below.
What your business systems hold, if you connect them: described in the next section.
2. Data your business connects to the scan
If you buy the Revenue Leak Scan or a product built on it, you choose which systems to connect. Those may include your payment processor, your CRM, your ad account, and records that a call happened. That data can include your own customers' names, email addresses and payment history.
Three things are true about it and stay true. Our access is read-only: we can read, and we cannot move money, change anything or contact your customers. We use it only to produce your report and run the product you bought, never to sell to anyone else and never to build a list. And you can disconnect a source at any time, after which we stop reading it.
For that data you are the one deciding what happens to it and we act on your instructions. You are responsible for having the right to connect it.
3. Why we use it
To take payment and deliver what you bought. To give you access to the community you paid for. To answer you. To send you the emails you agreed to. To measure which ads work. To keep the site secure and to meet our legal and tax obligations.
4. Who else touches it
Stripe processes payments, and also keeps a contact record for people who sign up for something free, such as a workshop or a download. Resend sends our email. Neon hosts our database. Vercel hosts the site and the member portal, where memberships run. GoHighLevel is our CRM, the system that holds our contact records; leads from the SCORE workshop page are copied to it once that connection is turned on. Meta receives advertising measurement events, described below. Each is given only what it needs to do its job.
We do not sell your personal information. We may disclose it if the law requires it, or to protect our rights, or to a buyer if the business is ever sold, in which case this policy follows the data.
5. Advertising and measurement
We run ads on Meta (Facebook and Instagram) and use two Meta tools to tell whether an ad led to a visit, a sign-up or a purchase.
The Meta pixel is a small piece of code on our public pages. When it loads, Meta receives the address of the page you opened, your IP address and browser details, and events such as a page view, a sign-up or a purchase, and Meta cookies are set in your browser. The pixel is not loaded when you open the SCORE workshop page, the member portal, our admin and review pages, or a link that carries a private code, such as the link to your profiler blueprint, and it does not report page views from them.
Our server also sends Meta some of these events directly (Meta calls this the Conversions API). When you sign up, register, book a call or buy, it can send: your email address, first name, last name and our customer number for you, each hashed (scrambled one way before it is sent, so the plain text is not sent); your IP address and browser details; the Meta cookie values; the page address; and, for a purchase, the amount and the product name. It sends your phone number, hashed, only if you ticked the box agreeing to calls and texts. A phone number you typed without that tick is not sent.
You can limit this through your own ad settings on Meta and through your browser's cookie controls.
6. Email and texts, and how to stop them
If you sign up for something free, register for a workshop or buy, we email you. Each form says in one line under its button which emails it sends, and sending the form is your agreement to those emails. Every marketing email we send identifies itself as an advertisement, carries a working unsubscribe link, and shows our postal address, which is what federal law requires (15 USC 7704). Unsubscribing stops the marketing. It does not stop the emails you need in order to use something you are paying for, such as a receipt, a booking confirmation or a notice about your subscription.
When you unsubscribe, we put your email address on a do-not-email list (a suppression list) in our database and on your record with our payment processor, and our marketing emails check that list before they are sent. We keep that entry for as long as we send email, so your choice keeps working, even if you later ask us to delete everything else.
We only send marketing texts or make automated marketing calls to your mobile number if you ticked the box agreeing to calls and texts. That box is never required to get anything free or to buy anything. Reply STOP to any text, or tell us any other reasonable way, such as an email to contact@bizgen.io, and we stop. You may get one final text confirming you opted out, with nothing else in it. Message and data rates may apply. We do not sell or share your mobile number or your consent to text with anyone for their own marketing.
7. How we protect it, and what happens if something goes wrong
We take reasonable measures to protect personal information held in electronic form, which Florida law requires of us (Fla. Stat. 501.171). In practice that means access is limited to the people who need it, connections are encrypted, and credentials are held in a secrets store rather than in code.
If there is a breach of security affecting your personal information, we will tell you as quickly as we practically can and without unreasonable delay. If a breach affects 500 or more people in Florida we must also notify the Florida Department of Legal Affairs within 30 days of determining it happened. If it affects more than 1,000 people we must also notify the nationwide credit reporting agencies. Those duties come from the same statute and we state them here so you know what to expect from us.
8. How long we keep it
Contact and purchase records are kept while you are a customer and afterwards for as long as we need them for tax, accounting and dispute purposes. We keep payment and tax records for at least seven years. Data you connected to the scan is kept while you use the product and is deleted on request.
What we do not do yet: apart from the referral program records in section 8a, nothing deletes old records automatically on a schedule. Contact details, form and quiz answers, SCORE page answers, member progress, wins and portal messages stay in our systems until you ask us to delete them or we remove them ourselves.
To ask us to delete your information, email contact@bizgen.io. A person handles it by hand within 30 days. We keep only what tax law makes us keep, and the do-not-email entry described in section 6, and we tell you what we kept.
8a. The referral program
If you apply to our referral program, or join it from the members portal, we keep: your application and the score it received, the record that you accepted the Affiliate Agreement (your typed name, the date, the version, and the IP address and device you used), the clicks on your referral link, and your commissions and payouts. Clicks are stored with a salted, one-way hash of the visitor's IP address, never the address itself, and are deleted after 13 months. The same is true of applications: they carry a salted hash of the IP address, not the address. When someone buys through a partner’s link, we keep a salted hash of the buyer’s IP address with that referral to catch repeated sign-ups from one network, and blank it after 13 months. The one place we keep a plain IP address is the record of your signed agreement, because the address you signed from is part of the signature. When you open a partner's referral link we set a cookie named bma_ref that lasts 60 days. It holds the partner's code and nothing about you, and it lets us credit a purchase to the partner whose link you opened last. Commissions, payouts and the signed agreement are kept for seven years after your last activity, because they are payment records. A declined application is deleted three years after you applied. Payout details are held by Stripe, not by us, and Stripe collects the tax information it needs under its own privacy policy.
9. Your choices
Email contact@bizgen.io and we will tell you what we hold about you, correct it, or delete it. We will do this whether or not a law compels it. If deleting something would break a service you are still paying for, or if we have to keep a record for tax reasons, we will say so plainly rather than quietly keeping it.
To be straightforward about the law here: Florida's Digital Bill of Rights creates a set of consumer data rights, but it only reaches companies with more than one billion dollars in global annual revenue. It does not apply to this business, so we are not going to describe rights under it that you do not have. What we offer above we offer as a matter of practice.
10. Children
This is a business-to-business site and is not intended for children. We do not knowingly collect information from anyone under 18. If you believe a child has given us information, email us and we will delete it.
11. Where data is held
We operate in the United States and our providers store data in the United States. If you are outside the United States, using this site means your information is handled there.
12. Changes
We may update this policy. The effective date at the top changes when we do, and a material change gets an email to customers rather than a silent edit.
13. Contact
contact@bizgen.io, or BGAI Ventures LLC at 2401 NE 65th St, #208, Fort Lauderdale, FL 33308.
This policy describes real practice and cites real law. It is not legal advice and it has not yet been reviewed by an attorney.
This page describes a tool and a training. It makes no promise of income, savings, or business results. Most people who buy trainings do nothing with them, and their results are exactly nothing. Any examples shown are demonstrations of software output, not typical customer outcomes.