01Who this policy is from, and what it covers
Shapei Tragico is an independent client acquisition systems consultant based in the Philippines. I build the infrastructure health and wellness coaches use to turn interest into booked consultations and clients, mostly inside HighLevel.
This policy explains what personal information I collect through shapeitragico.com, why, who sees it, how long it is kept and what you can ask me to do with it. It covers visitors to the site, people who enquire or book a discovery call, and clients during and after an engagement. Under the Philippine Data Privacy Act of 2012 (Republic Act No. 10173) I am the personal information controller for that information; under the EU or UK GDPR I am the data controller, and under California law I am the business.
It does not cover the contacts inside a client's own CRM, which belong to that client and are dealt with in section 07, or third-party sites you reach from links here. Questions go to [email protected].
02What I collect, why, and how long I keep it
Everything below is either something you handed me or something the site recorded while you used it. Each row gives the reason I hold it, the lawful basis for doing so, and when it goes.
Your contact detailsName, email and phone from a form, a resource download or the booking calendar. Used to reply to you and to send the confirmation, calendar invite and reminders for a call you booked.Basis: steps taken at your request · Kept 24 months after your last contact
Your answers before a callWhere your leads come from, what happens after someone shows interest, and the part of your client journey you want to stop managing manually. Used so the 30 minutes go on your business, not on background questions.Basis: steps taken at your request · Kept 24 months
Engagement recordsAccount access, files, brand material, project documentation, invoices and payment records for clients. Used to deliver the work and keep proper books.Basis: our contract and legal obligation · Kept as long as Philippine tax and accounting rules require; access credentials removed as soon as the work is done
Marketing consentWhether you asked for resources or occasional updates, and what you opened or clicked.Basis: your consent, withdrawable any time · Kept until you unsubscribe, plus a suppression record so you are not contacted again by mistake
Technical and usage dataIP address, browser and device, referring page, pages viewed, and whether an email or SMS was delivered. Used to keep the site working and to see which content leads to conversations.Basis: legitimate interests in running the business · Aggregated in analytics on standard retention
Please do not send me sensitive personal information, and in particular the health information of your own clients. I do not need it to diagnose a client journey or build a system. If it arrives anyway, I delete it once the matter it relates to is closed.
I do not make decisions about you by automated means that have legal or similarly significant effects, and I do not profile you for advertising. If you want something removed sooner than the periods above, ask; I will do it unless a record has to be kept, and then I will tell you what and why.
03Emails and text messages
There are two kinds of message, and they work differently.
- Service messages relate to something you asked for: the confirmation and calendar invite for a call, a reminder before it, a resource you requested, or updates during a live project.
- Marketing messages are occasional emails about the system, resources and availability. You only get these if you opted in, and every one carries an unsubscribe link.
Stop marketing email any time with the unsubscribe link or by replying. For SMS, reply STOP to opt out and HELP for help; message and data rates may apply and frequency varies. Opting out of marketing does not stop service messages about a call or project already under way. Where US rules apply I follow CAN-SPAM for email and the Telephone Consumer Protection Act and carrier A2P 10DLC requirements for SMS, and SMS consent is never sold, shared or passed to anyone else for their own marketing.
04Cookies and analytics
- Essential: set by HighLevel so forms, the booking calendar and basic security work. The site cannot function properly without them.
- Analytics: Google Analytics, which reports in aggregate how many people visit and which pages they read. I do not use it to identify individuals.
- Attribution: HighLevel records the page and source a submission came from, so I know which content leads to conversations.
You can clear or block cookies in your browser, browse privately, or install Google's Analytics opt-out add-on. Blocking essential cookies may stop the forms or calendar working. Where the law requires it, I treat a Global Privacy Control or Do Not Track signal as an opt-out of analytics. The site runs no advertising or retargeting pixels; if that changes, this section and the date at the top change with it.
05Who else sees it, and where it is stored
I do not sell personal information and I do not share it for cross-context behavioural advertising. A small set of providers helps me run the business, and each gets only what it needs:
HighLevelForms, the booking calendar, the CRM record, and the email and SMS that go with them.
GoogleAnalytics for site measurement, plus email and file storage for business correspondence.
Carriers and banksThe networks that deliver an email or text, and the bank or transfer service that settles an invoice.
Professional advisersAccounting or legal advisers where a matter genuinely requires it, under a duty of confidentiality.
I may also disclose information where the law or a valid order requires it, to establish or defend a legal claim, or to protect someone's safety. If the business is ever transferred, records may pass to the new owner, who stays bound by this policy until you are told otherwise.
Where it lives. I work from the Philippines and those providers store data on servers elsewhere, mainly the United States, so your information may be transferred outside your own country. I remain accountable for it under the Data Privacy Act and use providers who commit to appropriate protection; for data leaving the EU or UK they rely on mechanisms such as the European Commission's Standard Contractual Clauses. Ask me which provider holds what and I will tell you.
06Your rights
Wherever you are, you can ask me to show you what I hold about you, correct it, delete it, stop using it for marketing, or send you a copy. Asking costs nothing and changes nothing about how you are treated.
- Philippines. The Data Privacy Act gives you the rights to be informed, to object, to access, to rectify, to erasure or blocking, to damages and to data portability. If you are unhappy with how I handle a request, you can complain to the National Privacy Commission.
- EU and UK. Access, rectification, erasure, restriction, portability and objection, including to processing based on legitimate interests. Where I rely on consent you can withdraw it any time, without affecting what happened before, and you can complain to your local supervisory authority.
- California. Request the categories and specific pieces of information collected, ask for deletion or correction, and opt out of any sale or sharing. I do not sell or share personal information and offer no financial incentives for it. An authorised agent may act for you with proof of authority.
Email [email protected] to use any of these. I may need to confirm who you are first, which usually means replying from the address I already hold. I aim to answer within a few business days and always within 30 days.
07Data inside a client's system
When I build or manage a system, I get access to the coach's own contacts, conversations and pipeline. That data belongs to the client, not to me. In that role:
- I process it only to deliver the agreed work, on the client's documented instructions.
- I do not use it for my own marketing or analysis, or to train any tool.
- I keep it confidential and limit access to what the work requires.
- I return or delete my copies at the end of the engagement or on request, keeping only what a legal obligation requires.
- The client stays responsible for having a lawful basis and proper consent for their own contacts, including email and SMS consent, and for their own privacy notice.
Where a client needs a separate data processing agreement, I will sign one.
08How it is protected
Access is limited to me, with multi-factor authentication on the accounts holding client data, encrypted connections, a password manager rather than shared credentials, device encryption and screen locks, and access removed as soon as it is no longer needed.
No system is completely secure, so I cannot promise absolute security. If a breach happens that is likely to put your rights at serious risk, I will notify the National Privacy Commission and the people affected within the timeframes the law requires, and tell you plainly what happened and what to do about it.
09Children, and changes to this policy
This site and these services are for business owners and professionals. I do not knowingly collect information from anyone under 18, and the site is not directed at children. If you believe a child has given me information, tell me and I will delete it.
I update this policy when what I do changes, or when the law does, and the date at the top always reflects the current version. If a change materially affects how your information is used I will make that clear on the site and, where it matters, by email. Continuing to use the site after a change means you accept the updated policy.