Privacy Policy | Madly Productive Pathways
Policies

Privacy policy

Last updated 1 October 2026

We are a curriculum shop, not a data business. We do not sell your information and we never will. What we do collect is the ordinary stuff: your email if you want free resources, what you bought so we can send it to you, and analytics that tell us which pages are working. This page says exactly what that means, company by company.

Who we are

Madly Productive Pathways runs this site at madlyproductivepathways.com and sells curriculum to teachers. If you want anything on this page acted on, email hello@madlyproductivepathways.com and a real person will handle it.

What we collect, and when

When you are just reading the site

We do not ask you for anything, but analytics and advertising tools are running. Google Analytics records which pages you visited, what you clicked, roughly where in the world you are (worked out from your IP address, not precisely), and what browser and device you used. Google Analytics is linked to our Google Ads account, so Google can also use those visits to show our ads to you later and to tell us when an ad led to a sale. The Meta pixel records the same kind of thing for Facebook and Instagram ads. Both set cookies in your browser. Our hosting provider keeps a normal server log of the request, which includes your IP address.

We do not know who you are at this stage. None of it is tied to your name, because we do not have it.

When you sign up for a free resource or the newsletter

We ask for your email address and usually your first name. One landing page also asks for a last name. That goes to Flodesk, the service that sends our emails, and you are added to the list straight away. There is no confirmation email to click, so if you typed the address by mistake, just tell us and we will remove it.

At the same moment, we send Facebook a scrambled (hashed) copy of your email address and first name, along with your IP address, so they can tell us the ad worked. Hashing means they get a fixed string of letters and numbers rather than the address itself, which lets them match it against an account they already have without us handing over a readable list.

We also share our email list with Google Ads the same way, as hashed addresses, so Google can show our ads to the teachers already on the list and to people whose interests look similar. Google only uses it to match against Google accounts; it cannot read the addresses back out, and it does not add them to anything of its own. When you unsubscribe you leave the list, and you are left out of the next copy we send.

When you buy something

Checkout happens on Stripe's own page, not ours. You type your name, email, card details and billing address there, and we never see the card number. Stripe is also the merchant of record for these sales, trading as Link, which means Stripe is the seller, works out the sales tax, collects it, and sends you its own receipt. Your statement will read "Sold through Link".

We keep no orders database. There is nothing to log into and no account to create. The record of your order lives at Stripe, and every time you open your order page or click a download link we ask Stripe again whether that order was paid. Alongside the order we attach what you bought, the advertising cookie values from your browser, and a note of which ad or link brought you to us: the campaign name and click id on the link you followed, the page you landed on, and the site you came from. That is how we tell which ad led to the sale. We do not attach your IP address to it.

Once the order is paid, we tell Meta and Google Analytics that a sale happened, so each can match it to the ad or the visit that led to it. Meta gets a hashed copy of your email address and first name, the advertising cookie values, your browser user agent, and what you bought and what it cost. Google Analytics gets what you bought and what it cost, filed against the same anonymous visit it already knew about, with no name and no email address.

Your email address goes to Resend, which sends the email with your download links, and to Flodesk. A little later, Resend also sends you one note from us asking for a review. Buying puts you on our email list. Every email we send has an unsubscribe link, and one click is the end of it.

When you email us or use the contact form

The contact form sends your name, email and message through Web3Forms, which forwards it to our inbox. Because your browser talks to them directly, Web3Forms also sees your IP address and browser. We keep the message in our email for as long as we would keep any other conversation.

When you leave a review

The review form asks for a star rating and what you thought. Your name, your school or role, and your email address are all optional. The review goes to our own server, which emails it to our inbox through Resend. Nothing is stored anywhere else, and nothing goes live automatically. If you give your email, we look it up in our Stripe orders to check that the review comes from a buyer. If it does, we email you a thank-you discount code and mark that order as rewarded, so the code only goes out once. Your email is never published. If we publish your review, the name and role you gave appear publicly on the product page, and search engines can pick them up and show them in results. That is what the permission box on the form is about. Leave it unticked, or write to us later, and it stays private or comes down.

The companies that handle your data

These are all of them. Each one only gets what it needs to do its job.

CompanyWhat it doesWhat it gets
Stripe Payments and merchant of record Your name, email address, card details and billing address, all entered on Stripe's own checkout page. We never see or store your card number. We also note on the order which ad or link brought you to us.
Flodesk Our email list Your email address, your first name, a last name if you gave one, and which lists you belong to (including which course you bought).
Resend Order and review emails Your email address and the names of what you bought, so we can send your download links, a note later asking for a review, and a discount code if you leave one. It also carries the review itself to our inbox.
Web3Forms Contact form Whatever you typed into the contact form, and, because your browser sends it straight to them, your IP address and browser user agent.
Google Analytics (GA4) and Google Ads Pages you viewed, where you arrived from, your device and browser, a rough location worked out from your IP, and, when you buy, what you bought and what it cost. For Google Ads, a scrambled (hashed) copy of the email addresses on our teacher list, so Google can show our ads to the people on it and to people like them. Never your name, and never a readable email address.
Meta Facebook and Instagram ads Pages you viewed and actions you took, their advertising cookies and your browser user agent. When you sign up for a free resource, your IP address and a scrambled (hashed) copy of your email address and first name. When you buy, a hashed copy of your email address and first name, what you bought and what it cost. Never a readable name or email address.
Vercel Hosting and file storage The ordinary web server record of your visit, including your IP address. They also store the resource files themselves.

Cookies and tracking

We do not show a cookie banner. Analytics and advertising cookies start working when you arrive, and we would rather tell you that plainly here than hide it behind a button that most people click without reading. Here is everything that gets stored in your browser:

  • _ga and _ga_… Google Analytics, to tell one visit from another.
  • _fbp and _fbc Meta, to connect an ad click to what you did afterwards.
  • lastExternalReferrer and lastExternalReferrerTime Meta. The pixel's own note of which site you arrived from, and when.
  • mppCart Ours. It is your shopping cart, kept in your browser so it survives a page reload. It never leaves your device except at checkout.
  • mppSrc Ours. It remembers which ad or link brought you here, for up to 30 days, so an order can be matched to it. It stays in your browser and is only sent when you start checkout.
  • mppFbc Ours. A copy of the Facebook click id from the link you followed, kept so that a sign-up or a checkout started a few pages later can still be matched to the ad.
  • mppPurchased Ours. One entry per order, remembering that its confirmation page was already counted, so reopening your downloads does not report the same sale twice. It never leaves your device.
  • mpp_unlock and mppUnlocked Ours. They remember that you entered the free library password. The value is literally the number 1. It is not a login and it identifies nobody.
  • mppOptOut Ours, and only there if you ask for it. Open any page on this site with ?mppoptout=1 on the end of the address, and this browser stops loading Google Analytics and the Meta pixel. ?mppoptout=0 turns them back on. It does not change what is sent when you buy.

To turn the tracking off: block third-party cookies in your browser, use Google's opt-out add-on, turn off ad personalization in Google's ad settings, and adjust your Facebook ad settings. Of our own entries, only the cart and the free library ones are needed for the site to work. Clearing the others breaks nothing. We do not currently respond to Do Not Track or Global Privacy Control browser signals, so if you want out, use the mppOptOut switch above or email us.

What we never do

  • Sell, rent, or trade your email address or any other personal information.
  • Store your card number. It never touches our systems.
  • Ask you to create an account or set a password on this site.
  • Collect anything from your students. Nothing here talks to your classroom.
  • Publish a review, a name, or a school without permission.

Children and students

This site is built for teachers, and everything on it is sold to adults. It is not directed at children, and we do not knowingly collect personal information from anyone under 13. Our resources are files you download and use in your own classroom on your own terms, so no student ever creates an account here, logs in, or is tracked by us. If you think a child has sent us information, email hello@madlyproductivepathways.com and we will delete it.

Your choices

We will do any of these for anyone who asks, wherever you live:

  • Tell you what we hold. Ask, and we will go through every service listed above and tell you what is in each.
  • Delete it. We will remove you from the email list, take down a published review, and delete your messages.
  • Correct it. Wrong name on the list, wrong email, we will fix it.
  • Unsubscribe. The link is at the bottom of every marketing email. You will still get order and download emails, because those are how you receive what you paid for.
  • Stop the ad tracking. See the cookies section above, or just ask.

One honest limit: because Stripe is the merchant of record, your payment and billing records belong to Stripe, and we cannot delete them for you. Tax and accounting rules require them to be kept. Everything else on this page we can act on ourselves. For Stripe's own records, contact them directly.

There is one address for all of this: hello@madlyproductivepathways.com. No form to fill in, no ticket number. We aim to reply within a few days.

If you are outside the United States

We are based in the United States and the companies listed above process data there. If you are in the UK, the EU, or anywhere with its own data protection law, the rights in the section above are yours on request, and we will not ask you to prove you are entitled to them. Where a law requires a legal basis for what we do, ours are: your consent for marketing email and advertising cookies, performing our contract with you for orders and downloads, and our legitimate interest in understanding which pages of the site work.

How long we keep things

  • Email list. Until you unsubscribe or ask us to delete you.
  • Orders. Held by Stripe under their retention rules, which are tied to tax and accounting requirements.
  • Messages you send us. As long as we keep any other email conversation, and we will delete yours on request.
  • Published reviews. Until you ask us to take yours down.
  • Analytics and ad data. Under Google's and Meta's own retention settings, not ours.

Security

The site runs over HTTPS everywhere. Payments happen on Stripe's own page, so card details never reach us. Download links are signed and expire after thirty minutes, and every one is checked against Stripe before it works, so a link that leaks is not a standing key to the files. Because we keep no orders database and no accounts, there is no store of customer records here to break into.

Changes to this policy

If we start using a new service, or an existing one starts receiving something different, we will update this page and change the date at the top rather than alter it quietly. The version that applies to you is the one published on the day you used the site.

Want your data out of all of this?

Email hello@madlyproductivepathways.com and say so. You do not need a reason, you do not need to explain, and it will not affect anything you have already bought. Your downloads keep working.