Effective
Privacy Policy
1. Who we are
S & CC Group Inc ("S&CC Group", "we", "us") is a California corporation. We build, host, and maintain websites for owner-led service businesses in the United States. We also offer specialty services (AI and automation, fractional leadership, book publishing, publicity, and illustration), digital products, free resources, and two private areas: the CMO Academy, which is a free marketing leadership course for invited participants, and the Library, which is a private collection of book guides. Our fractional leadership work, such as serving as a part-time chief marketing officer, can include running a client's online advertising and publishing to its social media accounts.
S & CC Group Inc30650 Rancho California Rd, Suite D406 #375
Temecula, CA 92591
Email: [email protected]
Web: sandccgroup.com
This policy covers sandccgroup.com and the services offered on it.
2. Who this policy covers
This policy covers five groups of people:
- Visitors to sandccgroup.com.
- People who contact us, book a call, ask for a website outline, sign up for our newsletter, use our free resources or tools, buy a digital product, or take part in the CMO Academy or the Library.
- Customers who buy the Managed Business Website service, and the contacts they name.
- Clients of our specialty services, and the contacts they name.
- Businesses we contact about our website service, and the people who answer for them. Our Notice for Businesses We Contact is written for this group.
3. What we collect and where it comes from
3.1 Information you give us
| When | What we collect |
|---|---|
| Contact form | Your name, email, business name (optional), the topic you choose, your message, and your preferred timing (optional). |
| Website outline request | Your request, sent by email or through our contact form, and the business details you share so that we can prepare a free one-page website outline for your business. |
| Booking a call | Your name, email, chosen time, and anything you add to the booking. Calendly runs the booking calendar. Calls take place on Google Meet. |
| Website purchase | The plan you choose, your acceptance of the Managed Website Service Agreement (which version you accepted, and the date and time you accepted it), and your email and billing details as provided to Stripe. |
| Questionnaire | Your name and project email, business name, what your business does, where you serve customers, your website goals, the name and email of the person who approves the website, your domain and current website details, public contact details for your site, customer questions, brand notes, a link to your materials, current email setup, preferred mailbox address, a technical contact, a target date, and any notes you add. |
| Specialty services | The business information, files, and messages you share with us for the work, and your email and billing details as provided to Stripe when you pay. |
| Newsletter sign-up and free downloads | Your email address and the resource or newsletter you asked for. |
| Tools page access form | Your name, email, company, the tool you asked for, and the biggest challenge you pick from a list (optional). |
| Tools page Notify Me form | Your email address. |
| Digital product purchase | Your email and billing details, collected by Stripe on its checkout page, and the product you bought. |
| CMO Academy | For enrolled participants: your first name as listed on the course roster, your course progress and assignments, your discussion posts, and instructor feedback on your work. |
| Library book suggestions | The book title, author, and note you submit. |
| Emails and phone calls with us, and requests to change text or images on your website | What you write or send us, including any files, and our notes of what was said on a call. We do not record calls. |
Please do not send us passwords, payment card details, or private information about your own customers through these forms.
3.2 Information collected automatically
- Server logs. When you visit our website, our hosting provider, Cloudflare, processes technical details such as your IP address, browser type, the page requested, and the date and time. This is needed to deliver pages and to keep the website secure.
- Visitor statistics. We use Cloudflare Web Analytics to count page views and measure how the website performs. It uses no cookies, does not track individuals across websites, and shows us totals, not who viewed a page. Customers' private order, questionnaire, and Manage website pages carry no visitor statistics.
- Bot and spam protection. Our contact, newsletter, download, and tools forms use Cloudflare Turnstile to tell people from automated traffic. Turnstile looks at technical signals from your browser. The Library suggestion form limits repeat submissions using a scrambled version of your IP address.
- Browser storage. Some of our pages store your light or dark display preference in your browser. During a purchase, we keep a private order reference in your browser session so you can return to your order. CMO Academy pages also keep your course progress in your browser.
3.3 Information from other sources
Businesses we contact. For outreach, we keep a record about each business we plan to contact, called an outreach record. It holds:
- From the business's public Google Maps listing: the business name, phone number, type of business, address, Google star rating and number of reviews, the web address of the listing, and the website the listing gives.
- If the listing gives no website of the business's own, the results of one web search for the business's name, which we run to check whether it has one.
- From the business's own website, if it has one: the email addresses published on its home page or contact page, the page where each appears, a saved copy of those pages, and basic facts about the site, such as whether it uses a secure connection, whether it is set up for phone screens, the copyright year it shows, and the service it was built with. We take email addresses only from a business's own website, never from a booking, directory, or social media page.
- Our own notes, such as the date we collected the details and the business's place in our contact order, and a log of each email, call, and reply.
Stripe. Stripe shows us whether a payment succeeded, the card brand, the last four digits, the expiry date, and your billing email, so we can manage your plan or deliver your purchase.
Calendly. Calendly sends us the details of calls you book.
3.4 Sensitive personal information
We do not ask for sensitive personal information, such as health details, government ID numbers, or precise location. If you include it in a message, a questionnaire answer, or files for specialty work, such as a book manuscript, we use it only to provide what you sent it for.
4. Why we use personal information
Some privacy laws outside the United States ask a business to state a legal reason, called a legal basis, for each use of personal information. One of those reasons is a legitimate interest: a genuine business reason that we weigh against your privacy.
| Purpose | Examples | Legal basis |
|---|---|---|
| Answer you | Reply to a contact form message, prepare a website outline, hold a call. | Steps you ask us to take before a contract; our legitimate interest in answering inquiries. |
| Send what you asked for | Email a free download, a digital product you bought, the newsletter you signed up for, or the tool launch news you asked for on our Tools page. | Your request; performing our contract with you. |
| Share what is working | Email people who used the access form on our Tools page, now and then, about what is working for the businesses we help. | Our legitimate interest in keeping in touch with people who asked for our tools, balanced against the right to stop at any time. |
| Provide the service | Process your order, send your questionnaire link, plan and build your website, send project questions, launch confirmations, billing notices, and renewal reminders. Deliver specialty work under its written agreement. | Performing our contract with you. |
| Run our courses | Save CMO Academy course progress and assignments, show discussion posts, and share instructor feedback. | Performing our arrangement with course participants. |
| Take payment | Charge the setup fee and the monthly or annual payments in your plan, take payment for digital products and specialty work, handle refunds, keep invoices. | Performing our contract; legal obligations. |
| Keep things secure | Block spam and automated abuse, investigate problems, keep logs. | Our legitimate interest in a safe service. |
| Understand our website | Count page visits and measure speed, without cookies. | Our legitimate interest in improving our website. |
| Improve our tools | Use what people tell us on our Tools page, such as the challenge they pick, to decide how to improve our tools. | Our legitimate interest in improving our tools. |
| Reach out to businesses | Email a business about our website service at the address published on its own website, and call it once if it does not reply. Call a business that publishes no email address once instead. | Our legitimate interest in offering a relevant business service, balanced against the right to say no at any time. |
| Meet legal duties | Tax and accounting records, responding to lawful requests. | Legal obligations. |
We do not use personal information to make automated decisions that have legal or similarly significant effects on anyone. We do not train AI models with personal information. We turn off model training in the settings of the AI tools we use, so their providers do not train their models on the information we give them.
5. Cookies and similar technologies
Our own pages use no advertising cookies or advertising trackers. Here is everything that can store information in your browser or receive your browser's details when you use our website:
- Our own pages store the items described in section 3.2: your display preference, a private order reference during a purchase, and CMO Academy course progress.
- Library sign-in. If you sign in to our private Library, we set one cookie that keeps you signed in for up to 30 days. It is used for nothing else.
- Cloudflare may set a cookie that is strictly needed to protect the website from automated abuse. Cloudflare Turnstile runs the bot check on our forms.
- Stripe hosts the checkout and payment pages for our website service, digital products, and specialty work, and the page where customers manage their billing, on its own domain. Stripe uses its own cookies there, mainly to prevent fraud.
- Calendly provides the booking calendar on our Book a call page. The calendar loads from Calendly when it comes into view, and Calendly may set its own cookies when you use it.
- YouTube. Some CMO Academy pages show videos in YouTube's embedded player. YouTube may set its own cookies when these pages load or when you play a video. The YouTube Terms of Service and the Google Privacy Policy apply to these videos.
- Fonts and code libraries. Many of our pages load typefaces from Google Fonts, and a few load code libraries from jsDelivr. These services receive your IP address and browser details in order to deliver the files.
- Client pages. We host a few pages for a client of ours. They show the client's name and branding, not ours, and our menus do not link to them. One of them runs the client's Google Analytics, which sets cookies and sends Google details of your visit, such as your IP address and the pages you view, for the client's visitor statistics. Two of them load Google Maps, which receives your IP address and may set cookies.
You can block or delete cookies in your browser settings. Our website still works, although checkout, the booking calendar, the Library, and embedded videos may not.
6. Who helps us handle personal information
We do not sell the personal information this policy covers, and we do not share it for advertising that follows people across websites.
Each provider below receives personal information from us so that it can provide its service to us. Its own terms and privacy policy govern how it handles that information.
| Provider | What it does for us |
|---|---|
| Cloudflare | Website hosting, our orders and questionnaire database, CMO Academy and Library records, file storage, bot protection, and visitor statistics. |
| Stripe | Payment processing, saved payment methods, invoices, and the page where customers manage their billing. |
| Resend | Sending service emails, such as purchase confirmations, questionnaire links, launch confirmations, renewal reminders, and download links. |
| Business email provider | Hosts the business mailbox included with each customer website. |
| Calendly | Call booking. |
| Google Workspace | Our company email, calendar, documents, and video calls. |
| Google Voice | The phone number we use for business calls. |
| Apple iCloud | Storage of our working files, including outreach records. |
| AI writing, research, and image tools | Help us draft and check text, check our outreach lists, and create images. What we give them can include business details from outreach records and the business facts that customers and clients give us for their work. We turn off model training in the settings of the AI tools we use, so their providers do not train their models on the information we give them. On request, we name the tools we use. |
| Search data service | Supplies the Google Maps listing details and web search results described in section 3.3. It receives the searches we run, such as a trade and a city, or a business's name. |
| Providers for customer add-ons | Phone line, AI call-handling, customer relationship management (CRM), booking, payment, and email-sending providers. We use one only when a customer orders an add-on that needs it, and the quote for that add-on names it. |
We may also disclose personal information:
- To professional advisers, such as our accountant or attorney, under a duty of confidentiality.
- When the law requires it, or to protect the rights and safety of S&CC Group, our customers, or others.
- To a company that takes over our business or this service, which must honor this policy.
7. Communications and your choices
7.1 Service emails
If you are a customer, we send emails needed for your service: your purchase confirmation, questionnaire link, project questions, launch confirmation, billing notices, and renewal reminders. Completing the questionnaire does not subscribe you to marketing.
7.2 Newsletter, downloads, and Tools page
If you sign up for our newsletter or ask for a free resource, we email you what you asked for. The email with a free download also describes one of our paid products.
If you use a form on our Tools page, we open the tool you asked for or tell you when it launches, and we email you when new tools launch. If you used the access form, we may also email you now and then about what is working for the businesses we help.
You can stop these emails at any time using section 7.4.
7.3 Outreach to businesses
We find owner-led service businesses through their public Google Maps listings and their own websites, as section 3.3 describes, and contact them about our website service.
- If a business publishes an email address on its own website, we email it first. The email comes from David Hall, our founder, at [email protected]. If the business does not reply, we may call it once, a few business days later.
- If we found no email address for a business, we may call it once instead of emailing.
- We call a phone number no more than once in any 12 months, unless the business replies to us, asks for our free one-page website outline, or asks us to call.
Calls come from +1 (619) 289-8497 and are dialed by hand. Every outreach email says that it is an advertisement, names S&CC Group, gives our mailing address, and explains how to stop further email and calls.
7.4 How to stop contact
- Reply to any of our emails and ask us to stop, in any words. This works for any email we have sent you, however long ago.
- Email [email protected] and ask us to stop. If you write from an address we did not contact, include the email address or phone number we used, so that we can find you.
- Tell us during a call.
Once we receive your request, we send you no further outreach, marketing, newsletter, or Tools page emails and make no further outreach calls. We record the request on our do-not-contact list the same day. If you are a customer, or become one later, we still send the service and billing emails described in section 7.1, such as renewal reminders, while your service is active.
Each entry on the do-not-contact list holds only what the list needs to work: the email address, web domain, or phone number we must not contact, the reason, the date, and how the request reached us. A request to stop contact does not delete your other information. To have it deleted, make a request under section 15.2. If you also asked us to stop contact, your do-not-contact entry stays after the deletion, so that your request keeps working.
8. Payment information
Stripe collects and stores your payment card details. We never see or store your full card number or security code. With your consent at checkout, Stripe saves your payment method so it can be used for the later monthly or annual payments in your website plan. If you are a customer, you can change or remove your saved payment method through the Manage website link in the emails we send about your service. Stripe's own privacy policy explains how Stripe handles your information.
9. Information we handle for our customers and clients
Some of our services handle personal information about the people who contact our customers and clients, such as their own customers and callers. That information belongs to our customer or client. It includes:
- Website inquiry forms and business mailboxes: the messages visitors send and the email the mailbox receives.
- Business phone lines: call records, voicemail, text messages, and call recordings where the customer turns recording on.
- AI call handling: callers' voices, what they say, and any transcript or recording of the call. Our AI Disclosure explains what callers are told.
- Follow-up emails and customer relationship management (CRM) systems: contact and inquiry details, the emails sent, and consent and unsubscribe records.
- Bookings and payments: appointment and registration details. The payment provider handles card payments, and we do not store card numbers.
We handle this information only on the customer's or client's behalf, for the purposes in our agreement with it, such as delivering inquiry messages, hosting its business mailbox, and running the add-ons it orders. We do not sell it, use it for our own marketing, use it to train AI models, or combine it with personal information from other sources. The providers that handle it for us do so under written contracts that limit them to providing their service to us.
Our services are not built for health information protected by HIPAA, the federal health privacy law, and we do not sign HIPAA business associate agreements. A customer that HIPAA covers may not use our forms, mailboxes, phone lines, or AI call handling to collect patients' health information.
Each customer website carries the customer's own privacy notice, which we draft for the customer to approve as its own.
If you sent a message through the website of one of our customers and have a question about it, please contact that business. If you contact us, we pass your request to the business and help it respond.
10. Accounts on other platforms
A customer or client can authorize us to work in one of its online accounts, such as a Facebook Page, an Instagram professional account, a Google Business Profile, Google Search Console, Google Ads, a YouTube channel, or a CRM. We use that access only to deliver the services agreed with the customer or client.
- Facebook and Instagram. Our Meta app, Waterfront Social Publisher, publishes posts that a client has approved to the client's Facebook Page and to the Instagram professional account linked to it. When a person at the client connects the app, Meta gives us that person's public profile, such as their name and a Facebook user ID for our app, the name and ID of each Page they choose to connect, an access token for each of those Pages, and the ID of the linked Instagram account. An access token is a key that lets the app work with the Page. We use this access to publish the client's approved posts, to confirm that they were published, and to count the reactions, likes, and comments on the posts there so that we can report the totals to the client. The app asks Meta only for the permissions these tasks need: to find the Pages the person manages, including Pages held in a Meta business portfolio, to publish to the Page and the Instagram account, and to read the posts on them. From each post we keep only its ID, date, type, web address, and totals. We do not copy the Page's followers, the people who react or comment, or what they write into our records.
- Google Search Console and Google Ads. Our own software connects to these services through Google's programming interfaces, called APIs. With a client's authorization, it reads the account's settings and figures, such as search statistics or campaign and keyword figures, and makes changes the client has agreed to. Our Developer Tools and API Use page describes our Google Ads tool.
- YouTube. When a client authorizes us to manage its YouTube channel, we use YouTube API Services to upload the client's approved videos and to read the channel's list of videos. By authorizing us, the client agrees to be bound by the YouTube Terms of Service. The Google Privacy Policy explains how Google handles information.
- Other accounts, such as a Google Business Profile or a CRM that a client adds us to as a user: we see what that user role shows and use it only for the agreed work.
Our use and transfer of information received from Google APIs, including YouTube API Services, follows the Google API Services User Data Policy, including its Limited Use requirements.
A client can remove our access at any time in the platform's own settings, and for a Google account on Google's security settings page. Our Data Deletion Instructions give the steps for each platform and explain how to have us delete what we copied.
11. How long we keep information
| Information | How long we keep it |
|---|---|
| Contact form messages, outline requests, call bookings, newsletter sign-ups, Tools page requests, and download requests that do not lead to an order | 24 months after our last contact with you |
| Orders, billing records, signed agreements, and records of your acceptance of the Managed Website Service Agreement, including consent to automatic renewal | 7 years after your service or engagement ends, to meet tax and accounting rules and to keep proof of what you agreed to. For a one-time purchase, such as a digital product, 7 years after the purchase. |
| Payment card brand, last four digits, and expiry date | We do not copy them into our own records. Stripe keeps them under its own privacy policy. |
| Questionnaire answers, project correspondence, including reports we send clients, and files for specialty work | For the life of your service or engagement, then 24 months |
| Website files | For the life of your service and 60 days after it ends. You can ask for a handoff at any time until then. |
| Messages, mailbox contents, call records, recordings, transcripts, and CRM records that we handle for customers and clients | For the life of the customer's service or the client's engagement and 60 days after it ends. A customer or client can ask us to delete them sooner. |
| Information our tools copy from an account a client authorized us to work in, including access tokens | While we work in the account for the client, except that we keep information received through YouTube API Services for no more than 30 days and do not put it in the reports we send clients. If the client asks us to remove our access or to delete this information, by email or through the platform's own data deletion tool, we do both within 7 days after we verify the request. When our access or our work in the account ends in any other way, including when the client removes our access in the platform's own settings or on Google's security settings page, we delete it within 30 days. |
| CMO Academy progress, assignments, discussion posts, and instructor feedback | While you take part in the course, and 24 months after your last activity in it |
| Library book suggestions, including the scrambled IP address stored with each | For as long as the Library runs, unless you ask us to delete a suggestion sooner |
| Library sign-in | We keep no record of sign-ins. The sign-in cookie in your browser expires after 30 days. |
| Outreach records about businesses we contact | 12 months after the last email, call, or reply between us and the business. If we never contacted the business, 12 months after we collected its details. |
| Do-not-contact list | For as long as needed to make sure we do not contact you again |
| Server and security logs | 30 days where we can set the period. Logs kept by Cloudflare, our hosting provider, follow Cloudflare's privacy policy. |
You can ask us to delete your information sooner.
12. Security
We protect personal information with measures suited to a business of our size: encrypted connections, access limited to the people who need it, private order links that only the customer receives, and established providers with their own security programs. We store only a scrambled version of each private link, so the link cannot be read from our database.
No website or email system can be made fully secure. If a security incident affects your personal information, we tell you as the law requires and explain what happened and what you can do.
13. Children
Our website, products, and services are for businesses and adults. We do not knowingly collect personal information from anyone under 18. If you believe a child has given us personal information, contact us and we will delete it.
14. Where information is processed
S&CC Group is based in the United States. Our providers process information in the United States and in other countries where they operate. If you visit from outside the United States, your information is transferred to and processed in the United States, where privacy laws may differ from those in your country. Where the law calls for it, our providers use contract terms approved for transfers of personal information between countries.
15. Your privacy rights
15.1 What we offer everyone
Whatever state you live in, you can ask us to:
- Tell you what personal information we hold about you.
- Give you a copy.
- Correct it.
- Delete it.
- Stop sending you outreach and marketing, as section 7.4 describes.
We will not treat you differently for making a request.
15.2 How to make a request
Email [email protected] with the subject line "Privacy request". Tell us which request you are making and how to find your information: the email address or phone number you used with us or that we used to contact you, your business name if we dealt with you as a business, and, for a Facebook, Instagram, or Google account you connected to our tools, the name of the Page, account, or channel. For a deletion request, our Data Deletion Instructions list what we delete and what we keep.
- Verification. We confirm that the request comes from you, usually by replying to the email address we have on file. We may ask one or two follow-up questions. We do not ask for government ID for routine requests. A request that reaches us through a platform's own data deletion tool, such as a deletion request that Facebook sends us for you, counts as verified when we receive it.
- Someone acting for you. An authorized agent can make a request for you. We ask for your written permission and may confirm it with you directly.
- Timing. We confirm that we received your request within 10 business days, and we respond to it within 45 days. If we need more time, we tell you why and how long it will take. A request to remove our access to an account you connected to our tools, or to delete what our tools copied from it, is completed within 7 days after we verify it.
- If we say no. We explain the reason, for example where the law requires us to keep a record. You can reply and ask us to look again.
A request to stop contact needs no verification and follows section 7.4.
15.3 California
The California Consumer Privacy Act applies to a for-profit business that does business in California and meets at least one of three tests: its annual gross revenue in the prior calendar year was over $26,625,000; it buys, sells, or shares the personal information of 100,000 or more California consumers or households a year; or it earns 50% or more of its annual revenue from selling or sharing California consumers' personal information. S&CC Group meets none of these tests, so the Act does not apply to us as a business. When we handle personal information for a customer or client that the Act covers, as section 9 describes, we follow the Act's rules for service providers.
We do not disclose personal information to other companies for their own direct marketing.
16. Visitors from the European Economic Area and the United Kingdom
We do not direct our services to people in the European Economic Area or the United Kingdom. If you visit from those places, the legal bases in section 4 apply to your information. You may ask to access, correct, delete, or restrict your information, to object to its use, or to receive a copy. You may also complain to the data protection authority where you live. To make a request, use section 15.2.
17. Do Not Track and Global Privacy Control
Some browsers can send a "Do Not Track" signal or a Global Privacy Control signal. These signals ask websites not to track you across websites and not to sell or share your information.
We do not sell or share this information, and the code we write for our pages does not track visitors across websites, with or without a signal. A signal therefore changes nothing on our side.
The outside services in section 5 work differently. YouTube on some CMO Academy pages, Google Fonts, jsDelivr, Calendly, Stripe, and the Google Analytics and Google Maps on our client's pages receive details of your visit from your browser, and each decides for itself whether to respond to these signals. To limit what they receive, block their cookies in your browser settings or avoid the pages and features that load them.
18. Changes to this policy
We may update this policy. The date at the top of this page is the date the current version took effect. When we change the policy, we post the new version here with a new effective date. If a change is significant, we also place a notice on our website, and we email customers where the change affects them.
19. Contact
Questions about this policy or about your information: email [email protected] or write to us at the mailing address in section 1.
