Legal
Privacy Policy
What we collect, why we collect it, and how to make us stop. Written in plain English, because a privacy policy nobody can read isn't transparency.
Last updated: September 5, 2026
The short version
- We collect what you type into our forms — and almost nothing else about you personally.
- We use it to answer you, deliver what you bought, and send you things you asked for.
- We never sell your information. Not to anyone, for any price.
- We use analytics and session-replay tools that record how pages are used, and AI to analyze the websites you submit.
- Email rengie@renzagroup.com and we'll show you your data, correct it, or delete it.
1. Who we are
This site is operated by RenzaGroup LLC ("we," "us," "our"), a Tennessee limited liability company doing business as Rengie Mendoza. This policy covers www.rengiemendoza.com and notes.rengiemendoza.com, along with the forms, tools, and emails we run from them.
Questions, requests, or complaints go to rengie@renzagroup.com. A mailing address is available on request.
2. What we collect
Information you hand us
- Contact and inquiry forms — your name, email address, business type, the bottleneck you describe, and whatever you write in the message field.
- Free Assessment — your answers about your business, plus your name and email so we can send the result.
- Newsletter signup — your email address.
- Website Copy Review — the website address you submit and your email address. We then fetch and read the public pages at that address.
- Positioning Questionnaire — detailed answers about your business: your offers, pricing, customers, competitors, and goals. This is commercially sensitive, and we treat it that way (see section 8).
- Website change requests — the changes you describe and any files you upload (up to 15 MB each).
- Purchases — your name, email, billing details, and what you bought. Card numbers go directly to our payment processor; see section 6.
- Scheduled calls — the name, email, and answers you give when booking through Calendly.
- Accounts — if you have a login for the admin area or the notes app, our authentication provider holds your email and credentials. We never see your password.
Information collected automatically
- Analytics — pages viewed, how you arrived, rough location from your IP address, device and browser type.
- Session replay and heatmaps — we use Microsoft Clarity, which records interactions like clicks, scrolling, and mouse movement so we can see where pages confuse people. We do not use it to collect passwords or payment details.
- Abuse prevention — to enforce rate limits on the free Copy Review, we store a one-way hash of your IP address and email. The hash cannot be reversed back into the original.
- Server logs — our host keeps standard request logs, including IP addresses, for security and troubleshooting.
3. What we use it for
- Replying to you and answering what you asked.
- Delivering what you bought — the audit, the rewrite, the strategy session.
- Running the free Copy Review, which means fetching your page and analyzing it.
- Sending emails you signed up for, and follow-ups about an offer you started or bought.
- Understanding what works on the site so we can fix what doesn't.
- Preventing abuse of our free tools.
- Meeting our legal, tax, and accounting obligations.
We do not make automated decisions that produce legal or similarly significant effects about you.
4. What we never do
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We don't rent, trade, or hand our list to anyone. The only parties who touch your data are the service providers in section 5, and they work under contract on our behalf.
5. Who processes your data for us
Running this site takes a handful of specialized services. Each sees only what it needs:
- Vercel — hosting, serverless functions, and encrypted file storage.
- HighLevel — our CRM and checkout. Holds your contact record, tags, and purchase history.
- Resend — sends our transactional email (reports, resume links, confirmations).
- Anthropic — the AI that analyzes the website copy you submit. See section 7.
- Firecrawl — fetches the public pages of the website address you submit.
- Clerk — authentication for account holders.
- Calendly — call scheduling.
- Google Analytics 4 — site analytics.
- Microsoft Clarity — session replay and heatmaps.
We may also disclose information if the law requires it, to enforce our Terms of Service, to protect someone's safety, or as part of a merger or sale of the business — in which case this policy follows your data to the new owner.
6. Payments
Checkout runs on our processor's hosted pages. We never see, handle, or store your full card number, CVV, or bank details. What comes back to us is the fact of the purchase, the amount, your billing name and email, and the last four digits of the card. If you need your card details removed, contact the processor or us and we'll help.
7. AI processing, stated plainly
The Copy Review and parts of our writing process use AI. Here's exactly what that means:
- When you submit a website for review, we fetch the public content of that page and send it, along with the fact that a review was requested, to Anthropic's API for analysis.
- Under Anthropic's commercial API terms, inputs sent through the API are not used to train their models.
- Your email address is not part of what we send for analysis.
- AI drafts are reviewed by a human before anything is delivered to a paying customer.
- Only submit a website you own or are authorized to submit.
8. How we protect your data
- Everything travels over HTTPS.
- Positioning Questionnaire answers are encrypted at rest with AES-256-GCM before they're written to storage, because your pricing, margins, and competitive strategy are nobody else's business.
- Your questionnaire resume link contains a long, unguessable token. Anyone holding that link can open your draft, so don't forward it.
- Admin areas sit behind authenticated logins.
- API keys and secrets are stored as encrypted environment variables, never in our code.
No system is perfectly secure, and we won't pretend otherwise. If a breach affects your data, we'll tell you promptly.
9. How long we keep it
- Contact and CRM records — while the relationship is active and for up to 3 years after your last interaction.
- Copy Review results — up to 12 months, so we can resend your report if you lose it.
- Questionnaire answers — for the length of the project and 12 months after, unless you ask us to delete them sooner.
- Purchase and tax records — 7 years, as the law requires.
- Analytics — per each provider's retention settings, typically 14 months or less.
10. Cookies and tracking
We use cookies and similar technologies for three things: keeping you logged in, remembering your preferences, and measuring how the site is used. We do not run advertising or retargeting pixels on this site.
To limit tracking, you can:
- Install the Google Analytics opt-out browser add-on.
- Opt out of Clarity through Microsoft's privacy controls.
- Block or clear cookies in your browser settings.
- Turn on Global Privacy Control (GPC), which we honor as an opt-out request where it applies.
11. Emails and text messages
We send two kinds of email: transactional (your report, your receipt, your resume link) and marketing (the newsletter, follow-ups about an offer). Every marketing email has a one-click unsubscribe, and we honor it. Transactional email tied to something you actively bought or requested doesn't stop, because that's the thing you asked for.
If you give us a phone number and opt in to texts, message and data rates may apply. Reply STOP to any message to end them.
12. Your rights
Wherever you live, you can ask us to:
- Show you the personal information we hold about you.
- Correct anything wrong.
- Delete it, subject to records we're legally required to keep.
- Export it in a portable format.
- Stop marketing to you.
If you're in California (CCPA/CPRA): you have the rights above, plus the right to know what we collect and disclose, and the right not to be discriminated against for exercising them. We do not sell or share personal information as those laws define it.
If you're in the EU or UK (GDPR): we process your data on the basis of your consent, our contract with you, or our legitimate interest in running and improving the business. You can withdraw consent at any time, object to processing, and complain to your local supervisory authority. We are based in the United States, and using this site means your data is processed here.
Email rengie@renzagroup.com with what you want. We'll verify it's you, then respond within 30 days. There's no charge.
13. Children
This site is for business owners. It isn't directed at anyone under 18, and we don't knowingly collect information from children. If you believe a child has given us information, email us and we'll delete it.
14. Links to other sites
We link to other people's websites, and our checkout and scheduling run on third-party platforms. Once you leave this site, their privacy policies govern — not ours. Read them.
15. Changes to this policy
When we change this policy we'll update the date at the top. If the change is significant, we'll say so by email or a notice on the site. Continuing to use the site after a change means you accept it.
16. Contact
Privacy questions, data requests, or anything in this policy that isn't clear:
RenzaGroup LLC
Attn: Privacy — Rengie Mendoza
Middle Tennessee, USA
rengie@renzagroup.com
Looking for the other one?
Our Terms of Service cover what we sell, how delivery works, and refunds.