Introduction
This Privacy Policy governs the collection, use, and protection of personal information by ThePowerMoves.com (hereinafter referred to as the โWebsite,โ โSite,โ โThe Power Moves,โ โTPM,โ โwe,โ โus,โ or โourโ), a limited liability company based in Fort Lauderdale, Florida. Our website address is https://thepowermoves.com/. This policy outlines our practices regarding the personal data of users (โyouโ or โyourโ) to ensure transparency and compliance with applicable data protection laws.
We are committed to collecting only the information necessary to provide and enhance the Services offered through the Website, including content, courses, forums, and products. We do not seek to obtain or retain personal data beyond what is strictly required for these purposes. This Privacy Policy is effective as of May 17, 2019, with the last update on March 22, 2019, and may be amended at our discretion with notice provided via the Website.
1. Data Collection Principles
We collect personal information solely to facilitate the delivery of Services and improve your experience on the Website. Personal data is not requested unless essential to fulfill a specific function or service you have expressly requested. We do not share your personal information with third parties except as required by law, to develop or enhance our Services, or to safeguard our legal rights. Data is stored on our servers only to the extent necessary for the ongoing operation of the Website.
2. Types of Data Collected and Purposes
The following describes the categories of personal data we collect, the purposes for collection, and how such data is processed:
2.1 Activity Log
- Applicability: Applies to registered users only.
- Data Collected: User email address, user role, username, display name, WordPress.com and local user IDs, activity type, site ID, Jetpack version, timestamp, and, for certain activities (e.g., login attempts), IP address and user agent.
- Purpose: To record and manage site activities for administrative purposes.
- Activity Tracked: Login attempts, post/page updates, comment management, plugin/theme changes, widget updates, user management, and site settings modifications.
- Retention: Varies by activity type and site plan (see Jetpackโs activity list for details).
- Data Synced: Successful and failed login attempts, including IP address and user agent.
2.2 Notifications
- Applicability: Registered users logged into WordPress.com.
- Data Collected: IP address, WordPress.com user ID, username, site ID and URL, Jetpack version, user agent, visiting URL, referring URL, timestamp, browser language, country code, and, where applicable, email address, comment content, or follow actions.
- Purpose: To deliver notifications to users and site owners.
- Activity Tracked: Sending/opening notifications, actions within the notification panel (e.g., liking comments), and link clicks.
2.3 Protect
- Data Collected: IP address, email address/username attempted during login, and IP-related HTTP headers.
- Purpose: To monitor login activity and prevent fraudulent access.
- Activity Tracked: Failed login attempts (IP address and user agent stored); a โjpp_math_passโ cookie (1-day duration) verifies human users via math captcha.
- Data Synced: Failed login attempts, including IP address, attempted username/email, and user agent.
2.4 Subscriptions
- Data Collected: Subscriber email address, post/comment ID, and, for new subscriptions, HTTP request headers, IP address, and URI (REQUEST_URI and DOCUMENT_URI).
- Purpose: To manage blog and post subscriptions and prevent abuse/spam.
- Activity Tracked: Subscription cookies (347-day duration) track subscription preferences.
2.5 Newsletter Subscriptions
- Data Collected: Email address of subscribers who expressly opt in, name
- Purpose: To deliver newsletters to consenting recipients.
- Management: All emails include an unsubscribe option. You may request data export, review, or deletion by emailing connect (at) thepowermoves (dot) com with โGDPRโ in the subject line, specifying your request.
2.6 Products and E-Commerce
- Data Collected While Browsing: Products viewed, location, IP address, browser type, and cart contents (via cookies).
- Data Collected at Purchase: Name, billing/shipping address, email, phone number, payment details, and optional account credentials (username/password).
- Purpose: To personalize your experience (e.g., showing recently viewed products), estimate taxes/shipping, process orders, respond to inquiries, prevent fraud, comply with legal obligations, and send marketing messages (if opted in).
- Retention: Stored as long as necessary for these purposes or as required by law.
- Access: Currently, only the webmaster accesses order and customer information; future team members may access this data to fulfill orders, process refunds, or provide support.
- Payment/Shipping Data: Purchase total, currency, and billing information are shared with PayPal or Stripe (see their privacy policies); tax/shipping calculations use cart value and destination address.
2.7 WordPress.com Secure Sign-On
- Applicability: Registered users with WordPress.com accounts.
- Data Collected: User ID, role, email, username, display name, IP address, WordPress.com user ID, site ID/URL, Jetpack version, user agent, visiting/referring URLs, timestamp, browser language, country code.
- Purpose: To enable secure login.
- Activity Tracked: Login process events (start, completion, failure, redirection).
- Data Synced: User ID and role of successful logins.
2.8 WordPress.com Stats
- Data Collected: IP address, WordPress.com user ID/username (if logged in), user agent, visiting/referring URLs, timestamp, browser language, country code.
- Purpose: To track aggregate site usage (e.g., post views). Site owners cannot access individual user data.
- Activity Tracked: Page/post views, video plays, link clicks, search terms, and performance metrics (e.g., load times). Retained by Automattic for 28 days.
- Note: Does not honor Do Not Track (DNT) settings by default, though site owners may enable this.
2.9 Comments
- Data Collected: Name, email, site URL (if provided), timestamp, IP address, post ID, local user ID/username (if applicable), and comment content. reCAPTCHA (Google) may collect IP addresses.
- Purpose: To manage and display user comments.
- Activity Tracked: Commenter details stored in cookies (1-year duration) for convenience.
- Data Synced: All comment data and metadata, including status.
2.10 Spam Detection
- Process: Comments are screened via WP Security Audit Log (see their policy: https://www.wpsecurityauditlog.com/policy-notice/).
2.11 Social Media Features
- Facebook Comments/Widgets: Collects IP address, user agent, cookies, and interaction data if logged into Facebook (see: https://www.facebook.com/about/privacy/update).
- Twitter Tweet Button: Shares IP address with Twitter (see: https://twitter.com/en/privacy#update).
- LinkedIn Share Button: Tracks IP address (see: https://www.linkedin.com/legal/privacy-policy).
- Reddit Badge: Logs interaction data (see: https://www.redditinc.com/policies/privacy-policy).
- Google Analytics (Social Shares): Tracks shares per Googleโs policy (https://policies.google.com/privacy).
2.12 Media
- Note: Uploaded images may contain EXIF GPS data, extractable by visitors. Avoid uploading such images.
2.14 Cookies
- Types: Comment cookies (1 year), login cookies (2 days or 2 weeks with โRemember Meโ), screen option cookies (1 year), edit cookies (1 day), and temporary browser-check cookies (no personal data).
- Purpose: To enhance user experience and functionality.
- Control: Adjust browser settings to accept/decline cookies (e.g., Firefox, Safari, Internet Explorer, Chrome).
2.15 Analytics
- Tool: Google Analytics tracks usage (see: https://policies.google.com/privacy). Opt out via Google Ad Settings, Network Advertising Initiative, or Google Analytics Opt-Out Add-On.
3. Data Sharing
We do not sell, trade, or transfer your personal data to third parties without prior notice, except as necessary for Website operations or as legally required. Third-party providers (e.g., Mailchimp for newsletters: https://mailchimp.com/legal/privacy/) may process data under confidentiality agreements. Data may be released to comply with legal obligations, enforce policies, or protect rights, property, or safety.
4. Data Retention
- Comments: Retained indefinitely with metadata for moderation purposes.
- Registered Users: Profile data stored until account deletion (editable by users, except username).
- General: Data is retained only as long as necessary for its intended purpose or as required by law.
5. Your Data Rights
Under applicable laws, including the EU General Data Protection Regulation (GDPR), you have the following rights:
- Access: Request confirmation of data processing and access to your personal data, including purposes, categories, recipients, retention periods, and sources.
- Rectification: Correct inaccurate or incomplete data.
- Erasure (โRight to be Forgottenโ): Demand deletion if data is no longer needed, consent is withdrawn, or processing is unlawful (GDPR Article 17).
- Restriction: Limit processing if accuracy is contested, processing is unlawful, or data is needed for legal claims (GDPR Article 18).
- Notification: Be informed of rectifications, erasures, or restrictions shared with recipients.
- Portability: Receive your data in a machine-readable format or have it transferred to another controller (GDPR Article 20).
- Objection: Object to processing under GDPR Article 21.
- Complaints: Lodge a complaint with a supervisory authority.
To exercise these rights, contact connect (at) thepowermoves (dot) com with โGDPRโ in the subject line.
6. Data Protection Measures
We utilize Secure Socket Layer (SSL) technology to encrypt sensitive data transmitted to our payment gateway providers. Access to such data is restricted to authorized personnel bound by confidentiality. Note: The Website currently does not accept credit card payments directly, minimizing related risks.
7. Data Breach Procedures
We implement reasonable safeguards to prevent unauthorized access or breaches. However, no online transmission is entirely secure. In the event of a breach, we will:
- Notify our hosting provider (SiteGround) and relevant third-party software providers immediately;
- Contact affected users promptly if the breach poses significant risk, per applicable laws.
8. Contact Information
For inquiries regarding this Privacy Policy, Terms of Service, or related matters, contact us via:
- Email: connect@thepowermoves.com
- Website: Contact page
9. Governing Law
This Privacy Policy is governed by the laws of the State of Florida, USA, consistent with TPMโs operations as an LLC in Fort Lauderdale, Florida, without regard to conflict of law principles.
