DOCUMENT · LEGAL · PRIVACY
FILE PR-01 · VERSION 1.0

Privacy policy.

What data I collect, why I collect it, and what I do (and don't do) with it. Written like a real person who actually reads these things.

CONTROLLER
MARTÍN MENESES VÁZQUEZ
JURISDICTION
TLAXCALA · MX
LAST UPDATE
JUNE 2026
SECTION 01 · WHO I AM
01 / 10

Who I am

I'm Martín Meneses Vázquez, an individual professional based in Tlaxcala, México, operating under RFC MEVM901229FJA. I'm the data controller responsible for any personal information you submit through martinmeneses.com.

This means I'm the one who decides what data gets collected, how it's processed, and what happens with it. Not a corporation. Not a team. Me.

If you need to reach me for anything related to your data, you can email me directly at contact@martinmeneses.com. Real inbox, real reply.

SECTION 02 · DATA COLLECTED
02 / 10

What data I collect

Only what's necessary to do the work you're asking me to do. Specifically:

  • From the Free Diagnosis form: your name, email, the URL of the page you want me to review, and any context you choose to share (monthly visits, what feels off, etc).
  • From direct emails: whatever you choose to send me in the email itself.
  • Automatic (web analytics): anonymized usage data like pages visited, time on page, approximate location (country/city level), device type, and referral source.
  • Automatic (technical): IP address, browser type, and timestamps. Standard web request metadata.

I don't ask for, want, or store sensitive personal information like government IDs, financial accounts, health data, or anything similar. If you accidentally share something sensitive in an email, I'll let you know and delete it.

SECTION 03 · PURPOSE
03 / 10

Why I collect it

The data has specific, limited uses:

  • To deliver the Free Diagnosis you requested (review your page, write the observation, send it to you).
  • To respond to direct inquiries you send me.
  • To improve the site and the diagnostic process through aggregated analytics.
  • To comply with legal obligations if I ever receive a formal request from authorities (which I'll push back on if it's not legitimate).

That's it. No advertising profiles. No selling to third parties. No marketing automation that retargets you across the web.

SECTION 04 · LEGAL BASIS
04 / 10

Legal basis

Under GDPR (if you're in the EU/UK), the legal bases I rely on are:

  • Consent when you voluntarily fill out a form or email me.
  • Legitimate interest for basic analytics and security logs.
  • Legal obligation for any data I'm legally required to retain.

Under Mexican law (LFPDPPP), I operate as a data controller under your express consent, which you provide when you submit a form or send me an email.

Under CCPA/CPRA (if you're a California resident), I don't sell or share your personal information for cross-context behavioral advertising. There's nothing to opt out of because the sale doesn't happen.

SECTION 05 · RETENTION
05 / 10

How long I keep it

Different data has different retention:

  • Diagnosis form submissions: kept for up to 24 months in case you reach out for follow-up work or reference the original observation.
  • Email correspondence: kept for as long as the conversation is active, then archived for up to 36 months for context and continuity.
  • Analytics data: aggregated and anonymized, kept indefinitely in aggregate form. Individual session data is purged after 13 months.
  • Technical logs: kept for up to 90 days for security and debugging purposes.

You can ask me to delete anything related to you at any time, regardless of the retention windows above. See Section 07.

SECTION 06 · THIRD PARTIES
06 / 10

Who I share it with

I work with a small set of trusted service providers to operate the site and the diagnostic process. These are the ones that touch your data:

  • GoHighLevel (CRM and form processing): stores your form submissions and email correspondence.
  • Vercel (hosting and serverless functions): processes form submissions before they reach the CRM.
  • Google Analytics 4 / Microsoft Clarity (analytics): processes anonymized usage data.
  • Email provider (Google Workspace): processes direct email correspondence.

Each of these has their own privacy policy and data processing agreements that comply with international standards. I don't share your data with anyone outside this list, and I never sell it.

EXPLICIT COMMITMENT I don't post case studies or examples that identify your page, your offer, or your business without your express written permission. If I ever want to reference your case publicly, I'll ask first and let you approve exactly what gets mentioned.
SECTION 07 · YOUR RIGHTS
07 / 10

Your rights

Under the applicable regulations (GDPR, LFPDPPP, CCPA/CPRA), you have the right to:

  • Access your data (ask me what I have on you).
  • Rectify inaccurate or incomplete data.
  • Delete your data, fully.
  • Restrict processing of your data.
  • Portability: get a copy of your data in a portable format.
  • Object to processing based on legitimate interest.
  • Withdraw consent at any time, without retroactive effect.

To exercise any of these rights, send an email to contact@martinmeneses.com with the subject line "Privacy request". I'll respond within 15 business days, often much sooner. No forms to fill out, no support ticket system. Just an email reply.

SECTION 08 · COOKIES
08 / 10

Cookies and tracking

The site uses a minimal set of cookies and tracking technologies:

  • Essential cookies: required for the site to work (session, form CSRF protection, language preference). These can't be disabled.
  • Analytics cookies: Google Analytics 4 and Microsoft Clarity, used to understand aggregate usage patterns. Anonymized at the source.
  • UTM tracking: when you arrive from an ad or external link, the campaign source is stored in your browser session (sessionStorage) so I can understand which channels work. This data is purged when you close the tab.

I don't use third-party retargeting cookies (Meta Pixel, Google Ads remarketing, etc) on the site. You won't see ads for me chasing you around the internet after visiting.

You can disable non-essential cookies through your browser settings. Most modern browsers let you block cookies globally or per-site.

SECTION 09 · SECURITY
09 / 10

Security

I take reasonable measures to protect your data, including:

  • HTTPS encryption for all data in transit between your browser and the site.
  • Secure cloud infrastructure (Vercel, GoHighLevel) with industry-standard encryption at rest.
  • Access controls: only I have access to the data, with two-factor authentication on all relevant accounts.
  • Minimal data collection: the less I have, the less there is to protect.

That said, no system is 100% secure. If a data breach ever occurs that puts your information at risk, I'll notify you and the relevant authorities within 72 hours of becoming aware, as required by GDPR and Mexican law.

SECTION 10 · CONTACT
10 / 10

Contact and complaints

For any privacy-related question, request, or complaint, write me directly at contact@martinmeneses.com.

If you're not satisfied with my response, you have the right to file a complaint with the relevant supervisory authority:

  • If you're in México: Instituto Nacional de Transparencia, Acceso a la Información y Protección de Datos Personales (INAI) at inai.org.mx.
  • If you're in the EU/UK: your national Data Protection Authority. A list is available at edpb.europa.eu.
  • If you're in California: the California Privacy Protection Agency at cppa.ca.gov.

I'd rather you write me first and give me a chance to make it right before escalating. But the right to escalate is yours and I respect it fully.

CHANGES TO THIS POLICY If I update this policy, I'll update the "Last update" date at the top of the document. For material changes that affect how your data is handled, I'll notify affected users by email when reasonably possible.
SIGNED · MARTÍN MENESES VÁZQUEZ · TLAXCALA, MX
FILE PR-01 · END OF DOCUMENT