Privacy policy

Privacy policy

Last updated 26 July 2026

This policy explains what Anodize Labs, operating as Agent Playbooks, collects when you use playbooks.anodizelabs.com, why, and what you can do about it. It is short because we collect very little.

What we collect

DataWhenWhy
Email address When you buy something To send your receipt, your download link, and free updates to the edition you bought.
Order details: product, amount, currency, time, Stripe identifiers When you buy something To fulfil the order, issue download links, handle refunds and keep tax records.
Payment details At checkout Collected and processed by Stripe. They never reach our servers and we never see your card number.
Email address, the page you gave it on, and a truncated IP address If you ask for updates to a free piece To send you corrections and new editions of that piece, and nothing else. The page and the truncated address are kept as a record of when and where you asked, which is what lets us show the request was yours. Every message carries a one-click unsubscribe, and leaving is immediate and permanent.
Google Ads click identifier (gclid) If you arrive from a Google ad Stored in a first-party cookie and attached to your order so we can tell which ads produce sales. It identifies a click, not a person.
Anonymous usage events As you use the site Which pages you viewed, whether you reached the pricing section, whether you started a checkout, and how far you read a free chapter. Tied to a random id, not to your name or email. We measure this ourselves, and we also run Google Analytics to see visitor numbers and where people arrive from. If your browser sends Do Not Track or Global Privacy Control we collect nothing at all ourselves, and Google Analytics switches to a storage-free mode: no cookies, no identifier, only an anonymous count of the visit.
Download activity: time, count, IP address When you use a download link To enforce the download limit and detect link sharing.

We do not sell personal data, and we do not send your email address or any other personal identifier to an advertising platform. We do run Google's advertising and analytics tag, which can be used by Google to measure and personalise advertising. The controls over that are described under "Advertising measurement" below, and they are switched off entirely for anyone sending an opt-out signal.

Cookies

We set two first-party cookies of our own, and Google Analytics sets its own. None contains personal information, none is readable by other sites, and blocking any of them does not affect anything you can do here.

If your browser sends a Do Not Track signal or Global Privacy Control, we set none of our own identifiers and collect no usage events of our own. Google's tag still loads, but we immediately instruct it to deny analytics storage, advertising storage, advertising personalisation and the sharing of user data, so it runs without cookies and reports only an anonymous, aggregated signal.

Stripe sets its own cookies on the checkout pages it hosts, which are covered by Stripe's privacy policy.

Advertising measurement

We advertise on Google Search. When a sale results from an ad click, we may import that conversion into Google Ads using the click identifier described above. Where any customer data is used for advertising measurement, it is hashed before transmission and handled in line with Google's customer data policies. We do not transmit plain-text email addresses or other personal identifiers to Google.

We use Google Consent Mode v2. In the EEA, the UK and Switzerland every category is denied by default: ad_storage, ad_user_data, ad_personalization and analytics_storage. The tag loads but stores nothing, so visitors there are counted anonymously and are never added to an advertising audience. Everywhere else those categories are allowed, which is what lets us tell which ads produce sales, unless your browser sends Do Not Track or Global Privacy Control, in which case all four are denied for you regardless of where you are.

You can find Google's explanation of how it handles data in this context on its Business Data Responsibility page.

Who processes data on our behalf

Each is bound by its own contractual obligations to handle data only as instructed. Data may be processed in the United States and other countries where these providers operate, under the transfer mechanisms those providers maintain.

How long we keep it

Order records are kept for seven years, because tax law requires it. Download tokens and their activity logs are deleted 90 days after they expire. If you ask us to delete your email address from update notices, we do so immediately; the underlying order record has to stay for the tax period.

Your rights

You can ask us to show you the data we hold about you, correct it, delete what we are not legally required to keep, or send it to you in a portable format. Email support@anodizelabs.com and we will respond within 30 days. You do not need to use any particular wording, and we will not ask you to justify the request.

If you are in the EU or UK, you also have the right to complain to your local data protection authority.

Security

The site is served over HTTPS only. Product files are held in private storage and are reachable only through signed, expiring links tied to a specific order. We do not store card details at any point.

Children

These products are for professional use and are not directed at anyone under 16. We do not knowingly collect data from children.

Changes and contact

If this policy changes materially, the date at the top changes and, where it affects buyers, we say so by email.

Anodize Labs
522 W Riverside Ave Ste N
Spokane, WA 99201
United States
support@anodizelabs.com