This Privacy Policy explains how Dr James Cannan and Unique Interactions ("we", "us", or "our") collect, use, share, and protect personal information when you use www.jamescannan.com and related pages, forms, downloads, assessments, and digital products (the "Site" and "Services").
By using the Site, you acknowledge this policy. If you do not agree, please do not use the Site or submit personal information. For how we sell and deliver products and services, see our Terms and Conditions.
1. Who we are
The Site is operated by James Cannan through Unique Interactions. For privacy requests, contact:
- Email: james@uniqueinteractions.com
- Website: https://www.jamescannan.com
We operate primarily from Qatar. Depending on where you live, additional local privacy rules may also apply (for example UK GDPR / EU GDPR if you are in the UK or EEA).
2. What this policy covers
This policy covers personal data processed in connection with:
- Browsing the Site and reading blog content
- Contact and enquiry forms
- Newsletter and email list sign-ups (double opt-in where used)
- Free downloads and lead magnets (for example checklists and skill packs)
- CTO assessments, quizzes, and related reports or scorecards
- Paid digital products (for example The First-Time CTO Survival Guide and The Manager and Team Kit)
- Coaching, fractional CTO, and programme fit booking enquiries
- Cookie and analytics choices
Content Studio at /studio is an internal tool. Access is restricted. This public policy focuses on visitor and customer data on the marketing Site.
3. Information we collect
3.1 Information you provide
- Identity and contact: name, email address, and any other details you type into forms
- Message content: subject lines, enquiry text, coaching goals, and attachments you choose to send
- Newsletter preferences: optional name, interests, and signup source
- Assessment and quiz answers: responses you submit to personality or skills assessments, including free-text answers where offered
- Purchase details: email and fulfilment information needed to deliver digital products (card numbers are handled by Stripe, not stored by us)
- Booking details: information you give when booking a call through our calendar provider
3.2 Information collected automatically
- Device and usage: IP address, browser type, device type, pages viewed, referring URL, approximate location derived from IP, and timestamps
- Cookies and similar technologies: see Section 7
- Advertising click identifiers: when you arrive from paid ads, we may store click IDs (for example gclid, gbraid, wbraid) so we can measure conversions if you allow marketing cookies
- Security signals: rate-limit and abuse-prevention data (for example submission frequency from an IP or email)
3.3 Information from payment processors
When you buy a digital product or paid unlock, Stripe processes the payment. We receive limited confirmation data such as payment status, amount, currency, Stripe session or order identifiers, and the email associated with the purchase. We do not receive or store full card numbers.
4. How we use your information
We use personal data to:
- Respond to enquiries and provide coaching or consulting conversations
- Send confirmation, delivery, and transactional emails (downloads, receipts, booking confirmations)
- Send newsletters and product updates when you have subscribed (and confirmed, where double opt-in applies)
- Deliver assessment results, reports, and related follow-up emails you request
- Fulfil digital product purchases and prevent unauthorised download sharing
- Operate, secure, and improve the Site (including debugging and spam reduction)
- Measure traffic and marketing performance with analytics tools, subject to your cookie choices
- Comply with legal obligations and enforce our Terms
We do not sell your personal information. We do not rent email lists.
5. Legal bases (where GDPR / UK GDPR applies)
Where those laws apply, we rely on one or more of:
- Contract: to deliver products or services you request
- Legitimate interests: to secure the Site, prevent abuse, improve content, and answer business enquiries in a proportionate way
- Consent: for non-essential cookies/analytics/marketing where required, and for email marketing where consent is the lawful basis
- Legal obligation: where we must keep records for tax, accounting, or regulatory reasons
6. How we share information
We share personal data only with processors and partners who help us run the Services, under appropriate contracts where required:
- Hosting and infrastructure: Vercel (Site hosting) and related CDN/edge services
- Database and storage: Supabase (for example newsletter records, conversion events, assessment responses, order/access records, and private digital product files)
- Email delivery: SendGrid (transactional and marketing email)
- Payments: Stripe (checkout and payment processing)
- Analytics and ads measurement: Google Tag Manager, Google Analytics, Google Ads conversion tools, and PostHog, subject to consent settings
- Scheduling: Cal.com or a compatible booking provider when you book a programme fit or coaching call
We may also disclose information if required by law, to protect rights and safety, or in connection with a business transfer (for example sale or reorganisation of Unique Interactions), with appropriate safeguards.
Some providers process data outside Qatar (for example in the United States or EU). Where required, we rely on appropriate transfer mechanisms offered by those providers.
7. Cookies and similar technologies
We use cookies and similar storage (including localStorage) for essential site functions and, if you accept, for analytics and marketing.
7.1 Essential
- Security and basic site operation
- Remembering your cookie consent choice (
cookie_consent_v1) - Session features needed to complete a purchase or download
7.2 Analytics and marketing (non-essential)
- Google Tag Manager / Google Analytics page and event measurement
- PostHog product analytics on public marketing pages
- Google Ads conversion and related advertising measurement
On first visit we show a consent banner. You can Accept all non-essential cookies or Reject non-essential use. Essential security storage may still run. You can clear site data in your browser to reset the choice and see the banner again.
We use Google Consent Mode so advertising and analytics tags respect your choice where that mode is supported.
8. Email and marketing communications
Newsletter sign-up typically uses confirmation (double opt-in). You can unsubscribe using the link in marketing emails, or by emailing james@uniqueinteractions.com. Transactional messages (purchase receipts, download links, booking messages, security notices) are sent as needed to fulfil your request and are not the same as promotional newsletters.
9. Assessments, quizzes, and reports
If you take a CTO quiz or gap assessment, we process your answers to generate results and, if you request it, to email a report or follow-up. Assessment answers may be stored to improve the tools, prevent abuse, and deliver features you ask for (for example nudge emails or resume access). Do not submit special-category data (health, politics, religion, and similar) unless it is strictly necessary and you choose to share it; these tools are not designed for that purpose.
10. Children
The Site is aimed at adults in a professional or business context. We do not knowingly collect personal data from children under 16. If you believe a child has provided data, contact us and we will delete it promptly.
11. Retention
We keep personal data only as long as needed for the purposes above:
- Enquiries: typically for the life of the conversation and a reasonable follow-up period
- Newsletter: until you unsubscribe, then for a short suppression period so we do not re-add you by mistake
- Purchases and access tokens: for fulfilment, refund handling, fraud prevention, and accounting/tax retention periods
- Assessment data: while useful for delivering your results and improving the product, or until you ask us to delete it where we are not required to keep it
- Analytics: according to each provider's retention settings and your consent status
12. Security
We use reasonable technical and organisational measures, including HTTPS, access controls on admin tools, private storage for paid download files, rate limiting on forms, and separation of public pages from internal Studio tools. No method of transmission or storage is perfectly secure. If we become aware of a breach that affects your rights, we will take appropriate steps, including notifying you or regulators where required by law.
13. Your rights
Depending on your location, you may have rights to access, correct, delete, restrict, or object to certain processing, and to data portability. Where processing is based on consent, you may withdraw consent at any time (this does not affect earlier lawful processing).
To exercise rights, email james@uniqueinteractions.com with enough detail for us to verify and respond. We may need to confirm your identity before acting on a request.
If you are in the UK or EEA and believe we have not handled a complaint properly, you may contact your local supervisory authority. We would appreciate the chance to resolve concerns first.
14. Third-party links and embeds
The Site may link to third-party sites (social profiles, payment pages, booking tools, or partner resources). Their privacy practices are their own. Review their policies before sharing information with them.
15. Changes to this policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top will change when we do. Continued use of the Site after an update means you accept the revised policy, except where consent is required by law for a particular change.
16. Contact
Questions about privacy: james@uniqueinteractions.com.
Related: Terms and Conditions.