Privacy Policy.
Plain English, no legalese. Here’s what we collect, why, who we share it with, and your rights about it.
Last updated: 28 April 2026Who we are
Rational Magic is a productised brand strategy service operated by Frederick Loo, a sole trader based in Melbourne, Australia. Trading as Rational Magic. Contact: fred@rational-magic.com.
What we collect
Three categories of data, depending on how you interact with us:
- Intake form data. When you fill out the intake form at rational-magic.com/intake, we collect your name, business name, email, and the strategic context you provide across roughly 15 questions about your business, competitors, and customers.
- Payment data. When you buy a sprint, Stripe processes the payment and shares with us your name, billing address, email, and a Stripe customer ID. We don’t store credit card numbers — Stripe handles all card data on their PCI-compliant infrastructure.
- Site analytics. Cloudflare logs basic request data (IP address, user-agent, request timing) for security and performance. Vercel logs anonymous page views. We don’t use Google Analytics, advertising pixels, or session-replay tools.
- Email correspondence. When you email fred@rational-magic.com, your message and email address are stored in Google Workspace.
Why we collect it
- Deliver your sprint. The intake form is the entire input to the methodology — without it, we can’t do the work.
- Process payment. Stripe needs your billing details to take the money and issue an invoice.
- Communicate. Email is the channel. We use yours to send your deliverables, ask clarifying questions, and reply when you reach out.
- Prevent fraud and abuse. Cloudflare Turnstile verifies form submissions are from humans. Cloudflare logs help us spot and block attacks.
- Meet legal obligations. Australian tax law requires us to keep transaction records for seven years.
Who we share it with
We use a small set of vendors. Each one only sees the data it needs to do its job.
- Stripe — payment processing. Sees billing data and the customer email.
- Formspree — intake form submission delivery. Receives your form data and forwards it to our inbox.
- Cloudflare — DNS, CDN, bot detection (Turnstile). Sees request metadata; doesn’t see form contents in plaintext at the application layer.
- Vercel — site hosting. Serves the static pages.
- Google Workspace — email. Hosts fred@rational-magic.com and any correspondence with us.
- AI providers (Anthropic, OpenAI, and similar). During sprint research, we use AI tools to help process competitor reviews and draft strategy outputs. Snippets of the public material we research (your competitors’ reviews, websites, and so on) and your own intake responses may be sent to these providers as part of that work. They don’t train models on this data under their commercial API terms. We disclose this explicitly because Rational Magic’s entire pitch is “evidence-backed brand positioning for the AI era” — being honest about how we use AI is the foundation.
We don’t sell your data. We don’t share it with advertisers. We don’t share it with anyone outside this list without telling you first.
Where the data lives
Stripe stores in the US, EU, and AU regions depending on the customer. Vercel serves from a global edge network with origin in the US. Cloudflare runs at edges worldwide. Formspree and Google Workspace are US-based. AI providers are US-based.
If you’re in the EU or UK, your data may be transferred outside your region. The vendors above all operate under standard contractual clauses or equivalent safeguards.
How long we keep it
- Intake form data and sprint deliverables — kept indefinitely, in case you need a re-export or future engagement reference. Email fred@rational-magic.com if you want yours deleted.
- Payment records — kept for at least seven years to meet Australian tax retention requirements.
- Email correspondence — kept until you ask us to delete it.
- Site analytics logs — Cloudflare and Vercel rotate these on their default schedules (typically 30–90 days).
Your rights
Wherever you live, you can ask us to:
- Show you what we have. A copy of the data we hold about you.
- Correct it. If anything’s wrong or out of date.
- Delete it. Outside the seven-year tax retention window for payment records.
- Stop using it for a particular purpose. For example, don’t use my engagement as anonymised marketing material.
Email fred@rational-magic.com with the request. We’ll respond within 30 days.
If you’re in Australia and you’re not happy with our response, you can complain to the Office of the Australian Information Commissioner. If you’re in the EU/UK, you can complain to your national data protection authority.
Cookies
We don’t use marketing or advertising cookies. Cloudflare may set a small bot-detection cookie when you visit (essential security, no tracking). Vercel may set a session cookie. We don’t use Google Analytics, Facebook Pixel, or similar tracking tools. If we ever add analytics, we’ll update this page and ask for consent first.
Changes to this policy
If we update this policy, we’ll change the date at the top of the page. Material changes (new vendors, new data categories, new uses) will trigger a notification email to anyone we have an active engagement with. Existing engagements continue under the policy in effect at the time you signed up.
Contact
Questions, requests, complaints — all to fred@rational-magic.com. We aim to respond within two business days.