The Null Product Website and Community is powered by Podia.
This Policy explains how The Null Product LLC handles personal information across its public website, Podia-hosted membership portal and community, digital offerings, communications, and Microsoft Teams meetings. It also includes a cookie schedule based on a live-site scan completed August 20, 2026.
1. Who We Are and What This Policy Covers
The Null Product LLC is a Minnesota limited liability company (“The Null Product,” “we,” “us,” or “our”). We control personal information for the purposes described in this Policy when you visit thenullproduct.com, join or use our Podia-hosted membership portal and community, purchase or download an offering, communicate with us, or attend a Microsoft Teams meeting (collectively, the “Services”).
Podia and other providers may separately control personal information they collect for their own security, fraud prevention, platform, or legal purposes. Their privacy notices govern that independent processing. This Policy does not govern a third-party site after you leave our Services.
2. Information We Collect
Identity and contact
Examples: Name, alias, email address, account identifier, organization, role, and communication preferences.
Sources: You; Podia; an authorized organization.
Account and membership
Examples: Login and account status, tier, group or space access, enrollment, subscription status, preferences, and security events. Passwords are handled through Podia.
Sources: You; Podia.
Transactions
Examples: Offering, price, date, currency, billing country or postal code, taxes, payment status, processor token, and limited card details such as brand or last four digits. We do not receive a full card number.
Sources: You; Podia; Stripe; PayPal where eligible.
Community and messages
Examples: Profile information, posts, comments, reactions, direct or group messages, uploaded files, file metadata, reports, and moderation records.
Sources: You; other members; Podia; our moderators.
Communications and meetings
Examples: Support email, form submissions, scheduling details, Teams attendee information, chat, and meeting content. We will give notice before recording a meeting and seek consent where required.
Sources: You; Microsoft; Podia; meeting participants.
Technical and usage
Examples: IP address, browser and device data, approximate location inferred from IP, time zone, pages and actions, referral URL, logs, cookie identifiers, and security or diagnostic data.
Sources: Your browser or device; Podia; Stripe; PayPal; Cloudflare.
Email engagement
Examples: Delivery, bounce, unsubscribe, and, for Podia marketing emails, open, click, sale-attribution, and related campaign metrics.
Sources: Podia and your interaction with an email.
Inferences and aggregate data
Examples: Audience segments, service preferences, fraud or security indicators, and aggregated or deidentified statistics.
Sources: Generated from the categories above.
We do not ask you to provide Social Security numbers, government identifiers, account passwords, full payment credentials, health information, precise geolocation, trade secrets, confidential information, or MNPI through community features. Please do not submit such information.
3. How We Use Information and Our Legal Bases
Provide and administer Services
Information: Identity, contact, account, membership, transactions, community content, messages, files, and technical data.
EU/UK legal basis, where applicable: Perform a contract; steps requested before a contract.
Process payments and subscriptions
Information: Transaction, billing, account, and fraud-prevention data.
EU/UK legal basis, where applicable: Perform a contract; legal obligations; legitimate interests in payment security.
Operate the community
Information: Profiles, tier/group access, posts, messages, files, reactions, reports, and moderation records.
EU/UK legal basis, where applicable: Perform a contract; legitimate interests in a useful and safe community.
Communicate
Information: Contact details, preferences, support, transaction, and meeting information.
EU/UK legal basis, where applicable: Perform a contract; legitimate interests; consent for marketing where required.
Secure, moderate, and enforce
Information: Account, technical, content, messages, reports, and security data.
EU/UK legal basis, where applicable: Legitimate interests; legal obligations; establishment or defense of claims.
Improve and measure Services
Information: Usage, aggregate, email engagement, feedback, and diagnostic data.
EU/UK legal basis, where applicable: Legitimate interests; consent where a technology requires it.
Comply with law and protect rights
Information: Any relevant category, limited to what is reasonably necessary.
EU/UK legal basis, where applicable: Legal obligations; public interest; vital interests; legal claims.
Where we rely on consent, you may withdraw it at any time for future processing. Where we rely on legitimate interests, we balance those interests against the rights and expectations of affected people. If information is required to provide an account, transaction, membership, or requested feature, not providing it may prevent that use.
4. Community Visibility, Messages, Files, and Sensitive Information
Community posts and uploaded files are visible to members or selected groups based on membership tier, space, and group settings. Direct and group messages are visible to the selected recipients. Administrators, moderators, Podia, and relevant providers may access content when reasonably necessary for operation, delivery, support, security, moderation, investigation, or legal compliance.
Community access controls are not a confidentiality guarantee. Members may copy, download, photograph, or forward content. Do not submit personal data about another person without permission, or any Sensitive Information, Confidential Information, trade secrets, or MNPI. Our Terms of Service provide additional rules and reporting procedures.
If prohibited information is submitted, we may restrict access, remove or preserve it, investigate, notify affected persons or authorities, and take other steps reasonably necessary to reduce harm. We will limit processing to what is appropriate in the circumstances, but cannot guarantee that another member will not retain a copy.
5. How We Disclose Information
We disclose personal information only as described below, at your direction, or as otherwise permitted or required by law. We do not sell personal information or share it for cross-context behavioral advertising.
Podia
Role and information involved: Website hosting, accounts, community, messaging, files, digital delivery, email, subscription administration, support, and related platform functions. Podia receives the information needed for those functions.
Stripe
Role and information involved: Card and recurring-payment processing, payment methods, authentication, and fraud prevention. Stripe receives payment, device, transaction, and identifying data needed to process and secure payments.
PayPal
Role and information involved: Eligible one-time checkout and fraud prevention if PayPal is offered or selected. PayPal receives information needed to complete and secure the requested payment.
Microsoft
Role and information involved: The Microsoft Form is an external link, not an embedded form. If you click it or attend a Teams meeting, Microsoft processes form, account, device, meeting, and communication data under its own privacy notice.
Cloudflare
Role and information involved: Content delivery, network security, bot detection, abuse prevention, video-delivery support, and challenge services. Cloudflare may receive IP, device, request, security, and cookie data.
Members and selected groups
Role and information involved: Profile, posts, comments, reactions, messages, and files are disclosed according to the audience and access settings you select.
Advisers and authorities
Role and information involved: Lawyers, accountants, auditors, insurers, regulators, law enforcement, courts, and affected parties when reasonably necessary for advice, compliance, claims, security, or protection of rights.
Business transaction parties
Role and information involved: Potential or actual buyers, investors, lenders, successors, and advisers in a financing, merger, reorganization, sale, or transfer, subject to appropriate safeguards.
6. Cookies and Similar Technologies
Cookies are small files stored by a browser. Similar technologies include local storage, security signals, pixels, and embedded scripts. Our public pages load Podia platform code and Stripe, PayPal, and Cloudflare code for site, account, checkout, payment-fraud, content-delivery, and security functions.
Current configuration and banner position. In a live scan on August 20, 2026, we observed the first-party cookies and technology described below, a normal outbound link to Microsoft Forms, and no Google Analytics, Google Tag Manager, Meta Pixel, Hotjar, Microsoft Clarity, Mixpanel, Segment, Matomo, Plausible, Pinterest tag, or other advertising or behavioral-analytics tag enabled by The Null Product. We do not currently display a consent banner because the storage we observed was used for site operation, localization, accounts, security, or payment-fraud prevention. A detailed disclosure does not replace consent if a nonessential technology is later used. We will add consent controls before using consent-required cookies where applicable law requires them.
The scan covered the public home, offerings, software, terms, and privacy pages. It did not complete a live purchase or enter every authenticated community flow. Provider behavior can vary by browser, region, account state, security challenge, and payment method. The schedule therefore distinguishes public-page observations from conditional cookies.
podiasession
Provider: Podia
Purpose: Maintains the site or account session and supports authentication and security.
When and duration: Observed on public pages; about 30 days.
Category: Strictly necessary
podiastorefront_visitor_id
Provider: Podia
Purpose: Maintains visitor/session continuity required by the Podia storefront.
When and duration: Observed on public pages; session cookie.
Category: Strictly necessary
tz
Provider: The Null Product / Podia
Purpose: Stores the browser time zone so dates and event times can be displayed appropriately.
When and duration: Observed in site code; 1 year.
Category: Functional / necessary
coach_visitor_id
Provider: Podia
Purpose: Supports visitor continuity for Podia messaging or related platform functions.
When and duration: Observed on public pages; current response expiration is about 20 years.
Category: Strictly necessary per Podia
podiatrusted_device
Provider: Podia
Purpose: Remembers a verified device to avoid repeated login verification prompts.
When and duration: Conditional on verified login; 1 month.
Category: Strictly necessary
__stripe_mid
Provider: Stripe
Purpose: Assesses transaction and device risk for fraud prevention.
When and duration: Stripe code loads on public pages; up to 1 year.
Category: Payment security
__stripe_sid
Provider: Stripe
Purpose: Provides short-lived fraud-prevention and risk signals.
When and duration: Stripe code loads on public pages; about 30 minutes.
Category: Payment security
m
Provider: Stripe
Purpose: Helps Stripe distinguish legitimate activity from attempted payment fraud.
When and duration: Conditional Stripe network cookie; up to 2 years.
Category: Payment security
PayPal checkout cookies
Provider: PayPal
Purpose: Support a selected PayPal checkout, session, preferences, authentication, fraud prevention, and service security.
When and duration: No PayPal Set-Cookie header was observed in public-script probes; names and duration vary by checkout, region, and PayPal state.
Category: Conditional payment; consent may be required for nonessential PayPal uses
__cf_bm
Provider: Cloudflare
Purpose: Distinguishes automated traffic and supports bot-management security.
When and duration: Conditional; 30 minutes after inactivity.
Category: Strictly necessary security
cf_clearance
Provider: Cloudflare
Purpose: Remembers that a visitor passed a security challenge so the site remains reachable.
When and duration: Conditional; default about 30 minutes, configurable by provider/site.
Category: Strictly necessary security
Marketing email measurement. If you subscribe to Podia marketing emails, Podia may use a tracking pixel and instrumented links to measure delivery, opens, clicks, unsubscribes, sales attribution, and campaign performance. This occurs in the email context, not through the public-site cookie banner. You may unsubscribe using the link in a marketing email and may block remote images in your email client.
Your controls. You can block or delete cookies through browser settings, but necessary cookies may be reset and blocking them may break sign-in, community, localization, security, or payment features. Where a provider offers its own privacy or cookie controls, you may also use those controls. We will honor legally required opt-out preference signals for processing to which they apply; because we do not sell or share personal information for targeted advertising, such a signal does not change our current practices.
7. No Sale, Targeted Advertising, or Third-Party Site Analytics
We do not sell personal information, share it for cross-context behavioral advertising, or use it for targeted advertising. The Null Product has not enabled Google Analytics, Meta Pixel, Pinterest tag, Hotjar, Clarity, or comparable third-party site analytics on the scanned public pages. Podia may provide operational information needed to run its platform, and our Podia email tools provide campaign metrics as described above. If our practices change, we will update this Policy and provide any required opt-out or consent mechanism.
8. Retention
We retain personal information only as long as reasonably necessary for the purposes described, including while an account or membership is active; to provide downloads and community access; maintain transaction, tax, and accounting records; handle support, disputes, moderation, security, and legal claims; comply with law; and enforce agreements. Retention varies by category, provider, sensitivity, and legal need.
Account and membership records are generally retained while the account is active and for a reasonable period afterward for support, security, and legal obligations.
Transaction and tax records may be retained for the period required by financial and tax laws.
Community content remains until deleted by you or us, the relevant area is closed, or retention is no longer necessary; backup copies may persist for a limited period.
Security, abuse, moderation, and legal records may be retained as necessary to protect people, enforce rules, and establish or defend claims.
Aggregated or deidentified information may be retained where it no longer reasonably identifies an individual.
9. Security
We use reasonable administrative, technical, and organizational safeguards appropriate to the nature and volume of information we handle and rely on providers with security responsibilities. No internet transmission, community, email, file upload, or storage system is completely secure. Protect your account, use a unique password, sign out of shared devices, scan files before opening them, and report suspected incidents to info@thenullproduct.com.
10. International Processing and Transfers
We are based in the United States and use providers that may process information in the United States and other countries. Those countries may have different privacy laws. Where required, we and our providers use recognized transfer mechanisms or other safeguards, such as contractual protections. Contact us for information about applicable safeguards.
11. Your Privacy Rights
Depending on where you live and whether a law applies to us, you may have rights to:
confirm whether we process your information and access or obtain a copy;
correct inaccurate information;
delete information, subject to exceptions;
eceive portable information you provided in a usable format;
object to or restrict certain processing;
withdraw consent for future processing;
opt out of sale, targeted advertising, or qualifying profiling if those practices occur;
obtain information about categories, sources, purposes, recipients, or specific third parties where required;
appeal a decision on a request where applicable; and
complain to a regulator or supervisory authority.
To exercise a right, email info@thenullproduct.com and describe the request. We may verify identity and authority using information reasonably related to the request. An authorized agent may submit a request where law permits, but we may require proof of authority and direct verification. We will respond within the period required by applicable law, generally within 45 days under many U.S. state laws and within one month under EU/UK law, subject to permitted extensions. If we deny an appealable request, you may appeal by replying with “Privacy Appeal” in the subject line. We will not unlawfully discriminate against you for exercising a right.
12. Regional Disclosures
12.1 California
California law may apply only if statutory thresholds and other requirements are met. For the preceding 12 months, the categories of personal information we collected, sources, purposes, and recipient categories are described in Sections 2, 3, and 5. We do not sell personal information or share it for cross-context behavioral advertising, and we do not use or disclose sensitive personal information to infer characteristics. If those practices change or the law otherwise requires, we will provide the applicable links and honor Global Privacy Control signals.
12.2 Minnesota and other U.S. states
Minnesota’s Consumer Data Privacy Act and other state privacy laws apply only when their scope and thresholds are met. Where applicable, we provide the rights and disclosures described in this Policy, including access, correction, deletion, portability, opt-out rights, information about recipients, appeal, and non-discrimination. Even where a statute does not apply, we will make reasonable efforts to honor appropriate access, correction, or deletion requests consistent with security, provider capabilities, contracts, and legal obligations.
12.3 European Economic Area, United Kingdom, and Switzerland
If relevant data-protection law applies, The Null Product is the controller for the processing described in this Policy. Section 3 identifies our purposes and legal bases. You may have rights of access, rectification, erasure, restriction, portability, objection, consent withdrawal, and complaint. You may complain to the supervisory authority where you live or work or where an alleged violation occurred. We do not make decisions based solely on automated processing that produce legal or similarly significant effects.
13. Marketing and Service Communications
Podia sends service or transactional communications such as purchase confirmations, billing notices, password resets, community or message notifications, product-access notices, and security messages. Those communications are necessary to administer the relationship or requested feature. Marketing broadcasts or campaigns are sent according to your subscription choices and applicable law. You may unsubscribe from marketing emails through the message link; we may retain a suppression record so we can respect the choice.
14. Microsoft Forms, Teams, and Other External Links
Our Contact Us button is a normal link to Microsoft Forms. The form is not embedded on our site, and Microsoft content does not load until you click the link and leave thenullproduct.com. Microsoft’s privacy practices govern its site. Microsoft Teams meetings likewise use Microsoft’s systems. Other external links and member-posted links are governed by the destination’s terms and privacy practices. Review them before providing information.
15. Adults Only
The Services are not directed to, and may not be used by, anyone under 18. We do not knowingly collect personal information through the Services from a minor. If you believe a minor has provided information, contact info@thenullproduct.com so we can investigate and delete it where appropriate.
16. Changes to This Policy
We may update this Policy to reflect changes in law, providers, features, or practices. We will post the revised version with a new effective date and provide additional notice of material changes where required. If consent is required for a new use, we will request it rather than relying only on an updated Policy.
17. Contact
The Null Product LLC, a Minnesota limited liability company, operates virtually. For privacy questions, requests, complaints, or security reports, email info@thenullproduct.com. This email is our designated privacy contact. Marketing emails must separately include a valid physical postal address as required by applicable anti-spam law; that operational email-footer requirement is not replaced by this Policy.
Effective August 20, 2026