Home  /  Privacy Policy
Legal

Privacy Policy

How AI Ideas Bank collects, uses, and protects your personal data.

Last updated: January 26, 2026  ·  Effective: January 26, 2026

AI Ideas Bank (“we,” “our,” or “us”) is operated by Zarrar Tech, based in Rawalpindi, Pakistan. This Privacy Policy explains how we collect, use, and safeguard your information when you visit aiideabank.com or use our services.

Plain-language summary. We collect the minimum data needed to run this site: your email if you subscribe, cookie data for analytics, and payment info if you buy something (handled entirely by Stripe). We do not sell your data. We do not share it with advertisers. You can email privacy@aiideabank.com any time to see, download, or delete your data.

1. Information we collect

We collect three types of information:

a) Information you give us directly

  • Email address — when you subscribe to our newsletter, register for a course, or contact us.
  • Name — when you contact us or buy a product.
  • Payment information — card details are collected and processed by Stripe. We never see or store your full card number.
  • Content of your messages — when you email us or submit a contact form.
  • Case study / interview submissions — if you voluntarily share your founder story with us.

b) Information collected automatically

  • Device & browser data — IP address, browser type, operating system, device type.
  • Usage data — pages visited, time spent, links clicked, referring URL.
  • Cookie data — see our Cookie Policy for full details.

c) Information from third parties

If you sign up via a social login or click through from an affiliate partner, we may receive a limited data profile from that partner (e.g., name, email, referral source).

2. How we use your information

We use your information to:

  • Deliver the newsletter you subscribed to.
  • Fulfill orders for business plan PDFs, cohort courses, and other products.
  • Respond to your questions, feedback, and support requests.
  • Understand how the site is used, so we can improve it (aggregate analytics).
  • Prevent fraud, abuse, and violations of our terms.
  • Comply with legal obligations.

We do not sell your personal data to anyone, ever. We do not share your email with advertisers, sponsors, or third-party marketers.

3. Legal basis for processing (GDPR)

If you are in the European Economic Area (EEA) or United Kingdom, we rely on the following legal bases:

  • Consent — for newsletter signups, marketing cookies, and optional communications.
  • Contract — when you buy a product or enroll in a course, we process your data to deliver it.
  • Legitimate interest — for analytics, security, and improving the site.
  • Legal obligation — for tax records, fraud prevention, and regulatory compliance.

4. Cookies & tracking technologies

We use cookies to make the site work, understand how it’s used, and (with your consent) show relevant content. Full details are in our Cookie Policy. You can manage or reject cookies via our consent banner or your browser settings.

5. Third-party services we use

We use trusted third-party services to run the site. Each has its own privacy policy:

ServicePurposeData sharedPrivacy policy
Google Analytics 4Site analyticsAnonymized IP, page views, device dataLink
Google AdSense & EzoicDisplay advertisingCookie ID, page context (with consent)Link
BeehiivNewsletter deliveryEmail, engagement metricsLink
StripePayment processingCard data, name, billing addressLink
CloudflareCDN & securityIP address, request headersLink
VercelHosting infrastructureIP, request logsLink
Meta Pixel (opt-in)Ad attributionEvent data (with consent only)Link
YouTube (embedded)Video playbackCookie ID (privacy-enhanced mode)Link

6. Data sharing & disclosure

We share your data only in these limited circumstances:

  • Service providers — listed above, only as needed to run the site.
  • Legal requirements — if compelled by law, court order, or valid government request.
  • Business transfers — if Zarrar Tech is acquired or merges, your data may transfer as part of the assets. You’d be notified in advance.
  • With your consent — e.g., if you agree to be featured in a case study.

We do not sell, rent, or trade your personal information.

7. Data retention

  • Newsletter subscribers: retained until you unsubscribe, then deleted within 30 days.
  • Customer purchase records: retained for 7 years for tax/accounting compliance.
  • Contact form messages: retained for 2 years, then deleted.
  • Analytics data: retained per Google Analytics 4 default (14 months), aggregated only.
  • Server logs: retained for 30 days for security purposes.

8. Your rights (GDPR & CCPA)

Regardless of where you live, you have the following rights over your personal data:

  • Access — get a copy of the data we hold about you.
  • Correction — fix inaccurate data.
  • Deletion (“right to be forgotten”) — delete your data, subject to legal retention.
  • Portability — export your data in a machine-readable format.
  • Restriction & objection — limit how we process your data.
  • Withdraw consent — at any time, for anything based on consent.
  • Complaint — lodge a complaint with your local data protection authority.

California residents (CCPA/CPRA): You additionally have the right to know what personal information we collect, to opt out of the sale or sharing of personal information (we don’t sell or share for cross-context behavioral advertising), and to non-discrimination for exercising these rights.

To exercise any of these rights, email privacy@aiideabank.com. We’ll respond within 30 days.

9. Data security

We use industry-standard security measures: TLS/HTTPS encryption for all data in transit, encrypted databases, access controls limiting who on our team can see your data, and third-party processors (Stripe, Beehiiv) that meet SOC 2 / PCI-DSS standards. No system is 100% secure — if a breach occurs affecting your data, we’ll notify you within 72 hours as required by GDPR.

10. International data transfers

We’re based in Pakistan, and our service providers are primarily in the United States and Europe. When your data is transferred internationally, we rely on Standard Contractual Clauses (SCCs) and provider-level safeguards to protect it. If you’re in the EEA/UK, your data receives the same protections as if it stayed in Europe.

11. Children’s privacy

AI Ideas Bank is intended for users aged 16 and older. We do not knowingly collect personal information from children under 16. If you believe we’ve collected data from a child, email us at privacy@aiideabank.com and we’ll delete it.

12. Changes to this policy

We may update this Privacy Policy from time to time. If we make material changes, we’ll notify you by email (if you’re a subscriber) and post a notice on the site 30 days before the changes take effect. The “Last updated” date at the top will always reflect the most recent version.

13. Contact us

Questions, concerns, or data requests?

Share with