DayOneEcom
Privacy Policy
Effective Date: 01/07/2026
Last Updated: 03/08/2026
DayOneEcom is operated by Joe Nicklin trading as DayOneEcom ('DayOneEcom', 'we', 'us', 'our'), with a principal address at Apartment B709, 2 Greengate, Salford, M37HQ.
We operate the DayOneEcom mentorship programme and associated digital content, accessible at www.dayoneecom.com and through the Podia platform.
For all data protection enquiries, please contact us at: joe@dayoneecom.com
We are the data controller for personal data processed under this policy, and are subject to the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
You have the right to make a complaint to the Information Commissioner's Office (ICO) at www.ico.org.uk. We would appreciate the opportunity to address your concerns first — please contact us before approaching the ICO.
This policy explains how we collect, use, store, and share your personal data when you:
– Visit or use our website or our Podia-hosted pages
– Purchase or subscribe to a DayOneEcom membership
– Create an account and access course content, modules, or materials
– Participate in our member community
– Attend live calls, Q&A sessions, or other scheduled events
– Receive communications from us by email
– Contact us directly by email or through any of our business channels
– Submit a product idea using our free product validation for feedback
This policy should be read alongside our Member Terms & Conditions and any specific notices provided at the point of data collection.
– Full name
– Email address
– Billing address and postcode
– Account login credentials (managed via Podia)
– Membership status and subscription history
– Course progress and lesson completion records
– Community posts, comments, and messages (where applicable)
– Payment card details (processed and held securely by Stripe via Podia — we do not store raw card data)
– Subscription payment history, amounts, and dates
– Records of cancellations and refund requests
– IP address and approximate location
– Device type, browser type and version, operating system
– Login timestamps and session activity
– Pages visited and content accessed
– Cookies and tracking technology data (see Section 9)
– Emails sent to and from us
– Email engagement data (opens, clicks, unsubscribes)
– Notes from any calls or support interactions
We do not knowingly collect Special Category data (including health, race, religion, sexual orientation, biometric or genetic data) unless you choose to provide such information voluntarily. We do not collect phone numbers as standard.
3.7 Product Validation Data
– Product idea details you submit through our validation tool (e.g. product description, target customer, reasoning)
– Any additional context you choose to include in your submission
You provide data directly when you:
– Register for a DayOneEcom membership
– Complete checkout or subscribe
– Access course content or community features
– Contact us by email or through our platform
– Respond to surveys or feedback requests
– – Submit a product idea for validation feedback via our website
When you interact with our website and platform, we automatically collect Technical and Usage Data through cookies, server logs, and session tracking.
We may receive data from:
– Podia (account activity, course progress, membership data)
– Stripe (payment and transaction data)
– Our email marketing platform (email engagement data)
– Google Analytics and similar analytics providers
We use your personal data only where we have a lawful basis to do so under UK GDPR. The primary lawful bases we rely on are:
– Performance of a contract — to provide and manage your membership and course access
– Legitimate interests — to operate and improve our business, prevent fraud, and communicate relevant information
– Legal obligation — to comply with applicable law and tax obligations
– Consent — for direct marketing communications where required
Specifically, we use your data to:
– Create, manage, and maintain your account and membership
– Process subscription payments and manage billing
– Provide access to course content, community features, and member resources
– Send onboarding, membership, and service-related communications
– Send marketing emails and updates where you have consented or are an existing member and have not opted out
– Respond to support enquiries and complaints
– – Review and respond to product ideas submitted through our validation tool, and provide personalised feedback
– – Add you to our marketing email list where you have separately opted in when submitting a product idea for validation
– Analyse usage data to improve course content and platform experience
– Detect, investigate, and prevent fraudulent activity and chargebacks
– Retain evidence of terms acceptance and payment authorisation for dispute and legal defence purposes
– Comply with legal, tax, and regulatory obligations
We do not sell your personal data. We may share it with the following categories of recipients, strictly for the purposes described in this policy:
– Podia — course hosting, membership management, and account administration
– Stripe — payment processing and subscription billing
– Our email marketing platform — email communications and automation
– Google Analytics — website analytics
– Google Forms] — collection of product validation submissions
– Legal advisers, accountants, and insurers where necessary for compliance or professional advice
– Banks, card schemes, and payment processors in connection with payment processing and chargeback proceedings
– Law enforcement or regulatory bodies where required by law or court order
If DayOneEcom is sold or transferred as a business, your data may be transferred to the relevant successor. You will be notified of any material changes to how your data is processed as a result.
All third parties are required to handle your data in accordance with UK GDPR.
Some of our service providers are based outside the United Kingdom, including in the United States. As a result, your personal data may be transferred to and processed in countries outside the UK.
Providers that may process your data outside the UK include:
– Podia — United States
– Stripe — United States
– Google Analytics — United States
Where data is transferred outside the UK, we ensure appropriate safeguards are in place in accordance with UK GDPR, including Standard Contractual Clauses and adequacy decisions where applicable. If you require further information about specific safeguards, please contact us.
We retain your personal data only for as long as is necessary for the purposes for which it was collected. Our standard retention periods are:
– Active membership data — retained for the duration of your membership and for 6 years following the end of your membership, in line with HMRC record-keeping requirements
– Financial and transaction records — retained for a minimum of 6 years from the date of the last transaction, as required by law
– Dispute and chargeback records — retained for up to 6 years from the date of the relevant transaction or dispute
– Email marketing data — retained while your consent remains active or while you remain an active or recent member; removed upon request
– Communications and support records — retained for up to 3 years unless required for longer in connection with a dispute
– – Product validation submissions — retained for up to 12 months, or until you request deletion, whichever is sooner
In certain circumstances we may anonymise your personal data for analytical purposes, in which case it may be retained indefinitely in anonymised form.
Our website and the Podia platform use cookies and similar tracking technologies. These may include:
– Essential cookies — required for the website and platform to operate correctly, including account login and session management
– Analytics cookies — used to understand how visitors use our website, for example via Google Analytics
– Third-party cookies — set by embedded services such as Podia and Stripe
You can manage cookie preferences through your browser settings. Disabling certain cookies may affect the functionality of the platform. For more information about cookies, visit www.ico.org.uk.
Under UK GDPR and the Data Protection Act 2018, you have the following rights in relation to your personal data:
– Right of access — to request a copy of the personal data we hold about you
– Right to rectification — to request correction of inaccurate or incomplete data
– Right to erasure — to request deletion of your data where we no longer have a lawful basis to retain it
– Right to restriction — to request that we limit processing of your data in certain circumstances
– Right to data portability — to receive your data in a structured, machine-readable format where processing is based on consent or contract
– Right to object — to object to processing based on legitimate interests, including direct marketing
– Right to withdraw consent — where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing
Please note that some rights are subject to exemptions. We may retain certain data notwithstanding a deletion request where we have a legal obligation to do so, for example for tax compliance or dispute defence.
To exercise any of your rights, please contact us at joe@dayoneecom.com We will respond to all legitimate requests within one calendar month.
We take the security of your personal data seriously and have implemented appropriate technical and organisational measures to protect it against unauthorised access, loss, alteration, or disclosure. These include:
– Use of reputable, compliant third-party platforms with their own security certifications (Podia, Stripe, Google)
– HTTPS encryption across our web platform
– Login and session security managed via Podia's platform
– Access to personal data limited to authorised personnel only
No data transmission over the internet is completely secure. While we work to protect your data, we cannot guarantee absolute security. In the event of a data breach, we will notify affected individuals and the ICO in accordance with our legal obligations.
DayOneEcom is intended for adults aged 18 and over. We do not knowingly collect personal data from children under the age of 13. If you are under 13, please do not use our platform or submit any personal data. If we become aware that we have collected data from a child under 13, we will delete it promptly.
Our website and communications may contain links to third-party websites or platforms. We are not responsible for the privacy practices of those third parties, and their use of your data is governed by their own privacy policies. We encourage you to review the privacy policy of any third-party site you visit.
We review this policy regularly and will update it as our business, technology, or legal obligations change. The date at the top of this document reflects the most recent revision. Where changes are material, we will notify active members via email. Continued use of DayOneEcom following notification of an updated policy constitutes acceptance of the revised terms.
For all privacy-related queries, data subject requests, or concerns regarding this policy, please contact:
DayOneEcom
Operated by: Joe Nicklin trading as DayOneEcom
Address: Apartment B709, 2 Greengate, Salford, M3 7HQ
Email: joe@dayoneecom.com
Website: dayoneecom.com
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at www.ico.org.uk or by calling 0303 123 1113.
UK GDPR — The UK General Data Protection Regulation, as retained in UK law by the European Union (Withdrawal) Act 2018, supplemented by the Data Protection Act 2018.
Data Controller — The entity that determines the purposes and means of processing personal data. DayOneEcom is the data controller for data processed under this policy.
Data Processor — A third party that processes personal data on behalf of the data controller (e.g. Podia, Stripe).
Legitimate Interests — A lawful basis under UK GDPR permitting processing that is necessary for the genuine and proportionate interests of the data controller, provided those interests are not overridden by the rights and interests of the data subject.