Privacy Policy
Zakr Productions, a sole proprietorship operating in California ("Zakr," "we," "us," or "our") respects your privacy. This policy explains what we collect when you visit zakrproductions.com or use our services, who else touches it, and how to get it back or get it deleted.
We name every company that processes your information further down, by name, and we keep that list honest. If a tool is not on the list, we are not using it.
What You Give Us
When you fill in a contact form, an onboarding form, an audit or visibility check, or a newsletter signup, we collect what you type: your name, email address, phone number, business name, website, industry, location, and anything else you choose to tell us.
Calls get their own paragraph, because a call is not a form. We record our sales and client calls and have them transcribed by machine, using Fireflies.ai. That leaves an audio recording, a written transcript of what everybody said, an automatic summary, and a list of action items, and we keep those with the rest of your file so the next thing we make for you is grounded in what you actually asked for. We will tell you before a call is recorded, and if you would rather we did not, say so and we will take notes by hand instead. Ask us any time and we will send you your transcript or delete it.
If you become a client, we also hold the working information we need to do the job, such as your brand voice notes, the accounts you give us access to, and the content we produce for you.
What We Collect Automatically
Very little, and we would rather keep it that way.
Our host records standard server logs for every request, which include your IP address, the page you asked for, your browser type, and the time. That is normal web server operation and it is how the site stays up and stays secure.
We do not sell anything about you to anybody, and we never will.
We use Google Analytics to see which pages people visit and how they found us. It sets two cookies on the public pages, named _ga and _ga_2BG06NYHCW, and they are what let it tell a returning visitor from a new one. It tells us that a page was viewed, roughly what part of the world it was viewed from, and what kind of device was used. It does not tell us who you are. We do not upload customer lists to it. Google handles that data under its own privacy policy.
We also use HubSpot, which is where we keep track of conversations with people who get in touch. On the public pages it sets cookies named hubspotutk, __hstc, __hssc and __hssrc, and on each page view it requests a small tracking image from track-na2.hubspot.com. Those are what let it recognise the same browser across visits, so we can see which pages someone read before they decided to talk to us. Until you actually tell us who you are, that is a browser and not a person. If you do fill in one of our forms or book a call, HubSpot records what you submitted and links it to those earlier page views, which is how a first conversation starts with some idea of what you were already looking for. HubSpot does that with four separate scripts, and they are worth naming because they arrive from four different addresses. hs-analytics.net does the page view tracking. hscollectedforms.net watches for a form being submitted on our pages and records what was in it. hs-banner.com is its cookie banner code. hsadspixel.net is its advertising pixel, and that last one is an ad tracker rather than measurement, which is why the next paragraph is not only about our own code. HubSpot handles all of that under its own privacy policy.
We also run the Meta Pixel, and this one is an advertising tracker, so it gets its own paragraph rather than a mention. It sets a cookie named _fbp, plus _fbc if you arrived from a Facebook or Instagram ad, and on each page view it reports to Meta which of our pages you looked at. We use it for two things: showing our ads to people who have already been here, and telling whether an ad we paid for actually brought anyone. It does mean Meta learns you visited us, and Meta handles that under its own data policy. Two separate scripts can put it on the page: ours, which we control and which the opt-out further down switches off, and HubSpot's advertising pixel described just above, which loads Meta's tag by itself and does not ask us first. Those two are the only things on this site that report to somebody else's advertising system, and we would rather say that in a sentence you can find than leave you to spot it in a network tab.
The only other cookie we set is a session cookie on our own internal admin dashboard, which is for account administration and is never set for visitors.
Our pages load fonts from Google Fonts and Fontshare. Requesting a font from those services reveals your IP address to them, the same as any other web request.
Payment Information
Stripe handles every payment. Your card number, expiry, and security code go straight to Stripe and never reach our servers. We can see who paid, which plan, how much, and when. We cannot see your card.
How We Use It
To deliver the services you asked for, to answer you, to run your account and take payment, to send you marketing email you asked for, to keep the site working and secure, and to meet our legal obligations.
We do not sell your personal information. We never have and we are not going to.
We do share it in one narrow way, and we would rather name it than let a word do quiet work for us. Under California law, sharing means handing your information to somebody else so they can advertise to you on other sites and apps, and the advertising pixels described above do exactly that. Your Rights below sets out what that covers and how to stop it.
Who Processes Your Information
These are the companies that receive personal information from us and what each one is for. Each has its own privacy policy governing what it does with the data.
Stripe, for payments and subscription billing. ActiveCampaign, which holds our contact and lead records and sends our marketing email. HubSpot, which we use as a CRM alongside ActiveCampaign and which also records which pages you look at here, as described above. Meta, which receives those same page views so we can show our ads to people who have already been here and tell whether an ad we paid for actually worked. Google Workspace, including Gmail for our email and Google Chat for our internal notifications. Vercel, which hosts this website and keeps the server logs described above. Google Analytics, which counts page views as described above. Google Fonts and Fontshare, which serve the fonts on our pages. Fireflies.ai, which records and transcribes our sales and client calls as described above.
For client work, we also use AI providers to generate and review content, currently Anthropic, Google, and OpenRouter, and Zernio, formerly called Late, to schedule social posts to your own accounts. The information sent to those services is your business and campaign information, not your payment details.
1Password is on this list for the opposite reason to everything else on it. When a client platform cannot be delegated to us and a real login has to exist, that login sits in a 1Password vault and nowhere else, and our systems hold a pointer to the vault entry rather than the credential itself. It is named here so the list is complete, not because we send it anything about you.
We will also disclose information if the law requires it, or to protect our rights or somebody's safety.
Marketing Email
We only email marketing to people who asked for it. Every marketing email has an unsubscribe link, it works immediately, and it carries our postal address as the law requires.
Unsubscribing from marketing does not stop the emails you actually need, like receipts, billing notices, and answers to something you asked us.
How Long We Keep It
We keep client and billing records for as long as the relationship lasts and then for as long as tax and accounting law requires us to.
We keep lead and enquiry records while there is a live reason to, and we delete them when you ask. If you unsubscribe we keep the minimum needed to make sure we do not email you again.
Security
We use appropriate technical and organisational measures to protect your information, including encrypted connections, access controls, and keeping payment card data entirely out of our systems by leaving it with Stripe.
No system is perfect, and we are not going to pretend otherwise. If a breach ever affects your information we will tell you and we will tell you what we know.
Your Rights
Wherever you live, you can email heaalp@zakrproductions.com and ask us to show you what we hold about you, correct it, or delete it. We will not charge you and we will not make you explain yourself.
If you are a California resident, the CCPA as amended by the CPRA gives you the right to know what we collect and why, to get a copy, to correct it, to have it deleted, to limit the use of sensitive personal information, and to opt out of the sale or sharing of your personal information. We do not sell your personal information. We never have and we are not going to.
We do share it in one specific way, and we would rather spell that out than hide behind the word. Under that law, sharing has a narrow meaning: handing your information to somebody else so they can advertise to you across other sites and apps. The Meta Pixel described above does exactly that, whether it arrives from our own code or from HubSpot's advertising pixel. When it runs, Meta learns you were here, and we can pay to show you an ad later on the strength of it. Meta is the only place that sharing goes, by either route, and nothing else we use does it at all.
You can tell us to stop without emailing us and without dismissing a banner. If your browser sends a Global Privacy Control signal, our own Meta Pixel tag does not load. GPC is built into some browsers and is a free extension in the rest, and turning it on speaks for you on every site you visit rather than just this one.
There is an honest limit on that, and we would rather write it down than let you assume we had it covered. HubSpot runs its own advertising pixel here, and that pixel loads Meta's tag by itself, from HubSpot's script rather than ours. Our code cannot switch that one off, so with GPC turned on you can still end up with Meta's tag running on this site. What does stop it is tracker blocking in your browser. You can also switch the advertising itself off in Meta's own ad settings, and you can email heaalp@zakrproductions.com and we will delete whatever we already hold about you. We will never treat you differently for exercising any of these rights.
You can also unsubscribe from any marketing email using the link in it.
Children
Our services are for businesses. We do not knowingly collect personal information from anyone under 16. If you think a child has given us information, email us and we will delete it.
Changes to This Policy
If we start using a new processor, or change what we collect, we update this page and change the date at the bottom. If the change is material we will email people on our list.
Contact
Privacy questions, access requests, and deletion requests go to heaalp@zakrproductions.com.
Zakr Productions
26741 Portola Parkway
Suite 1E, #679
Foothill Ranch, CA 92610
United States
Last updated: September 1, 2026
Version 2026-09-01