Privacy Policy
Effective September 14, 2026
This Privacy Policy explains how Colton Holland, operating under the business name Vertical Apps ("Vertical Apps," "we," "us," or "our"), collects, uses, discloses, retains, and protects personal information across verticalapps.io, our application and scheduling flows, client services, AI Architect Academy courses and digital products, Whop storefronts and memberships, communications, physical fulfillment, and privacy-request channels (collectively, the "Services").
Notice at Collection
Depending on how you use the Services, we may collect identifiers and contact details; account, membership, course, transaction, shipping, professional, application, scheduling, communications, consent, user-content, internet, device, diagnostic, security, and limited inference information. We use this information to provide and secure the Services, create and manage accounts and course access, deliver content and requested physical items, process applications and transactions, provide support, communicate with you, honor choices, improve our work, enforce our terms, and comply with law.
Vertical Apps does not sell personal information. We do not share personal information for cross-context behavioral advertising and do not authorize advertising pixels or session-replay tools on the public Vertical Apps Site. We do not share mobile information or SMS consent with third parties or affiliates for their marketing or promotional purposes. Platform providers such as Whop may independently process information under their own privacy notices.
We keep information only as reasonably needed for the purposes described here, taking account of the relationship, access period, last activity, provider controls, backup cycles, security, consent evidence, suppression duties, transactions, disputes, and legal requirements. Section 16 gives intended baselines for specific records.
Marketing email and marketing SMS are optional. Leaving either choice blank does not prevent account creation, course access, an application, a purchase, support, or service email. Review this Policy before submitting information. You may use our Privacy Request page or email [email protected] to exercise a privacy choice.
1. Scope and Roles
This Policy applies to personal information Vertical Apps controls through the Services. It covers visitors, applicants, prospects, clients, customers, course members, learners, support contacts, and people who communicate with us. AI Architect Academy is a Vertical Apps brand and product line, not a separate legal entity.
Vertical Apps generally decides why and how it processes information it receives for its own Services. A provider may act as our processor or service provider for some functions and as an independent controller or business for others. We describe a provider as acting under our instructions only when its contract and configuration support that role. Client engagements may assign different roles in an Engagement Agreement or data-processing addendum.
The Services are operated from the United States. They may be accessible in other countries, and information may be transferred to and processed in the United States and other places where our providers operate. Where another jurisdiction's law applies, we will use an applicable legal basis, provide required rights, and use required transfer safeguards. Mandatory local rights remain in effect.
2. Information We Collect
Identifiers and contact details
First and last name, email address, phone number, business or brand name, postal or shipping address, country or region, Whop username, account identifiers, membership identifiers, communication identifiers, and similar contact information.
Account, membership, and course information
Enrollment date, product and access level, membership status, access start and end dates, lesson and video activity, progress and completion status, downloads, course questions, support history, account changes, suspension or termination records, and related administrative information.
Transactions and fulfillment
Product selected, offer and price, order and transaction identifiers, purchase or claim date, payment status, discounts, tax and refund information, shipping address, delivery eligibility, fulfillment status, and records of course-related materials, rewards, merchandise, certificates, or other physical items sent or offered. Payment-card and bank credentials are generally collected by the payment provider and are not stored by the public Vertical Apps Site.
Professional, commercial, and application information
Business description, audience or market, revenue range, software-product idea, desired functionality, timeline, prior build experience, decision-maker status, budget or readiness information, qualification results, application status, and other answers or materials you provide.
Scheduling, calls, and events
Appointment selections, availability, time zone, meeting links, calendar details, attendance status, rescheduling history, event participation, related notes, and the operational fact that a call or event occurred.
Communications, choices, and consent evidence
Email, SMS, call, meeting, support, direct-message, and other correspondence; delivery and engagement data; communication preferences; the notice and consent language presented; form, product, and response identifiers; opt-in date, time, source, version, and technical evidence; and opt-out, unsubscribe, HELP, complaint, and suppression records.
User content and feedback
Questions, comments, posts, reviews, assignments, project descriptions, files, images, links, feedback, testimonials, survey answers, and other content you choose to submit. Some community or review content may be visible to other users as shown where you post it.
Internet, device, activity, and diagnostic information
IP address, browser and device type, operating system, referring and exit pages, pages and lessons viewed, timestamps, approximate location derived from IP address, cookie or similar identifiers, clicks, searches, form and course interactions, files uploaded, error data, security events, and performance diagnostics.
Client, project, and service-delivery information
Contracts, billing, invoices, payment status, project records, product requirements, account access, support, deliverables, testing, launch, maintenance, and other information needed for a client engagement.
Referral, affiliate, and attribution information
Referral source, affiliate or tracking identifiers, campaign and offer information, eligible attribution, commission status, and limited interaction data needed to understand how a person reached the Services or to administer an authorized referral program.
Inferences
We may infer likely service fit, urgency, product category, learning interests, course engagement, readiness, communication preferences, support needs, or follow-up priority from the information above. We do not use the Services for solely automated decisions that produce legal or similarly significant effects unless we provide any notice and rights required by law.
Information we do not request
Do not submit passwords, authentication secrets, government identification numbers, precise geolocation, health information, biometric data, consumer financial-account credentials, information about children, production source code, trade secrets, or regulated data unless Vertical Apps specifically requests it through an appropriate secure process.
3. Sources of Information
- Directly from you: through accounts, checkout, forms, course activity, communities, support, calls, scheduling, email, SMS, contracts, surveys, and feedback.
- Automatically: from browsers, devices, cookies, logs, security systems, the Site, and course-platform activity.
- Platforms and service providers: including Whop, payment, form, CRM, scheduling, communications, hosting, security, analytics, and fulfillment providers.
- Your organization or representatives: when a partner, co-founder, employee, adviser, purchaser, or other authorized person communicates with us or provides access for you.
- Public and business sources: company websites, professional profiles, business directories, and other sources used to understand or verify a relationship where permitted by law.
- Referral and affiliate sources: when an approved partner, campaign, or tracking link refers you to a Service.
4. How We Use Information
- Operate, deliver, maintain, troubleshoot, secure, and improve the Services and embedded tools.
- Create and manage accounts, verify identity and eligibility, grant course or product access, track progress, provide downloads, and administer memberships.
- Process orders, payments, taxes, discounts, refunds, and transaction records through providers.
- Verify shipping information and deliver course-related physical materials, rewards, merchandise, certificates, or other items described by an offer or requested by you.
- Provide course, account, technical, client, accessibility, and customer support.
- Operate communities, display submitted content as indicated, moderate activity, prevent abuse, and enforce our Terms.
- Evaluate applications, verify information, determine fit, prioritize follow-up, and prepare for calls.
- Schedule, confirm, remind, reschedule, and conduct meetings and events.
- Respond to inquiries and communicate about accounts, courses, products, applications, potential engagements, client services, security, and requested information.
- Send marketing email or marketing SMS only as described in Section 9 and consistent with the choice you made.
- Prepare proposals, estimates, build plans, contracts, and other pre-engagement materials.
- Provide, administer, secure, support, and document client engagements.
- Measure content performance, understand product use, conduct research, and improve courses, products, communications, and operations.
- Administer authorized referrals, affiliates, promotions, surveys, and attribution.
- Honor consent, opt-out, unsubscribe, privacy, accessibility, and communication choices.
- Detect, investigate, prevent, and respond to fraud, abuse, security incidents, unlawful activity, intellectual-property misuse, and violations of our Terms.
- Establish, exercise, or defend legal claims and comply with contractual, legal, regulatory, tax, accounting, insurance, and audit obligations.
- Create aggregated or deidentified information that cannot reasonably identify you and maintain it in that form.
- Use information for another compatible purpose disclosed when collected or with your direction or consent.
5. Legal Bases Where Applicable
Where a law requires a legal basis, we rely on one or more of the following:
- Contract and requested steps: to create an account, deliver a course or product, process a transaction, fulfill an item, evaluate a requested engagement, and perform an agreement.
- Consent: for optional marketing email, marketing SMS, recording, or another use you affirmatively authorize. You may withdraw consent prospectively.
- Legitimate interests: to operate and secure the Services, provide support, improve content, evaluate business opportunities, communicate with business contacts, prevent abuse, and protect legal rights, balanced against affected rights.
- Legal obligations: to comply with law, lawful process, tax, accounting, recordkeeping, consumer-protection, and regulatory duties.
- Vital interests or public interest: in the limited circumstances where applicable law permits or requires those bases.
6. How We Disclose Information
We may disclose personal information:
- to platforms, service providers, and contractors supporting course delivery, accounts, hosting, CRM, forms, scheduling, communications, email, analytics, security, payments, accounting, legal services, insurance, fulfillment, and project delivery;
- to personnel, contractors, moderators, and professional advisers who need it for service delivery, support, application review, fulfillment, compliance, or protection of rights;
- to other users when you choose to post in a community, submit a public review, or use a feature that identifies its audience;
- to your organization, purchaser, representatives, or other people you direct us to include in an account, meeting, shipment, or engagement;
- to approved referral or affiliate partners only as needed to validate attribution and administer an authorized program;
- to comply with law, subpoena, court order, lawful government request, or legal process;
- when reasonably necessary to investigate fraud or abuse, enforce terms, protect rights, property, safety, and security, or establish, exercise, or defend a legal claim;
- in connection with a contemplated or completed merger, financing, acquisition, reorganization, bankruptcy, sale of assets, or transfer of operations, subject to appropriate confidentiality and legal requirements; and
- at your direction, with your consent, or for another purpose disclosed when the information is collected.
Vertical Apps does not receive money for personal information. We do not authorize use of personal information for cross-context behavioral advertising. If this practice changes, we will update this Policy and provide any required notice and opt-out before the change applies.
Mobile and text-message data: No mobile information will be shared with third parties or affiliates for their marketing or promotional purposes. Information sharing to subcontractors in support services, such as customer service and message delivery, is permitted only as needed to provide those services. All other use-case categories exclude text-message originator opt-in data and consent; this information will not be shared with third parties for their own marketing.
7. AI Architect Academy and Whop
AI Architect Academy is operated by Vertical Apps. Whop provides the storefront, account, checkout, membership, course-hosting, access, community, support, analytics, payment, tax, and related platform functions that may be used for Academy products. Whop may collect and process information for its own platform purposes under the Whop Privacy Policy.
Whop may provide Vertical Apps with account and contact details, checkout answers, shipping information, membership and access status, transaction records, course activity, support or community content, and other information needed to supply and administer the product. Vertical Apps uses that information only as described in this Policy and the applicable offer.
Submitting a shipping address does not guarantee that a physical item will be sent. When a product includes or later offers an eligible physical item, we may use the address to verify availability and complete delivery. We do not use a shipping address to visit you or contact you at home.
Deleting information held by Vertical Apps may not delete a separate Whop account or information Whop must retain for its own purposes. You may contact both Vertical Apps and Whop when a request concerns both records.
8. SMS and Mobile Privacy
The controlling program terms appear in the SMS Program Terms. Providing a phone number, creating an account, joining a course, buying a product, submitting a form, or accepting the Terms does not by itself authorize automated or marketing text messages.
You opt in only through a separate affirmative action that clearly identifies Vertical Apps, the message category, and the number to be used. For a marketing program, the disclosure will state that messages may be automated, consent is not a condition of purchase or access, message frequency varies, message and data rates may apply, and you may reply STOP to opt out or HELP for help.
We may store the consent wording and version, form or product and response identifiers, source page, date, time, time zone, phone number, affirmative choice, and related technical evidence. Missing, blank, incomplete, or failed evidence is treated as no consent. We will not send automated marketing SMS unless the sender, campaign, consent evidence, suppression, revocation, sending-window, and testing controls required for that program are active.
You may withdraw at any time by replying STOP or another reasonable message that clearly communicates revocation. We may send one non-promotional confirmation. Prior consent does not revive automatically after opt-out or number reassignment.
9. Email, SMS, and Other Communications
Service communications
We may send account, access, course-delivery, transaction, security, support, application, scheduling, contract, fulfillment, and other service email needed to provide something you requested or administer an ongoing relationship. Opting out of marketing does not stop these messages.
Optional marketing email
If you affirmatively opt in, Vertical Apps may send promotional email about AI Architect Academy, Vertical Apps services, educational content, events, launches, and related offers. You may unsubscribe through the link in a message or by contacting us. We honor opt-out requests and maintain suppression records.
Optional marketing SMS
If you separately affirmatively opt in, Vertical Apps may send recurring automated promotional or marketing text messages about AI Architect Academy, Vertical Apps services, educational content, events, launches, and related offers at the mobile number you provide. Consent is not a condition of purchase or access. Message frequency varies. Message and data rates may apply. Reply STOP to opt out or HELP for help.
Marketing email consent and SMS consent are separate. A choice for one channel does not authorize the other. Calling a message "transactional" does not make it so; a message with a sales pitch, cross-sell, upsell, or promotional offer is handled as commercial or marketing communication when required by law.
10. Calls, Recording, and Transcription
Automated recording, transcription, and AI notetaking are not enabled for the public application and scheduling calls. Vertical Apps may take ordinary written notes needed to evaluate an application, provide support, or administer a relationship.
If Vertical Apps proposes recording, transcription, or automated notetaking in the future, we will provide notice before it begins, identify the purpose and expected use, obtain affirmative consent where required, and provide a practical unrecorded option where reasonably available.
12. Do Not Track and Global Privacy Control
There is no generally accepted response standard for browser Do Not Track signals, and the public Site does not change behavior when it receives one. The Site is configured without advertising pixels, session replay, or targeted-advertising use.
The public Site does not currently change behavior in response to Global Privacy Control because Vertical Apps has not authorized a sale or cross-context behavioral-advertising disclosure for a signal to stop. If we begin a practice that requires recognition of GPC or another universal opt-out mechanism, we will implement and test the required control. You may submit a privacy request at any time.
13. Current Platforms and Service Providers
A listing explains a provider's function and does not mean the provider acts only under our instructions or that it cannot process data for its own disclosed purposes. Providers and functions may change as our operations change.
- Whop: Academy storefront, accounts, checkout, payments, tax tools, memberships, course delivery, access, communities, support, analytics, and related platform services. Privacy Policy
- GoHighLevel/LeadConnector: Site hosting, CRM, forms, communications, and workflow functions. Privacy Policy
- Typeform: application collection and consent evidence. Privacy Information
- Calendly: appointment scheduling and calendar coordination. Privacy Notice
- Zoom: video meetings when selected for a scheduled call. Automated recording and transcription are not enabled for public application calls. Privacy Statement
- Cloudflare: network delivery, security, bot management, performance, and limited operational measurement. Privacy Policy
- Microsoft 365 and GoDaddy: business email and related administration. Microsoft Privacy Statement and GoDaddy Privacy Policy
- Payment and fulfillment providers: payment, tax, address, shipping, and delivery services used for an applicable order or offer.
Client engagements may use additional development, cloud, analytics, project-management, payment, communications, AI, or professional-services providers identified in the applicable agreement or project documentation.
14. Artificial Intelligence and Automated Tools
Vertical Apps may use AI-assisted tools to prepare internal drafts, organize support, analyze non-sensitive operational information, or provide client work when an agreement permits it. We do not authorize personal information collected through the public Services to train a public or general-purpose model for a provider's independent benefit unless we first provide any notice and choice required by law.
Do not put credentials, regulated data, trade secrets, or other highly sensitive information into a course prompt, community, support message, or public form. If a specific feature sends information to an AI provider, the feature or applicable agreement will identify the purpose and any material provider terms.
15. Security and Data Governance
We use reasonable administrative, technical, and organizational safeguards suited to the information and Services, including access limits, account controls, provider review, secure transmission where supported, logging, retention rules, and incident response. No internet service, transmission, or storage method is completely secure.
You are responsible for protecting your account credentials, using a unique password, signing out of shared devices, and promptly reporting suspected misuse. We limit access to people and providers with a business need and require appropriate confidentiality or data-protection duties where applicable.
16. Retention Criteria and Intended Baselines
We determine retention by the purpose of the record, relationship and access status, last substantive activity, provider capabilities, backup cycles, security needs, consent and suppression duties, transactions, disputes, and legal requirements. Intended baselines are:
- Incomplete or unqualified applications: up to 12 months after the last substantive interaction.
- Qualified prospects that do not engage: up to 24 months after the last substantive interaction.
- Course accounts, memberships, and access records: while access is active and up to 24 months after access ends, unless a shorter provider control or longer legal need applies.
- Course activity, progress, downloads, support, and non-public learning records: while reasonably useful to provide the course and up to 24 months after the last activity or access ends.
- Community posts and public reviews: while published or needed to operate the community, subject to removal requests, moderation, backup cycles, and legal preservation.
- Shipping and fulfillment records: up to 24 months after delivery or the last fulfillment activity, except transaction, tax, dispute, fraud, or legal records that require longer retention.
- Client, transaction, tax, accounting, and supported project records: up to seven years after the relationship or transaction ends, unless law or contract requires a different period.
- Terms, privacy, and consent evidence: for the relationship and the period reasonably needed to prove the notice, agreement, or choice, generally up to seven years after the relevant interaction.
- Marketing unsubscribe, SMS opt-out, complaint, and suppression records: as long as reasonably needed to honor the choice, prevent re-enrollment, or comply with law.
- Security and diagnostic logs: generally up to 90 days, with longer retention for a detected incident, abuse investigation, or legal hold.
- Verified privacy-request files: generally up to 24 months after closure, subject to applicable law.
We delete, deidentify, or restrict information when the purpose and required retention period end, subject to backup cycles and technical limits. We do not promise that every provider offers the same deletion control; we will use available controls and document material limitations.
17. Your Privacy Rights and Choices
Depending on where you live and whether an applicable law covers the processing, you may have rights to know or access information, correct it, delete it, receive a portable copy, restrict or object to processing, withdraw consent, opt out of targeted advertising, sale, or profiling, and appeal a denied request. Vertical Apps does not discriminate against a person for exercising an applicable privacy right.
Submit a request through the Privacy Request page or email [email protected]. We may verify identity by matching information already held and will request only what is reasonably needed. An authorized agent may submit a request where law permits, subject to proof of authority and identity verification.
For a Whop account or platform record controlled by Whop, also use the request method in the Whop Privacy Policy. Vertical Apps will act on seller-controlled records and reasonably coordinate provider requests where required.
You may appeal a denial by replying to the decision within 30 days with the subject "Privacy Appeal." If a right does not apply, we may still honor a request voluntarily where practical and lawful.
18. United States State Privacy Notices
If a comprehensive state privacy law applies to Vertical Apps and your information, the categories collected, sources, business purposes, recipients, and retention criteria are described in Sections 2 through 16. We do not sell personal information or share it for cross-context behavioral advertising. We do not use sensitive personal information to infer characteristics about a person.
We collect the information reasonably needed for the purpose disclosed at or before collection. If we intend to collect a materially different category or use information for an incompatible purpose, we will provide a new notice and obtain consent where required.
19. International Users and Transfers
The Services are hosted or administered from the United States. If you use them from another country, your information may be transferred to the United States and other countries with different privacy laws. Where the European Economic Area, United Kingdom, or another transfer law applies, we will use an approved transfer mechanism or another lawful basis as required.
International users may contact us to exercise applicable access, correction, deletion, portability, restriction, objection, consent-withdrawal, or complaint rights. You may also complain to the data-protection authority where you live when the law provides that right.
20. Age Requirements and Children's Privacy
The Services are intended only for people age 18 or older. We do not knowingly collect personal information from anyone under 13 and do not offer accounts or Course Services to minors. Do not submit information about a child through an account, checkout, application, course, support, or community feature.
If we learn that we collected information from a person who is not eligible, we may suspend access, delete the information where required, preserve limited safety or legal records, and contact the account holder or platform. A parent or guardian who believes a child submitted information may contact [email protected].
21. Third-Party Links and Services
The Services may link to or embed third-party websites, platforms, software, AI tools, or content. Their terms and privacy notices govern their independent services. A link or integration does not mean Vertical Apps controls or endorses the third party's data practices.
22. Changes to This Policy
We may update this Policy as the Services, providers, or law change. The effective date shows when the current version begins. Changes apply prospectively. If a change materially affects how previously collected information is used, we will provide additional notice and obtain consent where required rather than relying only on a quiet or retroactive update.
23. Contact Us
Colton Holland, operating as Vertical AppsEmail: [email protected]
Phone: +1 (754) 350-6686
Use the Privacy Request page for a rights request. For accessibility help, email us with the subject "Accessibility Assistance" or read the Accessibility Statement. The Cookie Policy describes current online technologies.