Privacy Policy
Effective date: 25 April 2026 · Last updated: 10 August 2026 · Version: 1.3
1. Introduction
Pareto Partners Pty Ltd (ABN 45 699 671 111, ACN 699 671 111), trading as Habits of The Few (“we”, “us”, “our”) operates the marketing website at thehotf.com, the client portal at clients.thehotf.com (the “Portal”), and the link redirection service at go.thehotf.com, and provides personal branding, content production, and reputation management services (the “Services”).
This Privacy Policy explains how we collect, use, store, share, secure, and dispose of personal information and platform data, including data accessed through third-party APIs such as LinkedIn, Instagram (Meta), Google, and others. It applies to all visitors, prospects, clients, authorised users of client accounts, podcast guests, contractors, and anyone whose data is processed through our Services.
We comply with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), the EU General Data Protection Regulation (GDPR) and UK GDPR where applicable, the California Consumer Privacy Act (CCPA/CPRA) where applicable, and the platform-specific terms of every API we integrate with (including but not limited to the LinkedIn API Terms of Use, Meta Platform Terms, and Google API Services User Data Policy).
2. Who we are (Data Controller)
- Entity: Pareto Partners Pty Ltd (trading as Habits of The Few)
- ABN: 45 699 671 111
- ACN: 699 671 111
- Registered address: 307 Bridge Road, Richmond, Victoria 3121
- Privacy contact: Blake Ryan
- Email for all privacy and data requests: privacy@thehotf.com
For data we process on behalf of clients (e.g. their LinkedIn analytics, Instagram metrics, meeting transcripts), we act as a Data Processor with the client as Data Controller. For data we collect directly (e.g. website visitor analytics, billing records, prospect enquiries), we act as Data Controller.
3. Scope
This policy covers:
- Website visitors to thehotf.com, clients.thehotf.com and go.thehotf.com (cookies, analytics, advertising measurement, contact and booking forms).
- Prospects and leads who book discovery calls or submit enquiries.
- Clients and authorised users who log in to the Portal.
- Connected platform data retrieved via OAuth from LinkedIn, Meta (Instagram and Facebook), Google (Gmail, Calendar, Drive, YouTube, Analytics), Stripe, Fathom, and any other integration the client elects to connect.
- Podcast guests, contractors, and third parties whose information passes through our systems.
4. Data map, what we collect and why
The following table is a full register of data categories we process. We collect only what is necessary to deliver the Services (data minimisation).
| Source / Surface | Data categories | Purpose | Legal basis (GDPR) |
|---|---|---|---|
| Website visitors | IP address, device and browser metadata, pages viewed, referrer, randomly generated first-party cookie identifiers, campaign and link parameters (UTMs), Vercel Analytics and Speed Insights events | Operate, secure, and improve the website; aggregated traffic analysis; understand which campaigns and links bring people to us | Legitimate interests; consent for non-essential cookies |
| Advertising measurement (Meta Pixel) | Pages viewed, form and booking actions, device and browser metadata, and identifiers Meta uses to match activity to a Facebook or Instagram account | Measure advertising performance and build audiences for our own advertising | Legitimate interests, with notice (Australia and most regions); consent in the EEA, UK and Switzerland, where it does not run until you accept |
| Contact and enquiry forms | Name, email, phone, business name, message content, submitted attachments | Respond to enquiries; qualify leads; book discovery calls | Pre-contractual steps; consent |
| Account and Portal access | Name, email, password hash (never plaintext), role, login timestamps, session tokens, IP address | Authenticate users; provide the Portal; audit access | Performance of contract |
| Billing and payments (Stripe) | Billing name, billing address, invoice history, transaction IDs, last four digits of card, subscription status. We never see, store, or transmit full card numbers, these are tokenised by Stripe. | Process payments; issue invoices and receipts; tax and accounting compliance | Performance of contract; legal obligation |
| LinkedIn (Community Management API) | See Section 5 for the full LinkedIn data map | Provide post-level analytics, scheduling, reporting, and content management for the authorising member | Performance of contract; consent |
| Instagram and Facebook (Meta Graph API) | Account ID, username, profile picture URL, media items (posts, reels, stories) including captions and media URLs, comments, likes, reach, impressions, follower counts, audience demographics | Content scheduling, publishing, analytics and reporting for the connected account | Performance of contract; consent |
| Google Workspace integrations | Email metadata and content (only as needed), calendar events, files explicitly shared, YouTube video metrics, GA4 reports, scoped to the minimum OAuth scopes required | Operational workflows the client has specifically authorised | Performance of contract; consent |
| Fathom (meeting notes) | Meeting recordings, transcripts, AI summaries, attendee names and emails, meeting timestamps | Capture client and internal meeting context; populate CRM and content workflows | Legitimate interests; consent of all attendees |
| Notion (workspace and CRM) | Client records, deliverables, content briefs, meeting notes, internal task data | Internal operations and service delivery | Performance of contract; legitimate interests |
| AI processors (e.g. OpenAI, Anthropic) | Content drafts, transcripts, prompts, and outputs derived from the above data | AI-assisted drafting, summarisation, analytics, and content production | Performance of contract; legitimate interests |
| Podcast guests and contributors | Name, headshot, bio, social handles, recorded audio and video, written contributions | Produce and publish podcast episodes and derivative content | Consent (signed release); legitimate interests |
We do not intentionally collect special category (sensitive) personal data such as health, racial, religious, biometric, or sexual orientation information. If such data is incidentally captured (for example, in a meeting transcript), we will treat it under the strictest handling controls and delete on request.
5. LinkedIn Member Data, specific disclosures
5.1 Data Categorisation
When a LinkedIn member or company page admin authorises our application via OAuth 2.0, we may access and process the following categories of LinkedIn Member Data:
- Profile Data: member name, headline, profile URL, profile picture URL, vanity name, member ID (URN).
- Content Data: post text, post URN, image and video URLs attached to posts, document URLs, post timestamps, post visibility settings.
- Engagement Data: likes, comments, shares, reactions, impressions, click-through metrics, video views, video completion rates.
- Organisational Data (where applicable): company page identifier, follower counts, page-level analytics, visitor demographics (provided in aggregated and anonymised form by LinkedIn).
We do not collect or store: LinkedIn passwords, private messages, connection lists beyond what is required for the authorised feature, or any data outside the scope of the OAuth permissions the member has explicitly granted.
5.2 Purpose Limitation
Our LinkedIn integration is built on the LinkedIn Community Management API v2. LinkedIn Member Data is accessed and processed solelyto provide the authorising member with analytics and reporting on their own posts and account, content performance insights, and internal record-keeping for that member’s engagement with us.
Each LinkedIn OAuth connection authorises access to one LinkedIn member’s own account only. We do not aggregate, cross-reference, or process data across multiple LinkedIn members’ accounts. Each client’s LinkedIn data is stored, processed, and accessible solely in relation to that client’s own account.
We do not: sell, rent, lease, or licence LinkedIn Member Data; engage in data brokering; use it for advertising targeting; combine it with other sources for resale; use it to train general-purpose AI models; or provide it to any data aggregator except sub-processors strictly necessary to deliver the Service.
5.3 Data Retention and Deletion (LinkedIn)
- Operational retention: Maximum 24 months for historical analytics, after which it is deleted or fully anonymised.
- On disconnection: All stored LinkedIn Member Data is deleted within 30 days of revocation.
- Right to be forgotten: Verified deletion requests are actioned within 7 business days. Email privacy@thehotf.com.
5.4 Technical Security (LinkedIn Member Data)
- OAuth 2.0, we never store LinkedIn passwords.
- Encryption in transit: TLS 1.2+. Encryption at rest: AES-256.
- Access restricted on least-privilege basis with audit logs.
- Breach response: reported to LinkedIn and affected users per applicable law (72 hours for GDPR).
5.5 Third-Party Data Processing (LinkedIn)
LinkedIn Member Data is retrieved exclusively via LinkedIn’s official APIs (LinkedIn Community Management API v2). We do not scrape LinkedIn, use unofficial or undocumented endpoints, reverse engineer LinkedIn systems, or purchase LinkedIn data from any third party. Our integration fully complies with the LinkedIn API Terms of Use.
6. YouTube API Services, specific disclosures
Our YouTube integration uses YouTube API Services. By connecting a YouTube channel to our Service you are also agreeing to the YouTube Terms of Service, and Google’s handling of your information is described in the Google Privacy Policy.
6.1 Data Categorisation
When a channel owner authorises our application via OAuth 2.0, we may access and process the following categories of data:
- Channel Data: channel ID, channel title, channel thumbnail, and where available subscriber, video and view counts.
- Upload capability:permission to upload video files to the authorising channel on that client’s behalf, together with the title and description supplied with each upload.
We do not collect or store: Google or YouTube passwords, private messages, comment threads, watch or search history, monetisation or payment data, or any data belonging to channels other than the one authorised.
6.2 Purpose Limitation
YouTube data is accessed and processed solelyto publish content the client has already reviewed and approved, to confirm that content is being published to the correct channel, and to report back to that client on their own channel. No video is uploaded without the client’s prior approval of that specific piece of content.
Each connection authorises one channel only. We do not aggregate or cross-reference data across channels. We do not: sell, rent, lease or licence YouTube data; engage in data brokering; use it for advertising targeting; combine it with other sources for resale; or use it to train general-purpose AI models.
6.3 Data Retention and Deletion (YouTube)
- Authorisation tokens: stored encrypted at rest and deleted within 30 days of disconnection or revocation.
- Channel metadata: maximum 24 months, after which it is deleted or fully anonymised.
- Uploaded video:once published, the video resides on the client’s own channel and is under their control. Our working copy of the media file is removed from our delivery storage after publication.
- Right to be forgotten: verified deletion requests are actioned within 7 business days. Email privacy@thehotf.com.
6.4 Revoking access
You can revoke our access to your YouTube channel at any time, with or without contacting us, through the Google security settings page at myaccount.google.com/permissions. Revocation stops all future access immediately and triggers the deletion timelines in 6.3.
6.5 Technical Security and API Use (YouTube)
- OAuth 2.0, we never store Google or YouTube passwords.
- Encryption in transit: TLS 1.2+. Encryption at rest: AES-256.
- Access restricted on a least-privilege basis with audit logs.
- Data is retrieved exclusively via official YouTube Data API endpoints. We do not scrape YouTube, use undocumented endpoints, or purchase YouTube data from any third party.
7. TikTok, specific disclosures
Our TikTok integration uses TikTok’s official Login Kit and Content Posting API, and is subject to the TikTok Terms of Service.
7.1 Data Categorisation
- Account Data: open ID, union ID, username, display name and avatar URL of the authorising account.
- Publishing capability: permission to upload and post video content to the authorising account, together with the caption supplied with each post.
We do not collect or store: TikTok passwords, direct messages, follower lists, or any data belonging to accounts other than the one authorised.
7.2 Purpose Limitation
TikTok data is accessed and processed solely to publish content the client has approved to their own account and to confirm the correct account is connected. We do not sell, rent, licence or broker TikTok data, use it for advertising targeting, or use it to train general-purpose AI models.
7.3 Data Retention and Deletion (TikTok)
- Authorisation tokens: stored encrypted at rest and deleted within 30 days of disconnection or revocation.
- Account metadata: maximum 24 months, after which it is deleted or fully anonymised.
- Published video:resides on the client’s own account and is under their control.
7.4 Revoking access
You can revoke our access at any time from the TikTok app under Settings and privacy, Security and permissions, Manage app permissions. Revocation stops all future access immediately and triggers the deletion timelines in 7.3.
8. How we use your information (purpose limitation)
We use the data described above to:
- Provide, operate, and maintain the Portal and Services.
- Authenticate users and secure accounts.
- Deliver content production, scheduling, analytics, and reporting workflows the client has engaged us for.
- Communicate with prospects, clients, and contractors about the Services.
- Issue invoices, process payments, and meet tax and accounting obligations.
- Improve and develop the Services in aggregate (using anonymised or de-identified data where possible).
- Comply with legal obligations and respond to lawful requests by public authorities.
We will not use personal information for any materially different purpose without first obtaining consent or providing notice as required by law.
9. Sharing and sub-processors
We do not sell personal information. We share data only with:
- Sub-processors who provide infrastructure or tools we rely on to deliver the Services, including: cloud hosting (AWS, Cloudflare, Vercel), database and auth providers (Supabase, Auth0), payment processors (Stripe), email and communications (Google Workspace, Postmark), AI processors (OpenAI, Anthropic), CRM (Notion), meeting capture (Fathom), call booking (Cal.com), website analytics and performance measurement (Vercel Analytics and Vercel Speed Insights), and advertising measurement (Meta Platforms, via the Meta Pixel, only where you have accepted advertising cookies).
- The client whose account the data belongs to.
- Professional advisers (legal, accounting, insurance) under confidentiality.
- Authorities and courts where required by law.
- A successor entity in the event of a merger, acquisition, or sale of assets.
A current list of sub-processors is available on request from privacy@thehotf.com.
10. International data transfers
We are based in Australia. Some sub-processors store or process data in the United States, the EU, the UK, and other jurisdictions. We rely on Standard Contractual Clauses (SCCs), adequacy decisions, and vendor commitments to comparable security standards.
11. Data retention and deletion (general)
| Data category | Retention period |
|---|---|
| Website analytics (GA4) | 14 months (default) |
| Prospect / lead enquiry data | 24 months from last contact, then deleted |
| Active client records | Duration of engagement plus 7 years (Australian tax requirement) |
| Billing and invoicing records | 7 years (ATO requirement) |
| LinkedIn Member Data | Maximum 24 months; deleted within 30 days of disconnection |
| Instagram / Meta data | Maximum 24 months; deleted within 30 days of disconnection |
| Google integration data | Deleted within 30 days of disconnection |
| Meeting transcripts and recordings | 24 months from meeting date |
| Account credentials and session logs | 12 months after account closure |
12. Security
- Encryption at rest: AES-256 for all databases and persistent storage.
- Encryption in transit: TLS 1.2 or higher.
- OAuth 2.0 for all third-party integrations, we never store platform passwords.
- Role-based access, MFA for admin accounts, audit logging.
- Sub-processors vetted for SOC 2, ISO 27001, or equivalent.
- Encrypted backups with defined retention and recovery procedures.
- Breach response: Notifiable Data Breaches reported to the OAIC and affected individuals as soon as practicable. GDPR-covered breaches reported within 72 hours.
No system can be guaranteed 100% secure. We do not warrant absolute security and you provide your information at your own risk to the extent permitted by law.
13. Automated decision-making and AI processing
We use AI tools (including large language models from OpenAI and Anthropic) to process and summarise meeting transcripts, draft and refine content, generate analytics insights, and suggest optimal posting times or content formats.
These automated processes do not produce legal effects concerning you. All material outputs are reviewed by a human before external publication. We do not use AI for credit, employment, or similarly significant decisions.
LinkedIn Member Data, Instagram Member Data, and Google user data are not used to train any general-purpose AI model.
If you would prefer your data not be processed by AI tools, contact privacy@thehotf.com.
14. Cookies and similar technologies
These are the cookies and tags we actually run. We do not use Google Analytics.
- Strictly necessary: session management, security and authentication on the Portal, and
hotf_consent(records the choice you make below) andhotf_geo(a two-letter country code, used only to decide which consent rules apply to you). These cannot be disabled, and none of them identify you to a third party. - Analytics and performance: Vercel Analytics and Vercel Speed Insights, which are first-party and store no identifier on your device; and our own attribution cookies —
hotf_vid,hotf_sid,hotf_clickandhotf_utm— which hold randomly generated values used to understand which campaigns and links bring people to us. Identifiers are hashed before storage, raw IP addresses are not retained, and none of this is shared with an advertising platform. - Advertising: the Meta Pixel. This one is different: it is a third-party tag, and it sends your activity on our sites to Meta Platforms, who may match it to your Facebook or Instagram account and use it to measure and target advertising.
If you are in the EEA, the UK or Switzerland, a cookie banner asks you to choose when you first arrive, and nothing in the analytics or advertising categories runs until you answer.
Everywhere else, including Australia, analytics and advertising cookies are set when you arrive, on the basis of our legitimate interests in measuring and improving what we do. We are telling you here rather than asking you first, which is what Australian privacy law requires of us. You can still opt out at any time by the means below, and we will honour it.
Where a choice is recorded it is remembered for twelve months across thehotf.com, clients.thehotf.com and go.thehotf.com. To opt out or change your mind: block or clear cookies for thehotf.com in your browser settings, use your browser’s “Do Not Track” or tracking-protection setting, or email privacy@thehotf.com and we will action it for you. Opting out does not affect anything collected beforehand.
15. Your rights
Depending on your location, you may have the right to:
- Access a copy of the personal data we hold about you.
- Correction of inaccurate or incomplete data.
- Deletion(“right to be forgotten”), subject to legal retention requirements.
- Restriction or objection to certain processing.
- Portability, receive your data in a structured, machine-readable format.
- Withdraw consent at any time.
- Lodge a complaint with a supervisory authority , in Australia, the OAIC; in the EU, your local DPA; in the UK, the ICO.
California residents have additional rights under the CCPA/CPRA. We do not sell or share personal information as defined under the CCPA.
16. Contact for data requests
Privacy Contact: Blake Ryan
Entity: Pareto Partners Pty Ltd (trading as Habits of The Few)
ABN: 45 699 671 111 · ACN: 699 671 111
Email: privacy@thehotf.com
Postal: 307 Bridge Road, Richmond, Victoria 3121
Response time: Acknowledged within 5 business days; substantive response within 30 days.
17. Children
The Services are not directed to individuals under 18. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact privacy@thehotf.com and we will delete it.
18. Limitation of liability and disclaimers
To the fullest extent permitted by law, and except for liability that cannot be excluded under the Australian Consumer Law or any other non-excludable statutory right:
- The Services and Portal are provided “as is” and “as available”.
- We are not liable for loss or damage from unauthorised access resulting from events beyond our reasonable control.
- Aggregate liability is limited to fees paid in the 12 months preceding the claim, or AUD $100, whichever is greater.
- We are not liable for indirect, consequential, special, or punitive damages.
- We are not responsible for acts, omissions, or policy changes of third-party platforms.
19. Indemnity
You agree to indemnify and hold harmless Pareto Partners Pty Ltd from any claim arising out of your breach of this policy, data you upload without legal authority, or your misuse of outputs delivered through the Services.
20. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. Material changes will be notified to active users at least 30 days before they take effect. Continued use of the Services after the effective date constitutes acceptance.
21. Governing law and jurisdiction
This Privacy Policy is governed by the laws of Victoria, Australia. Disputes are subject to the exclusive jurisdiction of the courts of Victoria, save that nothing prevents you from exercising statutory rights in your country of residence.