Skip to content
Maco Strategy LLC logo Maco Strategy LLC Digital readiness and access guidance
  • Home
  • Personal
  • Business
  • Guidance
  • Assessments
  • Insights
  • About
  • Contact
Account Lockout Test

Privacy Notice

Privacy Notice

How Maco Strategy LLC collects, uses, discloses, and protects personal information.

Legal

Maco Strategy LLC

These terms apply to the website, assessments, and related Maco Strategy LLC interactions described on this page.

  • Terms and Conditions Website terms
  • Privacy Notice Data practices

Last updated: June 17, 2026 Effective date: June 17, 2026

This Privacy Notice describes how Maco Strategy LLC (“Maco,” “we,” “us,” or “our”), a Virginia limited liability company, collects, uses, discloses, and protects personal information of individuals who visit our websites, complete any of our free online assessments, or otherwise interact with us (collectively, “you”). This Notice also describes the rights of California residents under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA/CPRA”), and applies to all U.S. residents.

One legal entity, one brand, one site. All Maco products — for individuals, families, and businesses — are offered under the single brand and legal entity Maco Strategy LLC, through the website at www.macostrategy.com (the “Site”). Maco also controls the domain www.digitalestateadvisors.com, which simply redirects visitors to www.macostrategy.com and has no separate content. Wherever you submitted your information — at macostrategy.com or any related landing page — this Notice describes how we handle it.

Our assessments are offered to U.S. residents only. We do not knowingly collect personal information from individuals located in the European Economic Area, the United Kingdom, or other non-U.S. jurisdictions through our assessments.

1. Scope and Coverage

This Notice applies to personal information we collect through:

(a) the website at www.macostrategy.com (and the www.digitalestateadvisors.com domain that redirects to it);

(b) The SMB Tech Risk Check, The Account Lockout Test: Are They Blocked?, and any related landing pages, forms, or thank-you pages (the “Assessments”);

(c) emails we send you (including transactional Results Emails and Marketing Emails); and

(d) cookies, pixels, software development kits, and similar technologies used in connection with the foregoing.

This Notice does not apply to information collected by third parties whose websites or services link to or from ours; their privacy practices are governed by their own notices.

2. Categories of Personal Information We Collect

In the past twelve (12) months, we have collected, or may collect, the following categories of personal information (using the categories defined in CCPA/CPRA, Cal. Civ. Code § 1798.140(v)):

CCPA/CPRA CategoryExamples for our Assessments
IdentifiersName (if provided), email address, IP address, online identifiers, device identifiers, cookie IDs, and — for paid customers — billing name, billing address, business name (if applicable), and the masked/last-four digits of any payment card returned to us by our payment processors
Customer records (Cal. Civ. Code § 1798.80(e))Name and email address combined
Commercial informationRecords of products or services considered or purchased, including the fact that you completed an Assessment, your Score band, your purchase history (Kits and Educational Coaching Packages), and engagement with our marketing emails
Internet or other electronic network activityBrowsing history on our Site, interaction data, pages visited, referring URL, time on page, click-stream data, cookie/pixel data from analytics and advertising tags
Geolocation data (non-precise)Approximate location inferred from IP address (e.g., U.S. state)
Professional or employment-related information (SMB Tech Risk Check and Small Business Tech Readiness Kit)Your role, business size, industry, business name, business sector, and inferences about your business technology environment derived from your responses
Personal-context information (Account Lockout Test and Online Account Readiness Kit)General categorical information about how organized your digital accounts and digital files are, whether you have designated trusted persons or legacy contacts, whether you have a will or executor, and similar non-credential categorical responses
InferencesYour Score and score band, segment classification for marketing, and other inferences about your readiness drawn from your responses
Audio, electronic, visual, thermal, olfactory, or similar informationNone collected through the Assessments
Sensitive personal information (Cal. Civ. Code § 1798.140(ae))We do not intentionally collect sensitive personal information through the Assessments. We expressly ask you not to submit Social Security numbers, financial account numbers, passwords, PINs, account credentials, biometric templates, cryptocurrency seed phrases or private keys, security-question answers, precise geolocation, government IDs, racial or ethnic origin, religious or philosophical beliefs, union membership, communications contents, genetic data, biometric identifiers, health information, or sex life/orientation data through the Assessments. If you voluntarily submit such information despite our request not to, we will use it only to respond to you and will delete it as soon as reasonably practicable.
Biometric information; genetic data; health information; education information; protected classifications; sex life/orientationNot collected

We do not intentionally collect personal information from anyone we know to be under 16 years of age.

3. Sources of Personal Information

We collect personal information from:

(a) You directly, when you submit an Assessment, send us email, subscribe to our list, or otherwise communicate with us;

(b) Automatically, when you visit our websites or interact with our emails, through cookies, pixels, web beacons, server logs, and similar technologies; and

(c) Service providers and third parties that help us operate the websites, deliver the Assessments, send emails, process analytics, and serve advertising, as described in Section 5.

4. How We Use Personal Information (Business and Commercial Purposes)

We use personal information for the following business and commercial purposes:

(a) to provide the Assessments, calculate your Score, and deliver the Results Email;

(b) to send Marketing Emails about Maco’s content, products, and services , and to measure their performance;

(c) to operate, maintain, secure, and improve our websites, the Assessments, and our methodologies, including detecting and preventing abuse, fraud, and security incidents, and debugging errors;

(d) to understand how visitors use our websites through analytics (e.g., Google Analytics);

(e) to advertise our products and services to you and similar audiences across other websites and platforms (including Meta and Google), and to measure advertising performance;

(f) to personalize our communications and the website experience;

(g) to manage our customer relationships and our prospect pipeline (CRM);

(h) to process payments for paid products (currently the Online Account Readiness Kit, the Small Business Tech Readiness Kit, and Educational Coaching Packages) through our checkout and payment platform Zoho Checkout and our payment processor Zoho Payments, which together collect payment-card and bank account information directly from you on Zoho-hosted pages; we do not see or store full payment-card numbers, CVV codes, or full bank account credentials, and we receive only limited transaction metadata (e.g., last-four digits, card brand, billing ZIP, transaction ID, success/failure status);

(i) to comply with law, respond to lawful requests, enforce our Terms, protect our rights and the safety of users, and exercise or defend legal claims; and

(j) for any additional purpose with your consent.

We will not use personal information for materially different, unrelated, or incompatible purposes without providing you notice and, where required, obtaining your consent.

5. Categories of Third Parties; Disclosure, Selling, and Sharing

5.1 Service providers

We share personal information with the following categories of service providers, each of which is contractually restricted from using personal information for any purpose other than performing services for us. The following are the principal vendors used in connection with the Assessments and our other operations:

VendorRolePersonal information disclosed
ScoreApp Ltd. (United Kingdom; servers located in the UK and/or European Economic Area)Hosts and delivers the Assessments; collects your responses and email address on the Assessment page; pushes lead data into our Zoho CRM via native integrationIdentifiers, customer records, Assessment responses, score outputs
Zoho Corporation (Zoho Campaigns, Zoho CRM, Zoho Sign, Zoho Bookings, and other Zoho One components)Email delivery, CRM, contract signature, schedulingIdentifiers, customer records, commercial information, Assessment responses, engagement records
Zoho Checkout (Zoho Corporation)Hosts the checkout pages for paid productsIdentifiers, billing information, transaction metadata
Zoho Payments (Zoho Corporation)Payment processing backendBilling identifiers entered directly with Zoho Payments (we do not see full card or bank credentials)
Google LLC (Google Analytics)Website analyticsIdentifiers (including online identifiers), internet activity, approximate geolocation
Meta Platforms, Inc. (Meta Pixel)Advertising and ad measurementIdentifiers (online identifiers), internet activity
Hosting, security, email-delivery, and analytics infrastructure providersWebsite operation and securityAs needed for operation and security
Professional advisors (legal, accounting, insurance)As needed for legal and business purposesAs needed

5.1.1 International data transfer (ScoreApp)

ScoreApp Ltd. is based in the United Kingdom and stores Assessment-related data on servers located in the UK and/or the European Economic Area. When you submit an Assessment, your response data is transmitted to and stored by ScoreApp on those servers, and a copy is also pushed into our Zoho CRM. Maco Strategy LLC has entered into a Data Processing Agreement with ScoreApp that includes appropriate transfer safeguards (including Standard Contractual Clauses where applicable). The UK and EEA have data protection laws that generally provide protections at least as strong as U.S. law. If you have questions about this arrangement, please contact [email protected].

5.2 Sale of personal information

We do not sell personal information for monetary consideration.

5.3 Sharing for cross-context behavioral advertising

We may use cookies, pixels, and similar technologies (including the Meta Pixel and Google Analytics with advertising features) that disclose certain online identifiers and internet activity information to third parties for cross-context behavioral advertising purposes. Under CCPA/CPRA, these disclosures may be considered “sharing.” The categories of personal information that may be shared in this way are: identifiers and internet or other electronic network activity. The categories of recipients are advertising networks and analytics providers (currently, Google and Meta).

You have the right to opt out of this sharing. See Section 8 below and the “Do Not Sell or Share My Personal Information” link in the Site footer.

5.4 Other disclosures

We may also disclose personal information: (a) to comply with law, legal process, or lawful government requests; (b) to enforce our Terms or other agreements; (c) to protect the rights, property, or safety of Maco, our users, or others; (d) in connection with a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or part of our business; and (e) with your consent.

5.5 No sale or sharing of personal information of minors under 16

We do not knowingly sell or share personal information of consumers under 16. If we obtain actual knowledge of such a consumer, we will delete the information.

5.6 Single marketing list with source tagging

Maco Strategy LLC operates a single marketing email list covering all of its products for individuals, families, and businesses. When you sign up via an Assessment, your contact record is tagged in our CRM with the source of your sign-up (which Assessment you took). We may send you content about any of our products on a single list, including educational content and product announcements. You control your participation through the unsubscribe link in any Marketing Email. A single unsubscribe removes you from all Marketing Emails.

5.7 Information shared during paid coaching

If you purchase an Educational Coaching Package, you may share information about your business or personal situation with us during the session and clarification window. We treat that information as confidential under the Educational Coaching Terms and use it only to deliver the Coaching Package. We do not knowingly accept HIPAA-regulated protected health information, PCI-DSS cardholder data, classified information, or controlled unclassified information through our services, and we ask that you not share those categories with us. We also ask that you not share account credentials, passwords, PINs, or seed phrases during coaching.

6. Cookies and Tracking Technologies

Our websites use cookies, pixels, and similar technologies for the purposes described above. Categories include:

(a) Strictly necessary cookies required for the site and Assessments to function (e.g., session, security);

(b) Functional cookies that remember your preferences;

(c) Analytics cookies (Google Analytics) that help us understand how the Site is used; and

(d) Advertising cookies and pixels (Meta Pixel; certain Google Analytics advertising features) used for cross-context behavioral advertising and conversion measurement.

You can control cookies through your browser settings, our cookie preferences tool on the Site, and the opt-outs described in Section 8.

7. Retention

We retain personal information for as long as reasonably necessary for the purposes described in this Notice, after which we delete or de-identify it. Our default retention periods are:

CategoryRetention period
Assessment responses and lead contact informationUp to 24 months after your last meaningful engagement (open, click, or content interaction), then deleted or de-identified
CRM contact records (active prospects/customers)Duration of the relationship plus up to 6 years to address contract, tax, and other legal record-keeping requirements
Email engagement and marketing analyticsUp to 24 months after collection
Web analytics (Google Analytics)Up to 14 months after collection
Cookie dataAccording to the cookie’s stated lifetime (session to 13 months for non-essential cookies)
Server and security logsUp to 12 months after collection
Records of consumer rights requests (as required by 11 CCR § 7101)At least 24 months after the request
Tax, payment, and financial records (including transaction records, invoices, refunds, chargebacks)7 years as required by federal and state tax law
Coaching session records (booking confirmations, Topics Covered notes, clarification-window emails)Duration of the relationship plus up to 6 years

We may retain personal information for longer if required by law, in connection with an investigation, audit, claim, or litigation, or to enforce our agreements.

8. Your Privacy Rights

8.1 Rights of California residents (CCPA/CPRA)

If you are a California resident, you have the following rights, subject to verification and applicable exceptions:

(a) Right to know. You have the right to request that we disclose the categories and specific pieces of personal information we have collected about you in the past 12 months (or a longer period if you request), the categories of sources, the business or commercial purposes for collecting, selling, or sharing, and the categories of third parties to whom we have disclosed, sold, or shared personal information.

(b) Right to delete. You have the right to request that we delete personal information we have collected from you, subject to statutory exceptions (e.g., to complete a transaction, detect security incidents, comply with law).

(c) Right to correct. You have the right to request that we correct inaccurate personal information about you.

(d) Right to opt out of sale or sharing. You have the right to opt out of the “sale” or “sharing” of your personal information. As described in Section 5, we may “share” identifiers and internet activity for cross-context behavioral advertising. To exercise this right, click “Do Not Sell or Share My Personal Information” in the Site footer, or use the methods in Section 8.4. Our opt-out is symmetric: opting out requires no more steps than opting in.

(e) Right to limit use of sensitive personal information. You have the right to direct us to limit our use and disclosure of your sensitive personal information to specified permitted purposes. We do not currently use sensitive personal information for purposes that would trigger this right; if that changes, we will provide a “Limit the Use of My Sensitive Personal Information” link.

(f) Right to non-discrimination. We will not discriminate against you for exercising any of these rights. We will not deny you any Assessment, charge you a different price, or provide a different level of quality solely because you exercised your privacy rights.

(g) Right regarding automated decision-making and profiling. As contemplated by the 2026 CPPA regulations, where we use automated decision-making technology in ways that produce legal or similarly significant effects, you have rights to information and, where applicable, opt-out. The Assessment is rules-based and does not produce legal or similarly significant effects on you (it is informational only); if our practices change, this Notice will be updated.

8.2 Global Privacy Control (GPC)

We honor opt-out preference signals, including the Global Privacy Control (GPC), sent by your browser or extension. When we detect a GPC signal, we treat it as a valid request to opt out of the sale and sharing of personal information for that browser or device, and, where we can reasonably link the browser to a known consumer profile, for that profile as well. We will display a confirmation that the signal has been processed.

8.3 Authorized agents

You may use an authorized agent to submit a request on your behalf. We may require: (a) written, signed permission from you authorizing the agent (or a valid power of attorney under California Probate Code §§ 4000–4465); (b) verification of your identity directly with us; and (c) your direct confirmation that you authorized the agent. We will not require these of agents acting under a valid power of attorney.

8.4 How to submit a request

To submit a request to know, delete, correct, opt out, limit, or appeal:

(a) Email: [email protected] with the subject line “Privacy Request — [type of request]”; or

(b) Web form / opt-out link: click “Do Not Sell or Share My Personal Information” in the Site footer (interactive form available there).

8.5 Verification and timing

We will acknowledge your request within 10 business days and respond substantively within 45 calendar days. We may extend the response period by an additional 45 days (90 days total) where reasonably necessary, and will notify you of any extension within the first 45 days.

For requests to know specific pieces of personal information, we may need to verify your identity to a “reasonably high degree of certainty” by matching at least three data points and obtaining a signed declaration under penalty of perjury. For category-level requests to know, we will verify to a “reasonable degree of certainty” by matching at least two data points. We will not require verification beyond identifying your record for opt-out-of-sale/sharing or limit-use-of-sensitive-PI requests, which we will honor within 15 business days. We will not require you to create an account to submit a request.

8.6 Appeals

If we deny your request in whole or in part, you may appeal by replying to our denial email within 60 days. We will respond to the appeal within 60 days. If you remain dissatisfied, you may contact the California Privacy Protection Agency at https://cppa.ca.gov, or the California Attorney General at https://oag.ca.gov.

8.7 Other state privacy rights

We provide the rights above to all U.S. residents on a voluntary basis where we are not otherwise required to do so by law. Residents of other states with comprehensive privacy laws (including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and others) may have similar rights and may submit requests using the same methods. We will respond consistent with applicable law.

9. Children

The Assessments, the Kits, and the Site are intended solely for adults 18 and older, and our Terms and Conditions require every user to confirm they are at least 18. We do not direct any product or content to minors, and we do not knowingly collect personal information from anyone under 18. Consistent with the federal Children’s Online Privacy Protection Act (COPPA), we do not knowingly collect personal information from children under 13; and consistent with the CCPA/CPRA, we do not knowingly sell or share the personal information of any consumer under 16. If you believe a person under 18 has provided us personal information, or that we have collected information from a child in violation of law, please contact us at [email protected] and we will promptly delete it.

10. Notice at Collection

At or before the point of collection (the Assessment page), we provide a short on-form notice describing the categories of personal information collected, the purposes of collection, our retention periods, and a link to this Privacy Notice and to “Do Not Sell or Share My Personal Information.” This Section 10 (together with that on-form notice) constitutes our “notice at collection” under 11 CCR § 7012.

11. Data Security

We use reasonable administrative, technical, and physical safeguards designed to protect personal information against loss, misuse, and unauthorized access, alteration, or disclosure. However, no method of transmission or storage over the Internet is 100% secure, and we cannot guarantee absolute security.

Do not submit actual authentication credentials through our Assessments or any other channel. The Assessments are designed to ask about your general state of organization or readiness, not to collect the underlying sensitive information itself. You should never submit passwords, PINs, passcodes, biometric templates, cryptocurrency seed phrases, private keys, recovery phrases, security-question answers, account numbers, Social Security numbers, or any other credential or sensitive identifier through our Assessments. Our Assessments are not designed to securely store such information, and we will delete any such information we identify as soon as reasonably practicable.

12. Data Broker Status

Maco is not a “data broker” under California’s Delete Act (Cal. Civ. Code §§ 1798.99.80 et seq.). We collect personal information directly from individuals who intentionally interact with us through our Assessments, and we do not sell that information to third parties with whom you do not have a direct relationship.

13. Virginia Consumer Data Protection Act

Maco is based in Virginia. Based on our current operations, we do not meet the applicability thresholds of the Virginia Consumer Data Protection Act (Va. Code §§ 59.1-575 et seq.) (which require, among other things, controlling or processing the personal data of at least 100,000 Virginia consumers, or at least 25,000 Virginia consumers combined with deriving more than 50% of gross revenue from the sale of personal data). Even where VCDPA does not strictly apply, we voluntarily provide the rights described in Section 8 to Virginia residents who request them.

14. Do-Not-Track Signals

Our website does not currently respond to Do Not Track (“DNT”) browser signals other than as described above for the Global Privacy Control.

15. Third-Party Links

Our website and emails may contain links to third-party websites and services. Their privacy practices are governed by their own notices, which we encourage you to read. We are not responsible for the privacy practices of those third parties.

16. Changes to This Notice

We may update this Notice from time to time. The “Last updated” date at the top reflects the most recent revision. Material changes will be communicated by email (where we have your address), by a banner on the Site, or by other reasonable means. Your continued use of the Site or any Assessment after the effective date of a change constitutes acceptance of the updated Notice. We will review and, where appropriate, update this Notice at least every 12 months as required by CCPA/CPRA.

17. Contact Us

If you have questions, complaints, or requests regarding this Notice or our privacy practices, please contact:

Maco Strategy LLC Attn: Privacy 732 Eden Way N, Suite E, #173 Chesapeake, Virginia 23320 Email: [email protected]

Maco Strategy LLC

Assessment-driven guidance for accounts, access, personal preparedness, and business readiness.

Focus Areas

  • Personal preparedness
  • Business preparedness
  • Account access readiness
  • Assessment review and prioritization

Next Step

Start with the free Account Lockout Test, or use the assessment hub to compare the readiness paths.

Take the Account Lockout Test

View assessment hub

Legal

  • Terms and Conditions
  • Privacy Notice
  • Do Not Sell or Share My Personal Information