Skip to main content
YOUNGER • NEXT • LIFE •
ShopFree KitsCreditsMembershipSoundsContact
YNL
Free KitsSample LibrariesMelody KitsDrum KitsPreset KitsAll Kits
CreditsMembershipSoundsContact
Follow on TikTok

PRIVACY / YNL-POL-01

Effective: August 5, 2026

Privacy, without the blur.

This notice explains what Younger Next Life collects, where it is stored, which vendors receive it, and which uses require your selection. YNL does not require a storefront account or password.

On this page

  1. Scope and operator
  2. Data we process
  3. Why we process it
  4. Service providers
  5. Product recommendations
  6. Retention
  7. Security boundaries
  8. Your choices and rights
  9. Children
  10. Changes and contact

Short version: checkout data stays with the commerce providers, subscriber email stays in Kit and Shopify, and registered site measurement goes to PostHog’s U.S. cloud. Raw email, installed-font arrays, and rendering signatures are not included in PostHog event payloads. Like any web service, PostHog’s ingestion host receives ordinary connection metadata, including the source IP, when the browser connects; YNL sets the event$ip property to null. Optional device diagnostics are isolated in encrypted YNL storage and are not used to rank products, reconnect identities, set prices, or choose experiments.

1. Scope and operator

Younger Next Life, also referred to as YNL, operates this website and controls the site-specific processing described here. This notice covers the YNL storefront, Vault, product pages, email forms, contact forms, recommendation system, and related server endpoints.

Shopify, Whop, Kit, Discord, Zoom, YouTube, TikTok, and other linked services may independently control information you give them or generate while using their services. Their own notices apply once you enter those services. Questions about YNL’s practices can be sent to youngernextlife@gmail.com.

2. Data we process

Storefront operation and request security

The site processes ordinary HTTP request data, including an IP address, user agent, request time, requested route, and security headers. Netlify may process this information to host, route, secure, and troubleshoot the site. Shopify provides the catalog, cart, checkout, payment, order, and digital-delivery systems. YNL receives order and product records needed to confirm payment and record digital ownership.

Necessary browser storage holds the Shopify cart identifier, privacy-panel state, session activity, and similar storefront state. The Cookie and Storage Notice explains these mechanisms and the separate device-compatibility control.

Information you submit

  • Email signup forms collect an email address, an optional first name, the signup source, and anti-spam fields. Subscriber email and name are sent to Kit.
  • The contact form collects name, email, subject, and message through Netlify Forms.
  • The Platinum intake form may collect name, email, optional phone number, producer alias, work links, experience, goals, availability, and free-text answers.
  • Shopify or Whop collects checkout, billing, tax, and transaction information. YNL does not receive or store a complete payment-card number on this site.

Anonymous identity and profile mapping

Before you make a privacy selection, the browser creates an ephemeral UUID in memory and buffers a limited set of interaction events. It does not send those events. After either chooser outcome, the server can set a signed random visitor identifier named ynl_vid for the core storefront modules. The browser cannot use the recommendations API to choose another visitor’s identity.

When you submit an email address, YNL creates an opaque profile identifier and stores a keyed HMAC of the normalized email. A HMAC is a one-way, secret-keyed digest used for matching. The raw email remains in Kit and, when involved in a purchase, Shopify. YNL does not place the raw email in PostHog, URLs, or application logs. Permitted browser activity may be linked to the opaque profile for merchandising without creating a login.

Core site analytics

After either chooser outcome, posthog.capture(event, properties) sends a registered set of events and properties to PostHog’s U.S. cloud. These may describe acquisition source, sanitized paths, navigation, scroll depth, section dwell, product impressions and clicks, audio or video use, Vault downloads, consented landings from YNL email links, forms, cart and checkout activity, recommendations, experiment exposure, errors, latency, and Core Web Vitals.

PostHog automatic pageview capture, heatmaps, broad element autocapture, request bodies, and remote dependency loading are disabled. YNL sets$ip to null on registered analytics events and rejects unregistered properties, email-like values, secrets, and unsanitized URLs.

Aggregate email performance

Once daily, a server-only Netlify function makes read-only requests for Kit’s account and broadcast delivery statistics. It sends allow-listed totals such as messages sent, recipients, measured opens, clicks, unsubscribes, rates, tracking status, and reporting windows to PostHog’s U.S. cloud under the fixed non-person identifier ynl-kit-email-aggregate-v1. This scheduled reporting does not create browser storage and does not use a visitor, profile, browser, or subscriber identifier.

These snapshots exclude email addresses, names, subscriber identifiers, sender addresses, message subjects or content, link URLs, raw IP addresses, and the Kit credential. Kit’s tracked opens and clicks are measurements, not guaranteed human actions: image blocking, privacy proxies, automated scanners, and other mail-client behavior can produce misses or false positives.

Non-person Whop commerce reporting

Whop sends signed provider callbacks for membership purchases, failed payments, refunds, activations, deactivations, and scheduled cancellations. YNL validates and deduplicates those callbacks, then sends only allow-listed commerce fields such as tier, amount, currency, billing reason, and status to PostHog under the fixed non-person identifier ynl_whop_commerce_aggregate_v1. Customer, email, Whop user, payment, and membership identifiers are not forwarded to PostHog.

Core masked experience diagnostics

After either chooser outcome, posthog.startSessionRecording() may send a diagnostic replay of page structure and interactions. The configuration masks all input values, all text, and all element attributes; blocks marked sensitive sections; and does not record request headers, request bodies, canvas output, fonts, or cross-origin frames.

Optional device diagnostics

If you enable /api/privacy/telemetry → ynl-device-telemetry-v2, YNL collects a technical device snapshot. It can include browser and engine, operating system, Client Hints, screen and viewport dimensions, pixel ratio, color depth, languages, timezone, touch and pointer capability, CPU and memory buckets, connection characteristics, supported codecs and Web APIs, available fonts, a font-metric hash, hashed canvas and audio signatures, and a WebGL signature with the reported graphics vendor and renderer.

The server also encrypts the raw IP address and IP prefix. When configured, the raw IP is sent to IPinfo in an HTTPS POST body to return approximate city, region, country, timezone, autonomous-system number, provider, network type, and proxy classification. YNL does not request GPS location.

The system computes a versioned HMAC named ynl-fp-v1. Fingerprint matching and fingerprint personalization are disabled. The HMAC, raw IP, font list, font metrics, canvas hash, WebGL data, and audio hash do not enter recommendation scoring, identity reconnection, pricing, email, or experiment selection.

3. Why we process it

  • Render the site, keep a cart, secure requests, and hand off checkout.
  • Deliver digital products, free files, discounts, and membership benefits.
  • Respond to contact messages, applications, support, and accessibility requests.
  • Maintain subscriber preferences and send requested email when email delivery is active.
  • Record paid digital ownership so owned products can be suppressed or demoted.
  • Personalize product order using browsing and purchase activity linked to the signed anonymous visitor.
  • Measure site performance, diagnose failures, and test product changes through the core masked modules.
  • Prevent abuse, enforce terms, comply with law, and preserve transaction records.

YNL does not sell personal information. This implementation does not share personal information for cross-context behavioral advertising and does not include Meta Pixel or another third-party advertising pixel.

4. Service providers and destinations

Current production data paths
ServiceRole and dataNotice
ShopifyCatalog, cart, checkout, payment, orders, delivery, discounts, and digital ownership.Consumer privacy
KitEmail subscriber records, first name, source forms and tags, delivery fields, unsubscribe state, and aggregate delivery/open/click measurements.Privacy policy
PostHog USRegistered visitor analytics, experiments, core masked experience diagnostics, daily fixed-ID non-person Kit performance snapshots, and fixed-ID non-person Whop commerce outcomes.Privacy policy
NetlifySite hosting, server execution, request logs, YNL Blobs storage, contact forms, and Platinum intake forms.Privacy statement
SanityEditorial content and media delivery. A content request may expose ordinary network metadata to its CDN.Privacy policy
IPinfoOptional device-diagnostic enrichment from a raw IP address sent in an HTTPS POST body.Privacy policy
WhopMembership checkout, recurring billing, membership commerce records, and signed commerce-status callbacks sent to YNL.Privacy policy
Discord and ZoomCommunity access, calls, and mentorship when included in a membership and used by you.Discord / Zoom

Vendors may use subprocessors and may process data in the United States or other locations listed in their notices. YNL may also disclose information to professional advisers, a successor in a business transaction, or public authorities when reasonably necessary or legally required.

5. Product recommendations

When personalization is enabled, one deterministic recommendation service can use product pages viewed, card impressions and clicks, audio completion, Vault downloads, cart changes, checkout activity, Shopify purchases, current category, current cart, product metadata, availability, price, release date, and aggregate popularity. Behavioral signals use time decay and repeated-signal caps.

The ranker does not use raw IP, IP-derived network identity, fonts, font metrics, canvas, WebGL, audio fingerprint, composite fingerprint, raw email, or inferred demographic traits. Shopify purchases are the ownership source. Because the products are digital, paid ownership records may remain necessary to avoid advertising the same delivered file as an upsell. Consented email-link landing events and Kit account or broadcast performance snapshots never enter the behavior store or recommendation scoring.

6. Retention

YNL application retention schedule
RecordNormal periodReason
Signed purpose choice and anonymous visitor recordUp to 400 days from the latest explicit privacy choiceRemember the exact selected purposes and policy version.
Encrypted raw IP and IP prefix90 rolling daysOptional device diagnostics and technical investigation.
Device snapshot and fingerprint HMAC12 rolling monthsCollection-only diagnostic record; matching remains disabled.
Permitted behavior events12 rolling monthsMerchandising, attribution, and recommendation evaluation.
Recommendation shadow comparisons90 rolling daysCompare proposed and displayed ordering before activation.
Aggregate Kit performance snapshotsPostHog project retention setting, or until deletedMeasure email delivery and engagement trends without a person or browser identifier.
Non-person Whop commerce outcomesPostHog project retention setting, or until deletedMeasure membership purchases, payment failures, refunds, and status changes without a customer or browser identifier.
Profile mapping and digital ownershipUntil deletion where available, or while needed for delivery, ownership, fraud prevention, and legal recordsConnect requested email delivery and avoid repeat sale of an owned digital item.
Commerce, email, and support recordsProvider schedule and as needed for the transaction, support, tax, accounting, disputes, and lawFulfill and document the relationship.

Backups, provider systems, legal holds, and fraud-prevention records may extend these periods. De-identified or aggregate information may be retained longer when it can no longer reasonably be linked to a person or browser.

7. Security boundaries

YNL uses signed, HTTP-only identity and consent cookies; HTTPS; same-origin request checks; bounded request bodies; rate limits; signed Shopify and Whop webhooks; restricted analytics schemas; and AES-256-GCM encryption for isolated raw IP and raw device fields. Raw IP is not added to PostHog event properties, and raw font arrays stay outside PostHog, Kit, Shopify, URLs, and application logs by design.

No internet transmission or storage system is perfectly secure. If YNL learns of an incident that requires notice, it will provide notice as required by applicable law and the information reasonably available at that time.

8. Your choices and privacy rights

Use the site’s Privacy choices control to review or change device compatibility collection. Site analytics, product recommendations, and masked experience diagnostics remain core processing under either chooser outcome. Turning device compatibility collection off stops future collection for that purpose. It does not undo processing already completed before withdrawal.

Depending on where you live and which law applies, you may have rights to know, access, correct, delete, or obtain a portable copy of personal information; opt out of sale, sharing, targeted advertising, or certain profiling; limit certain sensitive-information uses; appeal a denied request; and receive equal service after exercising a right. YNL does not sell personal information or run cross-context targeted advertising through this site.

Send a request to youngernextlife@gmail.com with the subject “Privacy request”. Include your state or country and the email address, order reference, or browser context needed to find the record. YNL may request proportionate verification and may retain information where an exception applies, including transaction, security, legal, or ownership records.

An authorized agent may submit a request where applicable. YNL may ask for proof of authorization and direct identity confirmation. You can unsubscribe from marketing email using the link in the message or by contacting YNL.

9. Children

The site and its products are not directed to children under 13, and YNL does not knowingly collect personal information from a child under 13. A person under the age of legal majority must use the site and make a purchase only with permission and supervision from a parent or legal guardian.

10. Changes and contact

YNL may update this notice as the site, vendors, or law changes. The effective date at the top identifies the current version. If tracking purposes materially change, the purpose-choice policy version is changed so stored choices fail closed and the privacy panel appears again.

This notice describes the implementation and is not a certification that a particular statute applies to YNL. Mandatory rights and remedies remain available.

Privacy contact

Younger Next Life

Email youngernextlife@gmail.com

Also read the Cookie and Storage Notice and Terms and Conditions.

YNL

GRAMMY® Nominated Producers

ShopMembershipsFree KitsJoin the Discord

© 2026 Younger Next Life. All rights reserved.

PrivacyCookies & StorageTermsAccessibility
YNL / PRIVACY / 002

Choose what stays on

PrivacyCookie detailsTerms