This Privacy Policy explains how Dr. CAPI ("Dr. CAPI", "we", "us", or "our"), operated by Sid Mehandru, collects, uses, and shares information when you visit our website, submit a form, book a call, or interact with our ads.

1. Who we are

Dr. CAPI provides Meta Conversions API (CAPI) and tracking consulting services for coaches and other advertisers. For the purposes of applicable data protection law, the data controller is:

  • Controller: Sid Mehandru (trading as Dr. CAPI)
  • Address: Dubai, United Arab Emirates
  • Email: hello@sidmehandru.com

2. Information we collect

Information you give us

  • Contact & enquiry details — name, email address, phone number, business or website name, and any information you provide when you request a free audit, book a call, or contact us.
  • Funnel & account details — information you share about your marketing funnel, ad accounts, CRM, tools, and tracking setup so we can assess or perform the service.
  • Communications — messages, emails, and call notes exchanged with us.

Information we collect automatically

  • Usage & device data — IP address, approximate location, browser and device type, pages viewed, referring URLs, and actions taken on our site.
  • Cookies & similar technologies — including advertising and analytics pixels such as the Meta Pixel and Google tags. See Cookie Policy.

Information from third parties

  • Advertising platforms — Meta (Facebook/Instagram) and Google may provide aggregated campaign and conversion data.
  • Lead forms — if you submit a Meta lead (instant) form, we receive the contact details you provided to Meta.

3. How we use your information

We use personal information to:

  • respond to enquiries, schedule and conduct calls, and provide a free tracking audit;
  • deliver, manage, and improve our consulting services;
  • operate, secure, and improve our website;
  • measure and optimise our advertising and understand which campaigns work;
  • send you information you request or, where permitted, relevant marketing (you can opt out at any time);
  • comply with legal obligations and enforce our Terms & Conditions.

4. Legal bases (EEA/UK visitors)

Where the EU/UK GDPR applies, we rely on the following legal bases: consent (e.g. for non-essential cookies and marketing), performance of a contract or steps taken at your request (e.g. providing an audit or service), legitimate interests (e.g. running and measuring our business and ads, securing our site), and legal obligation. You may withdraw consent at any time without affecting prior processing.

5. Cookies & tracking technologies

We use cookies, pixels, local storage, and server-side event tracking to run the site, understand usage, and measure advertising. Some of these are set by us and some by third parties. For a full breakdown and how to control them, please read our Cookie Policy.

6. Advertising, the Meta Pixel & Conversions API

We advertise on platforms including Meta (Facebook and Instagram) and Google. To measure and optimise these ads, we use the Meta Pixel (browser-side) and the Meta Conversions API (server-side), as well as Google tags.

These tools may collect information such as your interactions with our site and, for the Conversions API, hashed identifiers (for example a hashed email or IP address) used to match events to ad interactions. This information may be shared with Meta and Google, who act as independent or joint controllers for their own advertising purposes as described in their policies:

You can control ad personalisation in your Meta ad preferences and Google ad settings, and manage cookies via our Cookie Policy.

7. How we share information

We do not sell your personal information. We share it only with:

  • Service providers that help us operate — for example website hosting, form and CRM tools GoHighLevel, scheduling Calendly, email, and analytics providers, acting on our instructions;
  • Advertising & analytics platforms such as Meta and Google, as described in Section 6;
  • Professional advisers and authorities where required by law, or to establish, exercise, or defend legal claims;
  • a successor entity in connection with a merger, acquisition, or sale of assets.

8. Data retention

We keep personal information only as long as necessary for the purposes described above, to comply with legal, tax, or accounting requirements, or to resolve disputes. When it is no longer needed, we delete or anonymise it. Typical retention for enquiry and client records is 24 months after our last interaction, unless a longer period is required by law.

9. Your privacy rights

Depending on where you live, you may have the right to access, correct, delete, or port your personal information, to object to or restrict certain processing, and to withdraw consent. If you are in the EEA/UK you may also lodge a complaint with your local supervisory authority. If you are a California resident, you may have rights under the CCPA/CPRA, including the right to know, delete, correct, and opt out of "sharing" for cross-context behavioural advertising; we do not sell personal information for money.

To exercise any right, email hello@sidmehandru.com. We may need to verify your identity, and we will respond within the timeframe required by applicable law.

10. How to delete your data

To request deletion of the personal information we hold about you, email hello@sidmehandru.com with the subject line "Data deletion request" and the email address or details you used. We will confirm and complete your request as required by law, except where we must retain certain information for legal reasons.

11. International data transfers

We and our providers may process information in countries other than yours, including where our advertising and analytics partners operate. Where required, we rely on appropriate safeguards such as Standard Contractual Clauses or equivalent mechanisms for such transfers.

12. Data security

We use reasonable technical and organisational measures to protect personal information. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.

13. Children's privacy

Our website and services are intended for business owners and are not directed to children under 18. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it.

15. Changes to this policy

We may update this Privacy Policy from time to time. The "last updated" date at the top reflects the latest version. Material changes will be posted on this page.

16. Contact us

Questions or requests about this policy or your data? Contact: