The short version
We run one tracking tool: Whop's pixel, because Whop is the checkout we sell through and the pixel tells us whether someone who arrived from one of our ads went on to buy. It is described in full below. Beyond that there are no analytics, no other pixels and no advertising cookies. The only personal data we hold ourselves is what you typed into a form, what you wrote in a public comment on one of our posts, what you told us during an engagement, or what Whop passes us when you buy. You can have all of it deleted by asking.
What we collect, and when
When you fill in the booking form
This is the only form on the site. It is on systo-ai.com/book and in the pop-up on the homepage. Everything in it is optional except your name and email, and everything you enter is stored in our CRM.
- Contact details: name, email address, phone number, company, website.
- About your business: role, industry, team size, monthly revenue band, current CRM, platforms you run.
- About your stack: which LLMs you pay for, what you run them in, what is blocking you.
- About the work: your goal, what you want built, timeline, budget band, and how you heard about us.
- Anything else you type in the notes field.
Why: so a human can prepare for your call instead of asking you the same questions again on it. That is the whole reason those fields exist.
When you comment a keyword on one of our posts
Our posts on Facebook and Instagram ask you to comment a word to get something free, usually a link to an open source repository or a page on this site. If you do, an automation replies publicly, sends you the link in a direct message, and creates a record for you in our CRM containing:
- Your name as your social profile shows it publicly.
- Which keyword you commented, which platform, and which post.
We are telling you this plainly because it is the least obvious thing on this page. Commenting on a public post is not the same as filling in a form, and you may not expect it to put you in a CRM. If you would rather not be in ours, say so in the direct message or email us, and the record is deleted. You will still get the link. Nothing is conditional on staying on a list.
We do not add anyone to a marketing sequence from a comment without them asking.
When you just read the site
- Server logs. Our host records ordinary request data, including your IP address, for security and to stop abuse of our forms.
- Your IP address, briefly, for rate limiting. It is used to count recent requests and is not written to any database or joined to anything else.
- One browser storage entry of our own. The key
leadModalShownrecords that the pop-up has already appeared so it does not appear again. It is session storage, not a cookie, it holds no identifier, and it is gone when you close the tab. - Whop's pixel. Every page loads a small script from Whop, at
t.whop.tw. It records that the page was viewed, the page you came from, and any ad-click tags in the link. It stores an identifier in a cookie and in local storage so that a later visit or purchase can be connected to this one, and it works out a device fingerprint (a code calculated from characteristics of your browser and device, using the open-source FingerprintJS library) so that connection survives cleared cookies. That data goes to Whop, and we see the results in our Whop dashboard: which ads led to visits and to sales. If you block Whop's script with a content blocker, everything on this site still works.
When you buy through Whop
Whop runs our checkout. It takes your payment, and we never see your card details. Whop passes us your name, your email address and what you bought, so that we can deliver it and contact you to get started.
What we do not do
- No analytics tools. No Google Analytics, no Plausible, no Fathom. Whop's pixel is the only thing on this site that measures visits.
- One pixel, and no others. No Meta pixel, no LinkedIn insight tag, no TikTok pixel. Whop's is here because it is the checkout we sell through.
- No cookies of our own. The only cookies on this site are the ones Whop's pixel sets.
- No selling your data. Not to advertisers, not to data brokers, not to anyone. There is no arrangement under which this could happen.
- No profile building. We do not enrich your record from third-party data sources or combine it with anything bought in.
Fonts leave our control too. Fonts are served
by Google Fonts, so loading a page on this site makes a request to
fonts.googleapis.com and fonts.gstatic.com, and
Google sees your IP address as a result. We would rather self-host them
and remove that, and it is on the list.
Who else touches it
Four companies, and only four.
- Cloudflare hosts this site and runs the form endpoints. They see request data including IP addresses.
- HighLevel (LeadConnector) is our CRM. Everything you submit through the form, and every comment-keyword record, is stored there. It is a US company.
- Google Fonts serves the typefaces, as above.
- Whop runs our checkout and the pixel described above. It sees what the pixel records and, if you buy, your payment and contact details. It is a US company.
If you book a call, the appointment is created in the same CRM. We do not use a separate scheduling tool that would add a fifth.
How long we keep it
- Form submissions: kept while there is a live conversation or engagement, and for 24 months after the last contact. Then deleted.
- Comment-keyword records: kept for 12 months, or deleted immediately on request.
- Server logs: kept as long as our host retains them, which is a matter of days, not years.
If you ask us to delete something sooner, we delete it sooner. There is no retention argument to have.
Your rights, and how to use them
Depending on where you live you may have formal rights over your data under the GDPR, the UK GDPR, the CCPA or your own local law. We apply the same answer to everybody regardless, because running two standards would be more work than running the generous one.
- See it. Ask and we will send you everything we hold about you.
- Correct it. Tell us what is wrong and we will fix it.
- Delete it. Ask and it goes, including the CRM record. We will confirm when it is done.
- Take it elsewhere. Ask and we will export it in a readable format.
- Tell us to stop. Ask and we stop contacting you. That does not require a reason.
How: email kyle@systo-ai.com. A person reads it. We aim to reply within a few days and to finish within 30.
If you are a client
During an engagement we hold more than this page describes: access to your accounts, a working copy of your code, and forwarded two-factor codes for the accounts we operate. That is a different arrangement with different commitments, and we wrote it all down separately rather than burying it here.
Read the handover checklist for exactly what we hold, where it sits, and who can reach it. Every person on the team is under a signed contract covering it.
Changes, and who to shout at
If we change how any of this works we will change this page, and the date below moves. We will not quietly widen what we collect and leave the page saying otherwise.
Systo is operated by Kyle Cabahug. Questions, corrections and deletion requests all go to kyle@systo-ai.com.
Last updated 11 September 2026. This page describes what our systems actually do, checked against the code rather than written from a template. It is not legal advice, and if you need a policy that has been reviewed by a solicitor for your own jurisdiction, this is not that.