Privacy policy
Last updated: {{DATE_EFFECTIVE}}
This policy explains what personal data {{COMPANY_LEGAL}} ("{{COMPANY}}", "we", "us") collects when you visit this website, buy a product or engage us for a project, why we collect it, who we share it with, how long we keep it and what you can ask us to do with it. We are the data controller for that data. Our registered address is {{ADDRESS_LINE1}}, {{ADDRESS_LINE2}}, United States.
1. What we collect
| Category | What it includes | Why we collect it |
|---|---|---|
| Contact details | Name, email address, and telephone number or company name if you give them | To deliver what you bought, answer support requests, and send receipts and service notices |
| Order and billing records | What you bought, the amount, the currency, the date, the last four digits and brand of the card, the country it was issued in, and the billing address where required | To fulfil the order, handle refunds, identify charges you ask about, and meet tax and accounting obligations |
| Account and usage data | Login records, feature usage and diagnostic logs from products you use | To operate the product, fix faults and prevent abuse |
| Technical data | IP address, browser and device type, referring page, pages viewed and timestamps | To keep the site secure, detect fraud and card testing, and understand which pages are used |
| Project information | Material you share with us to scope or build a project | To perform the work under the statement of work |
| Correspondence | Emails and call notes | To handle your request and keep a record of what was agreed |
We never receive your full card number. Card details are captured directly by Stripe's hosted payment form and do not pass through our systems. See Security & Payments.
2. Why we are allowed to use it
- To perform a contract with you — delivering a purchase, running a subscription, doing project work.
- To meet a legal obligation — tax, accounting and sanctions screening records.
- Our legitimate interests — keeping the site and our products secure, preventing fraud, and improving what we build, balanced against your rights.
- Your consent — optional marketing email, which you can withdraw at any time by using the unsubscribe link or emailing us.
3. Who we share it with
We do not sell personal data, we do not rent it, and we do not share it for anyone else's advertising. We share it only with service providers who process it on our instructions, under contract, for the purposes above:
| Provider | Purpose |
|---|---|
| Stripe, Inc. | Payment processing, fraud prevention, receipts and refunds |
| Cloudflare, Inc. | Website and application hosting and content delivery |
| {{PROVIDER_EMAIL}} | Transactional and support email |
| Cloudflare Web Analytics | Aggregate website analytics |
We may also disclose data where the law requires it, to enforce our terms, or to a successor in connection with a merger or sale of the business, in which case we tell affected customers by email.
4. International transfers
We operate from the United States, and our providers may process data in the United States and elsewhere. Where data is transferred out of the European Economic Area or the United Kingdom, that transfer relies on the European Commission's Standard Contractual Clauses or another lawful transfer mechanism operated by the provider concerned.
5. How long we keep it
| Data | Retention |
|---|---|
| Order and billing records | 7 years, to meet tax and accounting requirements |
| Account and usage data | While the account is active, then 12 months |
| Support correspondence | 3 years from the last message |
| Website technical logs | 12 months |
| Marketing contact details | Until you unsubscribe, then suppression-list only |
6. Your rights
Wherever you live, you can ask us to give you a copy of the personal data we hold about you, correct it, delete it, restrict how we use it, or send it to another provider, and you can object to processing based on our legitimate interests. If you are in the European Economic Area or the United Kingdom, these are your rights under the GDPR. If you are a California resident, the CCPA gives you the rights to know, to delete, to correct, to opt out of sale or sharing (we do neither), and not to be discriminated against for exercising them.
To exercise any of these, email {{EMAIL_LEGAL}}. We verify the request against the email address on the account, and respond within 30 days. There is no charge. If you are in the EEA or UK you may also complain to your local supervisory authority.
Note that records we must keep for tax and accounting purposes cannot be deleted before the retention period above expires; we restrict them instead.
7. Cookies
This website uses only the cookies that are strictly necessary to make it work and to keep it secure, plus the cookies Stripe sets to process a payment and to detect fraud. We do not use advertising cookies and we do not allow third parties to track you across other websites from here. You can block cookies in your browser; the site will still work, but a payment may not complete.
8. Children
Our products are not directed at children under 13, and we do not knowingly collect their personal data. If you believe a child has given us data, email {{EMAIL_LEGAL}} and we will delete it.
9. Security
We use encryption in transit, multi-factor authentication on administrative accounts, access limited to those who need it, and a payment flow that keeps card data out of our systems entirely. No system is perfectly secure; if a breach affects your personal data we will notify you and the relevant authority as the law requires.
10. Changes
We may update this policy. The date at the top shows when it last changed, and material changes are notified by email to active customers.
11. Contact
{{COMPANY_LEGAL}}
{{ADDRESS_LINE1}}
{{ADDRESS_LINE2}}, United States
Privacy contact: {{EMAIL_LEGAL}}
Telephone: {{PHONE}}