This policy describes how SmartKDP ("we", "us") handles personal data when you visit our website, create an account, or use our publishing tools. We have written it against what our systems actually do, table by table — not from a template.
Two things we want to say up front, because they shape everything below:
- We do not sell your personal data, and we do not share it with advertising networks or data brokers.
- We do not use advertising or tracking cookies. We use analytics cookies, and only if you accept them — nothing is set before you answer, declining costs you no functionality, and you can change your mind from any page.
Who is responsible for your data
The data controller is SmartKDP, Inc., a corporation incorporated in Delaware, United States. Contact details are on our Contact page. For anything involving personal data, email support@smartkdp.com — it reaches a person, not a queue, and it is the fastest route to a real answer.
What we collect and why
Account and identity
When you create an account we store your email address, your display name, your locale, and the time you last signed in. If you sign in with Google, we also receive and store the provider's identifier for you, whether that provider has verified your email, and your avatar URL.
We never see or store your password. Sign-in is handled by Firebase Authentication, which verifies your credentials and hands us back a token; the password itself never reaches our systems.
Why: to give you an account, to keep your work associated with you, and to contact you about your account. Legal basis (GDPR): performance of a contract.
Session and device records
Each time you sign in we create a session record containing a hashed session token (never the raw token), the expiry, your IP address, the country derived from it, your browser's user-agent string, and a device fingerprint.
We want to be direct about the fingerprint, because it is the item most people would want flagged rather than buried: when you sign in, an open-source fingerprinting library computes an identifier derived from your browser and device characteristics. We use it to detect account sharing and credential-stuffing attempts, and to recognise a suspicious sign-in. We do not use it for advertising, we do not sell it, and we do not use it to track you across other websites.
We also keep an append-only security log of authentication events (sign-in, sign-out, session revocation) with the same IP, country, and user-agent detail.
Why: account security, fraud and abuse prevention, and enforcing plan limits. Legal basis (GDPR): legitimate interests — keeping accounts secure. You can object; see Your rights below.
Consent records
When you accept our terms at sign-up we store which policy version you accepted, when, and the IP address and user-agent at the time. This is the evidence that consent was actually given, and it is what lets us tell you exactly which wording you agreed to.
Legal basis (GDPR): legal obligation and legitimate interests.
Billing and payment data
SmartKDP, Inc. is the seller for every order, and payments are processed by Stripe. Stripe processes payment data on our behalf; its own privacy policy describes how it handles the payment, fraud-prevention, and tax data involved in a transaction. If you pay with PayPal, PayPal processes that payment under its own privacy statement.
We never receive your card number. Card details are entered directly into payment fields served by Stripe and are transmitted to Stripe, not to us. We share your billing address and email address with Stripe for payment processing, fraud prevention, and calculating the sales tax or VAT included in your price. What we store on our side is: your Stripe customer identifier, your orders and payment records, your subscription status, and links to your Stripe-hosted receipts, which you can reach from Account → Billing.
Why: to honour your plan, show you your purchase history, and meet accounting and record-keeping duties. Prices include any applicable sales tax or VAT, calculated and remitted via Stripe Tax — determining and remitting it is our responsibility as the seller. Legal basis (GDPR): performance of a contract, and legal obligation for the financial records.
Your projects and uploads
Your puzzle books, project documents, generated puzzle sets, and any images you upload are stored on our infrastructure. We treat them as yours. We access them only to operate the service, to fix a fault, or where we are legally required to.
Legal basis (GDPR): performance of a contract.
Website analytics
We use Google Analytics 4, provided by Google Ireland Limited, to understand which pages are useful and where the site confuses people. It sets cookies (_ga, _ga_*) that distinguish one visitor from another.
We ask before any of that happens. Google Consent Mode is set to deny analytics storage before the Google script loads, so until you accept, no analytics cookie is set and no identifier that persists between visits is created. If you decline, none is set at all. You can change your answer at any time via Cookie settings in the footer, and it takes effect immediately.
We do not run advertising or remarketing, we do not enable Google Signals or ad personalisation, and we never send Google your name, email address, or any other identifier that would single you out personally. Your IP address is processed by Google to derive an approximate location and is not stored by Google Analytics in its raw form.
Google may process this data in the United States. Google LLC is certified under the EU–US Data Privacy Framework, and Google's standard contractual clauses apply in addition. Full detail is in Google's privacy policy and their description of how they use data from sites that use their services.
Separately, when you first arrive we keep a note of where you came from (referrer and any campaign parameters in the link) in your browser's sessionStorage. That is not a cookie and it is erased when you close the tab.
Legal basis (GDPR): consent, which you give via the cookie banner and can withdraw at any time. Withdrawing does not affect anything measured before you withdrew.
Product usage events
Where enabled, we record server-side events about how the product is used — for example that an export ran — linked to your account. There is no third-party SDK involved and no additional cookie. These are anonymised if you delete your account.
Legal basis (GDPR): legitimate interests — improving the product.
We send two kinds of email and they are governed differently.
Service email — receipts, refunds, payment problems, security notices, and updates about work you started, such as a large puzzle set finishing or an allowance running low. These come with having an account and cannot be switched off while you have one, because they are the record of what you were charged and what happened to your work.
Legal basis (GDPR): performance of our contract with you, and our legitimate interest in telling you about your own account.
Product updates — new tools, template releases, and publishing tips. Creating an account subscribes you to this list. We say so on the sign-up form, every message carries an unsubscribe link, and you can leave at any time from Settings → Notifications. Unsubscribing costs you nothing else: your account and every service email above are unaffected.
Legal basis: our legitimate interest in telling our own users about our own similar products — the "soft opt-in" in Regulation 22(3) of the UK's PECR and Article 13(2) of the ePrivacy Directive. You may object at any time, and unsubscribing is the whole of what objecting takes.
If you subscribe using the newsletter form on our website without creating an account, that submission is your consent, and you may withdraw it the same way.
For either kind we store your email address, when you subscribed, where you subscribed from, and a record of every time you changed the setting — including which version of this policy was in force when you did. We keep those records as evidence that we had a basis to email you, and we keep them even after you unsubscribe, which is the only way an unsubscribe can be proved.
Support conversations
If you email us, we keep the correspondence so we can help you and refer back to it.
Legal basis (GDPR): legitimate interests.
Who else processes your data
We use a small number of service providers ("subprocessors"). The current list, with what each one does and where, is maintained at /subprocessors and kept up to date there rather than restated here, so the two can never disagree.
We may also disclose data where we are legally required to, or to establish or defend legal claims. If our business is ever transferred, your data may transfer with it; we would tell you first.
International transfers
Some of our providers process data in the United States. Where personal data of individuals in the European Economic Area or the United Kingdom is transferred there, we rely on the transfer mechanisms offered by those providers, typically the European Commission's Standard Contractual Clauses.
How long we keep it
| Data | Retention |
|---|---|
| Account and profile | For as long as your account exists, then deleted or anonymised on request |
| Session records | Until expiry or revocation, then cleared on a rolling basis |
| Authentication and security logs | Up to 24 months, for abuse investigation |
| Consent records | For as long as your account exists, plus the period we may need them as evidence |
| Payment and order records | Retained as required by financial and tax law, typically 6–7 years, even after account deletion |
| Projects and uploads | Until you delete them, or your account is deleted |
| Analytics | Aggregate only, no personal data to retain |
| Newsletter subscription | Until you unsubscribe |
Note the payment row: when you ask us to delete your account, we remove or anonymise your personal data, but we must keep the underlying financial ledger. We will tell you exactly what was kept and why.
Your rights
Wherever you live, you can ask us to:
- Access the personal data we hold about you, and get a copy.
- Correct anything inaccurate.
- Delete your data, subject to the record-keeping duties above.
- Export your data in a portable format.
- Object to or restrict processing we carry out on the basis of legitimate interests, including the security fingerprinting described above.
- Withdraw consent for anything based on consent, such as the newsletter.
If you are in the EEA or UK, these are your GDPR rights and you also have the right to complain to your local supervisory authority. If you are in California, these are your CCPA/CPRA rights; we do not sell or share personal information as those terms are defined, and we will not discriminate against you for exercising a right.
To exercise any of them, email support@smartkdp.com. We will verify that the request is really from you, and we respond within 30 days.
Children
SmartKDP is a business tool and is not directed at children under 16. We do not knowingly collect their data. If you believe a child has given us personal data, email us and we will remove it.
Security
How we protect this data — including the fact that card details never touch our servers — is described on our Security page.
Changes to this policy
If we make a material change, we will update the version and effective date at the top of this page and notify account holders by email before it takes effect. Past versions are available on request.