SmartKDP
← All policies

Privacy Policy

Plain-English detail on every piece of data we hold, why we hold it, and the rights you have over it.

Version
1.0
Effective
Last updated

This policy describes how SmartKDP ("we", "us") handles personal data when you visit our website, create an account, or use our publishing tools. We have written it against what our systems actually do, table by table — not from a template.

Two things we want to say up front, because they shape everything below:

  • We do not sell your personal data, and we do not share it with advertising networks or data brokers.
  • We do not use advertising or tracking cookies. We use analytics cookies, and only if you accept them — nothing is set before you answer, declining costs you no functionality, and you can change your mind from any page.

Who is responsible for your data

The data controller is the operator of SmartKDP. Contact details, including a postal address, are on our Contact page. For anything involving personal data, email support@smartkdp.com — it reaches a person, not a queue.

What we collect and why

Account and identity

When you create an account we store your email address, your display name, your locale, and the time you last signed in. If you sign in with Google, we also receive and store the provider's identifier for you, whether that provider has verified your email, and your avatar URL.

We never see or store your password. Sign-in is handled by Firebase Authentication, which verifies your credentials and hands us back a token; the password itself never reaches our systems.

Why: to give you an account, to keep your work associated with you, and to contact you about your account. Legal basis (GDPR): performance of a contract.

Session and device records

Each time you sign in we create a session record containing a hashed session token (never the raw token), the expiry, your IP address, the country derived from it, your browser's user-agent string, and a device fingerprint.

We want to be direct about the fingerprint, because it is the item most people would want flagged rather than buried: when you sign in, an open-source fingerprinting library computes an identifier derived from your browser and device characteristics. We use it to detect account sharing and credential-stuffing attempts, and to recognise a suspicious sign-in. We do not use it for advertising, we do not sell it, and we do not use it to track you across other websites.

We also keep an append-only security log of authentication events (sign-in, sign-out, session revocation) with the same IP, country, and user-agent detail.

Why: account security, fraud and abuse prevention, and enforcing plan limits. Legal basis (GDPR): legitimate interests — keeping accounts secure. You can object; see Your rights below.

When you accept our terms at sign-up we store which policy version you accepted, when, and the IP address and user-agent at the time. This is the evidence that consent was actually given, and it is what lets us tell you exactly which wording you agreed to.

Legal basis (GDPR): legal obligation and legitimate interests.

Billing and payment data

Our order process is conducted by our online reseller Lemon Squeezy. Lemon Squeezy is the Merchant of Record for all our orders. That means Lemon Squeezy is the seller for the payment transaction and is an independent data controller for it, not merely our processor — Lemon Squeezy's own privacy notice governs the billing, tax, and fraud-prevention data it collects from you.

We never receive your card number. Card details are entered directly into Lemon Squeezy's checkout and are transmitted to Lemon Squeezy, not to us. What we store on our side is: your Lemon Squeezy customer identifier, your orders and payment records, your subscription status, and receipt links.

Why: to honour your plan, show you your purchase history, and meet accounting and record-keeping duties. Determining and remitting sales tax or VAT on your purchase is Lemon Squeezy's responsibility as merchant of record, not ours. Legal basis (GDPR): performance of a contract, and legal obligation for the financial records.

Your projects and uploads

Your puzzle books, project documents, generated puzzle sets, and any images you upload are stored on our infrastructure. We treat them as yours. We access them only to operate the service, to fix a fault, or where we are legally required to.

Legal basis (GDPR): performance of a contract.

Website analytics

We use Google Analytics 4, provided by Google Ireland Limited, to understand which pages are useful and where the site confuses people. It sets cookies (_ga, _ga_*) that distinguish one visitor from another.

We ask before any of that happens. Google Consent Mode is set to deny analytics storage before the Google script loads, so until you accept, no analytics cookie is set and no identifier that persists between visits is created. If you decline, none is set at all. You can change your answer at any time via Cookie settings in the footer, and it takes effect immediately.

We do not run advertising or remarketing, we do not enable Google Signals or ad personalisation, and we never send Google your name, email address, or any other identifier that would single you out personally. Your IP address is processed by Google to derive an approximate location and is not stored by Google Analytics in its raw form.

Google may process this data in the United States. Google LLC is certified under the EU–US Data Privacy Framework, and Google's standard contractual clauses apply in addition. Full detail is in Google's privacy policy and their description of how they use data from sites that use their services.

Separately, when you first arrive we keep a note of where you came from (referrer and any campaign parameters in the link) in your browser's sessionStorage. That is not a cookie and it is erased when you close the tab.

Legal basis (GDPR): consent, which you give via the cookie banner and can withdraw at any time. Withdrawing does not affect anything measured before you withdrew.

Product usage events

Where enabled, we record server-side events about how the product is used — for example that an export ran — linked to your account. There is no third-party SDK involved and no additional cookie. These are anonymised if you delete your account.

Legal basis (GDPR): legitimate interests — improving the product.

Email and newsletters

If you join our newsletter we store your email address, the time you subscribed, and where you subscribed from. Newsletter signup is double opt-in: you have to confirm via a link before we send you anything. Every email carries an unsubscribe link.

Legal basis (GDPR): consent, which you may withdraw at any time.

Support conversations

If you email us, we keep the correspondence so we can help you and refer back to it.

Legal basis (GDPR): legitimate interests.

Who else processes your data

We use a small number of service providers ("subprocessors"). The current list, with what each one does and where, is maintained at /subprocessors and kept up to date there rather than restated here, so the two can never disagree.

We may also disclose data where we are legally required to, or to establish or defend legal claims. If our business is ever transferred, your data may transfer with it; we would tell you first.

International transfers

Some of our providers process data in the United States. Where personal data of individuals in the European Economic Area or the United Kingdom is transferred there, we rely on the transfer mechanisms offered by those providers, typically the European Commission's Standard Contractual Clauses.

How long we keep it

DataRetention
Account and profileFor as long as your account exists, then deleted or anonymised on request
Session recordsUntil expiry or revocation, then cleared on a rolling basis
Authentication and security logsUp to 24 months, for abuse investigation
Consent recordsFor as long as your account exists, plus the period we may need them as evidence
Payment and order recordsRetained as required by financial and tax law, typically 6–7 years, even after account deletion
Projects and uploadsUntil you delete them, or your account is deleted
AnalyticsAggregate only, no personal data to retain
Newsletter subscriptionUntil you unsubscribe

Note the payment row: when you ask us to delete your account, we remove or anonymise your personal data, but we must keep the underlying financial ledger. We will tell you exactly what was kept and why.

Your rights

Wherever you live, you can ask us to:

  • Access the personal data we hold about you, and get a copy.
  • Correct anything inaccurate.
  • Delete your data, subject to the record-keeping duties above.
  • Export your data in a portable format.
  • Object to or restrict processing we carry out on the basis of legitimate interests, including the security fingerprinting described above.
  • Withdraw consent for anything based on consent, such as the newsletter.

If you are in the EEA or UK, these are your GDPR rights and you also have the right to complain to your local supervisory authority. If you are in California, these are your CCPA/CPRA rights; we do not sell or share personal information as those terms are defined, and we will not discriminate against you for exercising a right.

To exercise any of them, email support@smartkdp.com. We will verify that the request is really from you, and we respond within 30 days.

Children

SmartKDP is a business tool and is not directed at children under 16. We do not knowingly collect their data. If you believe a child has given us personal data, email us and we will remove it.

Security

How we protect this data — including the fact that card details never touch our servers — is described on our Security page.

Changes to this policy

If we make a material change, we will update the version and effective date at the top of this page and notify account holders by email before it takes effect. Past versions are available on request.