PRIVACY POLICY .
Effective 27 June 2026 · version 1.0
The short version
We sell digital wrap designs. To run that, we need your email (for receipts and access codes), your payment info (handled entirely by Stripe — we never see your card), and your IP address (logged briefly for fraud prevention).
We don't sell or share your data with anyone for advertising. We don't run tracking pixels, third-party analytics, or social-login widgets. The only browser storage we use is essential — your theme preference, your access code if you've bought something, and your favourites list.
Three services help us run the business: Stripe (payments), Supabase (database and file storage), Resend (transactional emails). Each is named below with what they do.
Email hello@pixelwrapstudios.com any time to access, correct, or delete your data. We respond within 7 days.
1. Who we are .
Pixel Wrap Studios is a small digital design studio based in Sydney, Australia. We make printable cake-wrap, mug-wrap and pattern files sold as instant downloads.
For all privacy matters, contact hello@pixelwrapstudios.com. Trading name and ABN: [insert before publishing — placeholder while business registration is finalised].
2. What we collect, when, and why .
From paying customers
- Email address — required at checkout. We use it to send your access code and download links, send purchase receipts, and reply if you contact us. Lawful basis: contract performance (GDPR Art 6(1)(b)).
- Payment information — your card details are submitted directly to Stripe and never touch our servers. We see only the last 4 digits, the brand (Visa/Mastercard/etc.), payment status, amount, and currency. Lawful basis: contract performance.
- Order records — what you bought, when, how much, and the access code we generated for the order. Lawful basis: contract performance + legal obligation (tax records).
From all visitors (paying or not)
- IP address — logged briefly when you interact with the site or hit our APIs, for fraud prevention and to block abuse. IP logs are deleted after 30 days. We also receive aggregate country-level IP geolocation from Stripe at the moment of payment for fraud-risk scoring. Lawful basis: legitimate interest (GDPR Art 6(1)(f)) — preventing fraud and protecting our customers.
- Browser local storage — your theme preference, your access code if you've made a purchase, and your favourites list. This is stored in your browser only, never on our servers (until subscriptions launch and you opt in to sync). You can clear it any time via your browser's site-data settings. Strictly necessary for the service to function as advertised — no consent banner required under GDPR / UK ICO / EU ePrivacy guidance.
What we don't collect
- We don't use tracking pixels, advertising cookies, fingerprinting, or third-party analytics (no Google Analytics, no Meta pixel, no Hotjar, etc.).
- We don't have Facebook/Google "social login" widgets that pass your data to those services.
- We don't collect a physical address — every product is a digital download, no shipping.
- We don't ask for personal preferences, demographic info, or anything beyond what's needed to fulfil your order.
3. Who else processes your data .
These are our sub-processors — third-party services we rely on to run the business. Each was chosen specifically because they meet or exceed the standards we hold ourselves to.
| Service | What they handle | Where data lives | Their compliance |
|---|---|---|---|
| Stripe Inc. | Payment processing, card data, receipts, fraud-risk scoring | United States (with EU/UK/AU data residency options) | PCI-DSS Level 1, SOC2 Type II, ISO 27001, GDPR DPA · Privacy policy |
| Supabase Inc. | Order records, access codes, product database, design file storage | AWS US-East-1 (United States) | SOC2 Type II, GDPR DPA, HIPAA available · Privacy policy |
| Resend Inc. | Transactional email (access codes, receipts, support replies) | United States | SOC2, GDPR DPA · Privacy policy |
If we add or change a sub-processor, this list is updated at least 30 days before the change takes effect. Existing customers will be notified by email.
4. Where your data is stored .
The majority of our infrastructure is hosted in the United States. By using our service, you consent to your personal data being transferred to and stored in the US. We rely on Standard Contractual Clauses (SCCs) (or the equivalent framework in force) for international data transfers from the EU, UK, and Australia.
5. How long we keep your data .
- Order records and access codes — 7 years from the date of purchase (Australian tax retention requirement).
- Email correspondence — 2 years from your last message to us.
- IP address logs — 30 days.
- Abandoned / failed checkouts — 90 days.
- Browser local storage — until you clear it.
If you ask us to delete your data, we delete everything we're legally able to. We're required to keep order records for tax purposes — those are retained in a minimal form (transaction date, amount, tax) with personal details stripped where possible.
6. Your rights .
No matter where you live, you can ask us to:
- Access — get a copy of the personal data we hold about you
- Correct — fix anything wrong
- Delete — remove your data (subject to tax-retention obligations for completed purchases)
- Port — receive your data in a portable format (typically JSON)
- Object — tell us to stop processing based on legitimate interest (fraud logs are the main thing affected)
If you're in the EU / UK (GDPR / UK GDPR)
You have the additional right to lodge a complaint with your data protection authority. In the UK that's the ICO. In the EU it's whichever DPA covers your country of residence.
If you're in California (CCPA / CPRA)
You have the right to know the categories of data we collect, the right to delete it, and the right to non-discrimination for exercising your rights. We do not sell or share your personal information for cross-context behavioural advertising — full stop. No "Do Not Sell or Share" link is necessary because we don't do either of those things.
If you're in Australia (Privacy Act 1988 / APPs)
You have the right to lodge a complaint with the Office of the Australian Information Commissioner if you believe we've mishandled your data. We encourage you to contact us first so we can try to resolve it directly.
How to exercise these rights
Email hello@pixelwrapstudios.com with the request. We respond within 7 days. We may ask you to verify ownership of the email tied to your purchase (we'll send a one-time confirmation link). There's no fee for the first request in any 12-month period.
7. Cookies and browser local storage .
We don't use any cookies for tracking, advertising, or analytics. The only storage we use is browser local storage (technically different from cookies — it never leaves your device unless you choose to share it). Specifically:
- Theme preference (light/dark mode)
- Access code after a purchase, so you don't paste it again on return visits
- Favourites list (designs you've hearted)
- Session preferences for whether you've dismissed certain on-page prompts
All of these are essential to the service working as advertised. Under GDPR ePrivacy guidance and the UK ICO's position, strictly necessary storage doesn't require a consent banner. You can clear all of it at any time through your browser's site-data settings — the site will still work, you'll just lose those preferences.
8. Security .
- All connections are encrypted with HTTPS / TLS 1.2+.
- All data is encrypted at rest within Supabase and Stripe (AES-256).
- Payment data never touches our servers — Stripe handles everything from card input through to authorisation.
- We don't store passwords. When subscription login launches, it will use magic links — short-lived single-use tokens emailed to you (no password to lose or breach).
- Access codes (PWS-XXXX-XXXX) are generated from a cryptographic random source over a 32-character unambiguous alphabet, giving them effectively unguessable entropy.
If we ever experience a data breach affecting your personal information, we'll notify you as soon as practicable, within the time required by applicable law (within 72 hours under GDPR; within 30 days under Australia's Notifiable Data Breaches scheme). We'll also notify the relevant authorities where required.
9. Children .
Our service isn't directed at children, and we don't knowingly collect personal data from anyone under 16. If you believe a child has provided data to us, email hello@pixelwrapstudios.com and we'll delete it.
10. Changes to this policy .
We may update this policy occasionally to reflect changes in services we use, laws, or our practices. For material changes (anything that materially affects how we handle your data), existing customers are notified by email. Minor edits like typo fixes don't trigger notification.
The most current version is always at pixelwrapstudios.com/privacy.html. The Effective date and version at the top tell you when this version was published.
11. Contact .
Pixel Wrap Studios
Sydney, NSW, Australia
Privacy contact: hello@pixelwrapstudios.com
ABN and full registered name will be added here once business registration is finalised. Until then, this email is the contact of record for all privacy matters.