Privacy Policy
The short version: this site has no advertising trackers, no analytics profiling, and no marketing pixels. It collects the minimum needed to take a payment and to remember what you bought. Everything below is the long version.
1. Who is responsible for your data
The data controller for this site is Your Legal Name or Company, of Full postal address, contactable at [email protected]. This policy covers whats-it-to-ya.com and the purchase and delivery of digital items through it.
2. Summary table
| Data | Why | Kept for |
|---|---|---|
| Email address | Receipts, access restoration, support | 7 years (tax records) |
| Purchase and subscription records | To know what you own and unlock it | Life of the purchase + 7 years |
| Payment card details | Held by Stripe, never by us | Per Stripe’s policy |
| Access cookie | To unlock your library without a password | Up to 1 year |
| Reading position, theme choice | Convenience; stays in your browser | Until you clear it |
| Server and security logs | Abuse prevention, debugging | 30 days |
3. What we collect
Nothing at all, if you only browse. You can read every catalogue page, look at the book covers, and use the free previews without giving us any personal data and without us setting any identifying cookie.
When you buy something, our payment processor Stripe collects your email address, your payment details, your name if you enter one, and the billing or tax-location information it needs. Stripe passes back to us the email address, a Stripe customer identifier, the identifier of what you bought, the amount, the currency, the country used for tax, and the last four digits and brand of the card. We never receive your full card number, expiry date, or security code.
To keep your library unlocked, we store a record linking your Stripe customer identifier to the items you are entitled to, and we issue your browser a signed cookie containing that identifier. See section 5.
If you email us, we keep your message and address so we can reply and so we have a record of the issue.
Automatically, our infrastructure provider (Cloudflare) logs standard request information — IP address, timestamp, requested URL, HTTP status, user agent, and approximate location derived from the IP. This is used to serve the site, block abuse, and diagnose faults. We do not use it to build a profile of you.
4. What we deliberately don’t collect
To be explicit, because these are the things people reasonably worry about:
- No third-party advertising or retargeting pixels.
- No Google Analytics or comparable behavioural analytics product.
- No cross-site tracking, data brokerage, or sale of personal data. We do not sell your data, and we never will.
- No passwords, because there are no accounts to have a password for.
- No reading-behaviour surveillance. Which page of a book you are on is stored in your browser, not on our servers.
- No newsletter signup harvesting. If you add a newsletter later, describe it here.
The one caveat: pages that embed a third-party video player load that player from the
provider. We use privacy-preserving embed modes where the provider offers them (for
example youtube-nocookie.com), but once a player loads, that provider can see
the request. See section 7.
5. Cookies and local storage
This site uses no advertising or analytics cookies, so it does not show a cookie consent banner. It uses exactly the following, all of them strictly necessary or set by your own action:
| Name | Type | Purpose | Lifetime |
|---|---|---|---|
wity_sess |
Cookie — HttpOnly, Secure, SameSite=Lax | A cryptographically signed token holding your Stripe customer identifier so the server can confirm what you own. It cannot be read by JavaScript and cannot be forged without our signing key. | Up to 1 year |
wity.entitlements |
Local storage | A cached list of what you own, so the interface can render unlocked immediately. Purely cosmetic — the server re-checks every actual file request. | Until cleared |
wity.reader.* |
Local storage | Your last page in each book, so the reader reopens where you stopped. | Until cleared |
wity.theme |
Local storage | Remembers whether you chose light or dark mode. | Until cleared |
| Stripe cookies | Cookie — set on Stripe’s domain | Fraud prevention and checkout function, during checkout only. | Per Stripe’s policy |
You can clear cookies and local storage at any time in your browser settings. Clearing
wity_sess will lock your library on that browser until you restore access using
the link in your receipt email.
6. Why we process it — legal bases
If you are in the UK, EU, or another jurisdiction with equivalent law, our lawful bases are:
- Performance of a contract — taking your payment, delivering what you bought, keeping your library unlocked, and running the subscription.
- Legal obligation — keeping invoice, tax, and VAT/sales-tax records for the period the law requires.
- Legitimate interests — preventing fraud and abuse, securing the site, diagnosing faults, and responding to your support messages. We have balanced these against your rights and consider the impact minimal.
- Consent — only where we ask for it explicitly, which currently we do not.
7. Who we share it with
We share data only with the service providers needed to run the site. Each acts on our instructions under a data processing agreement, or as an independent controller where noted.
| Provider | Role | What they see |
|---|---|---|
| Stripe, Inc. | Payments, subscriptions, customer portal. Independent controller for payment data. | Your name, email, card details, billing country, purchase history. |
| Cloudflare, Inc. | Hosting (Pages), edge compute (Functions), file storage (R2), entitlement storage (KV), DNS and CDN. | Request logs including IP address; the stored entitlement records and your email address as stored by us. |
| Email provider Name your email host |
Sending and receiving support correspondence. | Your email address and the content of your messages. |
| Video platform e.g. YouTube / Vimeo / Cloudflare Stream |
Serving embedded training videos. | Your IP address and player interactions, once a video loads. |
We may also disclose data where we are legally required to, or where necessary to establish or defend legal claims. If the business is ever sold or transferred, purchase records may transfer with it; you would be told before that happened.
8. International transfers
Stripe and Cloudflare are United States companies operating global infrastructure, so your data may be processed outside your own country, including in the United States. Both provide contractual safeguards for international transfers — Standard Contractual Clauses and, where applicable, the EU–US and UK–US Data Privacy Framework. We rely on those safeguards.
9. How long we keep it
Purchase, invoice, and tax records are kept for seven (7) years after the transaction, because tax law requires it. Entitlement records are kept for as long as the entitlement lasts — indefinitely for a one-time purchase, so that you never lose access to something you bought outright. Support correspondence is kept for two (2) years. Cloudflare’s request logs are retained for approximately 30 days. Anything held only in your own browser stays there until you clear it.
10. Security
Purchased files are never served from a public URL. They are stored in a private Cloudflare R2 bucket with no public access, and every request passes through a server-side endpoint that re-checks your entitlement before a single byte is streamed. Book preview limits are enforced on the server, not in the page.
Your access cookie is signed with HMAC-SHA256 and is HttpOnly and Secure, so it cannot be read by scripts or tampered with. Incoming payment webhooks are verified against a shared secret with a replay window, so a forged “payment succeeded” message is rejected. All traffic is served over HTTPS with HSTS, and the site sets a restrictive Content Security Policy.
No system is perfect. If we ever suffer a breach that is likely to result in a risk to your rights, we will notify the relevant supervisory authority within 72 hours where required, and tell affected people without undue delay.
Found a vulnerability? Please tell us privately at [email protected] before disclosing it publicly. We will not pursue good-faith security research.
11. Your rights
Depending on where you live, you have some or all of the following rights:
- Access — a copy of the personal data we hold about you.
- Rectification — correction of anything inaccurate.
- Erasure — deletion, except where we must keep records for tax or legal reasons.
- Restriction and objection — including objecting to processing based on legitimate interests.
- Portability — your data in a machine-readable format.
- Withdraw consent — where processing is based on consent.
- Non-discrimination — exercising a right will never degrade your access to what you bought.
To exercise any of these, email [email protected] from the address you used at checkout. We will respond within 30 days and will not charge you for a reasonable request. Note that deleting your purchase record also deletes your entitlements, which means losing access to what you bought — we will confirm that you understand this before acting.
If you are unhappy with how we have handled your data you may complain to your local supervisory authority. In the UK that is the Information Commissioner’s Office (ico.org.uk); in the EU it is your national data protection authority.
12. Children
This site is not directed at children and we do not knowingly collect data from anyone under 16. Some fiction published here may be intended for adult readers; age guidance appears on the relevant product page. If you believe a child has given us personal data, contact us and we will delete it.
13. Changes to this policy
We will update this page when our practices change, and revise the “Last updated” date. If a change is material — a new processor, a new category of data, a new purpose — we will post a notice on the site and email active subscribers.
14. Contact
Email: [email protected]
Controller: Your Legal Name or Company
Address: Full postal address
Data Protection Officer / EU-UK representative, if you are required to appoint one
See also: Terms of Service · Refund Policy · License