TinyToolKits legal document
Privacy Policy
1. Controller
The data controller for this website and TinyToolKits products is:
| Controller | [INSERT LEGAL SELLER NAME] |
|---|---|
| Trading name | TinyToolKits |
| Registered address | [INSERT REGISTERED ADDRESS] |
| [INSERT CONTACT EMAIL] |
Replace the placeholders before publishing.
2. Personal data we collect
Depending on how you use the website, we may collect:
- Contact details: name, email address and messages you send to us.
- Purchase details: product purchased, price, currency, order number, payment status, download/access information and invoice-related information.
- Email-list data: email address, sign-up source, consent records, email opens/clicks where tracked, unsubscribe status and preferences.
- Technical data: IP address, browser/device information, server logs, security logs and basic website usage data.
- Support/refund/withdrawal data: order references, complaint details, correspondence and resolution records.
- Analytics and marketing data: only if analytics, pixels or marketing cookies are enabled.
We do not intentionally collect special-category data such as health diagnosis information, mental health records, political opinions, religious beliefs, biometric data or similar sensitive data. Please do not send sensitive personal information through contact forms or support emails unless genuinely necessary.
3. How we collect data
We collect data when you browse the website, complete a form, download a free resource, subscribe to emails, buy a product, contact support, request a refund/withdrawal, or interact with TinyToolKits on social media.
Payments and digital delivery may be handled by third-party providers such as Payhip, Stripe and PayPal. Email delivery/list management may be handled through LeadsLeap/SendSteed or another email platform. Hosting and email may be provided through Namecheap and Google Workspace.
4. Purposes and lawful bases
| Purpose | Data used | Legal basis |
|---|---|---|
| Process and deliver purchases | Contact, order and delivery data | Performance of a contract |
| Provide free resources and newsletters | Email-list data | Consent, or where legally applicable, soft opt-in/legitimate interest |
| Customer support, refunds and withdrawal requests | Contact, order and correspondence data | Contract, legal obligation and legitimate interests |
| Accounting, tax and compliance | Order, invoice and payment records | Legal obligation |
| Website security and troubleshooting | Technical logs and security data | Legitimate interests |
| Analytics and marketing performance | Usage data, cookies/pixels if enabled | Consent where required; otherwise legitimate interests for low-risk aggregate analytics |
5. Email marketing
If you sign up for a free resource, newsletter or email sequence, we will use your email address to send the requested material and related TinyToolKits updates. You can unsubscribe at any time using the unsubscribe link in emails or by contacting us at [INSERT CONTACT EMAIL].
We do not sell email lists.
6. Cookies and analytics
At launch, this static website should use only strictly necessary technology unless you add analytics, advertising pixels, embedded forms or tracking scripts.
If you add non-essential cookies, tracking pixels, behavioural advertising, retargeting or similar tools, you should implement a clear cookie banner/consent mechanism before those technologies load, and give users a genuine way to refuse or withdraw consent.
Strictly necessary cookies or comparable technologies may be used for security, checkout, delivery or site functionality.
7. Third-party processors and platforms
We may use third-party service providers to operate the business, including:
- Namecheap — domain, hosting and related services.
- Payhip — digital product checkout and delivery.
- Stripe / PayPal — payment processing.
- LeadsLeap / SendSteed — email lists, sign-up forms and email delivery.
- Google Workspace — business email, documents and storage.
- Buffer and Supergrow — social media planning, publishing and analytics.
- AI/automation tools — content operations, workflow automation and internal productivity, where used.
These providers may process personal data under their own contracts, privacy notices and security arrangements. Some may process data outside Hungary or the European Economic Area. Where required, appropriate safeguards should be used, such as adequacy decisions or standard contractual clauses.
8. International transfers
Because online tools and cloud providers may operate globally, your data may be transferred outside Hungary and outside the EEA. Where GDPR requires safeguards for such transfers, we rely on lawful transfer mechanisms provided by the relevant service provider.
9. How long we keep data
We keep personal data only for as long as needed for the purposes described above, unless a longer period is required or permitted by law.
| Data category | Indicative retention period |
|---|---|
| Email marketing data | Until you unsubscribe or withdraw consent, then suppression data may be kept to avoid re-contacting you. |
| Customer support messages | Normally up to 3 years after the last interaction, unless needed for a dispute. |
| Purchase, invoice, accounting and tax records | Normally at least 8 years where Hungarian accounting rules require retention. |
| Technical/security logs | Usually short-term, unless needed to investigate abuse, fraud or security incidents. |
| Withdrawal/refund records | For as long as needed to evidence the request, response and legal position. |
10. Your GDPR rights
Subject to legal conditions, you may have the right to:
- access your personal data;
- correct inaccurate or incomplete data;
- request deletion;
- restrict processing;
- object to processing;
- receive certain data in a portable format;
- withdraw consent where processing is based on consent;
- complain to a data protection authority.
In Hungary, the supervisory authority is the Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH). Website: naih.hu.
11. Security
We use reasonable technical and organisational measures to protect personal data. However, no online service is completely secure, and you are responsible for keeping your own devices, email account and passwords safe.
12. Children
The website and products are intended for adults. We do not knowingly collect personal data from children. If you believe a child has provided personal data, please contact us.
13. Changes to this Privacy Policy
We may update this Privacy Policy as tools, products or legal requirements change. The latest version will be posted on this page.