Privacy Policy

← Back to Stoolio
Legal Document

Privacy Policy

We take your privacy seriously. This page explains clearly what data we collect, why we collect it, and the full control you have over it.

📅 Effective: January 1, 2025 ✅ Applies Worldwide 🌍 GDPR Aligned
🌿
We don't sell your data. We never will.
Stoolio is a digital preset store. We collect only what's necessary to deliver your order and improve your experience. Your personal information is never sold, rented, or shared with advertisers — ever.
👤
Section 01
Who We Are

Stoolio ("we", "our", "us") is a digital creative studio producing and selling professional Lightroom presets through our website at stoolio.com. We are the data controller responsible for your personal information when you visit our site or purchase our products.

For all privacy matters: [email protected]

📊
Section 02
Data We Collect

We collect only what is genuinely necessary. Nothing more.

You give us directly:

  • Account registration: Name, email address, encrypted password
  • Purchase: Name, email, billing country. Payment card data is handled entirely by Stripe — we never see it
  • Support messages: Any information you share when contacting our team
  • Newsletter: Email address, only if you choose to subscribe

Collected automatically:

  • Technical data: IP address, browser type, device type, operating system
  • Usage data: Pages visited, time on site, clicks, referral source
  • Transaction data: Order IDs, amounts, timestamps — for fulfilment and support only
⚠️We never purchase or obtain personal data from third-party data brokers or marketing lists. Every piece of data we hold was provided by you or generated through your own interaction with stoolio.com.
🎯
Section 03
How We Use Your Data
PurposeData UsedLegal Basis
Processing & delivering your orderName, email, order detailsContract performance
Sending download link & confirmationEmail, order detailsContract performance
Customer supportName, email, order historyContract performance
Account & download historyAccount data, purchase recordsContract performance
Marketing emails (new presets, offers)Email addressYour explicit consent
Website improvementAnonymised usage dataLegitimate interest
Fraud prevention & securityIP, transaction dataLegitimate interest
Legal & accounting complianceTransaction recordsLegal obligation
✉️
We will only ever send you marketing emails if you have actively opted in. You can unsubscribe at any time from any email we send — instantly, no questions asked.
🤝
Section 04
Who We Share Your Data With

We do not sell your data to anyone. We work with the following trusted service providers who process data strictly on our behalf:

  • Stripe Inc. — Secure payment processing. They handle card data under their own privacy policy. We receive only a transaction reference.
  • Web hosting providers — Store our website and your account data on secure servers under data processing agreements.
  • Email service providers — Used to send order confirmations, download links, and (with consent) marketing emails.
  • Google Analytics — Receives anonymised, aggregated usage data only. No personally identifiable data is shared.
  • Legal authorities — Only when required by law, court order, or to protect safety and rights.
🍪
Section 05
Cookies
TypePurposeOptional?
EssentialLogin sessions, shopping cart, Stripe checkout securityNo — required
AnalyticsAnonymised traffic data via Google AnalyticsYes — opt out via banner
PreferencesRemembering language or display preferencesYes — opt out
MarketingAd conversion tracking — only with your explicit consentYes — opt out

On your first visit, our cookie banner will let you choose. You can change preferences at any time through the banner or your browser settings.

🔒
Section 06
How We Protect Your Data
  • SSL/TLS encryption: All data between your browser and our site is encrypted via HTTPS
  • PCI-DSS payment security: All card processing is handled by Stripe at PCI-DSS Level 1 — we never handle card details
  • Password hashing: Account passwords are stored using one-way cryptographic hashing (bcrypt)
  • Access controls: Customer data is accessible only by authorised personnel on a need-to-know basis
  • Regular reviews: We periodically review security practices and hosting infrastructure

If a data breach occurs that may affect your rights, we will notify you and relevant authorities as required by applicable law.

Section 07
How Long We Keep Your Data
  • Account data — Retained while your account is active. Deleted within 30 days of account closure, except where legally required
  • Transaction records — Retained for 7 years (legal/accounting obligation)
  • Download records — Retained while your account is active to allow re-downloading
  • Support communications — Up to 3 years from last interaction
  • Marketing opt-in — Until you unsubscribe; opt-out records kept indefinitely to prevent accidental re-contact
  • Analytics data — Anonymised; session data maximum 26 months
⚖️
Section 08
Your Rights
  • Access: Request a copy of the personal data we hold about you at any time
  • Rectification: Ask us to correct any inaccurate or incomplete data
  • Erasure: Request deletion of your personal data (subject to legal retention obligations)
  • Restrict Processing: Ask us to temporarily stop processing your data in certain circumstances
  • Data Portability: Receive your data in a structured, machine-readable format
  • Object: Object to marketing or processing based on legitimate interests
  • Withdraw Consent: Withdraw consent for marketing at any time with no penalty
  • Complain: Lodge a complaint with your local data protection supervisory authority
📧
To exercise any right, email [email protected]. We respond within 30 days. No charge, no penalty for asking.
🌐
Section 09
International Data Transfers

Some service providers (such as Stripe and Google Analytics) may process your data outside your country, including in the United States. Where this occurs, we ensure adequate protections via Standard Contractual Clauses, adequacy decisions, or the UK International Data Transfer Agreement (IDTA) as applicable.

Contact us at [email protected] for more details on international transfer safeguards.

👶
Section 10
Children's Privacy

Stoolio is intended for adults and is not directed at anyone under 16 years of age. We do not knowingly collect personal data from children. If you believe a child has provided us with their information, please contact [email protected] immediately and we will delete it promptly.

🔄
Section 11
Policy Updates

We may update this policy as our practices or legal requirements change. When we do, we will update the "Effective" date at the top of this page and notify registered customers by email where appropriate. Your continued use of our site after any update constitutes acceptance of the revised policy.

📬
Section 12
Contact
  • Email: [email protected]
  • Response time: Within 5 business days for general queries; 30 days for formal data subject requests
  • Supervisory authority: If unsatisfied with our response, you have the right to contact your local data protection authority

Privacy Question?

We read every message and will get back to you within 5 business days.

© 2025 Stoolio. All rights reserved.

Scroll to Top