Template — review before live
Privacy Policy
Last updated: 31 July 2026
1. Controller
DeckBox is the data controller for personal data processed through this site. Contact: hello@deckbox.uk.
2. What we collect
- Account data — your email address and, if you sign in with Google, your name and profile basics from Google.
- Designs — parameters, uploaded artwork, and preview thumbnails you save.
- Order data — what you bought, when, the amount, and for print orders the name and delivery address you give Stripe at checkout.
We do not collect or store card details; payment is handled entirely by Stripe.
3. Why we process it (lawful bases)
- Contract — running your account, storing designs, generating files, fulfilling orders.
- Legal obligation — keeping order and payment records for tax purposes.
- Legitimate interests — securing the service and preventing abuse.
4. Processors and recipients
Data is processed by Supabase (database, authentication, file storage), Stripe (payments and shipping addresses), Cloudflare (hosting and, if enabled, cookieless analytics), and Google (only if you choose Google sign-in). We do not sell personal data.
5. Retention
Account data, designs, and uploads are kept while your account exists and deleted when you delete your account. Order and payment records are kept for 6 years to meet UK tax requirements, even after account deletion.
6. Your rights
Under UK GDPR you can access, correct, export, restrict, object to processing of, or erase your personal data. The Delete account button on your Profile page erases your account, designs, and uploads immediately. For anything else, email hello@deckbox.uk. You may also complain to the ICO (ico.org.uk).
7. Cookies
DeckBox uses essential cookies only: your Supabase session (to keep you signed in) and Stripe's checkout cookies (to process payment). We use no advertising or cross-site tracking cookies, which is why there is no cookie banner. If analytics are enabled they are Cloudflare Web Analytics, which is cookieless.
8. International transfers
Our processors may store data outside the UK; where they do, transfers are covered by UK-approved safeguards (adequacy or standard contractual clauses) in each processor's terms.