Privacy Policy

Last updated: October 5, 2026

This policy explains what personal data Tidypage collects, why, how long we keep it, who we share it with, and the rights you have. We collect as little as we can: only what we need to take your order, build your website and keep the service secure.

In short: we do not sell or share your personal information, we do not use analytics or advertising cookies, and we do not send marketing emails.

Who is responsible for your data

The controller of your personal data is Hoang Films Limited, which operates Tidypage.

  1. Registered address: to be completed: company address
  2. Registration: to be completed: company registration number, to be completed: company jurisdiction
  3. Contact for any privacy question or request: hello@tidypage.app

Representatives in the European Union and the United Kingdom

  1. Our representative in the European Union (Article 27 GDPR): to be completed: eu gdpr representative
  2. Our representative in the United Kingdom (Article 27 UK GDPR): to be completed: uk gdpr representative

You can contact these representatives instead of us, about any question related to the processing of your personal data.

What data we collect

Data you give us

  1. Your email address, collected by Stripe when you pay. It becomes the email address of your Tidypage account.
  2. Your order: the date, the amount, the order status, and the Stripe references of your payment.
  3. Your onboarding questionnaire answers: information about your business and your audience, the pages you want, any texts or information you already have, your colors, the reference sites you like, a link to your logo, and the domain name you want. Some of this may be personal data, for example if you run your business under your own name, or if your texts mention your team.
  4. Your messages to our team through your dashboard, and our replies.
  5. Your approvals and requests: your approval of the texts we write for you, your revision requests, and your small edit requests after launch.
  6. Contact form submissions: your name, your email address and your message, if you write to us through the contact page.
  7. Your agreements: the record that you accepted our Terms of Service and, where applicable, that you asked us to start work during the withdrawal period and acknowledged the consequences (see our Refund Policy), with the date and time.

Data we receive from Stripe

When you pay, Stripe tells us your email address, the payment status and amount, and, where needed to calculate tax, your billing country and address. We never receive or store your full card number. Stripe handles your payment details directly.

Data collected automatically

  1. Essential cookies that keep you signed in, protect forms against forgery, and remember your cookie choice. See our Cookie Policy.
  2. Sign in links: when you ask to sign in, we create a single use link and send it to your email address. We store a secure token for it until it is used or expires.
  3. Technical and security data: your IP address, browser type, and the date and time of requests. We use them to limit abuse (for example too many sign in requests) and to keep server logs.
  4. Audit logs: a record of the actions our team takes in the administration area (for example changing the status of your order or issuing a refund), so that every action on your order can be traced.

We do not use analytics tools, advertising cookies, tracking pixels or fingerprinting. We do not make decisions about you based solely on automated processing, and we do not build profiles of you.

Data about other people

If the content you send us includes personal data about other people (for example the names or photos of your team members), please make sure you have the right to share it. We use it only to build your website.

If you are in the European Economic Area, the United Kingdom or Switzerland, we must have a legal basis for each use of your data.

Purpose Data Legal basis
Taking your order and payment Email, order, Stripe data Performance of our contract with you
Creating your account and signing you in Email, sign in tokens, session cookies Performance of our contract with you
Writing, designing, building, launching and hosting your website, and making small edits after launch Questionnaire answers, messages, approvals and requests Performance of our contract with you
Sending service emails (sign in links, order updates) Email Performance of our contract with you
Answering contact form messages Name, email, message Steps you ask us to take before a contract, or our legitimate interest in answering enquiries
Keeping proof of your agreement to our terms and of your withdrawal request and acknowledgment Agreement records Legal obligation (consumer law), and our legitimate interest in proving what was agreed
Remembering your cookie choice Consent preference cookie Legal obligation (cookie rules)
Keeping accounting and tax records, issuing refunds Order and payment records Legal obligation
Security, abuse prevention, audit logs IP address, technical data, audit logs Our legitimate interest in protecting our service, our customers and our team
Handling disputes and legal claims Relevant records Our legitimate interest in establishing, exercising or defending legal claims

Where we rely on legitimate interests, we have checked that these interests are not overridden by your rights. You can object at any time (see "Your rights").

How long we keep your data

Data How long
Sign in tokens Until used, or 24 hours at most
Session cookies and session records Until you sign out, or 30 days after your last activity
Questionnaire answers, messages, approvals and requests 12 months after the end of your 90 day small edit period (or after your order is cancelled), so we can answer follow up questions, then deleted
Contact form submissions that do not lead to an order 12 months after our last exchange
Order, payment and refund records, agreement records to be completed: accounting retention period after the end of the financial year of the order, as required by accounting and tax law
Account email address As long as you have an active order or we keep order records linked to it, as above
Audit logs 24 months
Server and security logs (including IP addresses) to be completed: server log retention period
Cookie choice 6 months, after which we ask again

When a period ends, we delete the data or make it anonymous. If a dispute is ongoing, we may keep the relevant data until it is resolved.

Who we share your data with

We do not sell your personal data, and we do not share it for advertising. We only disclose it to the service providers we need to run Tidypage. They act on our instructions, under contracts that require them to protect your data.

  1. Stripe (payment processing, receipts, refunds, and tax calculation where enabled). Stripe also acts as an independent controller for some purposes, such as fraud prevention and meeting its own legal obligations. See the Stripe privacy policy at https://stripe.com/privacy.
  2. to be completed: hosting provider (hosting of the Tidypage website and its database), located in to be completed: hosting location.
  3. to be completed: email provider (sending sign in links and service emails), located in to be completed: email provider location.
  4. to be completed: mailbox provider (our mailbox for hello@tidypage.app), located in to be completed: mailbox provider location.

We may also disclose data when the law requires it, to protect our rights in a dispute, or to a company that takes over the Tidypage service (in which case this policy continues to protect your data).

Your website itself, once launched, is hosted by us on to be completed: client site host for its first 12 months. For any personal data your website collects from its own visitors (for example through a contact form, or in server logs), you are the controller and we act only as your processor, on your instructions, under our Data Processing Agreement. Your website needs its own privacy notice, which is your responsibility.

International transfers

Hoang Films Limited is established in to be completed: company jurisdiction. Our team works from to be completed: team locations. Our service providers may process data in the United States and in other countries.

When we transfer personal data from the European Economic Area, the United Kingdom or Switzerland to a country that is not recognised as providing an adequate level of protection, we use appropriate safeguards:

  1. the Standard Contractual Clauses approved by the European Commission;
  2. for data from the United Kingdom, the UK International Data Transfer Addendum to those clauses (or the UK International Data Transfer Agreement);
  3. for data from Switzerland, the same clauses with the adaptations required by Swiss law;
  4. where a provider is certified under the EU US Data Privacy Framework (and its UK and Swiss extensions), that certification.

You can ask us for a copy of the safeguards that apply by writing to hello@tidypage.app.

Your rights

Depending on where you live, you have some or all of the following rights:

  1. Access: get a copy of the personal data we hold about you.
  2. Correction: have inaccurate data corrected or completed.
  3. Deletion: have your data deleted, unless we must keep it (for example accounting records).
  4. Restriction: ask us to pause the use of your data while a question is being resolved.
  5. Portability: receive the data you gave us in a structured, machine readable format, or have it sent to another provider.
  6. Objection: object to our use of your data based on legitimate interests.
  7. Withdraw consent: where we rely on your consent, withdraw it at any time, without affecting what was done before.

How to exercise your rights. Email hello@tidypage.app from the email address linked to your account, or send us a message from your dashboard. To protect your data, we may confirm your request by sending a link to that email address. We answer within one month (EEA, UK and Switzerland) or within 45 days (United States). If a request is complex, we may extend this period as the law allows, and we will tell you why.

Exercising your rights is free, unless a request is clearly unfounded or excessive.

California privacy rights

This section applies to residents of California, under the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA). It also serves as our notice at collection.

We do not sell or share your personal information. We do not sell personal information, and we do not share it for cross context behavioral advertising, as those terms are defined by the CCPA. We have not done so in the past 12 months. We have no actual knowledge of selling or sharing the personal information of consumers under 16.

Categories of personal information we collect

  1. Identifiers: email address, name (if you use the contact form), IP address, account and order references.
  2. Customer records: billing country and address where needed for tax, payment status (card details stay with Stripe).
  3. Commercial information: your order, its status, refunds.
  4. Internet or electronic network activity: technical and security logs, audit logs.
  5. Professional information: information about your business that you give in the questionnaire.
  6. Sensitive personal information: the sign in link we email you is a credential that gives access to your account. We use it only to sign you in and keep your account secure.

We collect this information from you, from Stripe, and automatically from your device, for the purposes described in "Why we use your data". We keep each category for the periods described in "How long we keep your data".

Disclosures for business purposes

In the past 12 months, we have disclosed identifiers, customer records, commercial information and internet activity to our service providers (payment processing, hosting, email delivery), only so they can provide their services to us.

Your California rights

  1. Right to know: the categories and specific pieces of personal information we hold about you, where it comes from, why we use it and who we disclose it to.
  2. Right to delete your personal information, subject to legal exceptions.
  3. Right to correct inaccurate personal information.
  4. Right to opt out of sale or sharing. We do not sell or share personal information, so there is nothing to opt out of. If this ever changes, we will update this policy before doing so and give you a way to opt out. We treat a Global Privacy Control signal from your browser as a valid opt out request.
  5. Right to limit the use of sensitive personal information. We only use sensitive personal information for purposes permitted by the CCPA (providing the service and keeping it secure), so this right does not need to be exercised. You can still contact us with any question.
  6. Right to non discrimination: we will not treat you differently for exercising your rights.

To exercise these rights, email hello@tidypage.app. We will verify your request by sending a confirmation link to the email address linked to your account. You can use an authorized agent; we may ask the agent for written proof of their authorization and ask you to confirm your identity directly. We respond within 45 days, and may extend this by another 45 days when reasonably necessary, in which case we will tell you.

Other US state privacy rights

If you live in a US state with a comprehensive privacy law (such as Colorado, Connecticut, Oregon, Texas, Virginia and others), you may have rights to access, correct, delete and obtain a copy of your personal data, and to opt out of targeted advertising, sale and profiling. We do not engage in targeted advertising, sale or profiling.

To exercise your rights, email hello@tidypage.app. If we decline your request, you can appeal by replying to our decision with the word "Appeal". We will answer your appeal within the time required by your state's law. If you are not satisfied with the outcome, you may contact the Attorney General of your state.

Other countries

If you live in Canada, Australia or another country with privacy laws, you also have the right to access and correct your personal information, and to complain to us and to your privacy regulator (for example the Office of the Privacy Commissioner of Canada, or the Office of the Australian Information Commissioner). We also comply with the data protection law of to be completed: company jurisdiction.

Children

Tidypage is a service for businesses. Orders must be placed by adults. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, contact us and we will delete it.

Security

We protect your data with measures suited to the risk, including:

  1. encrypted connections (HTTPS) on every page;
  2. no passwords: you sign in with single use links that expire;
  3. session cookies that scripts cannot read and that are only sent over secure connections;
  4. access to customer data limited to the team members who need it, with every administration action logged;
  5. limits on repeated requests to prevent abuse;
  6. payment details handled by Stripe, never by us.

No system is perfectly secure. If a breach affects your data, we will inform you and the authorities where the law requires it.

Complaints

If you have a concern, please contact us first at hello@tidypage.app. You also have the right to complain to a data protection authority:

  1. in the European Economic Area, the supervisory authority of the country where you live or work, or where the issue happened;
  2. in the United Kingdom, the Information Commissioner's Office (ico.org.uk);
  3. in Switzerland, the Federal Data Protection and Information Commissioner;
  4. in California, the California Privacy Protection Agency or the California Attorney General.

Changes to this policy

We may update this policy. We show the date of the last update at the top. If a change materially affects how we use your data, we will tell you by email or in your dashboard before it takes effect.