Privacy policy
Who is responsible
[Controller / legal seller name to be supplied], [Business address to be supplied]. Contact [Support email to be supplied] about your information.
Nursery photos and sign-in
Your browser sends your credentials directly to the nursery provider and holds access tokens in memory. Our payment backend does not receive your nursery password, access token, child names, source media URLs, or photo/video files. The website code processes previews on your device.
Payment and account matching
Your browser derives a deterministic SHA-256 hash from the provider identifier and your normalised nursery login email. It sends that hash to our payment server and Stripe to associate a purchase with the same nursery login across devices. The hash is pseudonymous, not anonymous: someone who knows the input can reproduce it.
Stripe stores the checkout/payment identifiers, configured price, payment mode, and payment status. Stripe processes the checkout email, payment details and receipts under its own privacy policy. We retrieve payment data directly from Stripe to verify purchases and handle refunds/disputes; our application does not maintain a separate payment database or store card details.
Cookies and device storage
The lm_source and lm_payment cookies remember account/payment references for up to one year. IndexedDB and exported progress files record download history until you clear or delete them. Older previews may also have an lm_checkout cookie. Browser storage is specific to a device; signing into the same nursery account restores the purchase, not another device’s download history.
Hosting and support
Netlify processes network information such as IP addresses and request details to deliver and protect the site. Our application logs fixed payment error codes, not private payloads. Payment rate limits use a daily keyed hash of the IP address; counter records expire and are cleaned up during subsequent requests. Support emails contain what you choose to send, including a diagnostic summary if you use the troubleshooting links. Do not send passwords, tokens, or children’s photos.
We do not install advertising trackers, analytics, or session recording. Necessary payment and progress storage supports the service you request.
Purpose and retention
Account matching and payment processing support performance of the purchase contract. Security and troubleshooting support our legitimate interests in running a reliable service. Where applicable, transaction records also support legal accounting obligations.
[Payment and support retention periods, and the deletion process, must be confirmed before launch.] Webhook event identifiers are kept for up to 90 days, with cleanup on subsequent deliveries. Account entitlements are needed to recognise repeat purchases; contact us before requesting their deletion.
Your choices and rights
You can clear local history and delete exported files. Contact us to request access, correction, deletion, or other applicable data rights. Some transaction records may need to be retained by law. You can complain to the UK Information Commissioner’s Office or your local data protection authority.
Stripe, and hosting providers may process data internationally. Before launch, the seller must confirm the applicable processor agreements, transfer safeguards, and retention arrangements.
Provider information: Stripe privacy · Netlify privacy.