Legal
Privacy Policy
Effective: September 2026.
1. Who we are
This Privacy Policy describes how Primwright (“we,” “us”) handles personal data for the Primwright Book 1 digital storefront and protected online reader (the “Service”).
Contact: support@primwright.com.
2. Data we store and why
We store only what the Service needs to operate your account and license:
| Data | Purpose |
|---|---|
| Account identifier and email address | Identity, sign-in, purchase-to-account linking, transactional email (receipts, account claim, password reset) |
| Entitlement status and license records | Know what you are licensed to read; enforce access |
| Bookmarks and reading progress | Sync your bookmarks and resume position across devices |
| Device and session state | Sign-in sessions, concurrent-session policy, reader authorization |
| Support correspondence | Respond to and follow up on your support requests |
| Administrative audit records | Log administrative actions (e.g., manual grant/revoke with reason) for accountability and reconciliation |
3. Data we do NOT hold: payment information
Payment is processed by Paddle (Paddle.com, Inc.) as the merchant of record. Paddle holds your payment credentials and payment/tax records; we never receive, collect, or store your card number or payment credentials. Financial transaction state is authoritative in Paddle; our system keeps only the minimum transaction identifiers needed for your license, support, reconciliation, and audit.
For how Paddle handles payment data, see Paddle’s own privacy policy.
4. Service providers
When the Service launches, it will run on the following providers, each of which will process the categories of personal data listed. Today only the marketing site (primwright.com) is live, hosted on Netlify; the reader infrastructure below is planned, not yet operational:
- Authentication & database — Supabase: account identifiers, email addresses, session tokens, entitlement and license records, bookmarks, reading progress, device/session state, audit records.
- API hosting — Fly.io: request metadata inherent to serving the API (IP addresses, request logs) for the webhook receiver, entitlements, and reader content delivery.
- Storefront & reader hosting — Netlify: standard web-hosting request data (IP addresses, request logs) for the marketing site and reader application.
- Transactional email — Resend: email addresses and message metadata needed to deliver receipts, account-claim, and password-reset emails.
- DNS & support email routing — Cloudflare: DNS query data; support emails addressed to support@primwright.com are forwarded to our support mailbox.
5. Cookies and similar technology
The Service uses:
- Authentication session cookies/tokens — to keep you signed in and authorize reader access;
- Reader preference storage — e.g., display and reading-position preferences.
We do not run advertising trackers and do not sell personal data. We do not share personal data with third parties for marketing. (Any future analytics beyond aggregate sales would be disclosed here before being introduced.)
6. How long we keep data
- Account and license records are kept for as long as your account exists and as long as needed to support your license, plus a reasonable accounting period thereafter.
- Support correspondence is kept for a reasonable period to maintain a support history.
- Audit records are kept as long as needed for reconciliation and accountability.
When data is no longer needed for these purposes, it is deleted or anonymized.
7. Your rights
Subject to applicable law, you may request:
- Access — a copy of the personal data we hold about you;
- Correction — correction of inaccurate data;
- Deletion — deletion of your account and associated personal data (financial records remain with Paddle and are subject to Paddle’s retention). Deleting your account ends your Book 1 license; a deleted account cannot access the reader.
- Portability — your data in a commonly used format where technically feasible.
Submit requests to support@primwright.com.
8. Data security
We apply reasonable technical and organizational measures: server-side entitlement checks on every content request, signed/expiring content URLs, per-user watermarking, encrypted connections in transit, and audit-logged administrative access. No system is perfectly secure, and we do not claim otherwise.
9. Children
The Service is a general-audience digital product. We do not knowingly collect data from children in a manner requiring parental consent; if you believe a child has provided us data, contact us and we will address it.
10. Changes to this Policy
Material changes will be posted on the storefront with an effective date before they take effect.
11. Contact
Privacy questions and data-rights requests: support@primwright.com.