Privacy Policy
Last updated: April 2025
1. Who We Are
The Pawfect Escape is the data controller responsible for your personal information. We are committed to protecting your privacy and handling your data in a transparent, fair, and lawful manner in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
If you have any questions about this policy or how we handle your data, please contact us at hello@thepawfectescapes.com
2. What Data We Collect
We may collect the following personal information:
- Email address — collected when you request a free taster pack or make a purchase, used to deliver your digital products.
- Payment information — handled entirely by Stripe. We never see or store your card details. Stripe may collect your name, billing address, and payment card details in accordance with their own privacy policy.
- Download activity — we store a record of download tokens associated with your email and purchase to prevent unauthorised sharing of your unique download link.
- Analytics data — if you have cookies enabled, we collect anonymised usage data via Google Analytics 4 (GA4), including pages visited, session duration, and device type. This data does not personally identify you.
3. How We Use Your Data
We use your data for the following purposes:
- To fulfil your order by sending your download link and/or Canva template link to your email address.
- To prevent fraudulent use or unauthorised sharing of purchased content.
- To respond to any support or customer service queries you send us.
- To understand how our website is used and to improve the experience for all visitors (via anonymised analytics).
We will never sell your personal data to third parties or use it for unsolicited marketing without your explicit consent.
4. Legal Basis for Processing
We process your personal data under the following lawful bases:
- Contract performance — processing your email and order details is necessary to deliver the digital product you have purchased.
- Legitimate interests — storing token/usage data to protect the integrity of our products and prevent unauthorised access.
- Consent — for analytics cookies, which you may accept or decline via our cookie notice.
5. Third-Party Services
We use the following trusted third-party services to operate our website:
- Stripe — payment processing. Your payment data is handled securely by Stripe and governed by their Privacy Policy.
- Resend — transactional email delivery. Your email address is shared with Resend solely to send you your product download link. See their Privacy Policy.
- Google Analytics 4 (GA4) — website analytics. GA4 uses cookies to collect anonymised data about how visitors use our site. Data may be transferred to and stored by Google. See Google's Privacy Policy.
6. Cookies
Our website uses cookies — small text files stored on your device — for the following purposes:
| Cookie | Purpose | Type |
|---|---|---|
| _ga, _ga_* | Google Analytics — measures site usage | Analytics |
You can control or disable cookies through your browser settings at any time. Please note that disabling cookies may affect the functionality of some parts of our website.
7. Data Retention
We retain your email address and associated download token records for up to 2 years following your purchase, to allow for customer support and to protect against misuse. After this period your data is securely deleted.
Anonymised analytics data held by Google Analytics is retained in accordance with Google's data retention settings (typically 14 months).
8. Your Rights
Under UK GDPR, you have the right to:
- Access the personal data we hold about you.
- Rectify any inaccurate personal data.
- Erase your personal data (right to be forgotten), where applicable.
- Restrict or object to processing in certain circumstances.
- Data portability — receive a copy of your data in a structured format.
- Withdraw consent at any time where processing is based on consent.
To exercise any of these rights, please contact us at hello@thepawfectescapes.com. We will respond within 30 days.
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) if you believe your data has been mishandled.
9. Data Security
We take appropriate technical and organisational measures to protect your personal data from unauthorised access, loss, or disclosure. Download links are unique, tokenised, and rate-limited. Payment data is never stored on our servers.
10. Changes to This Policy
We may update this Privacy Policy from time to time. Any changes will be published on this page with an updated date. We encourage you to review this page periodically. Your continued use of our website after changes are posted constitutes your acceptance of the updated policy.