Privacy policy
Link (Stripe) is the merchant of record for the transaction: it takes the payment, charges VAT, sends the receipt and handles payment matters. Below are the details of the service operator, who prepares and delivers the package and controls the data processed by the service.
Service operator and data controller
- Full name
- Maciej Płonka
- Address
- ul. Jasna 14a, 44-122 Gliwice, Polska
- hello@connecttables.com
1. Controller
The controller of data processed by the service is the operator named above. For personal data matters, write to the e-mail address given.
Purposes and legal grounds: order fulfilment and repeat access — GDPR Article 6(1)(b); tax and statutory records — Article 6(1)(c); security, abuse prevention and legal claims — Article 6(1)(f), the controller's legitimate interests. Necessary purchase data is required to perform the contract. Accepting the terms or reading this policy is not blanket consent to data processing.
2. What we process
Order data: order reference, amount, currency, site language, payment status and access dates.
Project content: event title, names entered in the creator, chosen and custom prompts and print settings — only to generate and re-deliver the package.
Technical data includes a session identifier, recovery-code hash and security-related connection data. The server stores only the hash; the code itself may be kept locally in your browser and downloaded access file.
3. Your project before purchase
Until you place an order, the draft project is stored only in your browser and never reaches our server.
4. Recipients
Link (Stripe), as merchant of record, processes the details given at checkout (such as e-mail, name, country and payment details) under its own privacy policy. The service receives the payment status and amount from Stripe, never card details.
The hosting and bot-protection provider (Cloudflare, including Turnstile) processes technical connection data.
Cloudflare (hosting and bot protection) and Link/Stripe (payments) may process data in the USA. Transfers rely on the European Commission's adequacy decision (EU–US Data Privacy Framework) or standard contractual clauses. E-mail correspondence is handled by Zoho Mail in an EU data centre.
5. Retention
Project content (including names) is kept for the 30 days of access after payment and deleted within a day after access ends; unpaid projects after 7 days unless a payment is in progress. Sessions expire after 7 days and the recovery-code hash is removed when access ends. Hashed IP addresses used for rate limits are deleted within 24 hours. The order record (reference, amount, currency, language, statuses, dates, accepted document versions) is kept for 6 years from purchase for complaints and legal claims. We do not store the buyer's name or e-mail address — Link (Stripe) holds them. You can delete the local project in your browser.
6. Cookies
The service sets one strictly necessary session cookie (HttpOnly) that links your browser to the order; it does not require consent. IndexedDB stores the local project and sessionStorage holds recovery and checkout-operation data — only in your browser. We use no advertising or analytics cookies. Cloudflare Turnstile verification runs in a frame from challenges.cloudflare.com and processes technical browser data to prevent bots. The payment page checkout.stripe.com is governed by Link (Stripe).
7. Your rights
Where applicable under the GDPR, you may request access, rectification, erasure, restriction and portability, and object to processing based on legitimate interests. You may complain to the President of the Polish Personal Data Protection Office (UODO). Erasure does not cover records we must still keep by law.
Document version: 2026-10-06