Privacy policy
Last updated: 23 February 2026
1. Who we are (data controller)
Folio Press (“Folio”, “we”, “us”) publishes and sells digital ebooks at folio.llc. For the purposes of the EU General Data Protection Regulation (GDPR) and the UK GDPR, we are the data controller of the personal data described below.
Questions or requests about your data can be sent to privacy@folio.llc.
2. What we collect and why
We only collect what we need to run the store, deliver your books, and improve the reading experience.
| Category | What it is | Why we process it | Lawful basis |
|---|---|---|---|
| Account data | Email, hashed password, display name | To sign you in and secure your library | Contract (Art. 6(1)(b)) |
| Purchase data | Order ID, book(s) purchased, amount, currency, timestamps | To fulfil orders, provide receipts, comply with tax law | Contract + Legal obligation (Art. 6(1)(b), (c)) |
| Payment metadata | Stripe/PayPal session IDs and last-4 card digits (we never see the full card) | To process payments and prevent fraud | Contract (Art. 6(1)(b)) |
| Reading activity | Books opened, reading progress, bookmarks, highlights, streaks | To restore your place across devices and power streaks/milestones | Contract + Legitimate interest (Art. 6(1)(b), (f)) |
| Marketing data | Email address, unsubscribe token | To send Letters from the press when you opt in | Consent (Art. 6(1)(a)) |
| Analytics data | Anonymised page views, device type, referrer, GA client ID | To understand traffic patterns and improve the shop | Consent (Art. 6(1)(a)) — denied by default |
| Support data | Feedback messages you send us | To reply to you and fix bugs | Legitimate interest (Art. 6(1)(f)) |
3. Cookies and similar technologies
All non-essential cookies (analytics, advertising) are blocked by default under Google Consent Mode v2 until you accept them through our Secure Privacy consent banner. You can change your choice at any time via the Cookie preferences link in the footer.
The full inventory of cookies we set (name, provider, purpose, duration) lives on our cookie policy page and is mirrored in the banner's preference centre.
4. Third parties we share data with
We only share personal data with providers that help us run Folio. Each is bound by a data-processing agreement.
- Stripe, Inc. — card payments (USA, adequacy via EU-US Data Privacy Framework).
- PayPal (Europe) S.à r.l. — alternative payments, when enabled (Luxembourg).
- Resend — transactional and marketing emails (USA, DPF).
- Google LLC — Google Analytics 4 (USA, DPF). Consent-gated, IP truncated, no ad-personalisation without opt-in.
- Secure Privacy — cookie consent management (EU).
- MongoDB Atlas — application database hosting (EU region).
We do not sell your personal data. We do not use automated decision-making with legal effect.
5. International transfers
Some processors are based outside the EU/EEA (mainly the USA). Transfers rely on: (i) the EU-US Data Privacy Framework where the recipient is certified, or (ii) the European Commission's Standard Contractual Clauses (SCCs) with supplementary safeguards. Copies of the relevant safeguards are available on request from privacy@folio.llc.
6. How long we keep data
- Account and library — while your account is active. Deleted within 30 days of a deletion request.
- Order records — 7 years, to meet tax and accounting obligations.
- Newsletter — until you unsubscribe. One-click link in every email.
- Analytics — 14 months (default GA4 retention).
- Support messages — 24 months, then anonymised.
7. Your rights under the GDPR
You have the right to:
- Access the personal data we hold about you (Art. 15).
- Rectify inaccurate or incomplete data (Art. 16).
- Erase your data ("right to be forgotten", Art. 17).
- Restrict processing in certain cases (Art. 18).
- Data portability — receive your data in a machine-readable format (Art. 20).
- Object to processing based on legitimate interest (Art. 21).
- Withdraw consent at any time, without affecting past lawful processing (Art. 7(3)).
- Lodge a complaint with your local supervisory authority — for EU/EEA readers, the list is at edpb.europa.eu (Art. 77).
To exercise any of these rights, write to privacy@folio.llc. We respond within 30 days.
8. Security
Passwords are hashed with bcrypt. All traffic is served over HTTPS (TLS 1.2+). Card details are handled by our PCI-DSS-compliant payment processors — they never touch our servers.
9. Children
Folio is not directed at children under 16. We do not knowingly collect data from anyone in that age group. If you believe a child has provided us with personal data, contact us and we will delete it.
10. Changes to this policy
When we materially change this policy, we'll update the “Last updated” date above and, where required, notify you by email or an in-app banner before the change takes effect.