What this site collects, who else sees it, and how to get rid of it. Last updated 13 September 2026.
What owldraft.com collects
If you send a support ticket: your name, your email address, what you write, and your IP address. The IP is used to rate-limit the form and for nothing else.
If you buy something: whatever Lemon Squeezy needs to take the payment and issue an invoice. We see your email address, your licence and your country for tax purposes. We never see a card number.
If you activate a licence: the site address you activated it on, so the licence can count its sites and so that you can move it later.
What it does not collect
There is no advertising pixel on this site, nothing sold to anyone, and no cookie set for a visitor who is not signed in.
Who else sees it
Lemon Squeezy takes the payments and is the merchant of record. Resend delivers our email and therefore sees the address a message goes to. Cloudflare sits in front of the site and sees the requests. Nobody else, and none of them for their own purposes.
Your readers’ data is not ours
This is the part worth reading twice. If you run Owldraft Publisher, your members live in your database, on your server. Their names, email addresses and subscription state never reach us — there is no account with us to make, nothing phones home with a member list, and we could not produce your subscribers if we were asked to. For your readers, you are the data controller and we are not a processor, because we never receive their data at all. The same is true of their payments, which go from them to your Stripe account.
Our own social accounts
We publish to Pinterest, X and Instagram from our own accounts, through their APIs. Our Pinterest app exists for one reason: to post pins that link to what we write here, and to read the statistics Pinterest keeps about those pins — impressions, saves, outbound clicks, and the boards they sit on.
It is not a product and nobody else signs into it. We do not ask any other person to connect a Pinterest account, we have no means of reading anyone else’s account, and no data belonging to a Pinterest user other than ourselves is received, stored or processed by us. The token for our own account is held as an encrypted secret on our own infrastructure, is never passed to a third party, and stops working the moment we revoke it from Pinterest’s settings. The statistics we read are used to decide what to write next; they are not sold, and they are not joined to the support or purchase records above. If we stop using the API we delete the token and the figures we cached from it.
How Pinterest itself handles your data when you use Pinterest is covered by Pinterest’s privacy policy, not by this one.
How long we keep things
Support tickets for two years, so a conversation from last year can be picked back up. Purchase and licence records for as long as tax law requires us to, which is currently seven years.
Getting it back, or getting rid of it
Write to [email protected] and ask. We will send you everything we hold about you, or delete it, within thirty days. The exception is the purchase records tax law requires us to keep.
Security
Found a vulnerability in one of our plugins or themes? Write to [email protected] rather than filing it publicly. We will confirm within two business days and credit you in the release notes unless you would rather we did not.
