Privacy Policy
This policy explains how the platform currently called bitmutt (the "Service") handles personal information. bitmutt is a working name. If the Service is renamed or moves to a new web address, this policy keeps applying under the new name.
It covers the Service's own site, the early access and sign-up pages, and the admin area that site owners use. We do not run advertising, we use no analytics or tracking tools, and we do not sell personal information. For the short version as a list, see how this site handles your data.
1. Who we are
The Service is operated by Nicholas Provost, 406 Marcus Garvey Blvd, Apt 4R, Brooklyn, NY 11216, United States. You can reach us about privacy at legal@bitmutt.com.
2. The two roles we play
For site owners, and people who ask for early access, we decide how personal information is used, and this policy describes that. It covers people who ask for early access, people we invite, and everyone with an admin account on a site.
For visitors and buyers on a site built with the Service, the site's owner decides how personal information is used, and we handle it only on their behalf. If you bought something from such a site, joined its mailing list or sent it a message, that site's own privacy notice applies, and its owner is the right person to ask. Every site has its own page at /legal/data listing what it collects. Section 3 still lists what we hold for site owners, so you can see the whole picture.
3. What we collect
When you ask for early access: your name, your email address, what you tell us you want to build, and a link if you give one. We do not record your IP address with the request.
When we invite you: your email address, the message we wrote to you, a private note for our own records, who sent the invitation, and whether and when it was used. The invitation code itself is never stored, only a one-way fingerprint of it.
When you create a site and use your account:
- your first and last name, your email address, and a scrambled (hashed) copy of your password, never the password itself;
- your site's name and address, and your business's name if you give one;
- if you turn on two-step sign-in, the secret that links your authenticator app, and your recovery codes;
- a security record of sign-ins and failed sign-in attempts, password-reset requests, password resets and sign-outs, with the time, the email address typed and your IP address, and a record of changes to your account;
- a record of which version of our terms was accepted for your site, by whom and when, with the sentence that was shown, and your IP address and browser details where we have them;
- your site's content and settings, its licence dates and the history of who has held its licence;
- a domain you connect to your site, and the results of checking it;
- support requests you send us: your name, email address, your site, what you wrote, and the version of the Service you were using;
- the notices we show in your admin area.
When you connect other services: the identifier and status of your Stripe account, and your Printful key, which we store encrypted. When we create your Stripe account for you, Stripe receives your site's name and your notification email address. Stripe checks your identity itself. We never see the documents you give Stripe, or any card numbers.
From every visitor's browser: the IP address and browser details that every web request carries. We use them to deliver pages and, in memory only, to slow down floods of sign-ins and form posts. We do not keep a log of page visits. An error report about a failed page includes the page's address and the browser's details.
What we hold on behalf of site owners:
- orders: the buyer's email address, phone number if given, delivery name and address, what was bought, and a record that the buyer accepted the store's policies, with the time and, where we have them, the IP address and browser details;
- a copy of each order email sent to the buyer;
- mailing-list sign-ups: the email address and the date;
- contact-form messages: name, email address, subject and message.
4. What we use it for
| Purpose | What we use | Why we are allowed to |
|---|---|---|
| Answering a request for early access, and sending an invitation | Name, email address, what you told us | You asked us to |
| Creating your site and letting you sign in | Account details | To carry out our agreement with you |
| Keeping accounts and the Service safe | Security record, IP addresses, anti-spam checks | Our legitimate interest in preventing abuse |
| Proving which terms were accepted | Acceptance record | Our legitimate interest in being able to show what was agreed |
| Telling you about the Service: licence reminders, changes to terms, security notices | Email address | To carry out our agreement with you |
| Answering support requests | Your request and contact details | To carry out our agreement with you |
| Finding and fixing faults | Error reports | Our legitimate interest in a working service |
| Running a site owner's store, mailing list and contact form | What we hold on their behalf | On the site owner's instructions |
| Meeting legal duties | Whatever the law requires | Legal obligation |
We do not send marketing email. We do not build profiles, and we do not make decisions about people by automated means.
5. Who else handles it
We use a small number of companies to run the Service. Each receives only what it needs.
| Company | What it does for us | What it receives |
|---|---|---|
| Railway | Runs the application, the database and the server logs, in the United States (Virginia) | Everything stored in the Service except uploaded files |
| Cloudflare | Stores uploaded files, runs our domain names, and carries every visit to a site that uses its own domain | Uploaded files; for those visits, the visitor's IP address and browser details |
| Postmark | Sends email | The recipient's address and the content of each email |
| Sentry | Receives error reports, and the reports browsers send when a page tries to load something it shouldn't | Technical details of a fault, including the page's address and the browser's details. Email addresses and sign-in tokens are taken out first |
| GitHub | Holds our private task tracker | A description of a bug or idea you reported, copied by hand. Your email address is never copied, and we check the rest for personal details first |
Site owners also connect their own providers. Stripe takes payments for a store. It receives the buyer's email address, name, phone number and delivery address, and collects the card details itself. Printful makes and ships printed products. It receives the buyer's name, delivery address, email address and phone number, and the artwork. Both act under their own privacy policies and under their agreement with the site owner.
We may also disclose information if the law requires it, to protect someone's safety, to deal with abuse of the Service, or to a company that takes over the Service, which would have to honour this policy.
The Service is operated from the United States, and the companies above may process information there and in other countries.
6. Cookies and browser storage
We use only what the Service needs to work:
| Name | What it is for | How long |
|---|---|---|
| Sign-in cookie | Keeps you signed in. On the Service's own addresses one cookie covers every site, so our staff can help on any site; on a site's own domain it covers only that domain | Until you close the browser, or with "Keep me signed in" until you go 7 days without visiting |
| Two-step cookie | Holds your place between your password and your code | 5 minutes |
| Form-protection cookie | Stops other websites from sending forms in your name | Until you close the browser |
| Theme preference | Remembers light or dark mode, if you switch it | 1 year |
| Cart (browser storage) | Remembers what is in a shopper's cart on that device | Until the order is paid, or the browser's data is cleared |
| Pending order (browser storage) | Lets a store empty the cart once the order is paid | Until that order is paid, or the browser's data is cleared |
| What's New (browser storage, admins only) | Remembers which release notes you have seen | Until the browser's data is cleared |
None of these track you across websites, and we set no advertising or analytics cookies, so a browser's "Do Not Track" setting changes nothing here. A site owner can embed content from other companies, such as a YouTube video or an Instagram post, or show a picture hosted on another website. Those load as soon as the page opens, and those companies may set their own cookies under their own policies.
7. How long we keep it
| Information | Kept for |
|---|---|
| Early access requests | Until you ask us to delete yours, or we no longer need it |
| Invitations | As the record of how a site was made, for as long as the site exists |
| Your account | Until your site is closed and you ask us to delete it |
| Record of accepted terms | For as long as the agreement lasts, and afterwards for as long as we may need to show what was agreed |
| Security record | For as long as we need it to keep accounts safe and settle disputes |
| Support requests | For as long as we need them to support your site, or until you ask us to delete them |
| Notices in the admin area | 90 days after they are closed |
| Error reports and server logs | A short period set by those providers, normally weeks |
| Contact-form messages held for a site owner | 90 days |
| Mailing-list addresses held for a site owner | Until the person unsubscribes, which deletes the address. A record that the privacy notice was shown stays |
| Copies of mailings a site owner sent | 2 years |
| Orders and order emails held for a site owner | For as long as the site exists, then as long as tax and dispute rules require |
Nothing deletes early access requests, invitations, accounts, security records, support requests or orders automatically yet. We delete them by hand on request, where the law lets us, and we will update this policy when we set fixed periods.
The database is backed up once a day. Backup copies hold the same information and are replaced on the hosting provider's own cycle, so something deleted from the Service can remain in a backup for a short time.
8. Your choices and rights
You can ask us to:
- tell you what we hold about you, and give you a copy;
- correct it;
- delete it;
- stop using it for a particular purpose, where we rely on our legitimate interests.
Write to legal@bitmutt.com. We answer within 30 days, and we may need to check that you are who you say you are. There are no self-service export or delete buttons yet, so we handle requests by hand. We cannot delete some records while we still need them by law or to settle a dispute. The record of which terms were accepted is one of those.
If your request is about a site built with the Service, such as an order you placed or a list you joined, please ask that site's owner first. If you write to us instead, we pass your request to them. Every mailing-list email has an unsubscribe link that works at once and deletes your address from that list.
We do not sell personal information or share it for advertising, so there is nothing to opt out of. We will not treat you differently for using any of these rights.
If you are in the European Economic Area, the United Kingdom or Switzerland, you also have the right to complain to your local data protection authority. When information about you is transferred to the United States, we rely on the safeguards the law provides for such transfers, including standard contractual clauses with our providers where they apply.
9. Security
Traffic to and from the Service is encrypted. Passwords are stored only in scrambled form, and repeated failed sign-ins are slowed down. Two-step sign-in is available to every admin. Keys for connected services are stored encrypted. Access by our own staff to a site's admin area is recorded.
No service can promise perfect security, and the Service is in Early Access. If a breach affects your information, we will tell you, and the authorities where the law requires it, without undue delay.
10. Children
Accounts are for adults. We do not knowingly collect information from anyone under 18 as an account holder, or from children under 13 in any way. If you think a child has given us information, write to us and we will delete it.
11. Changes to this policy
Each version of this policy has a number and a date, shown at the top of the page, and earlier versions stay readable here. When we publish a change that takes effect later, the page shows both the current and the coming version until then. If a change affects how we use information we already hold, we tell site admins by email and in the admin area before it takes effect. A new name or web address for the Service is not a change to how we handle information.
12. Contact
Nicholas Provost, 406 Marcus Garvey Blvd, Apt 4R, Brooklyn, NY 11216, United States. legal@bitmutt.com