Privacy policy

Last updated: September 2026

In short

We collect your email to manage your account and purchases, and we record when a paid product's code is viewed or downloaded so we can support you and decide refunds. We don't store payment details (Stripe handles that) and we never sell your data. The controller is JD, trading as GSAP Vault; contact details are at the end.

Who is responsible for your data

JD, trading as GSAP Vault and based in the United Kingdom, is the controller for the personal data collected through this site. That means we decide what is collected and why, and we are the one to contact about it. Stripe, our payment processor, and the merchant of record for buyers outside the UK, the US, Australia, New Zealand, Switzerland, Liechtenstein, Japan, Singapore, South Africa, Taiwan, Malaysia, Thailand and Iceland, is a separate controller for the payment itself: card details, billing address and tax status go to Stripe and never reach us (Stripe privacy policy).

What we collect

We only collect information necessary to provide our services:

  • Email address: to create your account and send purchase confirmations
  • Password: stored securely (hashed, never in plain text)
  • Purchase history: to provide access to your Library
  • Access records for paid products, meaning when a paid product's source is viewed or its download is served (see below)
  • Marketing preference: whether you ticked the updates box, and when you opted in or out
  • Support messages: whatever you send us by email, kept in our mailbox
  • Server and analytics data: page visited, referrer, browser type and approximate country, from your IP address, which is not stored (see Analytics)

If you sign in with Google, we receive your email address and Google account ID from Google; nothing else from your Google account.

Course progress and completion downloads

Exercise settings, reflections and completed labs are saved only in this browser, whether or not you are signed in. They are not sent to our database or synced across devices. Clearing this site's browser data removes them. On a shared device, other people using the same browser profile may see your work.

Historical course records saved against an account before this change are no longer used by the courses. Until removed, they remain subject to account deletion and our data-protection obligations; backup copies follow the applicable backup retention period.

Your optional completion download is generated on your device. The name you enter is used only for that file; we do not save or receive it. There is no public verification page. The learning workspace does not load site analytics or send lesson-completion events.

What we don't collect

  • Payment card details (handled entirely by Stripe)
  • Billing addresses and tax IDs (handled by Stripe)
  • Phone numbers or physical addresses

How we use your data, and the lawful basis

UK data protection law requires a lawful basis for each use. Ours are:

  • Creating and running your account, delivering purchases, sending receipts, sign-in links and password resets: performance of our contract with you
  • Support replies and refund decisions, including the access records described below: performance of the contract, and our legitimate interest in applying the refund policy fairly
  • Security and fraud prevention: rate limiting, blocking abuse, investigating chargebacks: our legitimate interest in keeping the site and its customers safe
  • Site analytics: our legitimate interest in understanding what is used, with data kept to a minimum and no profiling
  • Marketing email: your consent, given by ticking the box, withdrawable at any time
  • Tax and accounting records of sales: legal obligation, held mainly by Stripe as our payment processor, and the merchant of record for buyers outside the UK, the US, Australia, New Zealand, Switzerland, Liechtenstein, Japan, Singapore, South Africa, Taiwan, Malaysia, Thailand and Iceland

We don't send marketing emails unless you tick a box asking for them. Creating an account or buying something never adds you to a list on its own.

Mailing list

When you create an account there is an unticked box asking whether we may email you about new effects, templates and offers. Tick it and we record that request with the date. It only takes effect once you confirm your email address from the account confirmation link, so the address is verified before we send anything: one email, and it doubles as the account confirmation you would receive anyway. Signed in with Google? Your address is already verified, so the choice on your email preferences page applies straight away.

The cart has the same unticked box when you buy. Tick it and we record the request with the date against the account your purchase goes to; leave it and nothing changes.

You can change your mind at any time on that page, and every update email carries an unsubscribe link. Withdrawing takes effect immediately; we keep the date you opted in and the date you opted out as the record of consent. We use Resend to deliver these emails (Resend Privacy Policy). Account emails, such as sign-in links, receipts and password resets, are not marketing and are sent regardless.

Who we share data with

We share personal data only with the services that run the site, each under its own contract and privacy terms:

  • Stripe: our payment processor, and the merchant of record for buyers outside the UK, the US, Australia, New Zealand, Switzerland, Liechtenstein, Japan, Singapore, South Africa, Taiwan, Malaysia, Thailand and Iceland, for payment, receipts, tax and refunds (Stripe privacy policy)
  • Supabase: database and authentication, hosted in Stockholm, Sweden (Supabase privacy policy)
  • Our own server in Finland, which runs the site and the self-hosted analytics
  • Cloudflare: content delivery, caching and protection against attacks, which means it sees requests in transit (Cloudflare privacy policy)
  • Resend: sends account emails and, only if you opt in, update emails (Resend privacy policy)
  • Google: only if you choose to sign in with Google
  • Umami Cloud: a hosted analytics account receives the same cookieless data as our own server while we finish moving away from it (Umami privacy policy)

We may also disclose data to professional advisers such as an accountant, or to authorities where the law requires it or to protect someone's rights or safety. We never sell, rent or trade personal data.

Where your data is processed

Your account data lives in the EEA: the database in Sweden and the site itself in Finland. The UK recognises the EEA as providing adequate protection, so those transfers need no further safeguard. Resend, Cloudflare and Umami Cloud are US companies and may process data in the United States; those transfers rely on the UK Extension to the EU-US Data Privacy Framework where the provider is certified, and otherwise on the International Data Transfer Agreement or standard contractual clauses with the UK addendum. Stripe processes payment data under its own safeguards as our payment processor, and the merchant of record for buyers outside the UK, the US, Australia, New Zealand, Switzerland, Liechtenstein, Japan, Singapore, South Africa, Taiwan, Malaysia, Thailand and Iceland.

Cookies and browser storage

  • Session cookies: to keep you logged in
  • Offer cookies: to remember an offer you choose to unlock and apply it at checkout. Discovery rewards are remembered in that browser for up to seven days.

Our analytics sets no cookies at all. We don't use advertising or tracking cookies, so there is no cookie banner and nothing to opt out of: the two cookies above are strictly necessary. Course progress is kept in your browser's local storage until you clear this site's browser data. Your cart is also kept in your browser's local storage, not on our servers. You can clear all of it from your browser's settings at any time; doing so signs you out.

Analytics

We use Umami to understand how the site is used: which pages get visited, where visitors come from, roughly where in the world they are, and how quickly pages load for them. It is cookieless and we never use it to build a profile of you or to identify you personally. Your IP address is used only to work out an approximate country and to count you as one visitor rather than several; it isn't stored alongside your browsing.

We don't record your screen, your mouse movements, or what you type. If you'd rather not be counted at all, contact us at the email below.

Access records for paid products

When you view the full source of a paid product, or when we serve you its download, we record that it happened. The record holds your account ID (or, straight after checkout, your Stripe order ID), which product it was, whether it was a source view or a download, and the time. No IP address is stored. Free products and public demo pages are not logged.

We use these records for two things: helping you with support questions about your own purchases, and deciding refund requests fairly, particularly for passes and the Vault, where the amount of the collection accessed helps us assess fair use. Viewing or downloading an individual product does not by itself prevent a refund. They are not used for advertising, profiling or analytics, and they are never sold or shared.

The lawful basis is performance of our contract with you (delivering and supporting what you bought) and our legitimate interests in preventing abuse of the refund policy. Records are kept for 24 months and then deleted. You can ask us for a copy of yours at the email below.

How long we keep it

  • Account, purchases and marketing preference: for as long as your account exists. Deleting your account deletes them.
  • Access records for paid products: 24 months, then deleted.
  • Support emails: up to 24 months after the last message, so we can follow up on a purchase or refund.
  • Analytics: aggregated, with no identifier, and kept indefinitely in that form.
  • Sales records: Stripe keeps transaction records for as long as tax law requires, typically six years, independently of your account.

When data is no longer needed for these purposes it is deleted or anonymised.

Data security

All data is transmitted over HTTPS, passwords are hashed and never stored in plain text, database access is restricted to the application and to us, and secrets are held outside the code. No system is perfectly secure, so if you believe your account has been compromised, contact us and change your password.

Your rights

Under the UK GDPR you can ask us to:

  • access the personal data we hold about you, and receive a copy
  • correct anything inaccurate
  • erase your data: you can delete your account yourself from your Library, which removes it immediately
  • restrict or object to processing that relies on our legitimate interests
  • port your data to you in a machine-readable form
  • withdraw consent to marketing at any time on your email preferences page or via the link in any update email

Email us at the address below and we will respond within one month, extendable where the law allows for complex requests, and we may ask you to confirm you own the account first. If you are unhappy with how we handle your data you can complain to the Information Commissioner's Office at ico.org.uk, though we would rather hear from you first.

We don't sell your data

We will never sell, rent, or trade your personal information to third parties.

Changes

We may update this policy from time to time. Changes will be posted on this page.

Contact

Privacy questions and rights requests go to JD, trading as GSAP Vault, at . The postal address is available on request and appears on Stripe's receipts.

Your cart

Your cart is empty

The Vault £99

The Vault library, plus future additions to the library.