Privacy Policy
Effective date: June 10, 2026 · Version 2.0 · Covers GDPR (EU), UK GDPR, CCPA / CPRA (California), and similar US state laws.
★ At a glance
- All editing happens in your browser. Your photos, PSDs, ORAs, and templates never leave your computer.
- We do not sell or share personal information. No data broker relationships and no cross-context behavioural advertising.
- No third-party analytics or ads. We use no Google Analytics, no advertising cookies, and no cookie consent banner — only strictly necessary, first-party storage.
- License key stays local. The 16-character key lives only in your browser's localStorage and in the file you download.
- We never collect images, biometric data, geolocation, health data, or government IDs.
1. Who we are
PhotoEditRocket is an independent app run by a solo developer in the United States, and we decide how your data is handled (the “data controller”). Questions? Email support@photoeditrocket.com. EU/UK residents can use the subject line “GDPR request”; we reply within 30 days.
2. What we collect and why
We keep this to a minimum. We never collect your images, PSDs, templates, biometrics, location, health data, or IDs — all your editing stays in your browser.
- Your email & payment info — only when you buy, to deliver your license and handle refunds. Payment goes through Stripe; we never see your full card number.
- Aggregate page views — a simple counter (page URL + time) with no cookies and nothing that identifies you.
- Support messages — if you email us, we keep your message to reply and follow up.
- Basic security logs — our host may briefly log IP + browser type to keep the site safe.
3. Cookies
We use only the storage needed to run the site — no ads, no Google Analytics, no tracking, and no consent banner. Full details are on the Cookies page. Stripe sets its own security cookies on its checkout page.
4. Who we share data with
- Stripe — to take payment (stripe.com/privacy).
- CounterAPI — the cookieless page-view counter (URL + time only).
- Our web host — serves the site and keeps short security logs.
We do not sell or share your personal information for advertising, and we honor the Global Privacy Control browser signal.
5. International transfers
We operate from the United States, so your data is processed there. For EU, UK, and Swiss users we rely on the Data Privacy Framework and Standard Contractual Clauses where required.
6. How long we keep it
- Purchase records: 7 years (tax rules).
- Support emails: up to 24 months, then deleted.
- Visit counter: a running total only — no per-visit records.
- Server logs: up to 30 days.
7. Your rights
Wherever you live, you can ask us to show, correct, or delete your data, and opt out of any sale or sharing (we do neither). EU/UK/Swiss users also have full GDPR rights — access, erasure, portability, objection, and the right to complain to your data-protection authority. Just email support@photoeditrocket.com. Your first request each year is free, and we may verify your identity first.
8. Children
PhotoEditRocket isn’t for children under 16, and we don’t knowingly collect their data. If a child has sent us data, email us and we’ll delete it.
9. Security
We use HTTPS everywhere, a strict content-security policy, and tokenised payments through Stripe. If a data breach ever affects you, we’ll notify you promptly, as the law requires.
10. Changes
If we change this policy, we’ll update the date above and, for big changes, post a notice on the homepage for at least 14 days.
11. Contact
Email support@photoeditrocket.com for anything privacy-related. A postal address is available on request to people exercising legal rights.