Privacy
Last updated: 24 September 2026
The short version: no tracking cookies, no advertising trackers, no profiling, and no way for us to work out who you are unless you tell us.
Who is responsible
Hobrecker Webdesign, KVK 42134492, [email protected], is the controller for the data described here.
Cookies
No tracking cookies, and no cookies at all unless you create an account. If you sign in we set one: it holds a random session identifier so the site knows it is still you on the next page. It contains nothing else, it is not readable by scripts, and it is not shared with anyone. Signing out deletes it, here and on our server.
That single cookie is what the ePrivacy rules call strictly necessary — the sign-in cannot work without it — which is why you are not asked to agree to anything. Browse without an account and no cookie is ever set.
How we count visits
We record which pages are opened and which steps are taken, so we know whether the tool is understandable. To tie those steps into one visit we store a hash of your IP address and browser, salted with a random value generated fresh every day and deleted two days later. Once that salt is gone the hash cannot be turned back into an address, and the same person hashes to something unrelated the next day. Our analytics therefore hold no IP addresses.
The web server keeps ordinary access logs, and those do contain IP addresses. They are kept for 14 days, are used only to find faults and to deal with abuse, and are never combined with the analytics above. Legal basis: legitimate interest in knowing whether our own product works, and in keeping the server standing up.
What you type into the tool
Box dimensions and settings stay in your browser. They only reach us if you buy a file, in which case the configuration is stored with the order so the file can be regenerated, or if you attach them to a feedback message.
Accounts
If you create one we store your email address, a hash of your password — never the password itself — the date you signed up, whether that address has been confirmed, and your credit balance with the history behind it. Legal basis: performance of the contract. Ask us and the account and everything not legally required to keep goes with it; the invoices have to stay seven years, and nothing else does.
Payments
Payments run through Stripe Payments Europe. Card details go to Stripe and never reach us; we receive a payment reference and a status. Stripe processes some personal data as a controller in its own right, under its own privacy policy.
Who else touches your data
- Cloudflare carries the connection between you and our server and protects it from attack. It therefore sees your IP address and the requests you make. Cloudflare acts as our processor under an agreement that covers EU transfers.
- Stripe, for payments, as described above.
- Resend, which delivers our email — your file, your invoice, a password reset. It therefore handles your address and the contents of those messages. Delivery runs through Amazon SES in the EU (Ireland).
Nobody else. No analytics company, no advertising network, no social plug-ins, no AI provider, and nothing is ever sold.
Email addresses
Optional at checkout, used to send you your file, your invoice and nothing else. Optional in the feedback form, used only to reply to you. Never sold, never used for marketing you did not ask for.
Feedback
Messages you send are stored and forwarded to the person who builds this, and nobody else reads them. They are not sent to any outside service, and no language model sees them. If you left an email address it travels with the message so a reply is possible.
How long we keep things
Orders and invoices for seven years, because Dutch tax law requires it. Analytics events for 14 months. Daily salts for 48 hours. Sign-in sessions for 30 days, or until you sign out. Server logs for 14 days. Feedback for 12 months after it has been dealt with. Password reset links for one hour.
A nightly job enforces these, so this is what happens and not what we intend to do.
Your rights
You can ask for a copy of what we hold about you, ask for it to be corrected or deleted, ask for it in a portable form, or object to how it is used. Write to [email protected]; you will get an answer within a month. You may also complain to the Dutch Data Protection Authority, the Autoriteit Persoonsgegevens.
Where it lives
On our own server in the Netherlands, inside the EU. It is not a rented machine in a data centre and it is not shared with anyone else. Backups are encrypted before they leave it.