Skip to content
Instant DownloadPrint at Home

Privacy Policy

Last updated: 11 October 2026

This policy explains what personal data we process when you use page4fun.com, why, how long we keep it, and what your rights are. It follows the EU General Data Protection Regulation 2016/679 (GDPR) and the Romanian law that supplements it.

In short: we only collect what we need to deliver your books and run your account. We never see your card details, we use no analytics or advertising, and we never sell your data.

1. Who is responsible

  • Controller: Comanici Lavinia, a private individual based in Constanța, Romania
  • Email for any data question: hello@page4fun.com

We have not appointed a data protection officer (DPO), because the GDPR does not require one for an activity like ours (Art. 37).

2. What we process, why, and on what basis

When you buy a book, with or without an account

  • Data: your email address, your country (from the payment details), the books you bought, the price, any discount applied, the order number and date, and the moment you agreed to immediate download.
  • Why: to complete the order, send you the files and a confirmation by email, and be able to show what you bought and what you agreed to, if ever needed.
  • Basis: performance of the contract (Art. 6(1)(b) GDPR) and our tax and accounting obligations (Art. 6(1)(c)).

When you create an account

  • Data: your email address, your first name (if you give it), the date you created the account, your orders, and a technical fingerprint of each sign-in with its expiry date.
  • Why: so you can sign in without a password, using a link we email you, see the books you bought, and get 10% off your first order.
  • Basis: performance of the contract (Art. 6(1)(b)). The account is optional: you can always buy without one.

We store no passwords, because there are none. Sign-in links and the account cookie are stored only as a cryptographic fingerprint, which cannot be turned back into a working link.

When you subscribe to the newsletter or choose to receive offers by email

  • Data: your email address, your first name (if given), the site language, where you subscribed (the site footer or your account) and the date you agreed.
  • Why: to tell you about new books, free printables and offers.
  • Basis: your consent (Art. 6(1)(a)). The box is separate and never ticked in advance. You can unsubscribe at any time with the link in every email, from your account or by writing to us, and withdrawing does not affect anything done lawfully before.

When you exercise your right of withdrawal

  • Data: your name, email, order number and date, the products concerned, whether you downloaded the files, and anything you write in the optional fields.
  • Why: to handle the request and confirm we received it.
  • Basis: legal obligation (Art. 6(1)(c); Romanian Government Emergency Ordinance 34/2014).

When you email us

  • Data: your address and what you write.
  • Why: to reply.
  • Basis: our legitimate interest in answering messages (Art. 6(1)(f)), or performance of the contract if the message is about an order.

To keep the site safe

  • Data: your IP address, used in the moment to limit repeated attempts (for example, too many sign-in link requests). It is not saved in our database.
  • Basis: our legitimate interest in protecting the site and our customers from abuse (Art. 6(1)(f)).

Your card details never reach us. You enter them directly on Stripe's secure payment page, and we only receive confirmation that the payment went through.

3. What we don't do

  • No Google Analytics or any other traffic analytics.
  • No advertising pixels, retargeting or ad networks.
  • No profiling, and no automated decisions with legal or similarly significant effects on you (Art. 22).
  • We do not sell, rent or hand over your data to anyone for marketing.

4. Who else receives your data

We work with a few providers who process data on our behalf under a contract (Art. 28), and only as far as their job requires:

  • Stripe (Stripe Payments Europe Ltd., Ireland, and Stripe, Inc., USA): processes payments. Sales go through Stripe Managed Payments: its affiliate Sold through Link, LLC (USA) collects the payment on our behalf, calculates and pays the VAT, and sends you the receipt. For these, for fraud prevention and for the Link service, Stripe and Sold through Link act as independent controllers under their own privacy policy (link.com/privacy).
  • MailerLite (UAB MailerLite, Lithuania, EU): keeps the subscriber list and sends the newsletter and offers.
  • Resend (USA): sends the site's emails (order confirmations, sign-in links, withdrawal confirmations).
  • Cloudflare (Cloudflare, Inc., USA): manages the domain and forwards email sent to hello@page4fun.com.
  • Google (Google Ireland Ltd.): the mailbox where we read and answer your messages.
  • Hetzner Online GmbH (Germany): hosts the website and its database, on servers in the European Union.

We may also share data with public authorities, but only where the law requires it (for example, the tax authority).

5. Transfers outside the European Union

Some providers (Stripe, Sold through Link, Resend, Cloudflare) are based in the United States or may access data from there. These transfers rely only on the safeguards the GDPR requires (Art. 44–46): the EU–US Data Privacy Framework for certified companies, or the standard contractual clauses approved by the European Commission. You can ask us for a copy of the safeguards at the email address above.

6. How long we keep data

  • Orders and payment records: 5 years from the end of the year of the order, as tax and accounting law requires.
  • Your account: for as long as you use it. If you don't sign in for 3 years in a row, we delete it. Orders are kept only as long as the law requires, as above.
  • Sign-in links: expire after 30 minutes and are deleted automatically. Sign-ins on a device are deleted automatically after 30 days.
  • Newsletter and consent to offers: until you unsubscribe. After that we keep only the record of your consent and its withdrawal, for as long as it could be checked.
  • Withdrawal requests: 3 years, the general limitation period.
  • Emails: for as long as the conversation is useful, then deleted.

7. Cookies and browser storage

The site uses only what it strictly needs to work. There are no tracking or advertising cookies, so we don't ask for consent through a cookie banner.

  • p4f_account (cookie, 30 days): keeps you signed in. Set only after you sign in.
  • p4f_has_account (cookie, 1 year): remembers that you already have an account, so we stop showing the new-account offer. It contains only the digit "1".
  • Your cart (local browser storage): remembers the books you added.
  • p4f_welcome_seen (local browser storage): remembers that you've already seen the discount window, so it doesn't appear again.

Stripe's payment page sets its own cookies, needed for the payment and for fraud prevention, under Stripe's policy.

You can delete all of these at any time in your browser settings. Your cart will empty, and your account will ask for a new sign-in link.

8. How we protect your data

The site uses encrypted connections only (HTTPS). The database is not reachable from the internet, and only the controller has access to the data. Sign-in links and sessions are stored only as cryptographic fingerprints, and every order has its own unique download links.

If a data breach ever put your rights at risk, we would report it to the supervisory authority within 72 hours and tell you as well, as the GDPR requires (Art. 33–34).

9. Your rights

Under the GDPR (Art. 15–22) you have the right:

  • of access: to know what data we hold about you and get a copy;
  • to rectification: to have wrong data corrected;
  • to erasure: to have your data deleted, except what the law requires us to keep;
  • to restriction: to have processing paused;
  • to portability: to receive your data in a format that is easy to move;
  • to object: to processing based on legitimate interest;
  • to withdraw consent for offer emails, at any time.

Write to hello@page4fun.com. We reply within one month. That period can be extended by two more months for complex requests, and if so we'll tell you why. If needed, we may ask you to confirm that the email address is yours, so we never give your data to someone else.

If you think we have handled your data wrongly, you can complain to the Romanian supervisory authority, ANSPDCP (Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal), B-dul G-ral. Gheorghe Magheru 28–30, Sector 1, Bucharest, www.dataprotection.ro, anspdcp@dataprotection.ro, or to the authority in the country where you live. We would appreciate the chance to put things right first, so please write to us too.

10. Children

The books are for children, but the shop is for adults. We do not ask for or knowingly collect data from anyone under 16. If you learn that a child has given us their details, write to us and we will delete them.

11. Changes

When we change this policy, we update the date at the top. If a change matters to you, such as a new purpose or a new provider, we will also tell you by email if you have an account.