Privacy & Cookie Policy
Last updated: 16 July 2026
This policy explains how wrapsdesigner.com ("WrapsDesigner", "we", "us") collects and uses personal data, and how we use cookies, when you use our website and Service. We are the data controller for that personal data. For any privacy question or to exercise your rights, contact [email protected].
We process personal data in accordance with the UK GDPR and the Data Protection Act 2018, and we use cookies in line with the Privacy and Electronic Communications Regulations (PECR).
1. What we collect
- Account data — your email address and a securely hashed password.
- Design & content data — the designs, images, text and files you create or upload.
- Subscription & payment data — your plan, billing status, and transaction references. Card payments are handled by our payment provider; we do not receive or store your full card number.
- Usage & technical data — IP address, browser/device information, pages visited, and security logs.
- Cookies — small files stored on your device to keep you signed in and secure; see section 3.
- Communications — messages you send us by email or support.
2. How and why we use it (lawful bases)
| Purpose | Lawful basis |
|---|---|
| Provide your account and the Service; store your designs | Performance of a contract |
| Take payment and manage subscriptions | Performance of a contract |
| Keep the Service secure and prevent abuse/fraud | Legitimate interests |
| Send service and account emails (e.g. verification, billing) | Performance of a contract / legitimate interests |
| Comply with legal obligations (e.g. accounting/tax) | Legal obligation |
| Marketing emails (if any) | Consent (you can opt out at any time) |
3. Cookies
We keep cookies to a minimum and do not use advertising or third-party tracking/analytics cookies that profile you across other sites. We use cookies in line with the Privacy and Electronic Communications Regulations (PECR) and the UK GDPR.
| Cookie | Purpose | Type |
|---|---|---|
| session | Keeps you signed in and maintains your session | Strictly necessary |
| CSRF token | Protects forms against cross-site request forgery | Strictly necessary |
| Cloudflare | Security, bot protection (Turnstile) and service delivery | Strictly necessary |
Consent. The cookies above are strictly necessary to provide a service you have asked for (signing in, security), so they do not require consent under PECR. If we ever introduce non-essential cookies (for example optional analytics), we will ask for your consent first.
Managing cookies. You can block or delete cookies in your browser settings, but the Service may not work properly without the strictly necessary cookies (for example, you may not be able to sign in).
4. Who we share it with (processors)
We use trusted third parties to run the Service. They process data on our instructions:
- Hosting & infrastructure provider — runs our servers (within the UK/EU).
- Content-delivery & security provider — protects and delivers the Service, including bot protection.
- Payment provider — processes payments.
- Email provider — sends account and service emails.
- Backup provider — stores encrypted off-site backups.
We do not sell your personal data. We may disclose data where required by law or to protect our rights.
5. International transfers
Some providers may process data outside the UK. Where they do, we rely on appropriate safeguards such as UK adequacy regulations or the International Data Transfer Agreement / Addendum to the EU Standard Contractual Clauses.
6. How long we keep it
We keep account and design data for as long as your account is active, and for a reasonable period afterwards to allow reactivation and to meet legal/accounting obligations. Security logs are kept for a limited period. You can ask us to delete your account and content (see below).
7. Your rights
Under UK data protection law you have the right to: access your data; have it corrected; have it erased; restrict or object to processing; data portability; and to withdraw consent where we rely on it. To exercise any right, email [email protected]. We will respond within one month.
You also have the right to complain to the UK Information Commissioner's Office (ICO) at ico.org.uk if you are unhappy with how we handle your data.
8. Security
We use technical and organisational measures to protect personal data, including encryption in transit (HTTPS), hashed passwords, access controls, rate limiting, bot/abuse protection, and regular backups. No system is completely secure, but we take reasonable steps to protect your data.
9. Children
The Service is not intended for anyone under 18 and we do not knowingly collect data from children.
10. Changes
We may update this policy and will post the new version here with an updated date.
11. Contact
Data protection enquiries: [email protected].