In short
- We collect what we need to answer an enquiry, take a payment and deliver the work: your contact details, what you bought, what you tell us in the dashboard, and standard server logs.
- There is no analytics tool, advertising pixel or third-party tracker on this site, which is why there is no cookie banner.
- We are a United States company. If you are in the EU, the EEA or the UK, the GDPR still applies to what you give us. Where we pass it to a processor outside those regions we rely on Standard Contractual Clauses or, where the processor holds one, a Data Privacy Framework certification.
- We share data with Stripe, Wise and Hostinger to run the service, and otherwise only where the law requires it. We never sell it and keep it no longer than the periods listed below.
- You can ask for a copy, a correction or the deletion of your data at info@mindscrollers.com and we answer within one month.
The company
Who we are
MINDSCROLLERS LLC, a Wyoming limited liability company trading as MindScrollers, publishes this policy. We are the controller of the personal data described here, except where we say we act as a processor for a client. Our registered address is 30 North Gould Street, Sheridan, WY 82801, United States.
This policy covers mindscrollers.com, the shop, the client dashboard at mindscrollers.com/projects, and the work we do for clients, wherever they are. How to reach us is set out under Contact for privacy requests at the end of this policy.
We have not appointed a representative in the EU or the UK under Article 27 of the GDPR. Requests from the EU and the UK go to info@mindscrollers.com and are handled exactly as described under Your rights.
What data we collect on the site
Most of what we hold about you comes from you.
- Contact form
- Your name, email address, company, what the message is about, budget range and message, plus the IP address the form was sent from and the time of submission. It is stored on our server and emailed to our inbox. The form is rate limited per IP address and has a hidden field that only bots fill in.
- Shop checkout
- You buy fixed-scope services, one-time or monthly, through Stripe Checkout, a payment page hosted by Stripe. Stripe collects your card details, name, email address and billing address; we never see or store full card numbers. Stripe sends us your email address, the amount and currency, what you bought, and Stripe customer and session identifiers, from which we create an order record and a project ticket. Where tax calculation is enabled, Stripe may use your billing address to work out the tax due.
- Client dashboard
- You log in at mindscrollers.com/projects with a link emailed to the address that paid. The link works for 20 minutes; a session cookie then keeps you signed in for 30 days. The dashboard holds your intake answers, messages between you and us, files you upload (up to 20 MB per upload) and delivery status. Subscriptions are not managed in the dashboard. You manage or cancel one in the Stripe billing portal. To reach it, go to mindscrollers.com/shop/manage and enter the email you used at checkout, and we email you a secure portal link.
- Server logs
- Like any web server, the one that hosts this site records the IP address, browser user agent, pages requested and time of each request, used to keep the site running and to investigate abuse.
What data we handle during client work
When you become a client, we keep a client record: company, contact name, email address, phone number, website and notes. Alongside it we keep invoices, campaign and content records, and an append-only audit log of what our staff do in our own systems. We are the controller of these records.
Much of our work happens inside your own accounts: Google Ads, Meta (Facebook and Instagram), your WordPress or WooCommerce site and its hosting. Accounts, domain and code stay in your name. There we may see personal data about your customers, such as orders, form submissions or audience lists. For that data we act as a processor: only on your written instructions, under a written agreement with you, and for nothing else.
Ad spend goes from your own payment method straight to Google and Meta, with no markup, so we hold no payment data for it.
If you give us access to an account holding your customers' personal data, you remain its controller and are responsible for having a lawful basis to collect it.
Why we use your data and on what legal basis
The GDPR requires a legal basis for each use of personal data. These are ours.
- Answering an enquiry
- Legitimate interests (Article 6(1)(f)). Where the enquiry turns into work, contract (Article 6(1)(b)).
- Taking a payment in the shop
- Contract (Article 6(1)(b)): we need your email address, what you bought and the payment result to deliver it.
- Delivering the work and running the dashboard
- Contract (Article 6(1)(b)): intake answers, messages, files and delivery status are how the work gets done.
- Site security, rate limiting and fraud prevention
- Legitimate interests (Article 6(1)(f)): keeping the site up, stopping bots and abuse, spotting fraud.
- Keeping records of what was agreed
- Legitimate interests (Article 6(1)(f)): showing what was scoped, sent and approved if there is a dispute.
- Tax and accounting records
- Legal obligation (Article 6(1)(c)): invoices and payment records we must keep under tax law.
- Anything we ask your permission for
- Consent (Article 6(1)(a)): only where we ask for it explicitly. You can withdraw it at any time.
You are not obliged to give us any of this data, but without an email address and payment details we cannot take an order, and without intake answers the delivery clock cannot start.
Where we rely on legitimate interests, we have checked that your interests and rights do not override ours. You can object at any time.
International transfers
We are a United States company and the controller of the data you give us, when you contact us, buy from us or use the dashboard. Because we offer services to people in the EU, the EEA and the UK, the GDPR applies to us directly under Article 3(2), and that data is protected as this policy describes.
Where we pass personal data to a processor outside the EU, the EEA or the UK, we rely on the Standard Contractual Clauses adopted by the European Commission. For UK data we add the UK International Data Transfer Addendum. Both sit in that processor's contract with us. Where a processor holds a certification under the EU-US Data Privacy Framework (and, for UK data, its UK Extension), we may rely on that certification instead.
Ask at info@mindscrollers.com for a copy of the safeguards we rely on.
How long we keep data
We keep personal data as long as we need it for the purpose we collected it, then delete it.
- Enquiries and contact form submissions
- 24 months from your last message to us. If the enquiry becomes work, the client record period applies.
- Orders, invoices and payment records
- 7 years from the end of the tax year they belong to, as tax and accounting law requires.
- Client records
- 7 years after the last invoice, because they back the invoices.
- Project tickets, dashboard messages and uploaded files
- 12 months after the project closes, then deleted. Download what you want to keep before then.
- Client-work data held on your instructions
- Returned to you or deleted within 30 days of the engagement ending, at your choice. Data in your own accounts stays there.
- Server logs
- Kept by our hosting provider, Hostinger, under its own retention schedule, which we do not control. Any copy we take to investigate abuse is deleted within 90 days.
- Staff audit log
- Kept for as long as the client record it relates to, then deleted with it. It records what our staff did, not what you did.
- Dashboard session
- 30 days from login, or until you log out. The login link itself expires after 20 minutes.
A legal hold can extend any of these periods: if a dispute, an investigation or a request from an authority is under way, we keep the relevant records until it is resolved.
Security
We take reasonable technical and organisational steps to protect personal data:
- All traffic between your browser and the site is encrypted with TLS.
- Dashboard and staff sessions live in httpOnly cookies that scripts on a page cannot read.
- Access to client data is limited to the staff who need it, and staff actions are written to an append-only audit log.
- Files you upload to the dashboard are stored outside the public web root, out of reach of a guessed URL.
- We never store card numbers. Payment details are collected and held by Stripe.
No system is perfectly secure. If a breach is likely to put you at risk, we will tell you and notify the supervisory authority where the law requires it.
Your rights
The GDPR gives you these rights. We run the same process for everyone, wherever you are.
- Access
- See what personal data we hold about you and get a copy.
- Correction (rectification)
- Have anything that is wrong or incomplete corrected.
- Deletion (erasure)
- Have your data deleted, unless the law requires us to keep it, for example an invoice under tax law.
- Restriction
- Have us stop using your data while a dispute about it is settled.
- Portability
- Get the data you gave us in a common machine-readable format.
- Objection
- Object to any use based on legitimate interests. We stop unless we can show compelling grounds.
- Withdrawal of consent
- Withdraw consent at any time. That does not affect anything done before you withdrew.
- Automated decisions
- We make no decisions about you by machine alone that have legal or similar effects, and we do not profile you.
To exercise a right, email info@mindscrollers.com from the address we hold for you. If it comes from another address, we may ask you to confirm your identity first. We answer within one month. For a complex request, or several at once, we may take up to two more months and we tell you so within the first month. There is no charge unless a request is clearly baseless or repeated (manifestly unfounded or excessive), in which case we may charge a reasonable fee or decline it and say why.
You can also complain to a supervisory authority, in particular in the EU member state where you live or work. The European Data Protection Board lists them all at edpb.europa.eu. In the UK, the authority is the Information Commissioner's Office (ICO). We would rather hear from you first, but you do not have to contact us before you complain.
A note for US residents
We do not sell personal information and we do not share it for targeted advertising across other companies' sites (what US state laws call cross-context behavioral advertising).
Some US state privacy laws give you rights over your personal information: to know, delete or correct it, and to opt out of sale, sharing or targeted advertising. You can exercise them by emailing info@mindscrollers.com or calling +30 693 115 1063. We verify requests as described under Your rights. We will not discriminate against you for exercising any right.
Children
This site and our services are for businesses and the adults acting for them. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, email info@mindscrollers.com and we will delete it.
Changes to this policy
When we change this policy, we post the new version at mindscrollers.com/privacy-policy with a new effective date. If a change is material, for example a new processor or a new purpose, we email active clients 14 days before it takes effect.
Our Terms of service at mindscrollers.com/terms-of-service and our Refund policy at mindscrollers.com/refund-policy sit alongside this policy. Where they mention personal data, this policy governs.
Contact for privacy requests
For any question or request about personal data, reach us in this order:
- info@mindscrollers.com. The fastest route: an acknowledgement in writing within one business day, Monday to Friday; the full answer to a privacy request within one month as described under Your rights.
- Phone
- +30 693 115 1063. We still confirm every request in writing.
- Post
- MINDSCROLLERS LLC, 30 North Gould Street, Sheridan, WY 82801, United States.
Put the words 'privacy request' in the subject line and say which right you are exercising.