Privacy Policy

Last updated: 2026-04-15

Plain-English summary: I collect your email when you buy something, so I can deliver the product and email you when there's an update to the Tool you bought. I don't run trackers. I don't sell or rent your data. I don't use marketing automation. If you want me to delete your data, email me and I'll do it within 48 hours.

This is a full GDPR-compliant version of that same statement.


1. Data controller

Plumbnote is operated by a private individual in Slovakia. There is no parent company, no investors, no third-party data processors beyond the specific list in section 5.

2. What data I collect

DataWhenWhyLegal basis
Email addressWhen you buy a productTo deliver the product, send update noticesContract (GDPR Art. 6(1)(b))
First name (if provided)When you buy a productTo personalize the delivery emailContract
Country of residenceWhen you buy via GumroadRequired for EU VAT handlingLegal obligation (GDPR Art. 6(1)(c))
IP address (at checkout)During paymentFraud prevention by the payment processorLegitimate interest (GDPR Art. 6(1)(f))
Email address (if you subscribe to the newsletter separately)When you sign up on the websiteTo send product launch noticesConsent (GDPR Art. 6(1)(a))
Support emails you send meWhen you email meTo respond to your questionContract

I do NOT collect:

3. What I do with your data

I do NOT:

4. How long I keep your data

DataRetention
Purchase recordsKept for 10 years for Slovak tax/accounting purposes (required by law)
Email address (for product updates)Kept until you unsubscribe or request deletion
Newsletter subscriber listKept until you unsubscribe or request deletion
Support email threadsKept for 3 years, then deleted

5. Who I share your data with (third-party processors)

I use the following third parties to run the business. They each have their own privacy policies:

ProcessorWhat they processLocationPrivacy policy
Gumroad, Inc.Your email, name, billing country, payment infoUSA (with EU representatives)gumroad.com/privacy
Kit (ConvertKit) LLCYour email (if you signed up for newsletter)USAkit.com/privacy
Zoho CorporationMy outbound emails (including any to you) routed via Zoho MailIndia / EU (zoho.eu)zoho.com/privacy.html
Cloudflare, Inc.Website hosting and DNSGlobal CDN, EU nodescloudflare.com/privacypolicy
Anthropic PBCAny data I explicitly include in a Claude API call for support response draftingUSAanthropic.com/legal/privacy

I do NOT use:

6. International data transfers

Some of the processors listed in section 5 are based in the USA (Gumroad, Kit, Anthropic). These transfers are covered by:

I do NOT transfer your data to any country outside the EU/USA.

7. Your rights under GDPR

You have the right to:

To exercise any of these rights, email nikos@plumbnote.com. I'll respond within 48 hours and act within the 30-day GDPR deadline.

You also have the right to lodge a complaint with the Slovak Data Protection Authority (Urad na ochranu osobnych udajov Slovenskej republiky) at dataprotection.gov.sk.

8. Cookies

The Plumbnote website currently uses no cookies— not even functional ones. If this changes (e.g. if I add Gumroad's embedded checkout, which uses a session cookie), I'll update this policy and add a cookie notice on the site.

9. Children's privacy

Plumbnote products are business tools for adults. I do NOT knowingly collect data from anyone under 16. If you're under 16 and you've somehow bought a product, email me and I'll refund and delete.

10. Security

Your email and purchase data are stored on the platforms listed in section 5 (Gumroad, Kit, Zoho). I rely on their security infrastructure. I do not maintain my own customer database. Support emails sit in my inbox like any other email.

If I ever discover a data breach affecting your data, I will notify you by email within 72 hours per GDPR Article 34.

11. Changes to this policy

If I update this policy materially, I'll:

12. Contact

For any privacy question:

nikos@plumbnote.com— I'm a private individual, I read every email, I'll respond in plain English.


This Privacy Policy is written in plain English to be understood without a lawyer. It is based on the GDPR (Regulation (EU) 2016/679) and Slovak Act No. 18/2018 on Personal Data Protection. If you need a more formal or jurisdiction-specific statement, email me.