Privacy Policy
Last updated 27 July 2026
This is a plain-English privacy policy for sheetfolk (sheetfolk.com), a spreadsheet template shop operated as part of the Opsibyte portfolio. It is written to be genuinely readable, not to bury the important parts — but it is not a substitute for legal advice.
1. Who we are
sheetfolk is the data controller for the information described below. You can reach us at [email protected] for any privacy question, request, or complaint.
2. What we collect
- Purchase email — the email address Stripe Checkout collects when you buy a template, used only to deliver your download link and receipt.
- Payment information — handled entirely by Stripe (or Etsy, if you buy there). We never see or store your card number.
- Usage & device data — standard technical data every website collects: IP address, browser type, pages visited, and timestamps, via privacy-respecting analytics.
- Cookies — we don't use sign-in cookies (there's no account system). Our analytics provider (PostHog, EU-hosted) sets a first-party cookie to distinguish visitors; we don't use third-party advertising or cross-site-tracking cookies.
3. Why we collect it, and our legal basis
We process your email to deliver the template you paid for (contract), and use aggregate analytics to understand which pages and templates are working (legitimate interest). We don't use your data for anything beyond that.
4. Who we share it with
We don't sell your data, and we don't share it for advertising. We use a small set of service providers (subprocessors) to run sheetfolk:
- Stripe (and Etsy, for purchases made there) — payment processing.
- Resend — delivery of your download link and receipt email.
- PostHog — privacy-respecting product analytics (EU-hosted).
- Our hosting provider — to serve the static site and process the purchase webhook.
We may also disclose data if legally required to (e.g. a valid court order), or to protect the rights, safety, or property of sheetfolk, our users, or the public.
5. What we don't do
sheetfolk has no account system and no login — there's no personal profile of you beyond the purchase email described above. We don't request bank credentials, OAuth access to any third-party account, or anything beyond what checkout needs.
6. Data retention
Purchase records (email, product, date) are financial records and are retained for accounting purposes, typically several years, per local law. We don't build any other history tied to your email address.
7. Your rights
Wherever you're located, you can ask us to: tell you what purchase data we hold linked to your email; correct it; delete what isn't part of a financial record; or object to certain processing. If you're in the EU/UK, these are your rights under GDPR; if you're in California, similar rights exist under the CCPA/CPRA. Email [email protected] — we'll respond within 30 days.
8. Children's privacy
sheetfolk is not directed at children, and we don't knowingly collect personal data from anyone under 16. If you believe a child has provided us data, contact us and we'll delete it.
9. International data transfers
Our infrastructure and service providers may process data outside your country of residence, including in the United States and the European Union. Where required, we rely on standard contractual clauses or equivalent safeguards recognized under applicable data-protection law for these transfers.
10. Security
We use industry-standard measures — encryption in transit (HTTPS/TLS) and access controls on our infrastructure — to protect the limited data described above. No system is 100% secure, but the design of sheetfolk (no accounts, no stored card details) keeps what we hold to a minimum.
11. Changes to this policy
We may update this policy as sheetfolk evolves. The version at sheetfolk.com/privacy always governs, and we'll update the "Last updated" date above when we make a change.
12. Contact
Questions, requests, or complaints about this policy: [email protected].