Privacy Policy
Last updated 14 July 2026
This policy explains what personal data Living Page collects, why, and the rights you have over it. We keep it plain and only collect what we need to run the service.
1. Who we are
Living Page (“we”, “us”, “our”) is a service operated by Richard Henney, a sole trader trading as Living Page, based in the United Kingdom. We are the “data controller” for the personal data described here. You can contact us about privacy at hello@livingpage.app, or by post at 21 Valley Road, Stoke-on-Trent, ST3 6NN, United Kingdom.
2. What we collect
We collect only what we need to provide and improve the Service:
- Account details — your name, email address, password (stored securely, hashed), workspace and brand names, and your plan.
- Content you upload — the PDFs, documents, and related material you put into the Service (“Your Content”). This may contain personal data if you choose to include it; you control what you upload.
- Billing details — handled by our payment provider, Paddle. We receive limited information such as your plan, country, and the last few digits and type of card; we do not store your full card number.
- Usage and analytics — basic information about how the Service and your published readers are used, such as view counts and, on paid plans, per-page or reader-level analytics.
- Product analytics in the dashboard — when you are signed in, we record which screens you visit and which controls you use, so we can see which parts of the product work and which do not. These events are linked to your user account and your workspace. Because they record what you clicked, they can include the names of your clients and the titles of your documents. We do not record your screen — session replay is switched off.
- Error reports — when something breaks in the dashboard we automatically capture the error, the page it happened on and a stack trace, linked to your account. Almost nobody reports a broken page; they close the tab. This is how we find out.
- Website analytics — on our public website (not the dashboard) we count visits and record how people found us, using a first-party cookie that recognises a returning browser. It is not linked to your name or email unless you go on to buy, in which case it lets us tell which marketing brought the sale.
- Technical data — information your browser or device sends automatically, such as IP address, device and browser type, and log data, used for security and to keep the Service working.
- Reader email addresses — if you switch on a document’s “email gate”, we collect the address a reader enters in order to view it, and hold it on your behalf for 30 days. See section 4.
- Messages you send us — for example, support emails or newsletter sign-ups.
3. Why we use your data, and our legal basis
- To provide the Service — creating your account, hosting and delivering your flipbooks and embeds, and giving you analytics.Legal basis: performance of our contract with you.
- To take payment — managing subscriptions and refunds through Paddle.Legal basis: contract, and compliance with legal (e.g. tax) obligations.
- To keep the Service secure and working — preventing abuse, fraud, and technical problems. Legal basis: our legitimate interests in running a safe, reliable service.
- To communicate with you — service messages, replies to support requests, and important notices. Legal basis: contract and legitimate interests.
- To improve the Service and, if you opt in, send updates — product news or marketing where you have asked to hear from us (such as our newsletter).Legal basis: consent, which you can withdraw at any time.
4. Your Content and the people it may mention
When you upload documents, you decide what they contain. If Your Content includes other people’s personal data, you act as the controller of that data and we process it on your behalf (as your “processor”) to host and deliver it. You are responsible for having a lawful basis to upload and publish it. We only use Your Content to run the Service, as set out in our Terms of Service.
Email gate (lead capture)
On paid plans you can turn on an “email gate”, which asks a reader for their email address before they can view a published document. Where you do this:
- You are the controller of those addresses and we are your processor. You are responsible for having a lawful basis to collect them, for telling readers what you will do with their address, and for honouring any request they make to you.
- We show the reader, at the point of collection, that their address is shared with whoever published the document and that we delete it after 30 days.
- We delete captured addresses 30 days after capture (see section 7). We do not email readers, and we do not use their addresses for our own marketing or sell them to anyone. Export them if you need to keep them for longer — once exported, they leave our systems and become your responsibility.
An email gate is not access control: anyone can enter any address. Use a document password if a document must actually be kept private.
6. International transfers
Some of our providers process data outside the UK or EEA. Where they do, we rely on appropriate safeguards — such as UK/EU adequacy decisions or standard contractual clauses — so that your data keeps a similar level of protection.
7. How long we keep it
We keep personal data for as long as your account is active and for a reasonable period afterwards, then delete or anonymise it — except where we must keep certain records longer (for example, invoices for tax purposes). When you delete Your Content or close your account, we remove it within a reasonable period, allowing for backups and normal caching.
Two specific limits worth calling out:
- Email gate leads — 30 days. Addresses captured by a document’s email gate are automatically deleted 30 days after they are captured. Export them from your dashboard if you need them for longer.
- Anonymous shares — 24 hours. A document shared without an account, and the pages rendered from it, are deleted 24 hours after upload.
8. Your rights
If you are in the UK or EU, you have the right to access your data; to correct or delete it; to restrict or object to certain processing; to data portability; and to withdraw consent where we rely on it. To exercise any of these, email hello@livingpage.app and we will respond within the time the law allows.
If you are unhappy with how we handle your data, you can complain to the UK Information Commissioner’s Office (ico.org.uk) or your local data protection authority — though we would appreciate the chance to put things right first.
10. Children
The Service is for business and professional use and is not directed at children. We do not knowingly collect personal data from children under 16. If you believe a child has provided us data, contact us and we will delete it.
11. Changes to this policy
We may update this policy from time to time. If a change is significant, we will let you know (for example, by email or a notice in the app). The “last updated” date at the top shows the current version.
12. Contact
For anything about your privacy or this policy, email hello@livingpage.app.
Questions about this policy? Email hello@livingpage.app.