Online stamp maker privacy policy

Updated August 5, 2026

Scope and information we collect

This policy explains how Stamp Creator Online and its operator collect, use, store and share personal data when you use the website, create an account, save a design, make a purchase or contact Support.

Depending on the features you use, we may collect your email address, name, profile image, sign-in provider and password hash; saved stamp designs, preview images and file settings; checkout email, order references, plan, entitlement and payment status; support messages; and technical data such as IP address, browser and device information, requested pages, timestamps, approximate region, user agent, error details and security events.

If you sign in with Google, Google sends us the basic profile information you authorize, such as your Google account identifier, email, name and profile image. We do not receive your Google password.

Browser-based editing and uploads

Most stamp editing and image-tool operations are designed to run in your browser. Files selected only for those local tools are not sent to an image-generation service. Browser drafts and preferences remain on your device unless you choose a feature that transmits them.

A design or image is sent to our service when you expressly save it to My Library, save it for a paid order, request a server-processed export, or attach or describe it in a support request. We process that content to provide the requested feature, not to train a generative AI model.

How we use information

We use personal data to create and secure accounts; provide the editor, My Library, purchases and downloads; verify entitlements; process billing; respond to support and data-rights requests; diagnose errors; prevent abuse, fraud and security incidents; comply with legal obligations; and improve service reliability.

Where applicable, these activities are based on performing our contract with you, our legitimate interests in operating and securing the service, compliance with law, or your consent. We do not sell personal data or use it for third-party targeted advertising.

Cookies and local storage

The site uses strictly necessary session cookies to keep you signed in and may use browser storage for editor state, local drafts, preferences and consent choices. Production session cookies are protected with Secure, HttpOnly and SameSite settings where applicable. You can clear local values through your browser, although disabling required storage may prevent account or editor features from working.

The service does not currently enable its own analytics module or advertising cookies. If we introduce optional analytics or marketing technologies, we will update this policy and provide any consent controls required by law.

Data storage and retention

Service data is stored on managed Cloudflare infrastructure. Account and entitlement records are held in a service database; My Library design data is held in account-scoped key-value storage; preview images are held in object storage; and short-lived order design data is normally deleted automatically after 7 days. Local drafts and preferences remain in your browser until you clear them.

My Library items remain until you delete them or close your account. Account data remains while the account is active. After a verified account-deletion request, we delete or de-identify active account and library data within 30 days, although backups or residual copies may take up to 90 days to expire. Transaction, fraud-prevention and support records may be kept longer where reasonably needed for tax, accounting, chargeback, dispute or other legal obligations.

How we protect data

We use HTTPS/TLS to protect data in transit; hash email-account passwords rather than store them in readable form; use protected session cookies; apply same-origin checks, rate limits and input validation to sensitive endpoints; logically separate saved designs by account; and limit administrative and provider access to what is needed to operate and support the service.

Full payment card numbers and CVC codes are handled by the payment provider shown at checkout, such as Stripe or Waffo Pancake, and are not stored on our servers. You should keep your password and devices secure and contact Support if you suspect unauthorized access.

No method of storage or transmission is completely secure. If a security incident creates a material risk to your rights, we will investigate, take appropriate steps and notify affected users and authorities as required by applicable law.

Service providers and disclosure

We share only the data needed with providers that help deliver the service, including Cloudflare for hosting and storage, Stripe or Waffo Pancake for checkout and payments, Google when you choose Google sign-in, and a file-conversion provider when you request an export that requires server-side conversion. These providers process data under their own terms and security obligations.

We may also disclose data when required by law, to protect users or the service, with your direction or consent, or as part of a business reorganization subject to continued protection. Our providers may process data in countries other than yours; where required, we rely on contractual or other lawful transfer safeguards.

Your data rights

Subject to applicable law, you may ask to access or receive a copy of your personal data, correct inaccurate data, delete data, close your account, restrict or object to certain processing, obtain portable data, or withdraw consent where processing relies on consent. You may delete individual My Library designs with the library controls and clear local drafts through your browser.

To exercise another right or close your account, submit a request through the Support page from your registered email. State the right you want to exercise and include enough information for us to locate the account. We may ask for reasonable identity verification before acting. We normally respond within 30 calendar days, or within the period required by applicable law.

Account deletion permanently removes access to saved designs and account-based paid features after processing. We may retain limited transaction or security data when the law permits or requires it, and we will explain any limitation in our response. You may also complain to your local data-protection authority.

Children

The service is intended for adults and is not directed to children under 18. We do not knowingly collect personal data from a child. If you believe a child has provided personal data, contact us so we can investigate and delete it where appropriate.

Policy changes

We may update this policy when the service, providers or legal requirements change. We will post the revised policy and update the date above. For material changes, we will provide reasonable notice through the website, account or registered email when practicable.

Contact

Privacy questions and data-rights requests can be submitted through the Support page. Do not send passwords, full card numbers, CVC codes or identity documents unless we specifically request an appropriate verification method.