Privacy Policy
How we collect, use, and protect your personal data.
Last updated: May 20, 2026
1. Introduction
bookshelfcorner.com ("we") respects your privacy. This policy explains what personal data we collect, how we use it, the legal basis for processing, with whom we share it, and your rights as a data subject.
2. Data We Collect
2.1 When you register an account (all users)
- Basic identity: name, email, password (hashed);
- Social login data (if using Google OAuth): Google user ID, email, name;
- Avatar/profile photo (optional).
2.2 When you purchase an ebook (buyers)
- Transaction history: order ID, books purchased, amount, time, payment method;
- Payment data is not stored by us — processed entirely by PayPal. We only receive success/failure confirmation + transaction ID;
- IP address and user agent at download time (for security logs & misuse detection).
2.3 When you register as an author
Additional data required for author verification:
- Display name & author bio;
- PayPal account email (for royalty payouts);
- Content works uploaded (PDF file, cover, metadata).
2.4 Automatically from platform interaction
- Access logs: IP, browser, OS, pages visited, timestamp;
- Cookies — see §6. Cookies;
- Aggregate analytics data (see §7. Third Parties).
3. Purposes of Data Use
We process your personal data for the following purposes:
- Running your account (registration, login, authentication);
- Processing purchase transactions & royalty payouts;
- Author identity verification;
- Generating personal watermarks in the PDFs you purchase;
- Sending transaction-related notifications via email;
- Preventing fraud, plagiarism, piracy, and misuse;
- Complying with legal obligations;
- Improving the service (aggregate analytics, not per individual);
- Marketing communications (newsletter, promotions) — only with your explicit consent, and you can unsubscribe at any time.
4. Legal Basis for Processing
- Consent — you agree to this policy when registering;
- Contract performance — to deliver the services you purchase/use;
- Legal obligation — tax reporting, law enforcement cooperation;
- Legitimate interest — system security, fraud prevention, service development.
5. Storage, Location & Data Retention
5.1 Storage location
- Primary database: VPS server;
- Files & images: Cloudflare R2 (global object storage with replication);
- Backups: encrypted, stored at separate geographic locations for disaster recovery.
5.2 Retention
- Active account data: stored while the account is active;
- Deleted accounts: permanently deleted within 30 days (except transaction/tax records required for 10 years);
- Security & audit logs: 1–3 years.
6. Cookies & Tracking
We use cookies for:
- Essential (required): login session, CSRF token, language settings — cannot be disabled;
- Analytics (optional): measuring page traffic in aggregate (not per individual);
- Preferences (optional): saving search filters, display settings.
We do not use third-party advertising tracking cookies such as Facebook Pixel or Google Ads without your explicit consent.
You can manage/disable cookies via your browser, but some Platform features may not work (e.g. login sessions will keep resetting).
7. Data Sharing with Third Parties
We do not sell your data. We share data in a limited way only with:
7.1 Operational service providers (data processors)
- PayPal — payment processing. Data shared: name, email, order ID, amount. See PayPal's privacy policy.
- Cloudflare, Inc. — CDN, DNS, file hosting (R2). Your files are hosted on their infrastructure. Cloudflare privacy policy.
- Google LLC — if you log in via Google: Google account data as per your OAuth consent. Also for Google Vision API (cover image moderation).
- OpenAI — text moderation of works (sample max 5000 characters per work). OpenAI commits not to train models on API data.
7.2 Law enforcement & legal obligations
- We will comply with valid legal orders and official requests from law enforcement authorities;
- In cases of misuse/crime, data may be shared with authorized parties after verifying the legitimacy of the request.
7.3 Cross-border data transfers
Some providers (Cloudflare, Google, OpenAI) process data on servers outside your country. We ensure equivalent levels of protection through data processing agreements with each provider.
8. Your Data Rights
You have the following rights over your personal data:
- Right to information — about the legal basis, purposes, and accountability of data processing;
- Right of access — request a copy of data we hold about you;
- Right to rectification — request correction of inaccurate data;
- Right to erasure / "right to be forgotten" — request deletion (except data required by law);
- Right to restriction of processing;
- Right to withdraw consent;
- Right to object to automated processing including profiling;
- Right to data portability — receive your data in a common format (e.g. JSON / CSV).
To exercise these rights, send an email to privacy@bookshelfcorner.com with the subject "Data Subject Rights Request" + your identification (name, account email). We will respond within 72 business hours.
9. Data Security
- Passwords hashed with bcrypt (industry standard);
- HTTPS / TLS for all traffic;
- Daily database backups, encrypted;
- Internal access to sensitive data limited to verified admins, with audit logs;
- Personal watermark in PDFs to prevent leaks;
- Rate limiting & anti-fraud detection;
- Data breach notification: if an incident affecting your rights occurs, we will notify you within 72 hours.
While we make every effort, no system is 100% secure. You are also responsible for keeping your password and devices secure.
10. Minors
The Platform is not intended for children under 13. We do not knowingly collect data from children under 13. If you are a parent/guardian and become aware that your child has registered without your consent, contact privacy@bookshelfcorner.com — we will delete the account and associated data.
11. Policy Changes
This policy may change as the service and regulations evolve. Significant changes will be notified via email and a banner on the Platform at least 14 days before they take effect. Check the "Last updated" date in the header to ensure you're reading the latest version.
12. Privacy Contact
For questions, objections, or exercising data subject rights:
- Email: privacy@bookshelfcorner.com
- Email subject: "Data Subject Rights Request" for faster response