InkSmithery

Privacy Policy

Last updated: 3 June 2026

1. Who We Are

InkSmithery is operated by an individual sole trader based in the United Kingdom. This policy explains what data we collect, why, and how we use it.

2. What Data We Collect

When you browse the site

We use a session cookie (PHPSESSID) to maintain your shopping cart. This cookie is essential for the site to function and is deleted when you close your browser. We use a small first-party analytics script that sends aggregated browsing patterns (clicks, scrolls, time on page, search queries, cart events) to our own servers to help us understand how people use the shop and improve it. No third-party analytics, no tracking pixels, no session replay, no form values beyond the search box. See Section 7 for details.

We collect basic aggregate statistics about site usage (such as which design categories are most popular) using our own server. This data is anonymous and aggregated — we do not create user profiles from it.

Advertising measurement

When we run paid advertising on Pinterest or Google, we need to know which of our ads are actually producing sales. We do this in the most privacy-respectful way available — server-side, no cookies, and no personal information about you ever leaves our server.

What we send to Pinterest (for events like page view, add to cart, purchase):

  • The event name (e.g. "page_visit", "add_to_cart", "checkout")
  • The product IDs involved and, for purchases, the order total
  • Your IP address and browser user agent — required by Pinterest for fraud prevention, same as any website receives when you visit it
  • A random session token (no way to link to your identity)

What we send to Google Ads (only if you clicked one of our Google ads to reach the site):

  • The Google-generated click ID from the ad URL (gclid), the order total, and our order reference

What we deliberately do not send: your name, email address (hashed or otherwise), phone number, delivery address, or any data that could identify you as an individual. Pinterest and Google optimise our ad campaigns based only on event counts and the click ID they gave the click themselves.

This is server-to-server (not a browser tracking pixel) and sets no cookies on your device. Pinterest processes their portion under their own privacy policy; Google under theirs. Legal basis: legitimate interests (measuring the effectiveness of advertising we pay for). You can opt out of all advertising events by emailing orders@inksmithery.com.

When you place an order

We collect the following information through our payment provider, Stripe:

  • Your email address
  • Your delivery address
  • Your name (as provided at checkout)

We also store your order details (items purchased, quantities, prices, and order reference) in our database.

We do not collect or store your payment card details. All payment processing is handled by Stripe.

To enable secure card entry and fraud prevention, Stripe’s JavaScript loads on our cart and checkout pages. It collects technical signals about your device (browser, screen, IP address) which Stripe uses to detect fraudulent transactions. This is described in Stripe’s privacy policy.

If you choose to pay using Apple Pay, Google Pay, PayPal, Link or Amazon Pay, the wallet provider you select (Apple, Google, PayPal, Stripe Link or Amazon respectively) will see the merchant name and amount in order to authorise the payment. They handle this under their own privacy policies.

3. How We Use Your Data

Your data is used solely for the following purposes:

  • Order fulfilment: Your name, email, and delivery address are shared with our production partner, Printful, so they can print and ship your order.
  • Order queries: Your email and order reference allow us to respond if you contact us about an order.

We do not send promotional emails. Beyond the parties listed in Section 4, we do not share your data with anyone.

4. Third-Party Services

We use the following third-party services to operate the shop:

  • Stripe (stripe.com) — payment processing. Stripe handles your card details under their own privacy policy.
  • Printful (printful.com) — order fulfilment. Printful receives your name and delivery address to print and ship your order, under their own privacy policy.
  • Pinterest (pinterest.com) — advertising measurement only, via their server-side Conversions API. Pinterest receives only the event data described in Section 2 ("Advertising measurement"). No personal data, no browser tracking pixel. Processed under Pinterest’s privacy policy.
  • Google Ads (google.com) — advertising measurement only, when you’ve arrived from one of our Google ads. Google receives only the click ID from its own ad system, plus our order total and reference. No personal data, no browser tracking pixel. Processed under Google’s privacy policy.
  • Cloudflare Turnstile (cloudflare.com) — invisible spam protection on our contact form only. When you submit the contact form, a small Cloudflare script analyses technical signals from your browser (IP address, browser characteristics, request timing) to verify you’re a real person and not a spam bot. No cookies, no cross-site tracking, no advertising profile. Legal basis: legitimate interests (keeping our contact inbox usable). Processed under Cloudflare’s privacy policy.

We do not use third-party analytics, tracking pixels, or social media tracking scripts. The only browser-based scripts are: (a) our own first-party UX analytics, which sends aggregated browsing signals to our own servers — described in Section 7; (b) Stripe’s script on the cart and checkout pages for the fraud-prevention purpose described in Section 2; and (c) Cloudflare Turnstile on the contact page for the spam protection described above.

5. Data Retention

Order data (email, delivery address, items purchased) is retained for as long as needed to fulfil orders, handle returns, and comply with UK tax and accounting requirements. Session cookies expire when you close your browser.

6. Your Rights

Under UK data protection law (UK GDPR), you have the right to:

  • Request a copy of the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your data (subject to legal retention requirements)

To exercise any of these rights, email orders@inksmithery.com with your order reference.

7. Cookies and similar technologies

This site uses a single essential cookie:

Name Purpose Duration
PHPSESSID Maintains your shopping cart Browser session

No consent banner is required as this is a strictly necessary cookie.

We may also use localStorage (a browser-side storage mechanism similar to cookies) to remember small UI preferences — for example, whether you have already seen a one-time message and dismissed it. This data lives only on your device and is never transmitted to our servers. You can clear it at any time through your browser’s site-data settings.

First-party UX analytics. A small JavaScript file (~3KB, loaded asynchronously) records aggregated browsing signals on every page: click positions, scroll depth, time on page, viewport size, navigation between pages, and shop-specific events (search submitted, design viewed, variant selected, item added to cart, checkout started). These are sent directly to our own servers — no third party is involved at any stage. Each session is keyed by an anonymous hash of your PHPSESSID; we never store the raw session ID and never link this data to your name, email, or any account. We do capture the text you type into the shop’s search box (which helps us understand what visitors look for that we may not yet offer); we do not capture any other form input — your email, address, card details, and account fields are never recorded. We never record session replays, keystrokes, mouse traces, or any data that could identify you personally. Session-level data is retained for 30 days, after which only anonymous totals remain (e.g. “page X received N clicks last month”).

Because this data is keyed only by an anonymous session hash with no link to your name, email, or account, we cannot identify which historical sessions are yours. You can erase your current browser’s analytics data at any time by visiting /privacy/erase-my-analytics. Session-level data is automatically deleted after 30 days regardless.

8. Changes to This Policy

We may update this policy from time to time. The date at the top of the page shows when it was last updated.

9. Data Controller

The data controller for any personal data processed through this site is:

InkSmithery
Paul Newson trading as InkSmithery
Llanberris
Woods Loke East
Lowestoft
NR32 3DR
United Kingdom
orders@inksmithery.com

10. Contact

For any privacy-related queries, contact orders@inksmithery.com.

Free delivery on every order
30 days, no quibble returns
Buy with gift confidence — easy returns if it’s not right
Privacy-first — your data stays yours