Last updated: 11 September 2026
Privacy policy
Your board papers are assembled in your browser and are never uploaded: there is no upload endpoint and no server that could hold one. While you work, a temporary draft is saved in your own browser, and this page says exactly when it is deleted.
Controller
Max Werner, Einzelunternehmer, c/o Impressumservice Dein-Impressum, Stettiner Str. 41, 35410 Hungen, Germany. Contact: hello@boardpackfactory.com. Full details are in the imprint. This policy is written under the EU General Data Protection Regulation (GDPR).
What we do not process
Your documents. The PDFs you add, their filenames, the meeting title, the organisation name, the date and the finished pack are read, assembled and written entirely inside your browser. There is no API route that accepts a file, and there is no storage bucket. The draft described under Storage on your device stays on your device too. You can confirm this yourself: open your browser’s network panel, build a pack, and watch that nothing of the kind is sent.
A consequence worth stating plainly, because it cuts both ways: we cannot recover a pack you have lost, reproduce a problem you report, or look at your papers to help you. See the refund policy for what a support conversation can realistically look like.
What we do process
Server logs
Our host, Vercel, records the usual request metadata — IP address, time, page requested, user agent — to serve the site and to defend it against abuse. We do not build profiles from these logs and we do not join them to anything else.
Usage analytics
Vercel Analytics and Vercel Speed Insights collect aggregate, cookieless measurements of page views and loading performance. On top of that we count a dozen product events — the builder was opened, files were added and how many, a build took this long or failed with that error code, the checkout was opened, a download finished. Every property either is a number or comes from a fixed list of keywords, and the code that defines them allows nothing else. No filename, meeting title or organisation name is ever sent, because that would contradict the thing we are selling.
Your currency
One request asks our server which currency to show you. The answer is derived from the country our host infers from your IP address, is used to render three letters, and is neither stored nor logged by us. Choosing a different currency in the selector overrides it, and that choice is kept in your own browser.
Payment
Payments are processed by Stripe Payments Europe, Ltd. Card details are entered inside Stripe’s own form and never reach our servers. At checkout we ask for your email address, which goes to Stripe with the payment so that Stripe can email you a receipt and we can send you an order confirmation.
Kept with the payment in our Stripe account: the amount, currency, status and time, your email address, an order reference (it looks like BPF-7K2M-9Q4X), the version of the terms you accepted, and the time you asked for the pack to be generated immediately and acknowledged losing the right of withdrawal. That record is how we can confirm your purchase, answer a support request and meet our bookkeeping duties. Stripe also processes what it needs to take the payment and prevent fraud, under its own privacy policy. We do not keep a customer list of our own, and we do not use your address for marketing.
The emails we send
Two emails go out when a pack is bought, both sent through Resend. Your order confirmation goes to the address you gave at checkout and carries the order reference, the date, the price, the terms version and the consent described above. An internal sales alert goes to us and carries the amount, Stripe’s payment and charge identifiers and the time. Neither contains anything about your pack — no filename, meeting title or organisation name. Stripe’s receipt is sent by Stripe.
Email you send us
If you write to hello@boardpackfactory.com, we process your address and whatever you put in the message, for as long as it takes to answer you and to keep a record of the conversation.
Storage on your device
We set no cookies, and there is no analytics or advertising cookie anywhere on this site, which is why there is no consent banner. These things are written to your own browser by us:
- A draft of the pack you are building — your PDFs, their order and titles, the meeting details and the options — in IndexedDB, so that a stray refresh does not throw away your work. It never leaves your device. The builder shows whether the draft is being saved, and has a button to delete it at any time; you can also stop it being saved for the rest of the visit. It is deleted when you press that button, when you start over, or when you choose to delete it after downloading your pack. It is not deleted just because a download started, because we cannot tell whether the file reached your disk. A draft left untouched for 24 hours is deleted the next time you open the builder in this browser; until then, a draft from a tab you closed stays in this browser.
- The identifier tying that draft to its tab, in
sessionStorage. It dies when the tab closes. - If you buy a pack, a purchase record in
localStorage: the order reference, Stripe’s identifier and client secret for that payment, a random recovery key, the currency and amount, and — once paid — the email address you gave and a link to your receipt. It lets this browser finish or repeat the download of a pack you have paid for without paying again, if the page is refreshed, the download does not start or the payment takes a while to confirm. When your browser asks our server to check the payment with Stripe, it sends the payment identifier and the recovery key, and nothing about your documents. Each record is deleted after 30 days. - Your currency, in
localStorage, if you picked one — so we do not ask twice.
All of these are strictly necessary to provide the service you explicitly requested (§ 25 (2) no. 2 TDDDG). Clearing your site data removes them; the product then behaves as it does on a first visit.
One exception, which we would rather name than let you find: if you open the checkout, Stripe’s payment library sets two cookies of its own on this domain (__stripe_mid and __stripe_sid) and stores a little alongside them, to detect card fraud. They are strictly necessary to take a payment you have asked us to take. That library loads only when you open the payment window. Reading this site loads nothing from Stripe, and building a pack writes only the draft described above.
Legal bases
- Providing the site and the builder, taking payment for a pack, and sending your receipt and order confirmation — performance of a contract and steps taken at your request (Art. 6 (1)(b) GDPR).
- Recording the terms version and your consent to immediate generation with the payment, and retaining payment records — legal obligation (Art. 6 (1)(c) GDPR).
- Server logs, abuse prevention, aggregate analytics and the internal sales alert — our legitimate interest in running a site that stays up and in knowing which pages work (Art. 6 (1)(f) GDPR).
- Answering an email you sent us — Art. 6 (1)(b) or (f) GDPR, depending on what you asked.
Processors
- Vercel — hosting, plus Analytics and Speed Insights.
- Stripe — payment processing and payment receipts.
- Resend — delivery of your order confirmation and of our internal sales alert.
Each acts on our instructions under a data-processing agreement. All three are, or transfer data to, the United States; those transfers rest on EU Standard Contractual Clauses and the providers’ certifications under the EU–US Data Privacy Framework. Ask us and we will send you the relevant safeguards.
Web fonts are served from our own domain rather than from Google Fonts, so loading a page does not disclose your IP address to a font host.
Retention
- Documents and packs: not retained by us, because they are never received.
- The draft in your browser: until you delete it or start over, or until the builder is next opened in this browser after 24 hours untouched — see above.
- The purchase record in your browser: 30 days.
- Server logs: kept briefly by our host and rotated automatically.
- Analytics: aggregate figures, retained under Vercel’s own retention settings.
- Payment records, including your email address, the order reference and the recorded consent: as long as German tax and commercial law requires — generally up to ten years (§§ 147 AO, 257 HGB).
- Order confirmations and sales alerts: kept with our payment records; Resend keeps a delivery log under its own retention settings.
- Support email: as long as it takes to answer, plus a reasonable record.
Your rights
You have the right of access, rectification, erasure, restriction, data portability, and objection to processing based on legitimate interests, under Arts. 15–21 GDPR. Write to hello@boardpackfactory.com and we will answer within a month, usually within a day. Records we are legally required to keep — payment and bookkeeping data in particular — survive an erasure request until their statutory period expires. What is stored in your own browser, you can delete yourself: from the builder, or by clearing this site’s data.
We have not appointed a Data Protection Officer, because we are not required to. You may complain to a supervisory authority; ours is Der Hessische Beauftragte für Datenschutz und Informationsfreiheit (HBDI), Wiesbaden, Germany.
Changes
If this policy changes, the date under the title changes with it. There is no account to notify, and we would rather you could see at a glance whether anything has moved.