Privacy policy
Last updated: July 2026
01Introduction
LiteInk (“we”, “us”, or “LiteInk”) is a premium Astro template store operating at liteink.co, with a customer dashboard at dashboard.liteink.co. We’re a solo-run operation, and we believe in collecting as little data as possible — only what we need to process your orders, deliver your themes, and keep your account working.
This privacy policy explains what information we collect when you visit our site, sign in, or buy our themes; how we use it; and the choices you have about it.
This policy applies to liteink.co, dashboard.liteink.co, and every service we offer through them: Astro themes, All Access plans, and Lifetime licenses.
02Definitions
A few terms we use in this policy, kept short:
- Service — anything we offer: premium themes, All Access plans, Lifetime licenses, and the customer dashboard.
- Personal Data — information that can identify you directly, like your name or email address.
- Usage Data — non-identifying information about how visitors use our site, such as page views and browser type.
- Processor — a third-party company that handles data on our behalf, like Polar for payments or GitHub for authentication.
03Information We Collect
We keep data collection deliberately small. Here is exactly what we collect and where it comes from.
Account & authentication
When you sign in to your dashboard at dashboard.liteink.co, you authenticate using a third-party provider — currently GitHub or Google. When you do, we receive:
- Your email address (from the provider)
- Your display name (if available from the provider)
- A unique identifier from the provider (GitHub user ID or Google subject ID)
We do not receive your password, access to your repositories, or the ability to act on your behalf beyond reading your public profile. We never ask for write or admin scopes.
We store this information in our database to create and maintain your account. If you change your email on GitHub or Google, we automatically sync the new email on your next sign-in.
Payment information
When you buy a theme or plan, payment is handled by Polar (polar.sh), our Merchant of Record. Polar processes your transaction, handles tax compliance, and stores your payment details. We receive:
- Confirmation that a purchase was made
- Your email address (to link the purchase to your account)
- What you bought (which theme or plan)
We never see, touch, or store your full card number, CVV, or any sensitive payment data. That stays entirely with Polar.
Theme ownership & downloads
We maintain a record of which themes you own in our database, so we can show them in your dashboard and verify access when you download. This includes the theme name, when you purchased it, and the source (individual purchase, Yearly plan, or Lifetime).
Usage data (Umami analytics)
We run our own analytics using Umami, a privacy-friendly, self-hosted tool. It records aggregated, anonymous data about how the site is used:
- Which pages were visited
- Roughly how long visitors stayed
- Browser type and device
- Approximate country (derived from your IP address, then discarded)
Umami does not use cookies. It does not collect personal identifiers. It does not follow you across other websites. The customer dashboard does not run analytics — it’s an authenticated app, not a tracked marketing page.
What we DON’T collect. This is just as important as what we do collect. We do not use:
- Google Analytics or any Google tracking
- Facebook Pixel, LinkedIn Insight, or any ad-platform pixels
- Tracking cookies of any kind (no consent banner is needed because there’s nothing to consent to)
- Browser fingerprinting
- Cross-site tracking or remarketing tags
- Email marketing tools that profile your behavior
- Data brokers — we have never sold your data, and we never will
04How We Use Your Information
We use the information we collect for these specific purposes:
- Account access. Your provider ID and email let us authenticate you and maintain your dashboard session.
- Delivering themes. We store which themes you own so you can download them from your dashboard.
- Processing payments. Linking Polar purchase confirmations to your account so themes appear automatically after checkout.
- Account management. Showing your order history, subscription status, and plan details in the dashboard.
- Improving our site. Aggregated, anonymous usage data from the marketing site helps us see which pages work and fix what doesn’t.
- Legal obligations. Where we’re required to keep records for tax or other legal reasons.
We don’t use your data to build behavioral profiles, train AI models, or sell to anyone.
05Legal Basis for Processing (GDPR)
If you’re in the EU, UK, or another region covered by the GDPR, we process your personal data under these legal bases:
- Contract — when you buy a theme or plan, we process the data needed to fulfill that agreement (your email, theme ownership records, payment confirmation).
- Legitimate interest — we run anonymous analytics on the marketing site to improve it. This has no impact on your privacy because the data is aggregated and cannot identify you. The dashboard itself does not run analytics.
- Legal obligation — keeping records where the law requires it, for example transaction records for tax.
You can object to processing at any time — see “Your Rights” below.
06Data Sharing
We don’t share your data with anyone for marketing, advertising, or profit. We do share the minimum data needed with a few third parties to run the service:
- Polar (polar.sh) — acts as our Merchant of Record, processing all payments, handling tax compliance, and generating invoices. Polar receives your payment details and email. Their privacy policy applies to their handling of that data.
- GitHub — used for authentication when you choose “Continue with GitHub.” We receive your public profile data (email, name, user ID). Their privacy policy applies.
- Google — used for authentication when you choose “Continue with Google.” We receive your basic profile data (email, name, subject ID). Their privacy policy applies.
- Cloudflare — hosts our website, dashboard, database (D1), session storage (KV), and theme files (R2). They may process basic request data (such as IP address) to serve pages and protect against abuse.
Apart from these operational processors, we never sell, rent, trade, or share your personal data with anyone — unless legally compelled to by a valid authority, in which case we’d share only what’s required.
07Data Retention
We keep personal data only as long as we need it:
- Account data — your email, name, and provider ID are kept as long as your account is active. If you delete your account, we remove this data within 30 days.
- Theme ownership records — kept as long as you own the theme, so you can download it. If you request account deletion, these records are removed with your account.
- Order records — kept for the duration of your subscription (if any) and a reasonable period after (typically 2–3 years) for reference, support, and tax purposes.
- Session data — your dashboard login session is stored as an encrypted token that expires after 30 days of inactivity.
- Analytics data — Umami stores aggregated data for up to 12 months, then it is automatically rolled up or deleted.
If you’d like something deleted sooner, email us and we’ll remove what we’re not legally required to keep.
08Data Security
We take reasonable steps to protect your data:
- We don’t store payment data at all — it never touches our systems. Polar handles all card information.
- We don’t store passwords — we use OAuth sign-in only. No password hashes, no password breaches possible.
- All data is encrypted in transit (TLS) and at rest (Cloudflare D1 and R2 encryption).
- Session tokens are httpOnly, Secure, and SameSite cookies — not accessible to JavaScript.
- Our hosting (Cloudflare) provides built-in protections including TLS encryption, DDoS mitigation, and bot protection.
- Access to our infrastructure is limited to the solo operator running LiteInk, protected by two-factor authentication.
No system is perfectly secure. If a breach ever affects your personal data, we’ll notify you and the relevant authorities as required by law.
09Your Rights
Depending on where you live, you may have the right to:
- Access — ask what personal data we hold about you.
- Correct — fix anything that’s inaccurate or incomplete.
- Delete — ask us to erase your personal data, subject to legal retention requirements. You can also self-serve this from the dashboard Settings page.
- Port — receive a copy of your data in a machine-readable format.
- Object or restrict — ask us to stop or limit processing of your data.
- Withdraw consent — disconnect a provider (GitHub or Google) from your account at any time.
To exercise any of these rights, email hi@liteink.co with your request. We’ll respond within 30 days, usually much faster. If you’re in the EU or UK, you also have the right to complain to your local data protection authority.
10International Data Transfers
LiteInk operates online with no single physical base. Our processors may handle data outside your home country:
- Polar, GitHub, Google, and Cloudflare may process data in the United States or their global infrastructure.
- Our database (Cloudflare D1) is hosted in the APAC region.
When your data crosses borders, it’s protected by the contracts those processors have in place (such as Standard Contractual Clauses for transfers out of the EU/UK). We choose processors that take data protection seriously.
11Children’s Privacy
Our products are aimed at developers and businesses. We don’t knowingly collect personal data from anyone under 18. If you believe a minor has sent us information, contact us and we’ll delete it.
12Changes to This Policy
We may update this policy from time to time. When we do, we’ll change the “Last updated” date at the top. If a change is significant, we’ll note it on the site or notify active customers directly. Continued use of our site after a change means you accept the updated policy.
13Contact Us
If you have any questions about this privacy policy or your personal data, we’d rather you ask than wonder.
Email: hi@liteink.co