Privacy Policy
Published 2026-08-10. Grounded in the actual data inventory: CLAUDE/14-data-secrets-inventory.md. This is our own policy statement, not legal advice.Last updated: 21 August 2026
Jhonnie James Tech ("we", "us") operates this website-building platform (the "Service") — including this site and websites created by our users. This policy explains what personal data we collect, why, and your rights over it. We aim to comply with Singapore's Personal Data Protection Act (PDPA) and to align with the EU GDPR.
What we collect, and why
| Data | Source | Why (legal basis) |
|---|---|---|
| Account data — email address, name, password (stored as a hash) | you, at registration | to provide your account (contract) |
| Social-login identifiers (Google/GitHub/Discord/X), if you sign in that way | the provider you choose | to authenticate you (contract) |
| Two-factor authentication secrets and recovery codes, if you enable 2FA | you | account security (contract / legitimate interest) |
| Your page content — text, settings, layouts, themes, and images you upload | you, while building pages | the core Service: hosting and displaying your pages (contract). Content you publish on your public page is visible to anyone. |
| Social interactions — profile likes | you | Service features (contract) |
| Order/booking/lead details — names, contact details, delivery addresses submitted through commerce or contact components on user pages | visitors who submit them | fulfilling the order/booking/enquiry the visitor requested (contract with the page owner; we process on their behalf) |
| Camera-derived data, if you use vision/scanner components — object/face detections processed to power the feature | you, live from your camera | only with your action; used solely for the feature. Face-derived data is treated as sensitive: kept minimal and short-lived. |
| Technical/error telemetry — truncated error events with request context | automatic | keeping the Service working (legitimate interest). Retained ~90 days. |
| Payment data | Stripe | payments are processed by Stripe; card numbers never touch our servers (Stripe-hosted checkout). We keep only order metadata. |
We do not sell personal data, run third-party advertising, or use third-party analytics cookies.
Cookies
Only functional cookies: your sign-in session (and, if you enable it, a trusted-device token for 2FA). No tracking or advertising cookies. Because we use only strictly-necessary cookies, no consent banner is required; if that ever changes, we will ask first.
Automated processing and AI features
Some parts of the Service use machine learning. None of it makes a decision with a legal or similarly significant effect about you, and none of it profiles you. Each feature runs only when you choose to use it.
| Feature | Where the processing happens | What leaves our servers |
|---|---|---|
| Transcriber — speech-to-text from a video link | on our own servers, using a local Whisper model | nothing. We fetch the media from the URL you give us, so that host sees our server's address, not yours. The transcript is stored against your account. |
| Object and face detection in vision/scanner components | in your own browser (TensorFlow.js) | the video never leaves your device. Your browser downloads the model files from Google's model CDN, so Google sees your address when you start the feature. |
| Depth estimation in the particle-face component | in your own browser | as above, the model file (~50MB) is downloaded from the Hugging Face CDN on first use. |
| LEGO part identification | our server forwards the photo | your photo is sent to Brickognize to identify the part. Do not scan anything you would not want to share. |
| Automated comment replies | our own servers | nothing. These are rule-based — a keyword matches a reply you wrote yourself. There is no language model, so it cannot generate an answer of its own. |
We do not train any model on your content, and we do not send your account data, page content, or messages to a third-party AI provider.
If you are in crisis, please contact your local emergency services or a crisis line — in Singapore, the Samaritans of Singapore on 1767. Our automated replies are not a support service and cannot help you.
Who else processes data (our processors)
Infrastructure
- Hostinger International Limited — servers in Singapore where the Service and its databases run
- Cloudflare — DNS/CDN/security in front of the Service, where enabled
- GitHub — private source-code hosting (no user databases)
- Let's Encrypt — TLS certificates (public certificate transparency logs include our domain names)
Called by our servers, on your behalf (these see our server's address, not yours)
- Stripe — payment processing (when payments are enabled)
- Brickognize — receives a photo you scan with the LEGO part identifier
- Google Places — business profile and review data, when a page owner connects their Google listing to the review components
- Telegram and Meta (Facebook/Instagram) — only where a page owner connects that channel, to deliver the replies they configured
Contacted by your browser (these see your address)
- Google's model CDN and the Hugging Face CDN — machine-learning model files, downloaded only when you start a vision, scanner or particle-face feature. See the AI table above.
- Whatever a published page embeds — a page owner may embed images or video hosted elsewhere, and your browser fetches those directly from that host. We do not control those hosts.
Fonts used to belong in this last group and no longer do: every typeface is served from our own servers, so no font request reaches a third party.
We have or will put data-processing agreements in place with each processor. We do not transfer personal data internationally beyond these providers' documented locations.
How long we keep things
- Account + page content: while your account exists, then deleted within 30 days of account deletion (see rights below)
- Orders/bookings and other data collected through page forms: 365 days by default, and up to 7 years where tax or business records require it, then deleted or de-identified
- Error telemetry: ~90 days
- Backups: encrypted, rotated within 365 days; deleted data leaves backups as they rotate
Your rights
You may, at any time:
- Access / export — get a copy of your account data and page content
- Correct — fix inaccurate data (mostly self-serve in the editor)
- Delete — delete your account and content (30-day grace, then permanent)
- Withdraw consent — for anything based on consent (e.g. camera features: just stop using them; nothing is retained beyond the feature's operation)
- Complain — to us first, and to the PDPC (Singapore) or your local authority if we let you down
Export and deletion are self-serve. Sign in and go to Account → Security → Your data:
- Export downloads one JSON file containing your account, pages, content and app data.
- Delete my account schedules permanent deletion after a 30-day grace period. You can cancel it from the same place at any point during those 30 days. Deleting takes the same number of steps as signing up did.
For anything else — correction, a complaint, or a question about a page somebody else published — email web3toolsdotfun@gmail.com. We respond within 30 days.
Security
TLS everywhere; passwords hashed; least-privilege database access; encrypted secrets; firewalled infrastructure; access limited to the operator; tested backups. No system is perfect — if a breach affecting you occurs, we will assess and notify as the PDPA requires (and within 72 hours where GDPR applies).
Users' visitors
Our users' published pages may collect data from THEIR visitors (e.g. an order form). For that data the page owner is the controller and we are the processor/host. Visitors should direct requests to the page owner — and may also contact us at web3toolsdotfun@gmail.com; we will assist either way.
Children
The Service is not directed at children under 13, and we do not knowingly collect their data. Pages made for children — a party invitation, for example — are created and controlled by an adult account holder, who is responsible for what those pages collect.
Changes
We will post changes here with a new "last updated" date; material changes get an in-product notice.
Contact: Jhonnie James Tech · Singapore · web3toolsdotfun@gmail.com
Data Protection Officer: Jhonnie James · web3toolsdotfun@gmail.com