1. Who we are
The operator of Preschoolearn.com ("the Service", "we", "us") and the controller of your personal data is Katarzyna Woźniczko-Kajda, conducting business under that name, registered in the Polish Central Registration and Information on Business (CEIDG), NIP PL6372084605, address: ul. Zachodnia 15/81, 30-350 Kraków, Poland.
Contact for any privacy matter: contact@preschoolearn.com.
Because we are established in the European Union, the General Data Protection Regulation (GDPR) applies to everything described here, wherever you live. If you are a resident of a US state with a comprehensive privacy law, section 10 sets out the additional rights you have.
We have not appointed a Data Protection Officer; privacy requests are handled by the operator at the address above.
2. What we collect, why, and on what legal basis
| What | Why | Legal basis (GDPR) | How long we keep it |
|---|---|---|---|
| Account details: email address, username, password (hashed), first and last name | To create and run your account and give you access to the material you paid for | Art. 6(1)(b) — performance of a contract | For as long as the account exists. Write to us to close it and we delete it, except for what the row below obliges us to keep |
| Billing details: name, address, country, and the payment token / card brand and last four digits held by the payment processor | To take payment and to renew a subscription | Art. 6(1)(b) — performance of a contract; Art. 6(1)(c) — tax and accounting obligations | 5 years from the end of the tax year in which the payment was made (Polish tax law) |
| Order history and invoices | Accounting, and answering questions about a past order | Art. 6(1)(c) — legal obligation | 5 years from the end of the tax year |
| Newsletter address and subscription status, with the time, IP address and form of the sign-up | To send the newsletter and the free guide you asked for, and to be able to show that you asked | Art. 6(1)(a) — consent | Until you unsubscribe, then a suppression record so we do not email you again |
| Server logs: IP address, browser, requested URL, timestamp | Keeping the Service running and secure | Art. 6(1)(f) — legitimate interest in security | [[RETENTION — commonly 30–90 days; confirm with the host]] |
| Failed sign-in counters (by account and by IP) | Blocking password-guessing attacks | Art. 6(1)(f) — legitimate interest in security | 15 minutes to a few hours (the lockout window) |
| Analytics and advertising identifiers, page views, purchase events | Measuring how the Service is used and how well our advertising works | Art. 6(1)(a) — consent (see section 8) | Per the retention set in the tool; typically 14 months for Google Analytics |
Closing an account does not wipe the order history: invoices sit under a tax obligation we cannot waive (the row above), so they stay for the statutory period and are then deleted. Everything else goes when the account goes.
We do not sell personal data, and we do not use it to make decisions that have a legal or similarly significant effect on you (see section 12).
3. Children
The Service is sold to and used by adults — teachers and parents. It is not directed to children, and we do not knowingly collect personal data from anyone under 16 (under 13 in the United States, for the purposes of COPPA). The material on the site is *about* teaching children, but children do not have accounts here.
If you believe a child has provided us with personal data, write to contact@preschoolearn.com and we will delete it.
4. Who else sees your data
We share personal data only with the processors that make the Service work, and only to the extent each needs:
- Hosting —
[[HOSTING PROVIDER AND COUNTRY]], which stores the site, its database and its backups. - Payments — Stripe and PayPal, which handle checkout and renewals. They receive your name, email address and billing details, and they hold the card data; we never see or store a full card number — only the card brand and its last four digits, so we can show you which card is on file.
- Cookie consent — CookieScript, which shows the consent banner and stores your choice.
- Analytics and advertising — Google (Analytics, Ads, Tag Manager) and Meta (Pixel and Conversions API), **only after you consent to the marketing category** in the cookie banner. See sections 8 and 9.
- Sign-in providers — Facebook and Google, if you choose to sign in with them (section 6).
Two things we do not hand to anyone:
- The newsletter list stays on our own server. We run the newsletter from the site itself rather than through an external mailing service, so your address is not copied to a third-party platform.
- Transactional email (order confirmations, renewal notices, password resets) is sent by our own server through `[[MAIL SENDER — confirm with the host whether an external SMTP service is used]]`.
We also disclose data where the law requires it — for example, to a tax authority or in response to a lawful order.
5. Payments, including recurring payments
Checkout and renewals are handled by our payment processors. When you subscribe:
- you enter your card details on the processor's side, not ours;
- the processor returns a token to us, and that token — not your card number — is what we store and use for the automatic renewal;
- we keep the card brand and the last four digits so we can show you which card is on file.
Your subscription renews automatically until you cancel it. We email you seven days before each renewal. You can cancel at any time from your account, and you keep access to the end of the period you have already paid for.
6. Signing in with Facebook or Google
You may create an account or sign in using Facebook or Google. If you do:
- we receive from the provider your email address, your name, and the provider's own identifier for you;
- we do not receive your password with that provider, and we cannot post anything or read anything else from your account there;
- what the provider itself records about that sign-in is governed by *their* privacy policy, not this one.
7. Security
Measures we apply, in plain terms:
- the whole site is served over HTTPS;
- passwords are stored only as salted hashes, never in a readable form, and must meet a minimum strength policy;
- repeated failed sign-ins lock the account and the source IP address temporarily;
- the sign-in flow ties each attempt to the browser that started it, so a login link cannot be handed to you by somebody else;
- pages that show your own data are never stored in a shared cache;
- access to the administration panel is limited to the operator.
No system is perfectly secure. If a breach ever affects your data, we will notify the supervisory authority within 72 hours and notify you where the law requires it.
8. Cookies and similar technologies
We set cookies in four categories. Only the first is set without your consent:
| Category | What it does | Set before consent? |
|---|---|---|
| Strictly necessary | Signing in, keeping your session, remembering your cookie choices, security tokens | Yes — the Service cannot work without them |
| Performance | Aggregate measurement of how pages are used | No |
| Targeting | Advertising measurement and audiences (Google Ads, Meta) | No |
| Functionality | Remembering preferences such as your chosen view | No |
You can accept, refuse, or change your choice at any time through the cookie banner and the "Opt-out preferences" link in the footer. Refusing anything other than the strictly necessary category does not restrict your access to the material.
Your browser also lets you block or delete cookies entirely; blocking the strictly necessary ones will prevent you from signing in.
9. Analytics and advertising
Only after you consent to the marketing category:
- Google Analytics 4 measures how the Service is used. Data is collected under Google Consent Mode, which withholds it until you decide.
- Google Ads measures which advertising leads to a subscription. Where we send an identifier for enhanced conversions, it is a SHA-256 hash of your email address, never the address itself.
- Meta Pixel and Conversions API measure the same for advertising on Facebook and Instagram. Identifiers are hashed before they are sent, and the server-side channel checks your consent independently of the browser one.
If you refuse the marketing category, none of the above runs — neither in your browser nor from our server.
10. Your rights
Under the GDPR, you have the right to: access your data; correct it; have it erased; restrict how we process it; object to processing based on our legitimate interests; receive your data in a portable form; and withdraw consent at any time (which does not affect processing already carried out).
To exercise any of these, write to contact@preschoolearn.com. We answer within one month. You can also lodge a complaint with the Polish supervisory authority: Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warsaw, Poland.
If you are a resident of California, Colorado, Connecticut, Virginia, or another US state with a comprehensive privacy law, you also have the right to:
- know what categories of personal information we collect, use and disclose;
- access a copy of that information;
- correct inaccurate information;
- delete your information, subject to the retention obligations in section 2;
- opt out of the "sale" or "sharing" of personal information and of targeted advertising;
- not be discriminated against for exercising any of these rights;
- appeal a refusal, where your state law provides for an appeal.
We do not sell personal information, and we do not share it for cross-context behavioural advertising unless you have consented to the marketing cookie category. Withdrawing that consent in the cookie banner is the opt-out mechanism, and it takes effect immediately. We honour Global Privacy Control signals where your browser sends one.
To make a request, write to contact@preschoolearn.com with the email address on your account. We verify a request by confirming control of that address; for a deletion request we may ask for one further piece of information that matches our records. An authorised agent may act for you with written permission.
11. International transfers
We are established in Poland. Some of the processors listed in section 4 are established in the United States, so your data may be transferred there. Those transfers are made under the European Commission's Standard Contractual Clauses and, where the processor is certified, the EU–US Data Privacy Framework. You can ask us for a copy of the safeguards that apply to a particular transfer.
12. Automated decision-making and profiling
We do not make decisions about you by automated means alone that produce legal effects or similarly significantly affect you. We do use analytics to group visitors for advertising purposes, and only with your consent — you can withdraw it at any time through the cookie banner.
13. Forms and logs
Forms on the Service collect only what they say they collect, and each one states what the data is for.
When you subscribe to the newsletter we record, alongside your address, the time of the subscription, the IP address it came from, and which form you used — that record is our evidence that you asked for the newsletter, and it is what we would rely on if you ever asked us to prove it.
Messages sent through the contact form are emailed to us and not stored on the site; they live in our mailbox, and we delete them once the matter is closed.
The server keeps access logs. They are used for diagnosing problems and for security, and they are not combined with your account to build a profile of you.
14. Changes to this policy
We may update this policy — for example when we add a processor or a feature. The current version always carries an effective date at the top. Where a change materially affects your rights, we will tell you by email before it takes effect.