Privacy Policy
What CastPDF stores, why, for how long, who processes it for us, and how to use your data protection rights.
Last updated
Contents
The short version
- We store what we need to run your account and generate your documents, and delete it on the schedule below.
- This website sets no cookies and runs no analytics or tracking. The dashboard uses two strictly necessary cookies: one keeps you signed in, the other protects your sign-in.
- We do not sell personal data and we do not show ads.
- Payments are handled by Paddle, our Merchant of Record. Your card details never reach our servers.
No customer data is used to train AI models, by us or by any subprocessor on our behalf.
Who is responsible
CONSUL INTERNATIONAL 1991 SH.P.K., trading as CastPDF, is the controller for the personal data described in this policy: your account, sign-ins, billing records, emails with us, and the logs of this website and the API. Our registered address is Taulantia Str. 1, 2001 Durrës, Albania. Our company registration number is NIPT M61319502J (National Business Center, Albania). You can reach us about privacy at [email protected]. We have not appointed a data protection officer; the privacy address reaches the person responsible for data protection.
The templates, data and documents you process with CastPDF may contain personal data of other people, such as the customers named on your invoices. For that data, you are the controller and we are your processor: we handle it only to provide the Service, under the Data Processing Agreement. If you are one of those people, please contact the business that sent you the document.
Which law applies
We apply the standard of the EU General Data Protection Regulation (GDPR) and the UK GDPR to all personal data we process, wherever the person it is about lives. The article references in this policy are to the GDPR. As an Albanian company, we also comply with Albanian Law no. 124/2024 "On personal data protection", which follows the GDPR.
Visiting this website
This website is a set of static pages. It sets no cookies, loads no third-party scripts, fonts or images, and runs no analytics, tracking pixels or advertising. The web server records each request (IP address, requested page, time, browser user agent and referring page) in its access log, which we use only to keep the site running and secure. These logs are kept for 14 days.
Using the dashboard and the API
When you sign up and use CastPDF we process:
- Account data: your email address, optional name and password. The password is never stored: we keep only an argon2id hash of it.
- Sign-in data: while you are signed in to the dashboard, a session record with a hash of the session token, the IP address and browser user agent you signed in from, and when it was last used.
- API keys: we store a SHA-256 hash of each key and its first 14 characters, so you can tell keys apart. The full key is shown to you once, when it is created.
- Your content: templates (their HTML, CSS, sample data and settings), the data and HTML you send to generate documents, the PDFs we generate, and the log of your documents, including any file name and metadata you send.
- Usage and billing: your plan, monthly usage counts, spending cap, and the ids Paddle gives your customer record, subscription and transactions.
- Server logs: for each API request, the method, path, host, IP address, status and timing, details of errors, and the browser's user agent and the referring page, where your browser sends them. Our logs never contain request bodies, API keys, passwords, session tokens or the signatures of download links.
- Emails with us: what you write to us and our replies. They are stored by our mailbox provider, listed under Who processes data for us.
How long we keep it
We delete data automatically on the schedule below. The cleanup job runs every 10 minutes.
| Data | What exactly | Kept for |
|---|---|---|
| Account | Email address, name (optional), password as an argon2id hash, when the email was verified, the last sign-in time, and your workspace (its name and plan). | Until the account is deleted. |
| Sign-in sessions | A SHA-256 hash of the session token, the IP address and browser user agent at sign-in, created and last-seen times. | 30 days after the last use (each use extends it), or until you sign out or reset your password. |
| Email verification and password-reset links | A SHA-256 hash of the token, its purpose and expiry. | Verification links expire after 24 hours, reset links after 1 hour; the record is deleted once expired, or 24 hours after use. |
| API keys | A SHA-256 hash of the key, its first 14 characters (shown to identify it), name, mode and dates. | Until the account is deleted (a revoked key is kept, disabled, so the log can still name it). |
| Templates | Name, HTML, CSS, sample data and settings of each version. | The latest 50 versions of each template, plus the pinned one; older versions are deleted on save. A deleted template is removed from the dashboard and the API at once; it and its stored versions are erased 30 days after you delete the template, or when the account is deleted, whichever comes first. |
| Generated PDFs | The PDF file, when it is stored: always for live keys and the dashboard’s Generate PDF button, and for test keys only with "response": "url" or an Idempotency-Key. Previews and other test renders are never stored. | Your plan’s file retention (table below), then the file is deleted. |
| Document log | Per document: status, page count, size, mode, template and version, file name, error code, request id, time, and the metadata you sent. | Metadata: 30 days. The rest of the record: 120 days (and never before its PDF is deleted). |
| Request data | The data, html and css you send to render a document. | Not stored: used in memory to render the PDF, which is stored as described above. |
| Idempotency keys | The key you sent and a SHA-256 hash of the request. | At least 24 hours, then deleted by the next cleanup run. |
| Billing | Paddle customer and subscription ids, plan, billing interval and status, monthly usage counts, overage charges and their Paddle transaction ids. | Until the account is deleted; invoices and payment records are kept by Paddle as Merchant of Record. |
| Paddle event payloads | The subscription and transaction events Paddle sends us, which include your billing contact details. | 90 days after receipt. |
| Outgoing email queue | The email address and the message of the billing and usage emails we send you, kept so a failed send can be retried. | Deleted 30 days after sending. |
| Server logs | Per request: method, URL path, host, IP address, status and timing, error details, and the browser's user agent and the referring page, where your browser sends them. Never request bodies, API keys, passwords, session tokens or the signatures of download links. | 14 days |
| Backups | Encrypted copies of the database (everything above except PDFs, which are not backed up), with a key we keep offline. | On our own server (netcup GmbH, Nuremberg, Germany) only: the last 14 daily and 4 weekly copies, so none is older than 30 days. There is no off-site copy yet. |
Stored PDFs are kept for your plan's file retention:
| Plan | Stored PDFs are deleted after |
|---|---|
| Free | 1 day |
| Starter | 7 days |
| Growth | 30 days |
| Pro | 90 days |
| Scale | 90 days |
| Test-key documents (any plan) | 1 day |
Account deletion is available on request by email: write to [email protected] from the email address of your account (there is no self-service delete button yet). We then erase your account, templates, documents and billing records from our live systems within 30 days, except records we must keep by law. Copies in backups are deleted when the backups age out under our backup retention: backups are encrypted on our own server (netcup GmbH, Nuremberg, Germany) with a key we keep offline, and kept for at most 30 days; there is no off-site copy yet. Invoices and payment records are kept by Paddle under its own legal obligations.
Why we use it (legal bases)
- To provide the Service under our contract with you (GDPR Art. 6(1)(b)): your account, sign-in, generating and storing documents, billing, and the emails that belong to them.
- For our legitimate interests (Art. 6(1)(f)): keeping the Service secure and available (logs, rate limits, abuse prevention), fixing problems, and answering your emails. We keep these uses narrow and the data short-lived.
- To comply with the law (Art. 6(1)(c)): for example keeping records we are legally required to keep, or answering lawful requests from authorities.
We do not use consent-based processing: there are no marketing emails, no optional cookies and no tracking to consent to.
Cookies and browser storage
- This website sets no cookies and stores nothing in your browser.
- The dashboard sets two strictly necessary cookies.
__Host-castpdf_sessionkeeps you signed in. It holds a random token and expires 30 days after your last use of the dashboard, or when you sign out.__Host-castpdf_deviceis a security cookie set when you sign in: it holds your user id, the time it was set and a signature, and expires 180 days after it was set (it stays when you sign out). It lets a browser you have signed in from before keep signing in while someone else is trying wrong passwords for your account. Both areHttpOnly,SecureandSameSite=Lax. Because they are strictly necessary, they need no consent banner. - The dashboard also uses your browser's session storage, which is deleted when you close the tab, for: a safety copy of a template you are editing but have not saved yet, a verification link's token while you sign in to confirm your email, the state of a checkout in progress, and the starter template you picked on this website (
castpdf.pendingStarter: the template's short name, your user id and whether you just signed up in that tab), which is cleared once it has been used or when you sign out. - Checkout: Paddle's checkout script is loaded from Paddle when you open the billing page and a checkout is available (you have no active subscription, or you arrive from a Paddle payment link). Paddle may store its own data in your browser for payment and fraud prevention; Paddle's privacy notice covers it.
Emails
We send only transactional emails, through SMTP2GO: email address verification, password reset links, and notices about your subscription, payments and usage, and a security notice when someone tries many wrong passwords for your account. We do not send newsletters or marketing emails. Paddle sends its own receipts and invoices.
Payments
Paddle.com is our Merchant of Record. When you buy a subscription, you enter your payment and billing details on Paddle's checkout, and Paddle processes them as an independent controller under its own privacy notice. We receive and store only the ids of your Paddle customer record, subscription and transactions, and the subscription status. Paddle sends us subscription and transaction events, which include your billing contact details; we delete them 90 days after we receive them.
Who processes data for us
These processors handle personal data on our behalf, each only for the purpose shown and under a written agreement with us. The content of your templates and documents is processed only by the processors the table lists for it: the hosting provider, Cloudflare (which carries every request and response between you and our servers, encrypted to and from it), our mailbox provider (only what you put in an email to us) and, once it is in use, Google. SMTP2GO receives account email addresses only.
| Processor | Purpose | Personal data it receives | Location | Status |
|---|---|---|---|---|
| netcup GmbH | Server hosting: runs the API, the renderer, the database, stored PDFs and the encrypted database backups | All data the Service stores and processes, including template and document content | Nuremberg, Germany | In use |
| Cloudflare | Content delivery network, TLS termination and DDoS protection in front of the website, the dashboard and the API, and routing of email sent to our contact addresses | All requests and responses in transit, including IP addresses, template and request content and generated documents, and the email you send to our contact addresses; it caches only the public website | Global edge network (company based in the United States) | In use |
| Google Cloud EMEA Limited (Google Workspace) | Receives and stores the email you send to our contact addresses | The email you send to our contact addresses and our replies, including anything you put in them | Ireland (contracting company); the mail may be stored and processed in other countries where Google operates, including the United States | In use |
| SMTP2GO (Sand Dune Mail Ltd) | Transactional email (account verification, password reset, billing notices) | Account email addresses and the content of our transactional emails only | The data centre of our account region: the European Union (Amsterdam), the United States or Australia; company based in New Zealand | In use |
| Google (Gemini API) | AI template generation (not in use yet; only once the feature ships) | None today; once in use, the prompts and template content sent for generation | United States | Planned: not in use yet, no data is sent |
Paddle is not our processor. As Merchant of Record it sells the subscription to you and processes your buyer and payment details as an independent controller, under its own privacy notice (see Payments):
| Company | Purpose | Personal data it receives | Location | Status |
|---|---|---|---|---|
| Paddle.com Market Limited | Merchant of Record: checkout, payments, taxes, invoicing and refunds | Buyer name, email, billing address and payment details, which you give Paddle at checkout | United Kingdom | In use |
The Google (Gemini API) entry is planned for a future AI template feature and is not in use: no customer data is sent to Google today. Before it is used, we will update this list and notify customers as the Data Processing Agreement requires.
We share personal data with others only when the law requires it (for example a valid order from a court or authority), or to protect the Service and its users from fraud or abuse. We do not sell or rent personal data.
International transfers
We are established in Albania. The European Commission has not decided that Albania protects personal data adequately, so personal data of people in the EEA, the UK and Switzerland that we receive is protected by the Standard Contractual Clauses (with the UK Addendum and the Swiss amendments). Our servers are in Nuremberg, Germany. netcup GmbH hosts them.
Some processors are in other countries, as the table above shows. When personal data from the European Economic Area, the United Kingdom or Switzerland is transferred onward to a country without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses (with the UK Addendum and the Swiss amendments where they apply) or another lawful transfer mechanism. Transfers from Albania to countries that Albanian law does not consider adequate are protected in the same way. You can ask us for a copy of the relevant safeguards at [email protected].
How we protect it
Connections are encrypted with TLS; passwords are hashed with argon2id; API keys and session tokens are stored only as hashes; the rendering service runs isolated from our internal network; backups are encrypted as they are written, with a key we keep offline, so the server alone cannot read them; and logs leave out request bodies and secrets. The full list is in Annex 2 of the Data Processing Agreement.
Your rights
Depending on where you live, you have the right to:
- access the personal data we hold about you and get a copy of it;
- have inaccurate data corrected;
- have your data deleted;
- restrict or object to our processing, including processing based on our legitimate interests;
- receive your data in a portable format;
- complain to a data protection authority (see Complaints below).
To use these rights, including deletion of your account, email [email protected] from the email address of your account. We may need to confirm your identity. We answer within 30 days. Your templates and documents can be read and downloaded at any time through the dashboard and the API. Templates can be removed from use there. Stored PDFs are deleted automatically when their retention period ends, and everything is erased when your account is deleted (on request by email).
Complaints
If you think we have handled your personal data unlawfully, please contact us first at [email protected]. You also have the right to complain to the Albanian supervisory authority, the Commissioner for the Right to Information and Personal Data Protection (IDP), Rr. "Abdi Toptani", Nd. 5, 1001 Tirana, Albania, https://idp.al. If you live in the European Economic Area, the United Kingdom or Switzerland, you may instead complain to the data protection authority where you live, work, or where the issue happened.
Children
CastPDF is a service for businesses and developers and is not directed at children. You must be at least 18 years old to create an account.
Changes to this policy
When we change this policy we update the "Last updated" date above. For material changes, such as a new subprocessor or a new use of your data, we email account owners at least 30 days in advance.
Contact
Privacy questions and requests: [email protected]. Postal address: CONSUL INTERNATIONAL 1991 SH.P.K., Taulantia Str. 1, 2001 Durrës, Albania.