LEGAL & SUPPORT
Privacy Policy
Effective 9 September 2026
Littlepage respects your privacy. This policy explains what we collect, why we use it and the choices available to you.
Support and content reports
When you use the help form, we store the email address, topic, message, optional page address, request reference and submission time so we can review and reply. We forward the request to the Littlepage support inbox. Do not include passwords, sign-in links, session tokens or payment card details. Requests are removed from the application database after one year. Email copies may remain in the support inbox while needed to handle the request or meet legal obligations.
Email waitlists
When you join a page’s waitlist, we store the email address you submit, the waitlist card and the signup time for that page owner. The owner can view and export these signups; they are not displayed publicly. Littlepage does not verify these addresses. The owner can explicitly transfer selected signups to a connected email service and prepare an email draft there. Imports and tags may trigger automations the owner has configured with that service. Littlepage stores encrypted connection credentials and recipient snapshots for email preparations. Sending the campaign is completed in the connected service. Signups expire after one year through scheduled cleanup, including after a card is removed. You can request earlier removal using the form’s removal link or our privacy contact. Removing a card does not immediately erase its signups; deleting the owner’s account removes the stored signups, connection credentials and preparation history from Littlepage. Copies already transferred to an email service are managed by the owner in that service. Contact the page owner about their use of your email address or to request removal.
Page analytics
We count views of published pages, card visibility impressions and clicks on outgoing card links for page owners. Card impressions measure whether a card remained in the visible browser viewport long enough to count, once per page load. Repeat visits and repeat clicks count again; these event totals are not unique-visitor counts, sales or verified conversions. Analytics stores daily counts by page, card, outgoing social profile and broad traffic attribution, without analytics cookies, persistent visitor identifiers, stored IP addresses or browsing profiles. To limit fabricated activity, each page load uses a short-lived signed proof held only in browser memory. Our hosting provider applies temporary limits using rotating, cryptographically obscured network-address keys. We do not put the proof or those keys in the analytics database. For traffic attribution, the browser sends only the referring hostname (never its path or query) and the bounded utm_source, utm_medium and utm_campaign values present on the Littlepage address. Missing data is shown as unknown and visits with no external referrer or campaign are shown as direct. Separate event receipts prevent duplicate counting and are removed after about one day by daily cleanup; daily totals are retained for 365 days and removed when the page or account is deleted. Free accounts can view the latest 90 days. After a Plus downgrade, older retained analytics are hidden until Plus access returns or the data reaches its normal expiry. Upgrading cannot restore totals deleted before extended retention began on 21 September 2026. We inspect browser user-agent information to filter obvious bots and estimate broad device categories (mobile, tablet, desktop or unknown). We store only the category in analytics, not the user-agent string. Editor previews and visits opened from the owner analytics screen are excluded from views and impressions. Bot detection is practical rather than perfect: automated traffic may still be counted, and real activity may be missed when JavaScript or tracking requests are blocked, a proof expires, or abuse limits are reached.
Information we collect
When you create or use an account, we collect your email address, account identifier and authentication information. We also store the page content and images you choose to upload, including drafts and published versions.
Our hosting and authentication providers may process technical information needed to operate and secure the service, such as IP address, browser or device details, request times and diagnostic logs. We do not currently use advertising cookies, behavioural advertising or third-party analytics.
How we use information
We use information to create and secure accounts, save and publish your pages, deliver requested features, prevent abuse, diagnose faults, respond to support or legal requests and comply with law. We do not sell personal information.
What becomes public
Your email address and private drafts are not displayed on your published page. When you publish, the selected page address, profile content, enabled links and chosen images become publicly available. Search engines and other people may copy or retain public material after you change or remove it.
Cookies
Littlepage uses essential authentication cookies to keep you signed in and protect account access. These cookies may remain for up to 400 days and are refreshed while your session remains valid. You can remove them by signing out or clearing browser data, but doing so will require you to sign in again.
Service providers and overseas processing
Cloudflare provides website hosting, database and image storage. Supabase provides account authentication from its Sydney region. These providers may process operational data in Australia and other countries through their global infrastructure. We disclose information only as needed to run the service, protect users, comply with law or complete a business transfer subject to appropriate safeguards.
Retention and security
We retain account information and saved content while your account is active or as reasonably needed to provide the service, resolve disputes and meet legal obligations. Unused uploads are removed after a limited cleanup period. When you delete your account, we remove your pages and uploaded images from active systems and request deletion of the authentication account, subject to short technical, security or legally required retention.
We use access controls, encrypted connections and managed infrastructure to protect information. No internet service can promise absolute security.
Your choices and rights
You can edit or unpublish page information from your dashboard and delete your account from account settings. You may also ask for access to or correction of personal information, or make a privacy complaint. We will respond within a reasonable period.
Children
Littlepage accounts are intended for people aged 18 or older. Do not create an account if you are under 18.
Contact
Email hello@getlittlepage.com with privacy questions or complaints. If you are not satisfied with our response and Australian privacy law applies, you may contact the Office of the Australian Information Commissioner.
Changes
We may update this policy as the service changes. We will post the new effective date here and provide additional notice when a change materially affects how we handle personal information.
Payments
When paid checkout is available, Paddle handles payment details as merchant of record. We store Paddle customer, transaction and subscription identifiers, payment-period dates and subscription status to manage access and billing. We do not store card numbers. Minimal billing records may remain after account deletion for reconciliation and legal obligations; your pages, uploads and waitlist data follow the deletion process described above.