Privacy Policy
Last updated: 7 June 2026
Who we are
This Privacy Policy explains how Little Hearts ("we", "us") collects, uses and shares your personal data when you visit our website or use our subscription service. For the purposes of data protection law, Little Hearts is the data controller for the personal data described below.
What we collect and why
| Category | Examples | Why we use it |
|---|---|---|
| Account data | Name, email address, password (hashed) | To create and secure your account and provide the Service (contract performance). |
| Subscription data | Plan, subscription status, renewal date | To give you the correct access to content (contract performance). |
| Support messages | The content of your messages to us | To respond to your questions (legitimate interests). |
| Usage & device data | Pages viewed, device type, browser, IP address | Security, fraud prevention, and improving the Service (legitimate interests). |
| Marketing preferences | Whether you've opted into emails | To send occasional updates if you've asked us to (consent). |
Payment details (card number, billing address, tax ID) are collected and processed by Paddle, not by us.
Cookies
We use essential cookies to keep you signed in and remember preferences. If we add analytics or marketing cookies, we'll ask for consent.
Who we share data with
- Paddle — our Merchant of Record for subscriptions, payments, tax compliance, invoicing, subscription management, and refunds. Paddle privacy policy.
- Service providers for hosting, database, email delivery, and support tooling.
- Professional advisers where strictly necessary.
- Authorities where required by law.
Retention, transfers, rights, and security
We keep personal data only as long as needed for the Service, legal obligations, security, and support. Some providers may process data outside the UK or EEA using safeguards such as Standard Contractual Clauses or adequacy decisions. Subject to applicable law, you may access, correct, delete, restrict, object to processing, request portability, withdraw consent, or complain to a supervisory authority. We use encryption in transit, access controls, and least-privilege administration to protect data.
Contact
For privacy questions or rights requests, contact us through the support form linked from the Service.