Privacy Policy
Last updated 8 July 2026
This is a plain-language summary; if it and the full policy below ever disagree, the policy wins.
Who we are
curltact is an independent project operated from Colorado, United States
(“curltact”, “we”, “us”, or “our”). This policy
explains what we collect when you use curltact.holtzhost.com and the edit portal, why, and the
choices you have. Questions or requests: contact@curltact.com.
What we collect
Account identity (from GitHub or GitLab)
You sign in with GitHub or GitLab. We never receive your password. From your provider we store a
stable account identifier (for example github:12345), your current username, and your
display name and email address if the provider exposes them. Email may be blank and the
account still works.
Card content you publish
The whole product is a public contact card at curltact.holtzhost.com/my-name. The name and
the lines you engrave are stored so we can render the card, and are served publicly by design.
Do not put anything on a card that you are not comfortable making public - a card
is meant to be curled by anyone. We host and render it; we do not mine it.
Billing information (handled by Paddle)
When you buy something, the sale is made and processed by Paddle.com Market Limited (“Paddle”), acting as the merchant of record and authorised reseller. Your purchase contract is with Paddle, not with us. We never see or store your card number, and we do not receive your billing address or full payment details.
What we send Paddle: when you start a purchase we send them your email address and your name if we have one, so they can create a customer record and send you your receipt. That happens when checkout opens, not when payment completes, so an order you abandon still leaves a customer record with them. If your sign-in does not give us an email address, we ask you for one at that point, and it is used for the receipt.
What Paddle sends us: that a purchase completed and which items it covered. From that we keep a customer identifier, your purchase status, your list of owned cosmetics, and the receipt details for the sale (an invoice number, the total, the tax, and when it was billed). Paddle issues your receipt and handles payment and tax under its own privacy policy and buyer terms.
Technical data
To keep you logged in and to protect the service, we store a session record with your session identifier, IP address, and browser user-agent, plus a small login cookie in your browser.
How we use it
Only to run the service: to log you in and let you edit your own card, to render and serve your card, to take payment and grant what you buy, and to keep things secure and prevent abuse. We do not use your data for advertising, profiling, machine-learning training, or any purpose beyond operating your account, and we do not sell it to anyone.
Who we share it with
Only the providers that make curltact work: GitHub / GitLab (login), Paddle (payments; we never receive your full card details), and our hosting provider (to store data and serve the site). Our fonts are served from our own domain, so no font provider sees your visit. We may also disclose data if the law requires it or to protect the service and its users. That is the whole list; we do not share your data with anyone else.
Reviewing or changing your data
You can view and edit your card, and buy the Extended Card, seals, or skins, from the edit portal at any time. To access, correct, or delete your account data, or if you have any privacy request, email contact@curltact.com and we will help. Depending on where you live you may have additional rights under your local law; we will honour those to the extent the law requires, and we will respond within the time your law allows (one month under UK/EU data protection law, 45 days under California law). If we cannot verify that a request came from the account holder, we may ask you to confirm it from the account you signed in with.
Cookies and Do-Not-Track
We use strictly necessary cookies only: a session cookie that keeps you logged in and a token that protects forms against cross-site request forgery. Your theme preference is stored in your browser and never sent to us. We set no advertising or analytics cookies and no tracking pixels. Because we do not track you across websites, we do not treat “Do Not Track” browser signals any differently - there is simply no cross-site tracking to turn off.
How long we keep it
We keep your account and card data while your account is active, and we may delete it after you close your account or delete your card. We may keep limited records, such as transaction records, for as long as we reasonably need them for legal, tax, or accounting purposes. Paddle keeps payment records under its own schedule.
Security
We protect your data with access controls, encrypted connections (HTTPS), and by keeping passwords out of our systems entirely. No method of storage or transmission is perfectly secure, but we keep the attack surface small. If we learn of a breach that affects you, we will let you know and take appropriate steps.
Children
curltact is not directed to children and is not intended for anyone under 13, or under 16 where your country sets a higher age for consenting to online services (several countries in the European Economic Area set it between 13 and 16). We do not knowingly collect data from children. If you believe a child has provided us data, contact us and we will delete it.
International users
We are based in the United States and our data is processed here. If you use curltact from elsewhere, you understand your data will be processed in the United States, where privacy laws may differ from those in your country.
Changes to this policy
We may update this policy from time to time. When we do, we will revise the “Last updated” date above, and for material changes we will make a reasonable effort to notify you. Continued use after a change means you accept the updated policy.
Contact
Questions? Write to contact@curltact.com.
See also our Terms of Service.