Privacy Policy

Effective 14 August 2026

This policy explains what Ignite Imprint collects, why, who it is shared with, and how to have it deleted. It is written to describe what the software actually does rather than what a template says it might.

Two kinds of people, two different answers

Most of this policy depends on which of these you are, so it is worth separating them at the start.

What we collect

Account information

An email address, a display name, and a password — stored only as a scrypt hash, never in a form we can read or recover. Which organisations you belong to and what role you hold in each.

What you create

Posts and their text and media, files you upload, the review conversation around them, and the record of where a post was sent. Uploaded images are re-encoded when they are stored, which removes embedded EXIF metadata — including the GPS coordinates a phone camera records by default.

Measuring reach — and what is deliberately not collected

When somebody follows a shared link, we record that a visit happened so the organisation can see whether their campaign reached anybody. We do not set a cookie for this and we do not store the visitor’s IP address.

Instead we store:

We do not build profiles, we do not track anybody across sites, and we do not sell or share this or any other data for advertising.

Cookies

Ignite Imprint sets one cookie, and only after you sign in. It holds your session, is marked httpOnly so no script on the page can read it, and is SameSite=Lax so your browser will not attach it to requests from other sites. It is strictly necessary to keep you signed in.

There are no analytics cookies, no advertising cookies, and no third-party tags on our pages. That is why you are not being asked to dismiss a consent banner.

Notifications

If you turn on push notifications, your browser gives us an endpoint URL and two keys, which we store so we can send you a message. You can turn this off at any time from your browser or from the application, and removing it deletes those records.

Why we are allowed to hold it

For people in the UK, the EU and the EEA, our lawful bases under the UK GDPR and the GDPR are:

Who else sees it

We do not sell personal information and we do not share it for cross-context behavioural advertising. We use these processors to run the service:

We may also disclose information where the law requires it. If we are ever compelled to do so we will tell the affected customer unless we are prohibited from doing that.

Where it is held, and for how long

Data is stored in the United States. If you are in the UK or the EEA, that is a transfer outside your region, made under the appropriate safeguards our processors maintain — Standard Contractual Clauses in each case.

We keep account data and content for as long as the account exists. When a subscription ends, the account enters a read-only period and is then deleted according to the schedule in our Terms. Files whose records are deleted are removed from storage by a sweep that runs continuously, so deletion reaches the actual bytes rather than only the database row.

Records we are required to keep for accounting and tax — invoices and payment records — are retained for the period the relevant law requires, typically seven years.

Your rights

Wherever you are, you can ask us for a copy of what we hold about you, ask us to correct it, or ask us to delete it. Write to privacy@igniteimprint.com.

If you are in the UK, the EU or the EEA

You have the right of access, rectification, erasure, restriction of processing, data portability, and the right to object to processing based on legitimate interests. Where we rely on consent, you may withdraw it at any time without affecting what was done beforehand. You also have the right to complain to your data protection authority — in the UK, the Information Commissioner’s Office.

If you are in California

Under the CCPA as amended by the CPRA you have the right to know what personal information we collect and why, the right to delete it, the right to correct it, and the right to opt out of its sale or sharing.

We do not sell personal information and we do not share it for cross-context behavioural advertising, and we have not done so in the preceding twelve months — including for anyone under sixteen. There is therefore nothing to opt out of, and no financial incentive is offered for personal information. Exercising any of these rights will not get you worse service.

If you were sent a link by somebody

The organisation that sent it decides what to do with the post itself, so requests about a post are best directed to them. As for what we record about your visit: the pseudonym described above rotates daily and cannot be tied back to you, which means that in practice we cannot find “your” visits in order to show them to you or delete them individually. That is a consequence of collecting as little as possible, and we would rather keep it that way than start holding something that would let us identify you.

Deleting your data

To have your personal data deleted:

  1. Email privacy@igniteimprint.com from the address on your account, with the subject “Delete my data”.
  2. We will confirm within 5 business days and complete the deletion within 30 days.
  3. We will tell you what was removed, and what had to be kept — accounting records we are legally required to retain, and audit entries recording actions taken in an organisation’s account, which are that organisation’s record rather than yours.

If you belong to an organisation’s workspace, ask an administrator to remove you from it. Deleting your personal account does not delete posts the organisation owns.

Children

This service is for organisations and is not directed at children. We do not knowingly collect personal information from anybody under sixteen. If you believe a child has given us information, write to us and we will remove it.

Security

Each customer’s data is separated at the database level rather than by application code, so a query in one account cannot return another account’s rows. Passwords are stored as scrypt hashes. Uploaded files are held in a quarantine area that nothing serves publicly until somebody has reviewed them. Session cookies cannot be read by scripts.

No system is perfect. If you find a security problem, please write to support@igniteimprint.com and we will respond.

Changes

If we change this policy in a way that materially affects you, we will tell account holders by email before it takes effect. The effective date is at the top.

Contact

KRDL Solutions, Winchester, VA, United States
privacy@igniteimprint.com