This Privacy Policy explains how Reedster LLC ("8pagezine", "we", "us", or "our") collects, uses, and shares personal information when you use 8pagezine, our browser-based zine maker and marketplace at 8pagezine.com (the "Service"). We are the controller of the personal information described here. If you have questions or want to exercise your privacy rights, contact us at [email protected].
Last updated: July 27, 2026
This document is provided for transparency and to help you understand our practices. It is not legal advice. Please read it alongside our Terms of Service.
Quick summary
Here is the short version. The rest of this policy has the detail.
- You can start making a zine without an account. If you create an account, we collect your email, an optional display name, and a securely hashed password.
- We keep the content you create (your design text and uploaded images) and, for security, we record sign-in timestamps and sign-in IP addresses.
- Payments are handled by Stripe. Card details are entered on Stripe and never reach our servers. We store limited order information such as the buyer's email, the amount, and receipt tokens.
- We do not use advertising, analytics, tracking pixels, or session-replay tools, and no third-party trackers. We use only strictly necessary first-party cookies (chiefly to keep you signed in). Because none require consent, we show a brief informational cookie notice rather than a consent banner that asks you to accept or reject.
- We do not sell your personal information, and we do not share it for cross-context behavioral advertising.
- Content is private by default. It becomes public only when you choose to publish it or share a link. Share links, reader links, and file links are unguessable but do not expire and cannot be revoked in the app, so treat them like passwords.
- You can delete your account yourself. Some purchase records may persist after that; for a complete erasure request, email [email protected].
Scope
This policy applies to the 8pagezine website and Service. It does not apply to third-party services we rely on that have their own privacy policies (for example, Stripe's hosted checkout page), or to zines and storefronts operated by creators once you interact with them outside our Service. Creators are the sellers of their own zines. We provide the platform. See Terms of Service for more on that relationship.
Information we collect
Account information
When you sign up, we collect your email address and a password. You may also provide an optional free-text display name (a handle). Passwords are hashed with bcrypt and are never stored in plaintext. Each account has an internal unique identifier. Email confirmation is required, and if you change your email address you must confirm the new one before it takes effect.
Authentication and security data
To keep accounts secure and to support features like remember-me and account recovery, we record login activity for each account, including:
- your sign-in count;
- your current and last sign-in timestamps; and
- your current and last sign-in IP addresses.
These sign-in IP addresses are stored in our database and are overwritten by the next login. We do not run a separate purge schedule for them, so the two most recent addresses persist until replaced. Password reset links expire six hours after they are issued.
Creator storefront profile
If you open a creator storefront, we collect the profile fields you provide: a store name, a bio (up to 500 characters), a tag, and an automatically generated URL slug. When your store is listed, these fields are public. If you set an optional store password to make your store private, it is hashed with bcrypt. This store password is separate from your login password and has no recovery flow, so if you forget it you will need to set a new one.
Content you create
The zines you make are stored as a design "document" in JSON, along with any images you upload. Your design document can contain arbitrary text that you type, which may include personal information if you choose to include it. It is your choice what to put in your zine. Uploaded images may be JPEG, PNG, WebP, or GIF, up to 100MB each; we verify the real file type from the file's bytes rather than trusting the declared type. When you export a zine, we create an immutable snapshot that includes a rendered PDF, print images, and a 1200x630 cover image used as the social sharing ("og:image") thumbnail.
Purchase information
When you buy a zine, payment is processed by Stripe. Card details are entered on Stripe and never touch our servers. After payment, we store only:
- the buyer's email address (provided to us by Stripe);
- the amount and currency (USD);
- the platform fee amount;
- a Stripe checkout session identifier;
- a paid-at timestamp; and
- unguessable receipt and download tokens.
If you are a creator who sells zines, you complete your own onboarding with Stripe. Your identity, bank, and tax details go directly to Stripe, not to us. When your connected Stripe account is created, your email address is sent to Stripe.
Information collected automatically
We collect very little automatically. We use only strictly necessary first-party cookies and a couple of browser storage keys for preferences (described under Cookies and similar technologies). We do not use analytics, advertising, tag managers, tracking pixels, session-replay tools, or any third-party trackers. Our web host processes standard request traffic, including IP addresses, in the course of serving the Service.
Information we receive from Stripe
After a successful payment, Stripe provides us with the limited order information listed above (including the buyer's email). Stripe's own processing of your payment and identity information is governed by Stripe's privacy policy.
How we use information
We use the information we collect to:
- Provide the Service, including saving your zines, letting you return to an anonymous design, and claiming anonymous work into your account when you sign in;
- Render and export your zines to print-ready PDFs, print images, and cover thumbnails;
- Operate the storefront and marketplace, including publishing listings you choose to publish and showing public "look inside" previews;
- Process payments through Stripe, deliver purchased zines, and pay out creators through Stripe Connect;
- Send transactional email (see Email);
- Keep the Service secure, including authentication, account recovery, abuse prevention, and rate limiting; and
- Comply with legal obligations and enforce our Terms of Service.
Legal bases for processing (GDPR)
If you are in the European Economic Area (EEA) or the United Kingdom (UK), we process your personal information under the following legal bases:
- Performance of a contract: to create and operate your account, save and render your zines, run your storefront, process purchases, and deliver zines you buy or sell.
- Legitimate interests: to keep the Service secure, prevent abuse, apply rate limiting, record sign-in activity for security, and monitor for errors. We balance these interests against your rights and freedoms.
- Consent: where you voluntarily include personal information in the content you create, and where you choose to make content public by publishing it or generating a share link. You can withdraw consent by removing that content or by contacting us. Please note that, as explained under Public content and links, share links and file URLs cannot be revoked in the app and do not expire, so anyone who already holds such a link may retain access to a copy even after you remove the underlying content.
- Legal obligation: to comply with applicable laws and respond to lawful requests.
Cookies and similar technologies
We use only first-party cookies that are strictly necessary or functional, plus a couple of browser storage keys for preferences. We do not use advertising cookies, analytics cookies, tracking pixels, or any third-party tracking technologies, and we do not load third-party trackers of any kind.
Under the EU/UK ePrivacy rules and GDPR, cookies that are strictly necessary to provide a service you have asked for do not require prior consent, and the ones we set that are not strictly necessary (such as remember-me or unlocking a private store) are placed only when you take that action. So rather than a consent banner that blocks the site and asks you to accept or reject cookies, we show a brief, dismissible informational cookie notice the first time you visit. Dismissing it stores a small preference key in your browser so we do not show it again; it sets no additional cookie and collects no personal data. The full list of what we use:
- Rails session cookie (encrypted, http-only, SameSite=Lax, marked Secure in production): keeps you signed in and holds the CSRF security token.
- Remember-me cookie (persistent login, roughly two weeks by default): keeps you signed in between visits, and is cleared when you sign out.
- Anonymous-design cookie ("anon_design_token", signed, http-only, SameSite=Lax, expires in 14 days): lets an anonymous user return to an unsaved zine. Only a hashed digest is stored on our side.
- Store-access cookie (signed, http-only, session-scoped): remembers that you unlocked a private storefront. Changing a store's password re-locks all visitors.
- Local storage key ("salz-zine:show-guides"): stores an on/off preference for editor guides in the browser. It contains no personal data.
- Local storage key ("salz-zine:cookie-notice-ack"): remembers that you dismissed the cookie notice so it is not shown again. It contains no personal data.
When you check out, Stripe's hosted checkout page (a different domain) may set its own cookies, which are governed by Stripe's privacy and cookie policies.
We send only transactional email: account emails such as confirmation, password reset, account unlock, and email-change or password-change notices, plus the order delivery email that gives buyers their download and read-online links. We do not send marketing or newsletter email, so there is no unsubscribe mechanism (none is needed for strictly transactional messages). Email is delivered on our behalf by Resend.
How we share information
We do not sell your personal information. We share it only in the limited ways described below.
Service providers (subprocessors)
We share personal information with the service providers listed under Subprocessors so they can perform services for us, such as processing payments, delivering email, monitoring errors, and hosting our application and data.
Public sharing you choose
Some information becomes public only because you choose to publish or share it. This includes your listed storefront profile (store name, bio, tag, and slug), the title, description, and cover art of issues you publish, and any content reachable through a share link you generate. See Public content and links.
Legal and safety disclosures
We may disclose information if we believe in good faith that it is necessary to comply with a law, regulation, legal process, or governmental request; to enforce our Terms of Service; or to protect the rights, property, or safety of 8pagezine, our users, or the public.
Business transfers
If we are involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, your information may be transferred as part of that transaction. We will continue to protect it and will provide notice as required by law.
Subprocessors
The following service providers may process personal information on our behalf:
- Stripe (payments and Stripe Connect payouts): processes the buyer's email and full card and payment information, and, for creators who sell, identity, bank, and tax details used for payouts.
- Resend (email delivery): processes recipient email addresses and the contents of transactional emails.
- Sentry (error monitoring, production only): processes error and diagnostic data. It is configured not to send personal data by default (no IP address, cookies, or user identity is attached, and email, tokens, passwords, and user-authored document text are filtered out of logs). An error message could still incidentally contain some data.
- Our hosting and database provider (a cloud host that also provides managed PostgreSQL and Redis): processes all request traffic, including IP addresses, and stores all application data.
- Object storage for uploaded images and generated PDFs: your files are stored on our hosting provider's infrastructure and/or S3-compatible object storage. The operator should confirm which storage backend is live.
Some components run entirely within our own infrastructure and do not send data to an outside third party: a headless Chromium browser that renders PDFs and share images from our own pages, Redis and background job processing, and self-hosted fonts (we do not use Google Fonts).
Public content and links
Content is private by default and is visible only to you (or to whoever holds the anonymous-design cookie for an unsaved zine). It becomes accessible to others only when you take one of these actions:
- Share link: You can generate a private share link that uses an unguessable 32-character token. Anyone who has that link can read the full zine and download the PDF. There is no way in the app to revoke or rotate a share link once it is created, and it does not expire. Treat a share link like a password.
- Publishing a listing: Publishing surfaces the issue on your public storefront, per-zine pages, the public marketplace, and a public "look inside" reader. Publicly exposed information includes your store name, bio, tag, and slug, and each published issue's title, description, and cover art.
- Preview mode: The public "look inside" respects the preview mode you set per listing: "preview" (cover plus first spread only), "full" (the whole issue), or "locked" (cover only). The paywall is enforced on our server, so locked pages and the images they reference are never sent to the browser.
Two honest notes about how this works:
- The marketplace lists opted-in ("listed") stores that have published issues. Private listed stores appear too, shown with a lock and gated on click. Unlisted stores never appear. Because the "look inside" for a private store redirects rather than returning a "not found" page, a visitor can confirm that a private store exists, even if they cannot see inside it.
- Reader images, cover images, and buyer download links are served through unguessable URLs that have no configured expiry. Anyone who obtains such a URL can fetch that file. Treat these links as unguessable but effectively permanent.
International data transfers
We and our service providers may process and store personal information in the United States and in other countries where our providers operate. These countries may have data protection laws that differ from those in your country. Where required, we rely on appropriate safeguards for international transfers, such as the European Commission's Standard Contractual Clauses or an equivalent mechanism used by the relevant provider. If you would like more information about the safeguards we rely on, contact us at [email protected].
Data retention
We keep personal information for as long as needed to provide the Service and for the purposes described in this policy, unless a longer period is required by law.
- Anonymous, unclaimed designs expire on a 14-day sliding window (the timer resets each time the design is edited) and are permanently purged nightly, including their images and exports.
- Account data and owned content have no fixed retention limit. They are kept until you delete the content or your account.
- Sign-in IP addresses are retained until they are overwritten by your next login. There is no separate purge schedule for them.
- Order and buyer information (including buyer emails) is retained to support delivery, receipts, and record-keeping, and is not on a fixed deletion schedule. As explained under Deleting your account and data, some order records, including guest-checkout order emails and rows that are only disassociated from a deleted account, persist essentially indefinitely and have no self-serve deletion path; email us for a complete erasure request.
- Service providers retain data according to their own policies.
Data security
We use reasonable technical and organizational measures to protect personal information. Concrete measures include:
- passwords and the optional store password are hashed with bcrypt;
- traffic is served over HTTPS only in production, with HSTS;
- a Content Security Policy with per-request nonces is enforced;
- host-header allowlisting and rate limiting are applied to sensitive actions such as login, signup, password reset, checkout, and store unlock;
- uploaded file types are verified from the file's content; and
- Stripe webhooks are signature-verified and processed idempotently.
To be clear about the limits: beyond password and store-password hashing, we do not apply application-level field encryption to data at rest. Any disk or database encryption is a function of our hosting provider and is not implemented in our application. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
Your privacy rights (GDPR, EEA and UK)
If you are in the EEA or the UK, you have the following rights, subject to legal limits and exceptions:
- Access: ask for a copy of the personal information we hold about you.
- Rectification: ask us to correct inaccurate or incomplete information.
- Erasure: ask us to delete your personal information.
- Restriction: ask us to limit how we process your information.
- Portability: ask for your information in a portable format.
- Objection: object to processing based on our legitimate interests.
- Withdraw consent: where we rely on consent, withdraw it at any time (this does not affect processing already carried out).
- Complain: lodge a complaint with your local supervisory authority.
You can delete your own account through the Service (see Deleting your account and data). Because we do not offer a self-serve data-export or download-all endpoint, access and portability requests are handled by email. To exercise any of these rights, contact us at [email protected]. Note that self-serve account deletion may not remove every record, because some purchase records persist (see below), so a complete erasure request should be made to that email address.
Your privacy rights (CCPA and CPRA, California)
If you are a California resident, you have rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act.
Categories of personal information we collect
In the past 12 months, we have collected the following categories of personal information:
- Identifiers: email address, optional display name, account identifier, and store profile fields you provide.
- Commercial information: records of purchases, amounts, currency, platform fee, and order and receipt tokens.
- Internet or other network activity: limited to sign-in IP addresses and sign-in timestamps recorded for security. We do not use analytics or tracking tools.
- Other information you choose to provide: any personal information you type into your design content or upload in images.
Purposes
We use these categories for the business and commercial purposes described under How we use information, including providing the Service, processing payments, delivering purchases, securing accounts, and complying with law.
No sale or sharing
We do not sell personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined under California law. We have not done so in the past 12 months. We do not knowingly sell or share the personal information of consumers under 16 years of age.
Your California rights
- Right to know and access the categories and specific pieces of personal information we have collected.
- Right to delete personal information we have collected, subject to exceptions.
- Right to correct inaccurate personal information.
- Right to limit the use of sensitive personal information (note that we do not use sensitive personal information for purposes that trigger this right).
- Right to non-discrimination for exercising your rights.
To submit a request, email us at [email protected]. We will verify your request by matching the information you provide (such as your account email) against what we hold; we may ask for additional information to confirm your identity. You may use an authorized agent to submit a request on your behalf, subject to verification.
Children's privacy
The Service is not directed to children under 13, and you must be at least 13 years old to use it. We do not knowingly collect personal information from children under 13. If you are under 18 (or the age of majority where you live), you may use the free tools only with the involvement of a parent or guardian, and you may not buy or sell zines without your parent's or guardian's consent. Buying and selling require that you are an adult or have verifiable parental consent.
We do not verify age in the Service; the age requirement is a policy requirement, not a technical control. If you believe a child under 13 has provided us with personal information, please contact us at [email protected] and we will take steps to remove it.
Deleting your account and data
You can delete your account yourself using the "delete my account" action in the Service. Deleting your account removes the account and cascades to your zines, editions, listings, designs, exports, and uploaded files.
Please be aware of these honest limits on self-serve deletion:
- Records of purchases you made as a buyer (order rows, which include a buyer email) and orders placed by others for your listings are not all fully erased by the self-serve delete. Some are only disassociated from your account.
- When a seller deletes their account, that deletion also removes their buyers' purchase records and download links for that seller's zines.
- Order emails from guest checkout persist.
If you want a complete erasure of your personal information, please contact [email protected] so we can handle it as an erasure request. As noted above, we do not offer a self-serve "download all my data" export; access and portability requests are also handled by email.
Automated decision-making
We do not use automated decision-making that produces legal or similarly significant effects about you, and we do not build profiles of you for advertising or similar purposes.
Reporting abuse and copyright concerns
The Service does not currently include an in-app content-reporting or takedown button. If you need to report abuse or submit a copyright (DMCA) notice, please email [email protected] or contact our designated agent, Reedster LLC. For general support, contact [email protected].
Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date at the top and, where appropriate, provide additional notice. Your continued use of the Service after an update means you accept the revised policy.
Contact us
If you have questions about this policy or your personal information, contact us at:
- Reedster LLC
- Privacy: [email protected]
- Support: [email protected]
- Mailing address: 100 N Howard Street STE R, Spokane, WA 99201