Privacy Policy

Last updated: Wed Jan 22 2025

1. Introduction

Welcome to StoryKraft ("we," "our," or "us"), a trading name of Rain Ventures Limited. We are committed to protecting your personal information and your right to privacy.

1.1 Company Information

  • Company Name: Rain Ventures Limited
  • Registered Office: 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ
  • Company Registration Number: 16041437
  • ICO Registration Number: C1590372
  • Data Protection Contact: hello@storykraft.ai

1.2 Scope

This policy applies to all information collected through:

  • StoryKraft web application
  • Related websites and services
  • Customer support interactions
  • Marketing communications
  • Sales and billing processes

We process your personal data under the following legal bases as defined by UK GDPR:

2.1 Contract Performance (Article 6(1)(b))

  • Account creation and management
  • Story creation and storage
  • Character management
  • Subscription handling

2.2 Legal Obligation (Article 6(1)(c))

  • Financial records maintenance
  • Tax compliance
  • Child protection measures
  • Security requirements

2.3 Legitimate Interests (Article 6(1)(f))

  • Service improvement
  • Security measures
  • Analytics
  • Feature development Where we rely on legitimate interests, we perform balancing tests to ensure your rights are protected.

2.4 Consent (Article 6(1)(a))

  • Marketing communications
  • Optional features
  • Cookie preferences
  • Processing of children's data

3. Technical Infrastructure & Service Providers

3.1 Core Infrastructure

Our secure infrastructure includes:

  • Hosting: Vercel (UK/EU data centers)
  • Database: Neon (UK/EU data centers)
  • Storage: Cloudflare (UK/EU data centers)
  • Payment Processing: Lemon Squeezy

3.2 Additional Services

Supporting services include:

  • Customer Support: Crisp.chat
  • Analytics: Tinybird All processing occurs within UK/EU facilities

3.3 Data Processing Agreements

All service providers are bound by:

  • Data Processing Agreements (DPAs)
  • UK/EU Standard Contractual Clauses where applicable
  • Confidentiality obligations
  • Security requirements

4. Data Collection and Processing

4.1 Account Creation

Parent/Guardian Data:

  • Email address
  • Full name
  • Account credentials
  • Authentication data Legal basis: Contract Performance

4.2 Story Creation

  • Story content
  • Character associations
  • Creation timestamps
  • Usage analytics Legal basis: Contract Performance

4.3 Character Creation

  • Character details
  • Associated parent account
  • Creation timestamps
  • Usage patterns Legal basis: Contract Performance

4.4 Service Usage

Analytics data (Tinybird):

  • Usage patterns
  • Feature interaction
  • Performance metrics Legal basis: Legitimate Interests

4.5 Payment Information (Lemon Squeezy)

  • Billing information
  • Subscription status
  • Payment history Legal basis: Contract Performance and Legal Obligation

5. Special Category Data

5.1 Children's Data

We process children's data only:

  • With parental consent
  • For specific, limited purposes
  • With enhanced security measures
  • In compliance with UK GDPR Article 8

5.2 Age Verification

We verify age through:

  • Parent/guardian verification
  • Email verification
  • Declaration of parental responsibility
  • Consent verification

6. Data Retention

6.1 Retention Periods

  • Account data: Duration of account activity plus 2 years
  • Story data: Account duration plus 90 days
  • Analytics data: 12 months
  • Support conversations: 24 months
  • Payment records: 7 years (legal requirement)

6.2 Deletion Procedures

  • Automatic deletion after retention period
  • Manual deletion on request
  • Immediate deletion option available
  • Exception for legal requirements

7. Your Rights Under UK GDPR

7.1 Core Rights

You have the right to:

  1. Access (Article 15)
  2. Rectification (Article 16)
  3. Erasure (Article 17)
  4. Restrict processing (Article 18)
  5. Data portability (Article 20)
  6. Object (Article 21)
  7. Withdraw consent

7.2 Exercise Your Rights

To exercise your rights:

  • Email: hello@storykraft.ai
  • Response time: Within 30 days
  • No fee (except for excessive requests)
  • ID verification may be required

7.3 Complaints

You have the right to complain to: Information Commissioner's Office (ICO)

  • Website: www.ico.org.uk
  • Telephone: 0303 123 1113 Our ICO registration: C1590372

8. International Transfers

8.1 Data Location

Primary processing occurs in:

  • United Kingdom
  • European Union

8.2 Transfer Mechanisms

If transfers outside UK/EU occur:

  • UK/EU Standard Contractual Clauses
  • Adequacy decisions
  • Appropriate safeguards
  • Security measures

9. Security Measures

9.1 Technical Measures

  • Data encryption in transit and at rest
  • Access control systems
  • Security monitoring
  • Regular security audits

9.2 Organizational Measures

  • Staff training
  • Access limitations
  • Security policies
  • Incident response procedures

9.3 Breach Notification

In case of a data breach:

  • ICO notification within 72 hours
  • Affected user notification if high risk
  • Remediation measures
  • Investigation procedures
  • Essential
  • Functional
  • Analytics
  • Marketing

Manage cookies through:

  • Cookie preference center
  • Browser settings
  • Account settings Consent can be withdrawn anytime

11. Changes to This Policy

11.1 Updates

  • Regular policy reviews
  • Email notification of changes
  • Version history maintained
  • Major changes require consent

11.2 Version Control

  • Current version: November 6, 2024
  • Previous versions available on request

12. Contact Us

Rain Ventures Limited 71-75 Shelton Street, Covent Garden London, United Kingdom WC2H 9JQ

For data protection queries: Information Commissioner's Office

Last updated on