Legal
Privacy Policy
Draft for client and legal review.
This draft privacy policy describes how the Scribbl platform handles information today. It is not legally approved and will be updated after client and legal review.
Information we collect
Scribbl collects information needed to operate public business enquiries, sample requests, booking referrals, catalogue browsing where enabled, personalization, checkout, order fulfilment, and customer account features. The categories below reflect the current system rather than a final legal inventory.
Business contact information
When you contact Scribbl or book a demo through a configured booking provider link, Scribbl or its booking provider may receive business contact details such as name, email address, company information and enquiry context you choose to share.
Sample-request information
Sample requests may include contact details, business information and a postal address needed to mail a sample packet. Sample-request records are handled through Scribbl’s sample-request workflow and are accessible to authorised administrators.
Account information
When you create an account, Scribbl stores account credentials and profile information managed through the authentication system. Account access is protected by session-based sign-in.
Order and payment information
Where self-serve ordering is enabled, orders store configuration snapshots, pricing totals, postage totals, development tax estimates where applicable, payment status, and operational workflow status. Payment card details are processed by Stripe and are not stored by Scribbl.
Personalized message content
Composed message and personalization selections may be stored as part of cart and order records. Message content is treated as sensitive correspondence data and is stored in encrypted private payloads associated with cart and order items where those flows are used.
Recipient postal information
Recipient name and postal address details may be collected during personalization or campaign preparation and stored for fulfilment. Scribbl does not currently provide automated address verification in the customer flow.
Booking-provider links
Book a Demo may redirect to an external booking provider when configured. That provider processes scheduling and contact information according to its own terms and privacy practices.
Payment provider
Stripe processes payments where checkout is enabled. Stripe receives payment and checkout session information required to complete payment. Scribbl configures Stripe automatic tax and Stripe Tax as disabled in the current development configuration.
Email provider
Resend delivers transactional emails when email sending is enabled, including order confirmations and operational notifications such as sample-request acknowledgements. Email content is limited according to each notification’s purpose and excludes private recipient message content from order confirmations.
Hosting and database providers
Application data is stored in a PostgreSQL database operated as part of the Scribbl hosting environment. Infrastructure providers process data necessary to host the application, store records, and run operational workflows.
Administrative access
Authorized administrators may access order records, sample requests, operational statuses, and decrypted fulfilment data required to produce and mail correspondence. Access is limited to authenticated admin roles and operational workflows.
Security and access controls
Scribbl applies encryption for sensitive cart and order payloads and follows server-side authorization boundaries. No system can guarantee absolute security. Security controls will be reviewed before any live payment launch.
Retention
Specific retention periods for account, order, sample-request, lead and operational records will be confirmed by the client and legal advisers. Until then, records are retained according to operational and development needs.
Customer rights
Applicable privacy rights depend on your jurisdiction and final approved policy terms. Contact Scribbl using the details on the contact page to discuss access, correction, or deletion requests once support channels are configured.
Contact
Privacy questions should be directed through the contact page using the configured contact email when available, or through Book a Demo / Request Free Samples for related business conversations.
International processing
Scribbl may process and store information in locations determined by its hosting and service providers. Cross-border processing terms will be confirmed in the approved policy.
Policy updates
This draft policy may change as the product, providers, and legal requirements evolve. Material updates will be reflected on this page after client and legal review.
