Privacy Policy
Last updated: August 2026This privacy policy describes what information Global Book Passport collects, how it is used, with whom it is shared, and the security practices in place to protect it.
Information we collect
We collect the following information when you purchase a subscription or create an account:
- Name and email address — entered at checkout and used to create your curriculum and reading-app accounts.
- Payment information — card details are entered directly into Stripe's secure checkout and are never seen or stored by us.
- Account credentials — your email address and a hashed password, stored by Netlify Identity to secure your curriculum account.
- Reading activity — books logged, countries visited, stamps earned, and related data entered into the Global Book Passport app by you or your child.
How we use this information
- To process your payment and provide access to the curriculum and app.
- To create and manage your curriculum account and your child's reading-app account.
- To send transactional emails — account setup instructions, password resets, and purchase receipts.
- To determine when a subscription has expired and update access accordingly.
Who we share information with
We do not sell your personal information. We share it only with the services required to operate the product:
- Stripe — processes payments and stores your payment method and purchase history. Stripe is PCI-DSS compliant. See stripe.com/privacy.
- Netlify — hosts the curriculum website and manages account authentication. See netlify.com/privacy.
- Global Book Passport app — your name, email, and subscription details are sent to the app server to provision your family's reading accounts.
- Resend — delivers transactional emails (account setup, password reset). See resend.com/legal/privacy-policy.
Method of disclosure
Information is transmitted to third-party services via encrypted HTTPS connections at the time of purchase or account creation. No information is sold, rented, or disclosed for advertising purposes.
Security practices
- All pages are served over HTTPS.
- Payment data is handled entirely by Stripe and never passes through our servers.
- Curriculum account passwords are hashed and stored by Netlify Identity — we do not have access to them.
- Access to the curriculum is controlled by signed JWT tokens and role-based redirect rules.
Data retention
Stripe retains purchase records in accordance with its own policies. Netlify retains account data for as long as the account exists. You may request deletion of your curriculum account at any time by contacting us.
Children's privacy
Global Book Passport is a family product used by parents on behalf of their children. We do not knowingly collect personal information directly from children. Parents create and manage all accounts.
Contact
Questions about this policy can be sent to globalbookpassport@gmail.com.