Effective: 5 August 2026 · DesignerSystemsDigital
This Privacy Policy explains how DesignerSystemsDigital ("we," "us," or "our") collects, uses, discloses, and safeguards information when you use our websites and applications (collectively, the "Services"). By using the Services, you agree to the practices described here.
DesignerSystemsDigital is a sole-trader operation based in New Zealand. We build and operate the Services listed below. For privacy enquiries, contact privacy@designersystemsdigital.xyz.
Cloud storage and folder manager. Live at notetree.designersystemsdigital.xyz.
Fitness tracking PWA with friends and subscription features. Live at statsirl.designersystemsdigital.xyz.
Our marketing site. This page.
The data we collect depends on which Service you use.
sb-<project-ref>-auth-token) to keep you signed in.We do not collect personal data on this site. Cloudflare may collect aggregated, non-identifying analytics (request counts, country-level geo) for performance and security. No cookies, no third-party trackers.
We do not sell your data. We do not serve third-party advertising.
| Provider | Purpose | Data shared |
|---|---|---|
| Supabase (database + auth) | All app data and authentication | All data listed in §3 |
| Cloudflare (hosting + CDN) | Web hosting, DDoS protection | HTTP request metadata |
| Stripe (payments) | Subscription processing (paid apps only) | Email, payment method (tokenised) |
| OneSignal (push) | StatsIRL push notifications | Device token, user ID |
We use strictly necessary cookies only — those required for the Services to function (authentication sessions). We do not use advertising, tracking, or third-party analytics cookies. Because all cookies are strictly necessary (per Privacy and Electronic Communications Regulations and equivalent GDPR Art. 6(1)(f) "strictly necessary" exemption), no consent banner is shown — none would be required under EU/UK "cookie law" or the ePrivacy Directive for this class of cookie.
cf_clearance — first-party bot-protection cookie on the marketing site only; strictly necessary for Turnstile challenge to function. Cleared when you close your browser or after 30 minutes idle.All data is encrypted in transit (HTTPS / TLS 1.3) and at rest (Supabase default disk encryption). Access to production data is limited to the operator. Passwords are hashed with bcrypt via Supabase Auth. Supabase Row-Level Security (RLS) is enabled on every table — clients can only read or modify rows they own.
You have the right to:
privacy@designersystemsdigital.xyz. Deletion is permanent within 30 days.We retain your account data for as long as your account is active. If you delete your account, all associated data is permanently deleted within 30 days, except where retention is required by law (e.g. tax records for paid subscriptions, retained for 7 years per NZ Inland Revenue).
The Services are general audience services — they are not primarily directed to children. Access requires a sign-up with an email address, which acts as a soft age-gate. A user who can provide a valid email address and agree to these terms is presumed old enough to use the Services.
The Services are not intended for children under 13. We do not knowingly collect personal data from children under 13. If you believe a child under 13 has created an account, contact privacy@designersystemsdigital.xyz and we will delete the account and its data.
Data is stored in the United States (Supabase us-east-1, Cloudflare global edge). By using the Services, you consent to transfer of your data to the US. Supabase and Cloudflare participate in standard contractual clauses for EU/UK data transfers.
We may update this policy. Material changes will be announced via in-app banner and/or email at least 14 days before they take effect. The "Effective" date at the top will always reflect the latest version.
Privacy enquiries: privacy@designersystemsdigital.xyz
General support: support@designersystemsdigital.xyz
DesignerSystemsDigital · New Zealand
If you are located in the European Economic Area (EEA) or the United Kingdom, the following additional disclosures apply under Articles 13 and 14 of the GDPR/UK GDPR.
Contact our DPO at privacy@designersystemsdigital.xyz for any GDPR-related questions, including data access, rectification, erasure, restriction, portability, or objection requests.
As a small New Zealand-based company processing EEA/UK personal data only occasionally and at low volume, we rely on the Art. 27 exemption for organisations that do not process personal data on a large scale. If this changes, we will appoint an EU representative and update this policy.
You have the right to lodge a complaint with your local supervisory authority: