← DesignerSystemsDigital

Privacy Policy

Effective: 5 August 2026 · DesignerSystemsDigital

This Privacy Policy explains how DesignerSystemsDigital ("we," "us," or "our") collects, uses, discloses, and safeguards information when you use our websites and applications (collectively, the "Services"). By using the Services, you agree to the practices described here.

1. Who we are

DesignerSystemsDigital is a sole-trader operation based in New Zealand. We build and operate the Services listed below. For privacy enquiries, contact privacy@designersystemsdigital.xyz.

2. Services covered

NoteTree

Cloud storage and folder manager. Live at notetree.designersystemsdigital.xyz.

StatsIRL

Fitness tracking PWA with friends and subscription features. Live at statsirl.designersystemsdigital.xyz.

designersystemsdigital.xyz

Our marketing site. This page.

3. What we collect

The data we collect depends on which Service you use.

3.1 All Services (auth only)

3.2 NoteTree

3.3 StatsIRL

3.4 Marketing site (designersystemsdigital.xyz)

We do not collect personal data on this site. Cloudflare may collect aggregated, non-identifying analytics (request counts, country-level geo) for performance and security. No cookies, no third-party trackers.

4. How we use your data

We do not sell your data. We do not serve third-party advertising.

5. Third-party processors

ProviderPurposeData shared
Supabase (database + auth)All app data and authenticationAll data listed in §3
Cloudflare (hosting + CDN)Web hosting, DDoS protectionHTTP request metadata
Stripe (payments)Subscription processing (paid apps only)Email, payment method (tokenised)
OneSignal (push)StatsIRL push notificationsDevice token, user ID

6. Cookies and local storage

We use strictly necessary cookies only — those required for the Services to function (authentication sessions). We do not use advertising, tracking, or third-party analytics cookies. Because all cookies are strictly necessary (per Privacy and Electronic Communications Regulations and equivalent GDPR Art. 6(1)(f) "strictly necessary" exemption), no consent banner is shown — none would be required under EU/UK "cookie law" or the ePrivacy Directive for this class of cookie.

7. Data security

All data is encrypted in transit (HTTPS / TLS 1.3) and at rest (Supabase default disk encryption). Access to production data is limited to the operator. Passwords are hashed with bcrypt via Supabase Auth. Supabase Row-Level Security (RLS) is enabled on every table — clients can only read or modify rows they own.

8. Your rights

You have the right to:

9. Data retention

We retain your account data for as long as your account is active. If you delete your account, all associated data is permanently deleted within 30 days, except where retention is required by law (e.g. tax records for paid subscriptions, retained for 7 years per NZ Inland Revenue).

10. Children

The Services are general audience services — they are not primarily directed to children. Access requires a sign-up with an email address, which acts as a soft age-gate. A user who can provide a valid email address and agree to these terms is presumed old enough to use the Services.

The Services are not intended for children under 13. We do not knowingly collect personal data from children under 13. If you believe a child under 13 has created an account, contact privacy@designersystemsdigital.xyz and we will delete the account and its data.

11. International transfers

Data is stored in the United States (Supabase us-east-1, Cloudflare global edge). By using the Services, you consent to transfer of your data to the US. Supabase and Cloudflare participate in standard contractual clauses for EU/UK data transfers.

12. Changes to this policy

We may update this policy. Material changes will be announced via in-app banner and/or email at least 14 days before they take effect. The "Effective" date at the top will always reflect the latest version.

13. Contact

Privacy enquiries: privacy@designersystemsdigital.xyz
General support: support@designersystemsdigital.xyz
DesignerSystemsDigital · New Zealand

Effective 5 August 2026. Previous versions available on request.

14. EEA/UK GDPR

If you are located in the European Economic Area (EEA) or the United Kingdom, the following additional disclosures apply under Articles 13 and 14 of the GDPR/UK GDPR.

Legal basis for processing

Data Protection Officer

Contact our DPO at privacy@designersystemsdigital.xyz for any GDPR-related questions, including data access, rectification, erasure, restriction, portability, or objection requests.

EU Representative

As a small New Zealand-based company processing EEA/UK personal data only occasionally and at low volume, we rely on the Art. 27 exemption for organisations that do not process personal data on a large scale. If this changes, we will appoint an EU representative and update this policy.

Complaints

You have the right to lodge a complaint with your local supervisory authority: