Privacy Policy
Last updated: 3 April 2026
1. Who We Are
Authorspot (authorspot.io) is operated by [Your Name / Company Name], based in the United Kingdom. We are the data controller for personal data collected through this website. Contact: support@authorspot.io.
2. What Data We Collect
- Account data: name, email address, hashed password — collected when an author account is created (either by admin or through an invite link)
- Profile data: author biography, genre preferences, social media URLs, profile photo — provided voluntarily by authors to build their public profile
- Book data: book titles, descriptions, cover images, purchase links — provided voluntarily by authors or on their behalf under our managed service
- Contact form data: name, email, subject, message — submitted voluntarily
- Technical data: IP address (stored on contact form submissions for spam prevention), server logs
3. How We Use Your Data
- To provide and maintain author profile pages on the platform
- To send transactional emails (account creation, password reset, email verification) via Brevo (see Third Parties below)
- To respond to contact form enquiries
- To administer the platform and prevent abuse
4. Legal Basis for Processing (UK GDPR)
- Contract: processing necessary to provide the author profile service
- Legitimate interests: spam prevention, platform security, email deliverability
- Consent: where explicitly given (e.g. optional marketing communications, if added in the future)
5. Data Storage & Security
- Account and profile data is stored in a Supabase-hosted PostgreSQL database located in the European Union
- Profile photos and book cover images are stored in Wasabi cloud storage
- Passwords are hashed using bcrypt and are never stored in plain text
- Data is transmitted over HTTPS at all times
- We take reasonable technical measures to protect your data but cannot guarantee absolute security
6. Third Party Services
Supabase (supabase.com) — database hosting. EU region. See their privacy policy.
Wasabi Technologies (wasabi.com) — file storage. See their privacy policy.
Brevo (brevo.com) — transactional email delivery. See their privacy policy.
Vercel (vercel.com) — website hosting and deployment. See their privacy policy.
We do not sell your data to third parties. We do not use your data for advertising.
8. Data Retention
- Author account data is retained for as long as the account is active
- If an account is deleted, associated personal data is removed within 30 days
- Contact form submissions are retained for 12 months then deleted
- Server logs are retained for 30 days
9. Your Rights (UK GDPR)
You have the right to: access your data, correct inaccurate data, request deletion, restrict processing, data portability, and to object to processing. To exercise any of these rights contact support@authorspot.io. We will respond within 30 days. You also have the right to lodge a complaint with the Information Commissioner's Office (ico.org.uk).
10. Children's Privacy
Authorspot is not directed at children under 13. We do not knowingly collect data from children. If you believe a child has provided us with personal data please contact us and we will delete it.
11. Changes to This Policy
We may update this policy from time to time. The "Last updated" date at the top of this page will reflect any changes. Continued use of the platform after changes constitutes acceptance of the updated policy.
12. Contact
For any privacy-related questions: support@authorspot.io. You can also reach us via our contact form.