FewerSteps legal
Privacy Notice
Privacy information for commerce, product support, and optional consent-based Google advertising measurement.
Controllers, purposes, data, and legal bases
PANIC Studios Przemysław Dąbrowski, ul. Stefana Batorego 18/108, 02-591 Warsaw, Poland, controls FewerSteps-directed site, product, fulfillment, support, and business-record processing. Contact ThePanicDevelopment@gmail.com for privacy requests. Admission, assent, order, access, delivery, recovery, refund, complaint, and support records support requested pre-contract steps and contract performance. Accounting, tax, remedy, and regulatory records meet legal obligations. Security, abuse-prevention, reliability, incident, and claims records support legitimate interests and the establishment or defense of claims.
Sold through Link, LLC and applicable Stripe entities independently control Managed Payments processing where their terms say so and may act as processors where their data-processing agreement applies. They can process identity, contact, payment, transaction, device, fraud, tax-location, support, and regulatory data. Provider-controlled requests go through https://stripe.com/privacy and https://stripe.com/legal/privacy-center. This notice does not characterize the parties as joint controllers.
On an authorized Google paid-search route only, an affirmative Google-specific choice may permit limited advertising measurement for a landing view, checkout initiation, and provider-verified purchase. The legal basis for FewerSteps setting the optional choice cookie and loading the Google adapter is consent. Fixed event data can include the event type, a provider-scoped opaque conversion identifier for purchase deduplication, fixed value 59 and currency USD for a verified purchase, plus browser and transport metadata necessarily observed by Google. FewerSteps does not send an email address, audit answers, recovery value, raw order identifier, Checkout Session identifier, or Payment Intent identifier for this purpose.
Required data, recipients, and transfers
Data needed for a purchase, access, recovery, refund, complaint, or support request must be provided to complete or administer it. The payment provider, not FewerSteps, handles payment-card data. Infrastructure providers process connection and security metadata needed for routing, reliability, and abuse prevention. FewerSteps does not repurpose that metadata as advertising source measurement.
Recipients are limited to PANIC Studios personnel with an operational need; Google for the temporary Gmail support mailbox and, only after consent and activation, Google Ads measurement; Link and Stripe entities for Managed Payments; DigitalOcean, Neon or Databricks, and Cloudflare for infrastructure; and required financial institutions, advisers, authorities, regulators, and courts. Google acts as an independent controller for Google Ads measurement under https://business.safety.google/controllerterms/ and https://policies.google.com/privacy. Google Ads measurement may involve processing outside the EEA. Google's Controller Terms describe the transfer solution or Controller SCCs for the relevant Google entity. Safeguard information can be requested at ThePanicDevelopment@gmail.com.
The temporary support mailbox is a consumer Gmail account governed by https://policies.google.com/terms and https://policies.google.com/privacy. Google says it does not act as a data processor for consumer Gmail, and PANIC Studios does not represent that the Google Workspace or Cloud Identity Cloud Data Processing Addendum applies. Email may be processed outside the EEA under https://policies.google.com/privacy/frameworks. Send only information needed for support, never recovery codes, payment-card data, credentials, or business content.
Launch providers use their applicable transfer terms: https://stripe.com/legal/dta, https://www.digitalocean.com/legal/data-processing-agreement, https://www.cloudflare.com/cloudflare-customer-dpa/, https://neon.com/platform-terms, https://www.databricks.com/legal/dpa, and https://www.databricks.com/legal/databricks-subprocessors. Copies or safeguard information can be requested through support.
Tracking choices and policy changes
Google advertising measurement is prepared but remains inactive unless the exact provider, legal, campaign, and runtime gates are separately authorized. X, Meta, and TikTok remain inactive. FewerSteps does not sell personal information, use remarketing, create customer lists, enable advanced matching, or use Google Analytics or a Google Tag Manager container. A person can deny measurement without losing access to the product or checkout and can withdraw a granted choice through Ad privacy choices.
Do Not Track is not treated as affirmative Google consent. Global Privacy Control suppresses and denies optional measurement. The paid-search route can keep Google's bounded gclid, gbraid, or wbraid parameter in the browser URL for the consented tag. FewerSteps application code does not copy those parameters into its advertising-choice cookie, database, audit state, commerce records, or first-party source record. Cloudflare and DigitalOcean process the requested URL to deliver the page, the URL may remain in browser history, and Google may store ad-click information after consent. FewerSteps does not use this measurement to track a person across different websites.
Withdrawal replaces the grant with a withdrawn decision and prevents FewerSteps from loading the Google tag after reload. FewerSteps also attempts to expire the reachable first-party _gcl_au and _gcl_aw cookies and remove _gcl_ls from local storage. Withdrawal does not retract earlier transfers or guarantee deletion of Google-domain cookies or previously transferred data; those may remain until expiry or until they are cleared through browser or Google privacy controls. Provider-controlled services process information under their own notices.
Material changes to this notice are published at its canonical URL with a new effective date and a conspicuous notice on the site. Direct notice is also provided where an appropriate contact channel is available and applicable law requires it.
Retention and rights
Order, assent, refund, accounting, tax, dispute, complaint, and claims records remain only as long as contract, legal, or claims needs require, then are deleted or anonymized. Recovery and access state expires with the 90-day access term. Cookie maxima appear in the cookie notice; an advertising-choice record and cookie expire no later than 90 days after the decision or withdrawal. The offline workbook sends no project content to FewerSteps.
Depending on the legal basis and applicable limits, a person may request access, a copy, correction, erasure, restriction, portability, or object, and may withdraw consent where consent applies without affecting earlier lawful processing. Send PANIC Studios requests to ThePanicDevelopment@gmail.com. Where GDPR Article 12 applies, PANIC Studios responds without undue delay and within one month. That period may be extended by two further months where necessary because of the complexity or number of requests, with notice and reasons provided within the first month. A person may complain to the President of the Personal Data Protection Office, Poland, at https://uodo.gov.pl/en/681.