Printsnip

Privacy Notice

Printsnip Privacy Notice — version 2026-09-28.5

Operator: PrintSnip.com. Privacy contact: suppport@printsnip.com.

Photo and document editing runs on your device. Local edits and file content are not sent to server audit logs. Accounts, support conversations, security events and legal acceptance records are stored on our hosting server.

We store name, email, phone details you provide, password hashes, session records and sign-in/security information. Social sign-in uses Google or Facebook identity information you authorise. We do not receive your social-account password.

Direct device transfer uses temporary connection metadata on the server and encrypted WebRTC between devices. Where direct connectivity fails, a configured TURN relay forwards encrypted packets without storing file content. The relay necessarily processes connection IP addresses and traffic volume to route packets and enforce capacity limits. Temporary relay credentials expire after one hour; the shared server secret is not sent to devices. Public STUN services can receive your connection IP while discovering a route. Print-shop links temporarily store encrypted file packages in server memory; the decryption key is in the sharing link fragment. These packages expire, reach a download limit, are revoked or disappear when the server restarts. A recipient's downloaded files are outside our control.

Resend processes verification, password-reset and notification email. Google/Facebook process their own sign-in flows. Hosting and these providers apply their own processing and retention arrangements. We use essential session cookies; this acceptance does not opt you into marketing.

Operational logs use the retention period shown in company settings (five days by default). Account records and support tickets are retained until reviewed for deletion; legal acceptance records are retained for evidence and are not deleted by operational log cleanup. Backups may retain earlier copies. Contact us for access, correction or deletion requests; we will explain any retention obligations that apply.

We use access controls and security safeguards, but cannot guarantee that every device, network or service is risk-free. Send privacy or security concerns to the contact above.

Security and optional insights: the service receives your IP to respond to requests and limit abuse. Sign-in, recovery, password and logout events record a validated IP, status and time for security; normal session lists show a masked network. IPs may identify a shared network, VPN or proxy and do not prove an individual's identity or precise location. Browser and OS labels are estimates. Essential security and service records are separate from optional tracking.

Optional analytics records only your account ID, a named Printsnip tool category and opening time after you enable it. It never collects filenames, typed content, document images, keystrokes, passwords or social messages. There is no advertising, third-party analytics, device fingerprinting, cross-site monitoring or background location tracking.

Optional location is shared only when you select Share approximate location in Privacy controls and grant the browser request. Coordinates are rounded to two decimals on your device before transmission and stored as a single replaceable point, to provide account/support context. Rounding is roughly kilometre scale and varies with latitude. Staff can see retained optional data. Browser permission alone is not permission for continuous collection.

You may decline analytics without losing editing access, change your choice and delete optional records at /privacy-center. Turning analytics off deletes retained usage events. Delete optional data removes usage and shared location and turns analytics off. Browser location permission can separately be revoked in browser settings. Previously retained backups follow the operator's backup retention policy.

Optional records expire after the period displayed in Privacy controls (five days by default; staff can select 1–30 days). Security IP/event retention is separate (180 days by default; the operator must determine applicable retention duties before changing it). Other operational logs use the notification retention setting. Purpose/version/time receipts remain as consent evidence and are separate from operational cleanup; they contain no coordinates. Staff reads, privacy configuration changes and deletion requests are audited. Privacy export provides up to 1,000 recent records per category; ask support for larger requests or complete account information.

Account setup: Terms acceptance and Privacy Notice acknowledgement are recorded when you register. They are not requested on every sign-in. A changed policy version, or an account without an acceptance record, requires a one-time review before account workspace access. Optional analytics and location remain separate choices.

Email verification: your account can be created before email delivery is configured. An administrator controls whether verifying your email is required before editing. Disabling this requirement does not mark your email as verified. Verification and password-reset links expire and are usable once.

Notification emails can contain branding images configured by the operator. If your mail app loads remote images, their hosting service may receive your IP and request metadata. Printsnip does not add open-tracking pixels. Your mail app may offer a setting to block remote images.

Connection diagnostics: when a device cannot connect or loses its connection, the browser may send an error category, random attempt reference, timestamp, broad browser family, browser-reported network estimate, and the signed-in account association if any. These records do not include file contents, filenames, raw error messages, SDP credentials, QR/share URLs or IP addresses. Separate security request logs can still process an IP as described above. Staff use these service diagnostics to resolve failures, can disable collection and choose 1–90 day retention (five days initially). Anonymous reports are browser-reported and are not proof of a network fault. If the service is unreachable, reporting can fail too.

Portal artwork uploaded by staff is public website content and stored in the account database until an administrator replaces or deletes it. It is separate from customer photos processed locally. Changes to website settings, artwork and staff access to diagnostics are audited.

Document fingerprint: 70cac953c61c341e53601e40b2cef6db90491a98a772cdba7578f28ded4ff84e