01 Who We Are
This Privacy Policy applies to bookguide.club ("we", "us", "our"), a digital publishing store selling ebooks and guides.
Contact: info@bookguide.club
For customers in the European Union, this policy is compliant with Regulation (EU) 2016/679 (GDPR).
02 Data We Collect
We collect the following personal data when you make a purchase or contact us:
- Name and email address — required to deliver your ebook and send your receipt
- Payment data — processed securely by GoPay; we never store card numbers
- IP address and browser type — collected automatically for security and analytics
- Purchase history — which products you bought and when
We do not collect: social media profiles, location beyond country, or any sensitive data categories under GDPR Article 9.
03 How We Use Your Data
- To process your payment and deliver the purchased ebook via email
- To send your purchase receipt and order confirmation
- To send you free updates to products you have purchased
- To respond to your support or contact requests
- To improve our website and product offerings (aggregated analytics only)
- To comply with our legal obligations (tax records, fraud prevention)
We will never sell, rent, or trade your personal data to third parties for marketing purposes.
04 Legal Basis — GDPR
Under GDPR, we process your data on the following legal bases:
- Contract performance (Art. 6(1)(b)) — processing your order and delivering the ebook
- Legal obligation (Art. 6(1)(c)) — tax and accounting requirements
- Legitimate interest (Art. 6(1)(f)) — website security and fraud prevention
- Consent (Art. 6(1)(a)) — marketing emails, if you opt in
05 Data Sharing & Third Parties
We share your data only with essential service providers who help us operate:
- GoPay s.r.o. — payment processing for CZ/SK customers (GoPay Privacy Policy)
- Gumroad Inc. — payment processing for international customers (Gumroad Privacy Policy)
- Netlify Inc. — website hosting (servers in the USA; Netlify is EU-U.S. Data Privacy Framework certified)
- Email delivery provider — for sending your download link and receipt
All third parties are contractually required to protect your data and may only use it for the specified purpose.
06 Cookies
We use the following cookies on bookguide.club:
- Essential cookies — required for the website to function (session, security)
- Analytics cookies — anonymous usage statistics to improve the site (opt-out available)
- Advertising cookies — only placed with your explicit consent via the cookie banner
You can manage cookie preferences at any time via the cookie settings link in the website footer, or through your browser settings.
07 Data Retention
- Purchase records — retained for 10 years as required by Czech/EU accounting law
- Email address — retained until you request deletion or unsubscribe
- Analytics data — aggregated and anonymized after 26 months
- Support correspondence — deleted 2 years after resolution
08 Your Rights
Under GDPR, you have the following rights regarding your personal data:
- Right of access — request a copy of all data we hold about you
- Right to rectification — request correction of inaccurate data
- Right to erasure — request deletion of your data ("right to be forgotten")
- Right to restriction — request we limit how we process your data
- Right to portability — receive your data in a machine-readable format
- Right to object — object to processing based on legitimate interest
- Right to withdraw consent — withdraw marketing consent at any time
To exercise any right, email us at info@bookguide.club. We will respond within 30 days.
You also have the right to lodge a complaint with your national data protection authority. In the Czech Republic: Úřad pro ochranu osobních údajů (ÚOOÚ).
09 Security
We take the security of your personal data seriously. Measures we have in place include:
- HTTPS encryption for all data transmitted to and from our website
- Payment data handled exclusively by PCI-DSS compliant GoPay — we never see your card details
- Access to customer data restricted to essential operations only
- Regular review of third-party service provider security practices
In the event of a data breach that poses a risk to your rights, we will notify you and the relevant supervisory authority within 72 hours as required by GDPR Article 33.
10 Contact & Updates
This policy was last updated on 17 May 2026. We may update it as our services evolve. Material changes will be communicated via email to existing customers.