Privacy Policy
Effective: May 18, 2026
Last updated: May 18, 2026
What this policy covers
SmartPrintAI ("we", "us") provides an AI-powered print-on-demand service at smartprintai.com. This policy explains the personal data we collect, why we process it, who we share it with, how long we keep it, and the rights you have under the EU General Data Protection Regulation (GDPR).
Data controller: SmartPrintAI, operated by Matthieu Kokabi. For data-protection enquiries, contact privacy@smartprintai.com.
Service providers (processors)
We use the following processors to operate the service. Each one only receives the data needed for its specific task, under a written processing agreement.
- Stripe Payments Europe Ltd (Ireland) — parent Stripe, Inc. (US)Payment processing. Receives card details, billing address, email, and order amount.EU + US
- Printful Latvia, SIA (Latvia) and Printful, Inc. (US)On-demand fulfillment for Printful-routed items. Receives shipping address, recipient name, email, product variant, and design file URL.EU + US
- Gelato AS (Norway)On-demand fulfillment for Gelato-routed items. Receives shipping address, recipient name, email, product variant, and design file URL.Norway (EEA) + global production network
- Gooten, Inc. (United States)On-demand fulfillment for Gooten-routed items. Receives shipping address, recipient name, email, product variant, and design file URL.US
- Resend.com Inc. (United States)Transactional and marketing email delivery (order confirmation, shipment notification, support replies, discount-lead emails). Receives your email address and order metadata.US
- Google LLC — Gemini API (US) and Google Ireland Ltd. (Ireland)AI image generation. Receives the design prompt you type. Does not receive your email or shipping address.US + EU
- Google LLC — Google Analytics 4 (US) and Google Ireland Ltd. (Ireland)Aggregate site analytics. Loads cookieless pings always (consent-mode v2) and only stores cookies after you click Accept on the cookie banner. Anonymized IP is used.US + EU
- Make.com (Celonis SE, Czech Republic)Internal automation: order-event alerts, abandoned-cart triggers, daily ops digest. Receives order metadata (order ID, total, customer email, status).EU
- Hostinger International Ltd. (Lithuania / Cyprus)VPS hosting provider. Stores the database, design files, server logs, and backups that run the service.EU
Your rights under the GDPR
You have the following rights regarding the personal data we process about you:
- Right of access to your personal data (Article 15 GDPR)
- Right to rectification of inaccurate data (Article 16 GDPR)
- Right to erasure ("right to be forgotten") (Article 17 GDPR)
- Right to restriction of processing (Article 18 GDPR)
- Right to data portability (Article 20 GDPR)
- Right to object to processing (Article 21 GDPR)
- Right to withdraw consent at any time (Article 7(3) GDPR)
- Right to lodge a complaint with a supervisory authority (Article 77 GDPR)
To exercise any of these rights, email privacy@smartprintai.com from the address associated with your account. We aim to respond within 30 days as required by the GDPR.
If you believe we are not handling your data correctly, you may complain to the data-protection authority in the EU member state where you live, work, or where the issue occurred — for example the CNIL in France, the BfDI in Germany, or the AEPD in Spain.
How long we keep data
We keep personal data only as long as we have a lawful reason to:
- Order records: 10 years (mandatory under most EU tax and accounting law)
- Support requests: 2 years from last contact
- Marketing-list email (discount sign-up): Until you unsubscribe, then deleted within 30 days
- Analytics data (when consented): 14 months in Google Analytics 4, then automatically deleted by Google
- Server logs: 30 days, then automatically rotated
- Backups: 30 days rolling, then overwritten
Contact us
For any question, concern, or request about your personal data:
privacy@smartprintai.com