Privacy Policy
Last Updated: January 14, 2026
1. WHO WE ARE AND WHAT THIS POLICY COVERS
About Printsyde
Printsyde operates an online platform at printsyde.com where customers purchase custom print-on-demand products and digital downloads, while independent artists and designers earn commissions on sales featuring their creative work.
Important: When you purchase from Printsyde, you're buying directly from us. We are the merchant-of-record, not a marketplace connecting you with individual sellers.
Legal Entities:
OneF Holdings Limited (Hong Kong) - Primary company
- Registered Office: Suite C, Level 7, World Trust Tower, 50 Stanley Street, Central, Hong Kong
Printsyde LLC (Wyoming, USA) - US operations
- Registered Office: 2232 Dell Range Blvd, Cheyenne, WY 82009, United States
Operations Office: A30-X3 44 Nguyen Co Thach, Tu Liem Ward, Hanoi, Vietnam (staff location only, not a separate legal entity)
What This Policy Covers
This Privacy Policy explains what personal information we collect, how we use it, who we share it with, and your rights regarding your data.
This policy applies to:
- Our website (printsyde.com)
- Mobile applications (if any)
- Seller dashboard and customer accounts
- Email communications from us
This policy does NOT cover:
- Payment processor websites (PayPal and Stripe have their own privacy policies)
- Third-party websites we link to
- Social media platforms where we maintain pages
Three Types of Users
- Visitors - Browsing our website without creating an account
- Customers - Purchasing physical products or digital downloads
- Sellers/Artists - Uploading designs to earn commissions
Privacy Laws We Comply With
We follow privacy laws in countries where we operate and serve users:
- Hong Kong Personal Data (Privacy) Ordinance (Cap. 486)
- European Union General Data Protection Regulation (GDPR)
- United Kingdom UK GDPR
- United States California Consumer Privacy Act (CCPA/CPRA)
- Australia Privacy Act 1988
- Canada Personal Information Protection and Electronic Documents Act (PIPEDA)
2. INFORMATION WE COLLECT
When You Browse Our Website (No Account Required)
We automatically collect:
- IP address, browser type, device type, operating system
- Pages you view, time spent on site, website that referred you
- Country or region (not precise location)
When You Create a Customer Account
You provide:
- Email address
- Password (we store it encrypted, never in plain text)
- Your name
We generate:
- Unique customer ID number
- Account creation date
- Account status (active, suspended, closed)
When You Purchase Physical Products
You provide:
- Full shipping address (name, street, city, state/province, postal code, country)
- Phone number (for delivery notifications)
- Product selections (items, quantities, any customizations)
We generate:
- Order number, date and time
- Order total and currency
- Order status (processing, shipped, delivered)
We receive from payment processors:
- Payment confirmation (approved or declined)
- Transaction ID
- Payment method type only (e.g., "Visa ending in 1234" - we never see full card numbers)
We receive from fulfillment partners:
- Tracking number and carrier name
- Manufacturing status updates
- Delivery confirmation
When You Purchase Digital Products
Everything listed above for physical products, PLUS:
- License type: Personal Use
- Download date, time, and IP address
- Number of downloads you've used
- Download link status (active or expired)
- For UK/EU customers: Timestamp when you consented to immediate delivery and acknowledged losing your 14-day cancellation right
Why we track downloads: To prevent fraud and defend against payment disputes by proving you received the file.
When You Create a Seller Account
You provide:
- Full legal name, email address, phone number, country of residence
- Business name, business type (individual or company), business registration number (if applicable)
- PayPal account email or ID (for receiving commission payments)
We generate:
- Unique seller ID number
- Account status and tier
- Sales statistics (total sales, commission earned, pending balance available for payout)
- Compliance records (IP complaints, strikes, violations)
Important note about seller verification: PayPal conducts identity verification separately. They may request documents from you such as government ID, tax forms, or proof of address. You provide those documents directly to PayPal through their secure system, not to us. We only receive a "verified" or "not verified" status from PayPal.
When You Contact Customer Service
You provide:
- Details of your inquiry or issue
- Order number (if you're asking about a specific order)
- Photos or videos (if reporting a defect or return)
- Any other information you choose to share with us
We generate:
- Support ticket number
- Ticket status and resolution notes
- History of our correspondence
When Sellers Upload Content
You provide:
- Design files (images, graphics, digital product files)
- Product titles, descriptions, tags, categories
- Pricing information
Information We Receive From Third Parties
Payment Processors (PayPal and Stripe):
- Payment confirmations and transaction IDs
- Settlement status
- Chargeback and refund notifications
- Seller verification status (verified/not verified only)
- Seller payout eligibility status
Fulfillment Partners (Merchize, ShineOn, Printify, etc.):
- Manufacturing status updates
- Quality control reports
- Tracking numbers and delivery confirmations
- Return or damage reports
Shipping Carriers (USPS, FedEx, UPS, DHL):
- Package tracking events
- Delivery confirmations
- Delivery exceptions (delays, failed delivery attempts)
Analytics and Security Services:
- Google Analytics: Website traffic patterns (anonymized)
- Meta (Facebook) Pixel: Advertising performance and conversion tracking
- Cloudflare: Security threats detected, DDoS attacks blocked, performance metrics
3. HOW WE USE YOUR INFORMATION
Legal Basis for Processing (For EU/UK Users)
We process your personal information based on:
- Contract Performance - To fulfill your orders and provide services you requested
- Legal Obligations - To comply with tax laws, respond to legal requests, enforce our Terms of Service
- Legitimate Interests - For fraud prevention, customer service, business analytics, and marketing to existing customers (with opt-out)
- Consent - For marketing to non-customers, non-essential cookies, and promotional (you can withdraw consent anytime)
Specific Uses
To Fulfill Physical Product Orders:
- Assign your order to the appropriate manufacturing facility (US, Vietnam, or China based on efficiency)
- Send your shipping address to our fulfillment partner for production
- Generate and provide tracking information
- Coordinate delivery and handle failed delivery attempts
- Process returns, exchanges, and refunds
To Deliver Digital Products:
- Generate secure, temporary download links
- Track download activity (fraud prevention and chargeback defense)
- Maintain download link access for 30 days from purchase
- Process re-download requests if you contact customer service within the access period
- Collect evidence for payment disputes if necessary
To Process Payments:
- Send order details to PayPal or Stripe for payment authorization
- Receive payment confirmations
- Process refunds through payment processors
- Defend against chargebacks with transaction evidence
- Calculate and pay seller commissions on a monthly schedule
- Verify seller eligibility for payouts
To Provide Customer Service:
- Respond to inquiries via email (customerservice@printsyde.com) and phone
- Investigate order issues and quality problems
- Process refund and return requests
- Handle customer complaints and disputes
- Track support tickets through to resolution
To Manage Seller Accounts:
- Verify email ownership (confirmation links)
- Monitor sales performance and calculate commission earnings
- Enforce intellectual property policies (DMCA takedowns)
- Implement our three-strike system for violations
- Coordinate with PayPal to check seller verification status
- Manage account suspensions and terminations
For Security and Fraud Prevention:
- Detect suspicious patterns (multiple accounts from same device, unusual transaction velocity)
- Prevent payment fraud, fake orders, and chargebacks
- Block bot activity and automated scraping
- Enforce account security measures (password resets, login alerts)
For Legal Compliance:
- Process DMCA takedown notices (24-hour response time)
- Terminate repeat infringers (three-strike policy)
- Calculate and collect sales tax, VAT, and GST as required by law
- Respond to subpoenas, court orders, and government requests
- Enforce Terms of Service violations
- Execute seller indemnification obligations for legal claims
For Business Analytics and Improvement:
- Analyze sales trends and product performance (aggregate data only)
- Optimize website user experience (A/B testing, page load speeds)
- Measure marketing campaign effectiveness
- Monitor platform performance and uptime
- Identify popular products and categories
For Marketing and Communications:
Transactional emails (you cannot opt-out):
- Order confirmations
- Shipping notifications and delivery updates
- Commission payment notifications
- Account security alerts
Marketing emails (you can opt-out anytime):
- Promotional offers and discounts
- New product announcements
- Feature updates and platform news
- Seller newsletters
- Re-engagement campaigns
4. WHO WE SHARE YOUR INFORMATION WITH
Service Providers We Use
Payment Processors
- Who: PayPal, Inc. and Stripe, Inc.
- Why: To process customer payments and send commission payments to sellers
- What we share: Order details, customer names and email addresses, transaction amounts, seller payout information
Authentication Services
- Who: Google (Google Certificate API)
- Why: To enable the "Sign in with Google" feature
- What we share: Your email address and basic profile information (name, profile picture) if you choose to link your Google account
Address Verification
- Who: Smarty (address validation service)
- Why: To verify and standardize shipping addresses, reducing delivery errors
- What we share: Shipping addresses you provide during checkout
Manufacturing Partners (Physical Products Only)
- Who: Merchize Vietnam Co., Ltd. (Vietnam), ShineOn (USA), Printify (global network), Chinese manufacturing facilities
- Why: To produce custom print-on-demand products
- What we share: Shipping addresses, order details, design files for printing
Shipping Carriers
- Who: USPS, FedEx, UPS, DHL, and regional carriers
- Why: To deliver packages to customers
- What we share: Shipping addresses, phone numbers for delivery notifications, tracking numbers
Cloud Hosting and File Storage
- Who: Cloudflare R2, Cloudflare CDN
- Why: To host digital product files, generate download links, and ensure fast website loading
- What we share: Digital product files, download activity logs, website content
Email Services
- Who: Postmark
- Why: To send transactional and marketing emails (order confirmations, shipping updates, newsletters)
- What we share: Email addresses, names, order information, email content
Customer Support
- Who: Freshdesk
- Why: To manage support tickets and customer inquiries efficiently
- What we share: Contact information, order details, support ticket content, correspondence history
Analytics and Advertising
- Who: Google Analytics, Google Ads, Meta (Facebook) Pixel, Cloudflare Analytics
- Why: To understand website traffic, improve user experience, measure advertising performance, and retarget visitors
- What we share: Anonymized browsing behavior, page views, conversion events
Legal and Compliance Sharing
Law Enforcement and Government Authorities
We share information when legally required by:
- Valid subpoenas, court orders, or search warrants
- Proper legal process from government authorities
- Emergency situations involving imminent harm or danger to life
Intellectual Property Rights Holders
For IP infringement complaints, we:
- Forward DMCA takedown notices to accused sellers
- Process counter-notices per DMCA legal requirements
Important privacy protection: We do NOT disclose seller contact information to complainants without a valid court order. This protects seller privacy under GDPR, CCPA, and Singapore PDPA obligations.
Tax Authorities
As legally required, we provide:
- Sales tax, VAT, and GST reporting (aggregate data)
- Audit responses (specific transaction data only if legally compelled)
- Cross-border transaction reporting where required by law
Business Transactions
If Printsyde is acquired, merged, or sells assets:
- We may share information with potential buyers during due diligence (under strict confidentiality agreements)
- Information transfers to the successor company if the sale is completed
Your rights: We will notify you of any ownership change. You can close your account if you object to the new owner.
5. DATA SECURITY AND RETENTION
How We Protect Your Information
Important disclosure: Printsyde is a small operation. We implement reasonable security measures appropriate to our size and the sensitivity of data we handle.
Security measures we use:
- HTTPS encryption for all website traffic
- Firewall protection and DDoS protection (via Cloudflare)
- Limited staff access (only employees who need data to perform their job can access it)
- Multi-factor authentication required for all staff accounts
- Regular security updates and patches
- Automated alerts for suspicious activity
Important limitations you should know:
- No system is 100% secure. We cannot guarantee absolute security.
- You are responsible for keeping your password safe and confidential.
- We cannot be held responsible for unauthorized access resulting from your failure to protect your password.
- Report suspected security issues immediately to legal@printsyde.com
How Long We Keep Your Information
Customer and Seller Accounts:
- Active accounts: While your account remains open
- Order and commission records: 7 years (required by tax and accounting regulations)
- Support tickets: 3 years after resolution
- Deleted accounts: 30-day grace period (in case you change your mind), then permanent deletion. Exception: Order records kept 7 years for tax compliance even after account deletion.
Transaction Data:
- Payment records: 7 years (financial regulations)
- Chargeback records: 3 years after final resolution
- Refund records: 7 years (accounting requirements)
Digital Product Data:
- Download logs: 180 days after purchase (matches chargeback defense window)
- Download logs for active disputes: Up to 3 years if under investigation
- UK/EU consent records: 7 years (proof of compliance with withdrawal right waiver)
Website Data:
- Server logs: 90 days (rolling deletion)
- Security logs: 12 months
- Analytics data: 24 months for individual user data; indefinitely for aggregate trends (no personal identifiers)
- Marketing email lists: Until you unsubscribe plus 30 days
- Unsubscribe records: Kept indefinitely (to honor your opt-out request)
Seller-Specific Data:
- IP complaint history: 3 years after resolution (longer if active litigation)
- Terminated seller accounts:
- Commission and transaction data: 7 years (legal and tax requirements)
- Design files and personal information: Deleted within 90 days
- Indemnification records: Indefinitely (for legal defense purposes)
If a Data Breach Occurs
We will take the following steps:
- Investigate immediately - Identify what happened and what data was affected
- Stop the breach - Secure our systems and fix the vulnerability
- Notify as legally required:
- EU/UK users: Notify supervisory authority within 72 hours if the breach poses high risk to your rights and freedoms
- California users: Notify without unreasonable delay
- Singapore users: Notify if significant harm is likely
- All affected users: Direct notification if high risk (via email and account dashboard alert)
- Inform you clearly about:
- What happened and when
- What data was affected
- What we're doing to fix it and prevent future breaches
- Steps you can take to protect yourself
- How to contact us with questions
6. YOUR PRIVACY RIGHTS
Your privacy rights depend on where you live. This section explains what you can do and how to exercise your rights.
EU and UK Residents (GDPR)
Your Rights:
- Access - Get a copy of your data (30 days)
- Correct - Fix wrong information (30 days)
- Delete - Erase your data (30 days, with legal exceptions for tax records)
- Restrict - Pause how we use your data while resolving disputes
- Portability - Download your data in machine-readable format (CSV/JSON)
- Object - Stop us using your data for legitimate interests (we must stop unless we have overriding reasons). You can always opt-out of marketing - we must stop immediately.
- Withdraw consent - Stop future processing based on consent anytime
Automated decisions: We don't make automated decisions that significantly affect you. Fraud alerts are advisory only - humans make all final decisions.
Not satisfied? Lodge a complaint with your data protection authority:
- UK: ico.org.uk
- EU: edpb.europa.eu/about-edpb/board/members_en
California Residents (CCPA/CPRA)
Your Rights:
- Know - What personal info we collect, where it's from, why we use it, who we share it with (45 days)
- Delete - Remove your personal info (45 days, with legal exceptions)
- Correct - Fix inaccurate information (45 days)
- Opt-out of sale/sharing - We DON'T sell or share your data. No action needed.
- Limit sensitive data use - We DON'T collect sensitive data (SSN, precise location, health info, etc.). No action needed.
Non-discrimination: We won't deny service, charge more, or provide worse service if you exercise your rights.
Authorized agents: You can designate someone to make requests for you (requires written authorization).
Hong Kong Residents (Personal Data Privacy Ordinance)
Your Rights:
- Access - Request a copy of your personal data (40 days)
- Correct - Request correction of inaccurate data (40 days)
- Data Portability - Request data in commonly used format where technically feasible
- Object to Marketing - Opt-out of direct marketing at any time
Australian Residents (Privacy Act)
Your Rights:
- Access - See your personal information (30 days)
- Correct - Fix inaccurate, outdated, incomplete, or misleading information (30 days)
How to Make a Request
Email: legal@printsyde.com (fastest)
Mail:
- Singapore: 7500A Beach Road, #04-326, The Plaza, Singapore 199591
- USA: 2232 Dell Range Blvd, Cheyenne, WY 82009
Include:
- Your name and email
- What you want (access, delete, correct, etc.)
- Preferred response format
Response time: 30 days (45 days for California). Complex requests may take 60-90 days - we'll notify you if we need extra time.
7. INTERNATIONAL DATA TRANSFERS
Where Your Data Goes
Primary locations:
- Hong Kong: Main database servers (OneF Holdings Limited)
- United States: US subsidiary operations and some cloud services
- Vietnam: Operations office staff access (not a separate data controller)
Service provider locations:
- PayPal: US-based with global payment processing infrastructure
- Stripe: US-based, certified for EU data transfers
- Cloudflare R2: Worldwide data centers for file storage and CDN
- Fulfillment partners: Manufacturing in US (ShineOn), Vietnam (Merchize), China (various facilities)
Safeguards for EU/UK Data
If you're in the EU or UK, your data may be transferred to countries that don't have an EU "adequacy" decision. We protect your data through:
Standard Contractual Clauses (SCCs)
- EU Commission-approved contracts for international data transfers
- Create binding legal obligations on us and our service providers
- You can request a copy by emailing legal@printsyde.com
Additional protections:
- Encryption of data in transit and at rest
- Access controls and audit trails
- Regular security assessments
- Supplementary measures to address government surveillance risks where applicable
Specific transfers:
- Hong Kong: Has EU adequacy decision (as of 2024, subject to periodic review). Allows free flow of personal data from EU/UK to Hong Kong for organizations complying with Hong Kong PDPO.
- United States: Not deemed adequate. Standard Contractual Clauses or Privacy Shield successor frameworks for service providers.
- China: Manufacturing partner data (shipping addresses only). Limited strictly to order fulfillment purposes with contractual data protection obligations.
Your Rights Regarding International Transfers
You have the right to:
- Object to transfers to certain countries (may affect our ability to provide services to you)
- Request information about the safeguards in place for your data
- Obtain copies of transfer mechanism documents (such as Standard Contractual Clauses)
Contact: legal@printsyde.com
8. COOKIES AND TRACKING
What Are Cookies?
Cookies are small text files stored on your device when you visit our website. They help the site function properly and improve your browsing experience.
Types of Cookies We Use
Essential Cookies (Always Active - Cannot Opt Out)
These cookies are necessary for the website to function and cannot be disabled:
Purpose:
- Remember items in your shopping cart
- Keep you logged in as you browse
- Security tokens (prevent hacking and unauthorized access)
- Server routing (ensure fast page loading)
- Your cookie consent preferences
Duration: Session cookies (deleted when you close your browser) or up to 30 days
Why you cannot opt out: Without these cookies, core website features like checkout, login, and account access will not work. These cookies do not track your browsing across other websites and are strictly necessary for the website to operate.
Analytics & Marketing Cookies (Optional - Requires Your Consent)
EU/UK Users: We will ask for your consent before using these cookies
Non-EU Users: These cookies are enabled by default, but you can opt out anytime
These cookies include:
Analytics Cookies:
- Google Analytics: Traffic sources, popular pages, user flows, website performance
- Cloudflare Analytics: Performance metrics, security events, page load optimization
Marketing/Advertising Cookies:
- Meta (Facebook) Pixel: Track conversions, build audiences for Facebook/Instagram ads, measure ad campaign effectiveness
- Google Ads: Retargeting, conversion tracking, ad performance measurement
Duration: Up to 13-24 months depending on the specific cookie
What these cookies do:
- Help us understand how people use our site so we can improve it
- Show you relevant ads on Facebook, Instagram, and Google
- Measure whether our marketing campaigns are effective
- Remember your preferences for future visits
Email Tracking: We also use small pixels in marketing emails to track opens and clicks. This helps us understand which content is most valuable to you.
Privacy Note: Analytics data is anonymized with no personally identifiable information in aggregate reports. Marketing cookies may be used by third-party advertising networks to show you targeted ads across the internet.
Managing Your Cookie Preferences
EU/UK Users
You'll see a cookie banner on your first visit with these options:
Option 1: Accept All Cookies
- Essential cookies: Active (required)
- Analytics & Marketing cookies: Active
Option 2: Reject Optional Cookies
- Essential cookies: Active (required)
- Analytics & Marketing cookies: Disabled
You can change your preferences anytime using the "Cookie Settings" link in our website footer.
Non-EU/UK Users
All cookies are enabled by default, but you can opt out via:
Browser Settings (see instructions below for your browser)
Email Unsubscribe Links (stops email tracking pixels)
Industry Opt-Out Tools:
- Digital Advertising Alliance: optout.aboutads.info
- Network Advertising Initiative: optout.networkadvertising.org
Browser Cookie Controls
You can also manage cookies directly through your browser settings:
Google Chrome:
- Settings → Privacy and security → Cookies and other site data
- Choose "Block third-party cookies" or "Block all cookies"
Mozilla Firefox:
- Settings → Privacy & Security → Cookies and Site Data
- Choose "Delete cookies and site data when Firefox is closed" or custom settings
Apple Safari:
- Preferences → Privacy → Manage Website Data
- Choose "Block all cookies" or remove specific cookies
Microsoft Edge:
- Settings → Privacy, search, and services → Cookies and site data
- Choose "Block third-party cookies" or "Block all cookies"
Important: If you block all cookies, you will not be able to use essential website features like shopping cart and account login.
Consequences of Disabling Cookies
Key Point: You can fully use Printsyde with only essential cookies enabled. Disabling analytics and marketing cookies does NOT affect core shopping, checkout, or account features.
Third-Party Cookie Policies
The following third-party services set cookies on Printsyde:
Cookie Duration and Deletion
Session Cookies:
- Deleted automatically when you close your browser
- Used for: Login sessions, shopping cart
Persistent Cookies:
- Remain on your device for a specified period (up to 24 months)
- Used for: Analytics tracking, ad targeting, remembering preferences
How to Delete Cookies:
- Use browser settings to clear all cookies
- Use browser privacy mode/incognito mode (cookies deleted when session ends)
- Use our "Reject Optional Cookies" option for analytics and marketing cookies
Do Not Track (DNT) Signals
Current Status: Like most websites, Printsyde does not currently respond to "Do Not Track" browser signals because there is no universal standard for how websites should respond to DNT.
Your Control: You can control cookies through:
- Our cookie consent banner (EU/UK users)
- Browser cookie settings (all users)
- Third-party opt-out tools listed above
Updates to Cookie Practices
We may update our cookie practices from time to time to:
- Add new analytics or marketing tools
- Improve website performance
- Comply with new regulations
How we notify you:
- EU/UK users: New cookie consent request if we add new cookie categories
- All users: Updated "Last Modified" date at top of Privacy Policy
- Material changes: Email notification to account holders
Questions About Cookies?
If you have questions about our cookie practices, contact us at:
- Email: legal@printsyde.com
- Mail: See Section 11 for postal addresses
9. CHILDREN'S PRIVACY
Age Requirement
Minimum age: 18 years old
Our Terms of Service (Section 4.1) prohibit anyone under 18 from using Printsyde.
We Do Not Collect Children's Data
- Account registration requires you to confirm you are 18 or older
- We do not knowingly collect personal information from anyone under 18
- Our services are not directed to children
- If we discover a user is under 18, we will immediately terminate the account and delete all associated data
If you are a parent or guardian and discover your child created an account, contact us immediately at legal@printsyde.com so we can remove it.
10. POLICY UPDATES
When and How We Update This Policy
We may update this Privacy Policy to:
- Reflect changes in our practices
- Comply with new legal requirements
- Add new features or services
- Improve clarity and readability
Material changes (significantly affect your rights):
- Email notification to all active account holders
- 30-day notice period before the changes take effect
- Prominent banner displayed on our website
Non-material changes (minor updates, clarifications, formatting):
- "Last Updated" date at the top will change
- Changes effective immediately upon posting
- Your responsibility to check periodically for updates
Your Choices
- Continued use of Printsyde after the effective date means you accept the updated policy
- Close your account if you disagree with material changes (email legal@printsyde.com before the effective date)
- Previous versions available upon request at legal@printsyde.com
11. CONTACT US
11.1 Privacy Questions and Requests
Email (fastest method): legal@printsyde.com
Response time: 5-7 business days
Mail:
Hongkong: OneF Holdings Limited. Suite C, Level 7, World Trust Tower, 50 Stanley Street, Central, Hong Kong
United States: Printsyde LLC 2232 Dell Range Blvd Cheyenne, WY 82009
Operations Office (not for legal correspondence): A30-X3, 44 Nguyen Co Thach Tu Liem Ward Hanoi 100000, Vietnam
11.2 Data Protection Officer
For EU/UK GDPR inquiries: Email: legal@printsyde.com
(Designated Data Protection Officer will be appointed if/when required by processing volume)
END OF PRIVACY POLICY


