Privacy Policy

Last updated: September 21, 2026

This Privacy Policy explains how PdfGen (“we”, “us”, or “our”) collects, uses, shares, and protects personal data when you use the Service at https://pdfgen2.novtopro.com. It is written to align with common SaaS disclosures under frameworks such as the GDPR and CCPA/CPRA, adapted to what PdfGen actually does. By using the Service, you acknowledge this Policy. If you do not agree, do not use the Service.

1. Who we are and roles

Controller for account and billing-related personal data: the operator of PdfGen, reachable at novtopro@gmail.com.

For Customer Content that includes personal data about your end users, you are typically the controller and we act as a processor: we process that content only to render PDFs, enforce limits, and secure the Service, as instructed by your use of the API or dashboard.

2. Personal data we collect

Account data: email address and Google account identifier (subject) when you sign in with Google; plan, subscription status, and related account timestamps.

Authentication and preferences: session cookies; optional locale preference cookie.

API credentials: key display name, key prefix, and a one-way hash of the secret (the full secret is shown once at creation and not stored in plaintext).

Usage and metering: monthly successful PDF counts, related byte totals, and rate-limit counters tied to your account or API key.

Payments: checkout email, plan, provider session identifiers, and webhook event payloads via Waffo. We do not store full payment card numbers; cards are handled by the payment provider.

Security signals: Cloudflare Turnstile tokens/results when enabled on sign-in flows.

Render inputs: HTML/CSS bodies or URLs you ask us to fetch for convert/preview. These are processed to return a PDF and are not kept as a permanent document library.

Operational logs: timestamps, request metadata, status codes, and error messages needed to run and secure the Service.

We do not currently run third-party product analytics pixels (for example Google Analytics) on the marketing site.

3. Sources of data

We collect data directly from you (account, API requests, forms), automatically from your device/browser (cookies, logs), and from processors you interact with through us (Google sign-in profile basics; Waffo payment events).

4. How we use personal data

Provide, operate, and improve the Service (authentication, PDF rendering, dashboard, API).

Meter plans, enforce rate limits and quotas, and prevent abuse or fraud.

Process subscriptions and payments, and send transactional notices (billing, security, service changes).

Comply with law, respond to lawful requests, and establish, exercise, or defend legal claims.

We do not sell personal data and do not use it for third-party advertising.

5. Legal bases (EEA/UK and similar)

Contract (Art. 6(1)(b) GDPR): creating and managing your account, providing the API/dashboard, and processing paid subscriptions.

Legitimate interests (Art. 6(1)(f)): securing the Service, preventing abuse, basic operational logging, and product reliability—balanced against your rights.

Legal obligation (Art. 6(1)(c)): retaining transaction records where tax or accounting law requires.

Consent (Art. 6(1)(a)): where we rely on consent (for example certain optional cookies if introduced later); you may withdraw consent without affecting prior lawful processing.

6. Sharing and processors

We share personal data only with service providers that help us run PdfGen, under appropriate agreements: Google (OAuth sign-in), Waffo (payments and subscription webhooks), Cloudflare (Turnstile and related edge/security services), and hosting/infrastructure providers that process data to keep the Service online.

We may disclose data if required by law, to protect rights, safety, or security, or in connection with a merger, acquisition, or asset sale (with notice where required). We do not sell personal data.

7. Cookies and similar technologies

Essential cookies: session cookie to keep you signed in; locale preference cookie when you choose a language. These are necessary for the Service to function.

Security: Cloudflare Turnstile may set or read tokens as part of bot protection on authentication flows.

We do not currently use non-essential advertising or analytics cookies. If that changes, we will update this Policy and, where required, seek consent.

8. International transfers

We and our processors may process data in countries other than your own. Where required (for example transfers from the EEA/UK), we rely on appropriate safeguards such as the processor’s standard contractual clauses or other lawful transfer mechanisms.

9. Retention

Account profile and API key metadata: for the life of the account, then deleted or anonymized within 90 days after account closure, except where retention is required for disputes or law.

Sessions: until expiry or logout.

Usage metering records: typically up to 24 months for billing integrity and abuse prevention.

Payment and webhook records: generally up to 7 years where needed for tax, accounting, or chargeback handling (or shorter if law allows and business need ends).

Operational logs: typically up to 90 days, unless needed longer for security investigations.

Customer Content (HTML/CSS submitted for render): not retained as a document archive after the request completes, subject to transient processing memory/buffers and standard backup cycles of infrastructure that do not intentionally store document libraries.

10. Security

We use commercially reasonable measures including HTTPS in transit, hashed API secrets, session controls, and access restrictions on production systems. No method of transmission or storage is completely secure; you are responsible for protecting API keys and account access.

11. Your rights

Depending on your location, you may have rights to access, correct, delete, or export personal data; restrict or object to certain processing; and withdraw consent where processing is consent-based. California residents may have rights under the CCPA/CPRA (including to know, delete, and correct). We do not sell or share personal data for cross-context behavioral advertising as those terms are commonly defined.

To exercise rights, email novtopro@gmail.com. We may need to verify your identity. We aim to respond within 30 days (or sooner if local law requires). If we process Customer Content as your processor, contact your organization first for end-user requests about that content.

You may lodge a complaint with your local data protection authority.

12. Children

The Service is not directed to children under 13, and we do not knowingly collect personal data from them. If you believe a child has provided data, contact novtopro@gmail.com and we will take appropriate steps to delete it.

13. Changes to this Policy

We may update this Policy by posting a new version on this page and revising the “Last updated” date. Material changes will be highlighted when practicable (for example by email or notice). Continued use after the effective date means you accept the updated Policy.

14. Contact

Privacy questions and data-subject requests: novtopro@gmail.com. Website: https://pdfgen2.novtopro.com.