Last updated: July 20, 2026
Privacy Policy
1. Who we are
klarpage is operated by Khaled Matar ("klarpage", "we", "us"), acting as the data controller under the EU General Data Protection Regulation (GDPR). Contact: klarpagecom@gmail.com.
2. What we collect
Account data: your email address, name, and profile picture when you sign in with Google. Site content: the text, images, and settings you enter to build your website. Billing data: when you buy Pro, our payment processor Paddle collects your name, billing address, country, and payment details; we receive only a transaction reference, the last four digits of your card, and your billing country. Usage data: technical logs such as IP address, browser, and timestamps for security and abuse prevention. Analytics: PostHog (EU region) records anonymous product usage on klarpage.com; sites you publish use cookie-less, privacy-first analytics with no IP storage or fingerprinting.
3. Google user data
When you sign in with Google, we request only your basic profile (email, name, avatar) via OAuth. We use it solely to create and authenticate your klarpage account. We do not read, write, or store any other Google data, we do not use it for advertising, and we do not sell or share it with third parties for their own purposes. klarpage's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
4. Why we process your data (legal basis)
Contract: to provide the klarpage service you signed up for. Legitimate interest: to keep the service secure, prevent abuse, and improve the product. Legal obligation: to keep invoicing and tax records. Consent: for optional product emails, which you can withdraw at any time.
5. Payments
Payments are processed by Paddle.com Market Ltd., which acts as the merchant of record and an independent data controller for billing data. Paddle handles tax calculation, invoicing, fraud checks, and chargebacks. Their privacy policy is available at paddle.com/legal/privacy.
6. Sub-processors
We rely on a small set of vetted providers to run klarpage: Supabase (database, auth, storage — EU region), Cloudflare (hosting and CDN), Paddle (payments and invoicing), PostHog EU (product analytics), and Resend (transactional email). Each is bound by a data processing agreement.
7. International transfers
Your data is stored in the European Union whenever possible. Where a sub-processor operates outside the EU, transfers are covered by Standard Contractual Clauses or an equivalent safeguard.
8. Retention
Account and site data are kept for as long as your account is active. If you delete your account, we remove personal data within 30 days, except for records we must keep for legal reasons (billing and tax records: up to 10 years). Server logs are kept for up to 90 days.
9. Your rights
Under GDPR you can request access, correction, deletion, restriction, portability, or object to processing of your personal data, and withdraw consent at any time. Email klarpagecom@gmail.com and we'll respond within 30 days. You also have the right to lodge a complaint with your local data protection authority.
10. Security
Data is encrypted in transit (TLS) and at rest. Access is limited to what's strictly necessary to operate the service. No system is perfectly secure — we'll notify affected users without undue delay in the event of a personal data breach.
11. Children
klarpage is not intended for children under 16. We do not knowingly collect personal data from children.
12. Changes
We may update this policy. Material changes will be announced by email or an in-app notice at least 14 days before they take effect.
13. Contact
Data controller: Khaled Matar. Email: klarpagecom@gmail.com.