Book Market AI operates worldwide as a digital publishing platform and marketplace. This Privacy Policy is constructed in strict compliance with the European Union General Data Protection Regulation (EU GDPR — Regulation 2016/679), the UK Data Protection Act 2018 (UK GDPR), United States federal and state privacy frameworks (California CCPA/CPRA, CalOPPA, COPPA, Virginia VCDPA, Colorado CPA, Connecticut CTDPA, Utah UCPA, Texas TDPSA, Oregon OCPA, Florida FDBR), the Canadian Personal Information Protection and Electronic Documents Act (PIPEDA), the Australian Privacy Act 1988 (Australian Privacy Principles), and the New Zealand Privacy Act 2020.
1. Data Controller & Contact Directory
The legal Data Controller responsible for your personal information is Book Market AI. For all data privacy inquiries, Data Subject Access Requests (DSARs), or to contact our designated Data Protection Officer (DPO):
- Legal & Data Protection Officer Email: privacy@bookmarket.ai
- Customer Support & Operations: support@bookmarket.ai
- Physical Headquarters / Correspondence: Book Market AI Legal Department
- Statutory Response Timeline: All formal data requests are acknowledged within 48 hours and resolved within 30 days (or 45 days where permitted under applicable state statutes).
2. Age Eligibility & Children's Privacy (COPPA & Global Standards)
Age Threshold: Book Market AI is intended for general audiences aged 13 years and older (and 16 years and older for residents of the European Economic Area and the United Kingdom, unless parental consent is provided).
- COPPA Compliance (US 15 U.S.C. § 6501): We do not knowingly collect, solicit, or maintain personal information from children under the age of 13.
- Parental Notification: If we discover that a child under 13 has provided personal data without verified parental consent, we immediately delete that data from our production and backup databases.
- Parental Rights: Parents or guardians who believe their child has registered an unauthorized account may contact privacy@bookmarket.ai for immediate verification and account termination.
3. Categories of Information We Collect
We collect information directly provided by you, generated automatically through app usage, and required for commercial transactions:
- Account & Identity Data: Full legal name, display name, email address, password cryptographic hash (bcrypt), profile avatar images, and author biographical notes.
- Financial & Merchant Data (Square): Transaction timestamps, purchased items, subscription tier status, currency, and author payout histories. Sensitive payment card numbers, CVVs, and expiration dates are tokenized directly by Square (Block, Inc.) and are never stored on Book Market AI servers.
- Physical Print Shipping Address (Lulu Direct): Full recipient name, physical street address, city, state/province, ZIP/postal code, country, and phone number collected solely to fulfill print-on-demand paperback and hardcover book orders.
- Author Publishing Content: Digital manuscripts (EPUB, PDF, TXT), cover artwork, audio narration tracks, book descriptions, ISBN numbers, page counts, and royalty payout accounts.
- Reading Activity & Device Telemetry: Real-time reading progress (page number, percentage, chapter bookmarks), offline downloaded content, library collections, wishlists, search queries, device operating system, app version, and IP address for geolocation compliance.
- Device Permissions (Camera & Media Storage): Camera and photo gallery access are requested solely when an author or reader explicitly chooses to capture or upload a profile picture or custom book cover. We never access camera feeds or photo libraries in the background.
4. Authentication, OTP Verification & Supabase Infrastructure
Book Market AI utilizes Supabase Auth for high-security user identity management and authentication:
- One-Time Password (OTP) & Email Confirmation: When registering or resetting credentials, a secure cryptographic One-Time Password (OTP) token is transmitted to your verified email address. These OTP tokens expire automatically within 60 minutes.
- Row-Level Security (RLS): All personal libraries, reader statistics, private manuscripts, and billing logs are isolated at the database level using cryptographic PostgreSQL Row-Level Security policies.
- Encryption Standards: All communications are encrypted in transit using Transport Layer Security (TLS 1.3/HTTPS) and all sensitive database tables and file storage buckets are encrypted at rest using AES-256.
5. Square Payment Processing & Merchant Compliance
All digital book purchases, author subscription plans ($3/month or $20/year), and physical print orders are processed via Square (Block, Inc.):
- PCI-DSS Level 1 Certification: Square is a certified PCI-DSS Level 1 payment processor. Payment card information entered in the checkout form is encrypted directly via Square's Web Payments SDK iframe.
- Data Handling by Square: Square processes your payment card details, billing address, and transaction amount in accordance with the Square Privacy Policy (https://squareup.com/legal/privacy).
- Fraud Prevention & Risk Management: Transactions are monitored through Square Risk Manager algorithms to protect buyers and authors against unauthorized charges, credit card fraud, and chargeback abuse.
- Currency & Author Payout Settlement: Author net royalties (100% of digital sales less third-party processing fees) are calculated automatically and remitted to author accounts via verified electronic settlement.
6. Google OAuth & Social Sign-In Integration Disclosure
Where Google Sign-In or social authentication features are enabled within Book Market AI:
- Information Accessed via Google OAuth: When you choose to authenticate with Google, we request access only to basic profile scopes (email, profile, openid), which provide your verified email address, full name, Google account ID, and profile picture.
- Limited Use Compliance: Book Market AI's use and transfer of information received from Google APIs adheres strictly to the Google API Services User Data Policy, including the Limited Use requirements.
- No Advertising or Brokerage Use: Google user data is utilized exclusively for account authentication and user profile display. We never sell Google user data, share it with data brokers, or use it for targeted advertising.
- Revoking Access: You can revoke Book Market AI's access to your Google account at any time via your Google Security Settings (https://myaccount.google.com/permissions).
7. United States State Privacy Laws Compliance
We extend comprehensive consumer privacy protections across all 50 US states in accordance with state consumer privacy legislation:
- California (CCPA / CPRA / CalOPPA / Shine the Light): California residents have the Right to Know, Access, Correct, and Delete personal data. We do not sell personal information or share personal information for cross-context behavioral advertising (opt-out is enabled by default).
- Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA): Consumers have the right to confirm processing, access data, correct inaccuracies, delete data, obtain a portable copy, and opt-out of targeted profiling.
- Utah (UCPA) & Texas (TDPSA): Transparent disclosure of data categories, consumer rights to delete and access data, and strict purpose limitation standards.
- Oregon (OCPA) & Florida (FDBR): Comprehensive rights to obtain lists of specific third-party disclosures and sensitive data protection.
- Washington State (My Health My Data Act): Book Market AI does not collect, track, or process consumer health data.
8. European Union (GDPR) & United Kingdom (UK GDPR) Privacy Rights
Under Regulation (EU) 2016/679 (GDPR) and the UK Data Protection Act 2018, data subjects in the EEA and UK have the following statutory rights:
- Right of Access (Art. 15): Request confirmation of processing and obtain a complete copy of your personal data.
- Right to Rectification (Art. 16): Correct inaccurate or incomplete personal records.
- Right to Erasure / 'Right to be Forgotten' (Art. 17): Request permanent deletion of your data via our instant deletion portal or email.
- Right to Restriction of Processing (Art. 18): Limit the scope of data processing in disputed circumstances.
- Right to Data Portability (Art. 20): Receive your library, reading logs, and uploaded manuscripts in a structured, machine-readable format (JSON/CSV).
- Right to Object (Art. 21): Object to processing based on legitimate interests or direct communications.
- International Transfers & Standard Contractual Clauses (SCCs): For data transferred outside the EEA/UK, we execute European Commission Standard Contractual Clauses to guarantee equivalent protection.
- Supervisory Authority Complaint: You have the right to lodge a complaint with your local EU Data Protection Authority or the UK Information Commissioner's Office (ICO).
9. Canada (PIPEDA), Australia (APPs) & New Zealand Privacy Acts
- Canada (PIPEDA & Provincial Acts): We adhere to the 10 fair information principles under PIPEDA, providing clear purpose identification, explicit consent mechanisms, and transparent individual access rights.
- Australia (Privacy Act 1988 & APPs): Personal data is managed in compliance with the 13 Australian Privacy Principles, ensuring open and transparent management, cross-border disclosure safeguards, and direct correction mechanisms.
- New Zealand (Privacy Act 2020): Compliant with the 13 Information Privacy Principles (IPPs) regarding lawful collection, security, individual access, and cross-border transfer protections.
10. Transactional Communications & Email Notifications
We send essential transactional emails (order receipts, OTP verification codes, password resets, author sales digests, and critical platform security notices). We do not send marketing spam. You may manage optional communication preferences in your profile settings at any time.