Privacy Policy
Effective Date: April 27, 2026
1. Introduction
We are committed to protecting your personal data and respecting your privacy in compliance with applicable data protection laws worldwide, including but not limited to:
- EU General Data Protection Regulation (GDPR) - Regulation (EU) 2016/679
- Italian Legislative Decree no. 196/2003 (Privacy Code, as amended by D.Lgs. 101/2018)
- California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) - Cal. Civ. Code § 1798.100 et seq.
- Children's Online Privacy Protection Act (COPPA) - 15 U.S.C. §§ 6501-6506
- Brazil's Lei Geral de Proteção de Dados (LGPD) - Law No. 13,709/2018
- UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018
- Canada's Personal Information Protection and Electronic Documents Act (PIPEDA)
- Australia's Privacy Act 1988 and the Australian Privacy Principles (APPs)
- Other applicable national and regional privacy laws
This Privacy Policy explains what personal data we collect, why we collect it, how we use and protect it, and what rights you have in relation to your data when you visit and use our website and services at bloompdf.io.
Please read this policy carefully. If you do not agree with it, please refrain from using our Service.
2. Data Controller
The Data Controller for the purposes of applicable data protection legislation is:
[Full Company Name]
Registered office: [Address]
VAT Number: [Number]
Email: support@bloompdf.io
Website: https://bloompdf.io
3. Data We Collect
We may collect and process the following categories of personal data:
3.1 Identity and Account Data
If you create an account on BloomPDF, we collect:
- First name and last name
- Email address
- Password (stored in hashed form, never in plain text)
3.2 Usage and Technical Data
When you visit our website, we may automatically collect:
- IP address and approximate geolocation (country/region)
- Browser type and version
- Operating system
- Pages visited and time spent on pages
- Referring URL
- Session identifiers (via
PHPSESSIDsession cookie)
This data is collected via Google Analytics (through Google Tag Manager) for statistical and analytical purposes. See Section 7 (Cookies) for details.
3.3 Payment Data
When you purchase a subscription, payment is processed by Stripe, Inc. BloomPDF does not directly collect, see, or store your credit/debit card details. Stripe acts as an independent data controller for payment data. Please refer to Stripe's Privacy Policy for details.
3.4 Communication Data
If you contact us via the support form or email, we collect your name, contact details, and the content of your message in order to respond to your inquiry.
3.5 Data You Process With Our Tool (No Server Storage)
BloomPDF is designed with a privacy-first architecture. The PDF generation tool processes all your files — including spreadsheets, CSV/TSV files, images, and PDF templates — entirely within your own browser using client-side technologies (JavaScript, Web Workers, and IndexedDB for local temporary storage). Your documents and data files are never uploaded to, transmitted to, or stored on our servers. This is a fundamental design choice to guarantee the confidentiality of your business data.
4. Purposes and Legal Bases for Processing
| Purpose | Data Used | Legal Basis (GDPR / Global Equivalent) |
|---|---|---|
| Account creation and management | Identity data | Performance of a contract (Art. 6(1)(b) GDPR) |
| Providing the Service | Session data | Performance of a contract (Art. 6(1)(b) GDPR) |
| Payment processing | Payment data (via Stripe) | Performance of a contract (Art. 6(1)(b) GDPR) |
| Website analytics and improvement | Technical/usage data | Legitimate interest (Art. 6(1)(f) GDPR) / Consent |
| Responding to support requests | Communication data | Legitimate interest (Art. 6(1)(f) GDPR) |
| Legal and regulatory compliance | All relevant data | Legal obligation (Art. 6(1)(c) GDPR) |
| Cookie management | Cookie data | Consent (Art. 6(1)(a) GDPR) |
For users in jurisdictions that do not rely on the same legal basis framework (e.g. the United States), we process data based on the legitimate business purposes described above, your contractual relationship with us, or your consent where required.
5. Data Retention
We retain your personal data only for as long as necessary for the purposes set out in this policy:
- Account data: retained for the duration of your account and up to 2 years after deletion, unless a longer retention is required by law.
- Communication data: retained for up to 2 years after the closure of the support request.
- Analytics data: retained according to Google Analytics configuration (default: 26 months).
- Payment records: retained for up to 10 years as required by Italian and EU fiscal regulations.
6. Data Sharing and Third Parties
We do not sell, rent, or trade your personal data. We may share your data with the following third-party service providers, acting as data processors or independent controllers:
| Service | Purpose | Privacy Policy |
|---|---|---|
| Stripe, Inc. | Payment processing | https://stripe.com/privacy |
| Google LLC (Analytics + Tag Manager) | Website analytics and tag management | https://policies.google.com/privacy |
| Iubenda Srl | Cookie consent management | https://www.iubenda.com/privacy-policy/252372 |
| YouTube (Google LLC) | Embedded demo videos on our website | https://policies.google.com/privacy |
Data may be transferred to countries outside the European Economic Area (EEA) — in particular to the United States — only with appropriate safeguards in place (e.g., Standard Contractual Clauses, adequacy decisions, or other legally recognized transfer mechanisms).
7. Cookies
We use cookies and similar tracking technologies. Please refer to our Cookie Policy for full details on the cookies we use, their purposes, and how to manage your preferences.
In summary:
- PHPSESSID - Technical session cookie, necessary for authenticated user sessions.
- Iubenda cookies - Used to store and manage your cookie consent preferences.
- Google Analytics cookies - Used to collect aggregated, anonymized website usage statistics.
- Google Tag Manager - Used to manage and deploy analytics and marketing tags.
- YouTube cookies - Set when embedded videos are loaded (only if you consent).
You can manage your cookie preferences at any time via our cookie consent banner.
8. Your Rights Under GDPR (EU/EEA/UK Users)
As a data subject under GDPR or UK GDPR, you have the following rights:
Right to withdraw consent: Where processing is based on consent, you may withdraw it at any time.
Right to lodge a complaint: You have the right to file a complaint with the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali) at www.garanteprivacy.it, or with your country's authority.
9. Rights for California Residents (CCPA/CPRA)
If you are a California resident, you have additional rights under the CCPA/CPRA:
- Right to Know: Disclosure of categories and specific pieces of personal information collected.
- Right to Delete: Request deletion of personal info, subject to legal exceptions.
- Right to Correct: Request correction of inaccurate personal info.
- Right to Opt-Out: We do not sell your info, nor share it for cross-context behavioral ads.
- Right to Limit Use: We do not use sensitive info beyond what is necessary to run the Service.
- Right to Non-Discrimination: We will not discriminate against you for exercising your rights.
Categories of personal information collected (CCPA categories):
Identifiers (name, email, IP); Commercial info (subscription plan, Stripe records); Network activity (usage data, pages visited); Geolocation (approximate country/region via IP).
To exercise these rights, contact us at support@bloompdf.io. We respond within 45 days.
10. Rights for Other Jurisdictions
We respect global privacy rights. Depending on your location, you may have additional rights:
- Brazil (LGPD): Equivalent to GDPR (access, correction, deletion, portability).
- Canada (PIPEDA): Right to access data and challenge its accuracy.
- Australia (Privacy Act): Right to access and correct personal info held by us.
- United Kingdom (UK GDPR): Same rights as EU GDPR (see Section 8).
11. Security
We implement technical and organizational measures to protect your data against loss, destruction, alteration, or unauthorized access. These include HTTPS encryption for data in transit and secure password hashing. However, no internet transmission or electronic storage is 100% secure.
12. Children's Privacy
BloomPDF is not directed to children under 16 (or 13 where COPPA applies). We do not knowingly collect children's personal data. If you believe a child has provided us data, contact us at support@bloompdf.io and we will delete it promptly.
13. Links to Third-Party Websites
Our website contains links to external sites, including social media. We are not responsible for their privacy practices. Find us on: LinkedIn .
14. Do Not Track
Some browsers include a "Do Not Track" (DNT) feature. As there is no universally accepted standard for DNT signals, our website does not currently respond to them. You can control analytics tracking via our cookie consent banner.
15. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by posting the updated policy on this page and updating the "Effective Date."
16. Contact
If you have any questions or concerns regarding this Privacy Policy, please contact us: