Privacy policy
Last updated: October 9, 2026
This policy applies to all DotArt courses: balancesheet.art, regardedtrading.art, basispoints.art, and cookedbooks.art, our home page dotartcourse.shop, and any course site we add later. It explains how we (“we”, “us”), the makers of DotArt courses, handle personal data when you use those websites and the games on them (together, the “Service”). One account works on all of them, so this policy, including how to delete your data, covers your account on every one. Questions: privacy@dotartcourse.shop.
What we collect
- Without an account: your progress is stored only in your browser’s local storage. It is not sent to us.
- Account data: if you sign in with Google, X or Meta, the provider shares with us a unique account identifier and your display name or username. We store these to recognise you. We do not request your email address, contacts, posts, friends or followers, and we never post on your behalf.
- Learning progress: which chapters you have completed and which puzzles you solved on the first try, so your progress follows you across devices.
- Purchases: payments are processed by Stripe. Stripe collects your payment details and email address under its own privacy policy. We receive and store only a payment reference, what you bought, the amount, currency, date and refund status. We never see or store card numbers.
- Feedback: if you send us feedback, we store your message, the screen you sent it from, your account identifier if you were signed in, and your email address only if you choose to give one, so we can reply. We delete feedback once we have dealt with it.
- Analytics: we count page views with Cloudflare Web Analytics, which uses no cookies and does not track you across sites.
- Advertising measurement: we use the Reddit pixel to measure whether our ads on Reddit work: it reports page visits and key steps in the game (opening and finishing a chapter, clicking sign-in, starting checkout) and, when you buy a course, the purchase (the amount and an anonymous order reference, never your name or payment details). It sets a first-party cookie (_rdt_uuid), and if you arrived from a Reddit ad we keep that ad click’s identifier in a first-party cookie (rdt_cid) for 28 days. When you create an account or buy a course, our server also reports that event to Reddit directly (Reddit’s Conversions API) with a hashed form of your account identifier, those two Reddit identifiers if present, your IP address and browser type, and for a purchase the amount; to do so we pass the Reddit identifiers along with your checkout to Stripe. Reddit processes this under its own privacy policy. You can block the pixel and its cookies with your browser’s tracking protection or an ad blocker without affecting the game.
- Cookies: when you sign in, we set one strictly necessary cookie that keeps you signed in, and a short-lived one during the sign-in process. The Reddit cookies are described above. We use no other advertising or analytics cookies.
- Technical data: like any website, our hosting provider processes your IP address and request details (such as browser type and pages requested) to deliver the Service and protect it from abuse. These logs are kept for a short period.
How we use it
To run the Service: to sign you in, save and sync your progress, unlock what you have bought, answer your feedback, prevent fraud and abuse, and meet legal obligations such as tax and accounting rules. We also measure how many people visit and whether our ads lead to purchases. We do not sell your data, show ads on the Service, or build marketing profiles.
Where the GDPR or similar laws apply, our legal bases are performance of our contract with you (account, progress, purchases), our legitimate interest in running a secure service and improving it (technical data, feedback, analytics, advertising measurement), and legal obligation (payment records).
Who processes it for us
- Cloudflare: hosting, database and network security.
- Stripe: payment processing.
- Reddit: measuring our Reddit ads (the pixel described above).
- Google, X and Meta: only if you choose to sign in with them, under their own privacy policies.
These providers may process data outside your country. Where required, transfers are covered by appropriate safeguards such as standard contractual clauses.
How long we keep it
Account data and progress are kept until you delete your account. Feedback is kept until we have dealt with it. Payment records are kept for as long as tax and accounting law requires, even after account deletion. Technical logs are kept briefly.
Your rights
Depending on where you live, you may have the right to access, correct, export or delete your personal data, and to object to or restrict how we use it. To exercise any of these, email privacy@dotartcourse.shop. To delete your account, follow the steps under deleting your data below. You can also complain to your local data protection authority.
Children
The Service is not directed at children under 13, and children under 13 should not create an account. If you are under the age of digital consent where you live, use the Service with a parent’s or guardian’s permission. If you believe a child has given us personal data, contact us and we will delete it.
Deleting your data
You can ask us to delete your account and the data stored with it at any time. This applies to all DotArt courses: because they share one account, a single request deletes your data from every one of them.
How to request deletion
- Sign in on any of our course sites and open Account (balancesheet.art, regardedtrading.art, basispoints.art, cookedbooks.art). Note your account ID and the sign-in method you use.
- Email privacy@dotartcourse.shop with the subject “Delete my account”, and include your account ID. If you can’t sign in any more, tell us the sign-in method and the name it shows, and we will help you verify the account.
We may ask you to confirm the request so that nobody else can delete your account. We complete deletion within 30 days and confirm by email.
What is deleted
- your account and every sign-in method linked to it (the provider account identifiers and display names);
- your saved progress;
- your active sessions, which signs you out everywhere;
- any feedback you sent while signed in.
Payment records (a payment reference, amount, currency and date) are kept for as long as tax and accounting law requires. Stripe keeps its own records under its privacy policy. Deleting your account also removes access to any purchase made with it.
Signed in with Meta (Facebook)?
You can also remove our app (balancesheet.art) from your Facebook account under Settings & privacy → Settings → Apps and websites. That stops Meta sharing data with us; to delete what we have already stored, email us as described above.
Progress saved in your browser
Progress from playing without an account lives only in your browser, separately for each site. Clear it by deleting site data for balancesheet.art, regardedtrading.art, basispoints.art, and cookedbooks.art in your browser settings.
Changes
If we change this policy, we will post the new version here and update the date above. If a change is significant, we will make reasonable efforts to let signed-in players know.