Privacy policy
Last updated: 2026-05-11
Summary
Read Stacks is operated by Paulo de Vries (sole proprietor, Netherlands). We collect minimum data needed to provide the service, never sell personal data, and comply with GDPR (EU/UK) and CCPA (California).
What we collect
- Email (if subscribed): for the weekly stack newsletter + account login. You can unsubscribe with the link in every email.
- Reading history (Pro tier): chapters you've viewed, stored to enable progress tracking + bookmarks. Not associated with profiling.
- Usage analytics: via Plausible (privacy-first, cookieless, aggregated). See Plausible's data policy.
- Payment data (Pro/Founder/Deluxe): processed by Stripe; we never see your card number. See Stripe's privacy policy.
What we do NOT collect
- Browsing data outside readstacks.com
- Social-media profile data (TikTok engagement is anonymous to us)
- IP addresses beyond temporary security/rate-limit logs (purged after 7 days)
Affiliate & advertising
Read Stacks links to books via Bookshop.org affiliate links and Amazon Associates. We earn small commissions on qualifying purchases at no extra cost to you. Free-tier chapter pages may display AdSense ads in the future — when added, this section will be updated to disclose Google's use of cookies for personalized ads.
Cookies
Read Stacks uses essential cookies only (session, auth, CSRF). EU/UK visitors see a cookie banner per ePrivacy Directive compliance.
Your rights (GDPR + CCPA)
- Right to access your data (email hello@readstacks.com)
- Right to deletion (we'll remove all account data within 30 days)
- Right to portability (we export your reading history as JSON on request)
- Right to object to processing
- Right to withdraw consent (cookie banner allows reversal anytime)
Data retention
- Newsletter email: kept until you unsubscribe
- Pro account: kept while subscription active + 90 days post-cancellation
- Reading history: kept for active subscription + 90 days post-cancellation
- Billing records: 7 years per Dutch tax law
Third parties
- Cloudflare: DNS, CDN, registrar
- Plausible: privacy-first analytics
- Stripe: payments (Pro+ tiers)
- Buttondown or ConvertKit: email delivery (final choice pending Track 2 Week 1)
- Bookshop.org + Amazon: affiliate links (no data sharing — affiliate IDs only)
Children
Read Stacks is not intended for users under 13 (COPPA) or under 16 in the EU (GDPR child data).
Contact
Privacy questions: hello@readstacks.com