Privacy
What we collect, and why.
Creative Path 52 sells software and services to people building creative businesses, and runs the platforms some of them trade on. That means we hold information about you, and — if you're a WebDeck customer — information about your customers too. This page says exactly what, who else touches it, how long it stays, and how to get it back. Where the honest answer is "we haven't built that yet", it says so.
Who we are
Creative Path 52 is run by Damian Sémonin, a sole trader based in Cornwall. For everything on creativepath52.com and the products sold from it, we are the data controller — the ones responsible for your information.
Email support@creativepath52.com for anything on this page. A person reads it, and privacy requests are not routed anywhere different or slower than any other message.
We have not appointed a data protection officer. A business this size isn't required to, and inventing one would be worse than telling you there isn't one.
Two different relationships — this matters
Depending on who you are, we sit in a different legal position, and the difference decides who you go to about what.
- If you buy from us — a whitepaper, an InkFox licence, a white-glove install, a WebDeck subscription — we are the controller of your information. Everything on this page applies to you directly.
- If you are a customer of a business that runs on WebDeck — you booked one of their workshops, bought from their shop, emailed their support desk — then they are the controller and we are their processor. We hold the data because their site runs on our servers, but it is theirs, and it is their privacy policy that governs it. Ask them, not us. If you come to us anyway we will point you to them and tell them you asked.
One thing we will not gloss over. There is currently no signed data processing agreement between us and our WebDeck customers. UK GDPR requires a written contract between a controller and their processor, and we do not yet have one in place. It is being drafted. If you are a WebDeck customer and you need that paperwork now, ask and we will prioritise yours — and we would rather you read that sentence here than discover it in a due-diligence questionnaire.
Buying something
Buying from this website asks you for one thing: your email address. That, what you bought, the amount, and Stripe's reference for the payment is the whole of the order record.
It is worth saying what is not in it, because we checked rather than assumed. There is no name field, no billing address, no card number, no card type and no last four digits on an order — those columns do not exist in our database, so there is nothing there to lose or to leak.
Payment is taken on Stripe's own checkout page. Your card details go from your browser to Stripe and never pass through our servers. Where you buy something physical that has to be posted, Stripe collects the delivery address on that page and passes it to us for that order. Stripe holds the card under its own privacy policy and its own PCI certification.
Why we're allowed to hold it: performance of a contract, and legal obligation — UK tax law requires transaction records to be kept for six years.
InkFox licences and downloads
Buying InkFox mints a licence key for you. Your email address is inside that key, along with a business name if you gave one — it is a signed record of who it was issued to. A copy of every issued licence is appended to a ledger on our server so a lost key can be looked up and reissued.
Your download link is signed and specific to your order, and it expires after seven days. Whitepapers work the same way — the link in your receipt is generated for your order rather than being a public URL. We keep no log of who downloaded what.
We do not build anything into the app that reports back to us. There is no phone-home, no usage telemetry, no licence check-in. Once InkFox is on your Mac, what you do with it is not visible to us — including anything you point it at your own AI account to do.
Why we're allowed to hold it: performance of a contract.
The newsletter
If you subscribe we store your email address, the date, where you signed up from, and — where a form asked you to tick a box — the exact wording you agreed to, saved as it was shown to you. That snapshot is deliberate: it means we can always show what you actually consented to rather than what our form says today.
Signing up here is single opt-in — there is no confirmation email to click, so you are subscribed the moment you submit the form.
Every send carries a working unsubscribe link and the one-click unsubscribe header your mail app uses. Unsubscribing is honoured everywhere, and your address stays on a do-not-contact list afterwards so a later import can't quietly put you back.
Why we're allowed to hold it: your consent, which you can withdraw whenever you like.
Our emails from this address carry no tracking. The open-tracking pixel and click-rewriting our software is capable of are switched off for Creative Path 52 — we do not know whether you opened an email or which link you clicked, and no IP address or browser is recorded against you. We checked this rather than assumed it. If that ever changes, this page changes with it.
Support, and the forms on this site
The contact form sends nothing to our server — it opens your own email program with the message ready to send, so the only copy is yours.
The support form creates a ticket holding your name, email, what you wrote, which product it's about, and any file you attach. Email sent to our support address becomes a ticket the same way. Tickets are stored so we can answer you and so there's a record of what was asked and what we said.
Why we're allowed to hold it: performance of a contract where you're a customer; legitimate interests — answering someone who asked us something — where you're not.
The chat assistant
The chat button on this site sends what you type to an AI model — Anthropic's Claude, reached through a service called OpenRouter — which answers from our help articles.
Before your message leaves our server, email addresses, phone numbers and order or booking references are stripped out and replaced with placeholders; the reply is reassembled on our side, so the model never sees those values. Names are not stripped, and neither is the rest of what you type — so treat it as you would any message to a third party.
We don't store the conversation. If you ask to be put through to a person, that creates a support ticket, and at that point your name, email and the conversation are kept as a ticket.
The assistant drafts; it does not send on its own. A human reads anything that goes back to you by email.
Signing in to see your orders
If you want to look back at what you have bought, you sign in with your email address and a six-digit code we email you. There is no password — we don't ask you to make one and we don't store one, so there is no password of yours here to be stolen. The code is single-use, expires quickly, and is held only in the server's memory in a hashed form while it waits for you.
The verified email address is the identity. We create no separate account record for it.
Why we're allowed to do it: performance of a contract — it is how you get to the thing you bought.
If you run a WebDeck
A WebDeck is your own site, shop, bookings and CRM running in a container on our servers. Two kinds of information are involved.
Your account. Your name, email and a password stored only as a scrypt hash — a form it cannot be reversed from. Signing in sets one cookie, crew_session, which is HttpOnly, Secure and scoped to your deck's domain. It is strictly necessary: without it you cannot stay signed in. It carries no tracking of any kind.
Your customers' information. Their bookings, orders, contacts, support tickets and newsletter subscribers sit in your deck's own database. It is yours. We access it to run and support the service, and we do not use it for anything else — not to market to your customers, not to train anything, not to sell.
Two real behaviours worth knowing, because they're the ones that decide what happens if you leave:
- You can take it with you. Your deck's data exports as a zip of the actual tables — products, customers, bookings, orders, transactions, tickets, contacts, subscribers, reviews, media — served over a signed link that works once and expires after seven days.
- Closing a deck purges it after 30 days. When a deck is deprovisioned the clock starts; 30 days later a sweeper deletes the data volume, the backups and exports, and the deck's own configuration and secrets. Nothing is purged before that date. That is a real, running mechanism, not an intention — it runs every six hours and it is the one genuine retention clock we have.
While your deck is running we take a backup of it every night and keep the last fourteen, plus one a week for eight weeks. So a copy of your customers' records can exist in our backups for up to about two months after you delete something from the live database.
Cookies, tracking and fonts
This website sets no cookies. There's no cookie banner because there is nothing to consent to.
There is no analytics or tracking software on this site at all — no Google Analytics, no Meta pixel, no Plausible, no Hotjar, no advertising network, nothing. We do not know who visits, and we have not built anything to find out. Our web server does not even keep an access log of visitors' IP addresses.
Cookies exist in exactly two places in what we run, and neither is on the pages you are reading:
crew_session— the WebDeck sign-in cookie described above. Strictly necessary; set only once you log in.sellkit_staff— a staff-only cookie on the shop till, which customers never see. It lasts twelve hours.
If you sign in to look at your own orders, the token that keeps you signed in is kept in your browser's own local storage rather than in a cookie. It is on your device, it identifies your session to us and nothing else, and clearing your browser data removes it.
One honest exception to all of the above: Google Fonts. The typefaces on this site load from Google's servers, so Google sees your IP address when a page loads. No cookie is set and you are not identified by name, but it is a request to Google we could avoid by hosting the fonts ourselves. We intend to. Until we have, you should know it happens.
Who else handles your information
The real list, taken from what the system is actually wired to.
- Hostinger — the virtual server, located in the United Kingdom, that runs this site, the engine and every deck. They host it; they don't use it.
- Stripe — payments. Takes your card details directly from you, plus your email and the amount.
- Amazon Web Services (SES) — sends our email: receipts, licences, newsletters, support replies. Receives the recipient address and the message. Configured in the London (eu-west-2) region. AWS also receives inbound support email addressed to our support domain.
- Hostinger mail — the mailboxes behind our @creativepath52.com addresses.
- OpenRouter and Anthropic — the chat assistant and support-draft AI, receiving message text with emails, phone numbers and order references already removed.
- Google Fonts — receives your IP address when a page loads.
That is the whole list for this website. No advertising network, no data broker, no analytics company, no third-party email marketing platform. Our bookkeeping software has no connection to this website and receives nothing from it.
Where in the world: the server is a Hostinger virtual machine in Manchester, England, and the email sending and receiving run in Amazon's London region. So the data itself stays in the UK. Stripe, Anthropic, OpenRouter and Google are headquartered outside the UK and may process data abroad under the safeguards set out in their own terms. We have not independently verified each of those transfer mechanisms, and we would rather say so than assert something we have not checked.
How long we keep things
This is the section most privacy policies quietly invent, so here is the truth.
There is no automatic deletion of customer records. No part of our system sweeps up old orders, contacts or tickets on a schedule. They stay in the database until someone removes them by hand. We also keep dated backup copies, so a record can outlive its deletion from the live database for as long as those backups exist.
What we can state as fact:
- Transaction records — kept six years, because tax law requires it.
- Newsletter — unsubscribing removes you from sending immediately; your address stays on a suppression list so you are not re-added by a later import.
- A closed WebDeck — purged 30 days after deprovisioning, as described above. This one is enforced in code.
- Everything else — deleted when you ask us to.
Proper retention periods, and the code to enforce them, are work we have not done yet. Publishing that sentence is more use to you than publishing a schedule nothing keeps.
Your rights
Under UK GDPR you can ask us to:
- Show you everything we hold about you, and give you a copy.
- Correct anything wrong.
- Delete it — except transaction records tax law requires us to keep.
- Stop or limit what we do with it, including objecting to our use of it.
- Take it elsewhere in a portable form.
- Withdraw consent for the newsletter at any time, without affecting anything done before.
Email support@creativepath52.com. We will deal with it within one month. No charge, no reason needed.
Honest about the mechanics: apart from the WebDeck export described above, we have no self-service button for this. Requests are handled by hand against the database. That is slower than a button and we are building the proper tooling — but a request made today is done today, not queued behind a feature.
One deliberate exception when you ask to be erased: your email address stays on the do-not-contact list. Removing it along with everything else would turn "erase me" into "make me mailable again the next time my address turns up in a spreadsheet". That single entry is the thing that keeps you from being contacted again.
If you are unhappy with how we handled it, complain to the Information Commissioner's Office — ico.org.uk, or 0303 123 1113. You can go straight to them; you do not need our permission and you do not have to come to us first.
Keeping it safe
What we can evidence: everything is served over HTTPS with HSTS, and nothing is accepted unencrypted. Card details never reach our servers. Passwords are stored only as scrypt hashes. Sign-in is rate-limited against guessing. Each business's data is separated from every other's, enforced from the signed login token rather than anything a browser can set. Text is stripped of emails, phone numbers and order references before it goes to any AI model. Secrets live outside the code and outside version control.
What we are not going to claim: we hold no security certification, we have had no third-party audit and no penetration test, and we are not going to tell you we are "PCI compliant" — what is true is that card data never reaches us, which is a different and more useful statement. If a breach ever put your rights at risk we would tell you and tell the ICO, as the law requires.
If this page changes
If we change something that matters we will update this page and the date below. If a change needs your consent afresh, we will ask rather than assume.
Last updated: 31 August 2026.
This policy was written from what our systems actually do, by the person who built them, and it has not been reviewed by a solicitor. Everything in it is true to the best of our knowledge. If you find something that isn't, tell us and we will correct it.