Security & Privacy FAQ
Frequently asked questions about data security, account safety, GDPR compliance, and privacy on the NowToPrint platform.
Security & Privacy FAQ
Frequently asked questions about how NowToPrint protects your data and privacy.
Data Security
Is my data safe?
Yes. NowToPrint uses industry-standard security measures to protect your information:
- Encryption: All data is encrypted in transit and at rest using AES-256
- Firestore Security Rules: Strict role-based access control rules
- Authentication: Secure identity verification via Better Auth
- HTTPS only: All communication is encrypted over HTTPS
- Regular security audits: Periodic third-party security reviews
ISO 27001: Our data security practices align with international standards for information security management.
How long are my designs stored?
- Active projects: Indefinitely while your account is active
- Drafts: 90 days from last modification
- Completed orders: 1 year after order completion
- Deleted content: Up to 30 days (recovery possible within this window)
Account Security
Where can I enroll or use a passkey?
You can enroll during onboarding or later in Profile and use the passkey button on the sign-in screen. Enrollment is optional during onboarding and an unsupported browser does not block account setup. Privileged operations can nevertheless require a recently user-verified passkey; recovery revokes existing sessions before re-enrollment.
How does multi-factor authentication work?
NowToPrint uses a TOTP authenticator app for multi-factor authentication. When enforcement is active, every account that holds a platform role must complete enrollment before it can use normal application or admin surfaces. Google sign-in alone does not count as the second factor.
Sensitive operations require a user-verified WebAuthn passkey confirmation from the previous five minutes; TOTP is not accepted as critical-action proof. If enrollment is required but incomplete, the account can use only enrollment, recovery, and sign-out.
What if I lose my authenticator app?
Contact support. Recovery revokes all active application sessions and Firebase refresh sessions, removes the old factor, and requires enrollment again. Recovery for a privileged account requires two-person approval.
I forgot my password. What do I do?
- Select Forgot password on the sign-in page.
- Enter the account email. The response remains generic whether or not an account exists.
- Open the reset link and choose a new password of 15–128 characters.
- Sign in again. Existing sessions are revoked when the credential change completes.
Privacy & GDPR
How is my personal data used?
NowToPrint is fully compliant with GDPR and applicable data-protection laws:
Data we collect:
- Contact information (email address, phone number)
- Billing details (name, address, VAT number)
- Usage statistics and analytics
- Browser and device information
How we use it:
- Delivering and improving our services
- Customer support
- Legal and compliance obligations
Who we share it with:
- Print shops — only the order details they need to fulfil your job
- Payment processors (Stripe, iyzico) — for payment handling
- Analytics tools — anonymised, aggregated data only
Your data is yours. You can download or delete your personal data at any time from your Profile settings.
How do you use cookies?
| Cookie type | Purpose | Duration |
|---|---|---|
| Essential | Session management and authentication | Session |
| Analytics | Anonymised usage statistics | 1 year |
| Preferences | Language and theme settings | 1 year |
| Marketing | Ad optimisation (opt-in only) | 90 days |
You can update your cookie preferences at any time using the Cookie Settings button in the site footer.
Deleting Your Account
How do I delete my account?
Go to Settings → Account and scroll to the "Delete Account" section.
You must be signed in. The app creates a 15-minute confirmation request bound to your own account.
Confirm the matching request and click Delete Permanently. A missing, expired, or mismatched request is rejected. The request is protected by your session and browser CSRF token.
Warning: Account deletion cannot be undone. After confirmation, access is revoked and a resumable deletion process removes the approved personal-workspace inventory. A legal hold can pause erasure until the hold is released.
Deletion progress is checkpointed against a versioned, approved data inventory. Profile identifiers are replaced with a non-reversible privacy-domain pseudonym; authentication sessions, linked accounts and passkeys are removed through the separate identity lifecycle. Records that must be retained for legal, tax, fraud-prevention or dispute obligations are excluded until their approved retention period ends. This controlled path is available only when the production lifecycle worker and retention policy have been activated.
What gets deleted:
- Profile personally identifiable fields are cleared and the account is marked deleted
- User documents
- Studio designs
- User preferences and themes
- RFQs created by the user
- Producer eligibility redress submissions and their evidence references
What is anonymized or retained under policy:
- The principal profile is replaced with a non-reversible privacy-domain pseudonym
- Minimum IAM/security audit and identity-lifecycle evidence may be retained to prove compliance and prevent abuse
What is retained (legal obligation):
- Invoices and transaction logs required for tax, accounting, fraud prevention, or dispute handling
- Order and payment records that must remain available for legal or financial compliance
Can I delete individual designs without closing my account?
Yes. To delete a design:
- Open the design list and click the design you want to remove.
- Click the ⋮ (three-dot) menu and select Delete.
- Confirm the deletion.
For bulk deletion, select multiple designs using the checkboxes, then choose Bulk actions → Delete.
Contact & More Information
Where is the Privacy Policy?
The full Privacy Policy is available at /legal/privacy-policy and linked in the site footer.
How do I contact the data protection team?
- Email: privacy@nowtoprint.com
- Response time: Within 30 days (GDPR Article 12)
What happens in the event of a data breach?
- The relevant data protection authority is notified within 72 hours.
- Affected users receive an email notification promptly.
- We take immediate containment measures and publish a transparent incident report.
General FAQ
Common questions about the platform.
Billing FAQ
Questions about invoices, payments, and subscriptions.
Technical FAQ
Technical questions and troubleshooting.
Authentication
How sign-in and 2FA work.
Can I manage my registered passkeys?
Yes. Open Profile → Your passkeys to review display-safe details, rename a passkey, or delete one. Credential IDs, public keys, and other authentication material are never displayed. Rename and delete require fresh passkey proof. The final passkey cannot be deleted until a verified recovery path exists.
War dieser Artikel hilfreich?
Last updated on