Privacy policy

What is processed, why, for how long, who else can see it, and what your rights actually get you on a site with no accounts.

Who is responsible

The controller of the processing described here is Simone Panini, VAT 04241900366, Italy. Contact: hallo@pixelperlen.com.

There is no data protection officer. One is not required for processing of this kind and this size, and inventing a role nobody fills would tell you less rather than more. The address above reaches the person who decides.

If you think this policy is wrong, or that something is being done here that should not be, you can complain to the Garante per la Protezione dei Dati Personali — https://www.garanteprivacy.it — or to the supervisory authority of the EU country you live in. Telling us first is usually faster, but it is not a condition.

The short version

No account, no login, no user database, no newsletter, no advertising and no profiling. There is nothing here to build a profile out of.

The photograph you choose is opened by your own browser and converted there, on your own machine. It is never uploaded: no copy of it reaches this site, its host, or any third party, at any point.

What remains is small and dull: what a web server writes down in order to serve a page, what a payment processor needs in order to take a payment, what your own browser keeps so that a paid download stays unlocked, and — only if you agree to it — anonymous visit statistics.

Everything below is the long version of that paragraph. If the long version ever contradicts the short one, the long one is right and the short one is badly written; please tell us so we can fix it.

Your photograph never reaches us

This gets its own section because it is the part people reasonably expect to be marketing. It is not. The photograph you choose is read by your own browser, drawn onto a canvas by code running on your own machine, and reduced to a grid there. No request carries it anywhere. There is no upload endpoint on this site and no image host in the list of providers we use.

The consequences run in both directions, and both are worth saying out loud. We cannot look at your photograph, sell it, train anything on it, or hand it to anyone who asks for it. We equally cannot delete it for you, recover it if you lose it, or tell you whether you ever converted one, because no record of it exists on our side to search.

The same is true of the pattern and of the files. The PDF and the PNG are generated in your browser, by your machine, and saved by your browser to your device. They never exist on a server of ours, not even for a moment.

What is processed, why, and on what legal basis

Server logs. Serving a page means the host records the request: IP address, the page asked for, the time, the browser string. This is how a web server works, and it is how an attack gets noticed. Legal basis: our legitimate interest in keeping the site running and abuse under control, Article 6(1)(f) GDPR. These logs are not read to look at individuals and are not joined to anything else.

A payment, if you make one. It is handled by Stripe on a page of theirs: your card and your email address are entered there. Stripe processes card data as a controller in its own right, under its own privacy policy, and the card number never reaches this site. Legal basis: performance of the contract you asked for, Article 6(1)(b), and for keeping the record afterwards our legal obligation to keep accounting records, Article 6(1)(c).

The three labels we attach to a payment. They are: which site the payment was made on, what it unlocked — the identifier of the gallery pattern, or a marker meaning a purchase made in the pattern tool — and the language of the page you bought from. This means our record of a payment shows what was bought, and you should know that rather than discover it.

What the site itself reads back from Stripe is narrow: whether the payment succeeded, and those same three labels. It does not read your email address and it does not read your card details. In the Stripe dashboard, however, the operator of this site can see what Stripe records about a payment — the email you gave for the receipt, the billing country, the card brand and its last four digits. None of it is copied anywhere else.

The unlock. After a payment your browser keeps a short signed string proving the download is paid for. It contains no name, no email address and no identifier of you: only which site it belongs to, what it unlocks, when it was issued, when it expires, and a random value that makes each one distinct. It is stored on your device and not on any server of ours. Legal basis: performance of the contract — without it, somebody who paid would be asked to pay again.

Statistics, and only if you accept them. If you do, Google Analytics 4 measures which pages get opened, roughly where visitors arrived from, and what kind of device they used. Legal basis: your consent, Article 6(1)(a), which you can withdraw at any moment from the link at the foot of every page. Decline, and nothing is measured; the site behaves identically either way.

Emails you send. If you write to hallo@pixelperlen.com then we have your message and your address, and we keep them for as long as it takes to deal with what you wrote about. Legal basis: our legitimate interest in answering our own correspondence, or performance of the contract when you are writing about a purchase.

That is the complete list. There is no contact form, no chat widget, no session recorder, no heat map, no A/B testing tool and no advertising pixel anywhere on this site.

What is deliberately not processed

No name, no postal address, no telephone number, no date of birth and no password, because nothing on this site ever asks for them.

No profiling, and no automated decision-making of the kind Article 22 GDPR is concerned with. Nothing here makes a decision about you.

No special categories of data: nothing about health, religion, politics, sexuality or biometrics. Worth noting that a photograph can easily contain several of those, which is one more reason it is a good thing the photograph never leaves your device.

No advertising, ever. Advertising storage, advertising identifiers and personalised advertising are denied by default in the consent settings and are never granted. We do not ask for consent to them, because we do not do them.

Who else can see anything

Three providers, named in full on the sub-processors page. Cloudflare hosts the site and therefore handles the requests. Stripe takes the payment and therefore sees the payment. Google Analytics counts visits, and only if you accepted it.

Nobody else. Data is not sold, not shared with brokers, not fed to an affiliate network and not handed to a marketing agency, because none of those exists here. There is no fourth party.

Stripe and Google are American companies and process data in the United States as well as in Europe. They rely on the standard contractual clauses adopted by the European Commission and on their certification under the EU-US Data Privacy Framework. We accept their published data processing terms as they stand; this operation is not large enough to negotiate its own, and claiming otherwise would be a lie.

Data could also be disclosed where the law requires it — a court order, a tax inspection. That has not happened. If it does and we are permitted to tell you, we will.

How long each thing is kept

Server logs: as long as the host keeps them, which is a matter of weeks. We hold no copy of our own and do not archive them.

Payment records: ten years, because tax law requires it. That one is not our decision and is not open to request.

Statistics, if you accepted them: 14 months in Google Analytics.

The unlock: 30 days, on your device, after which it simply stops working. Your consent choice: it stays in your browser until you change it or clear your browsing data.

Emails: while the matter is open, and afterwards only where a payment or a possible legal claim makes it necessary to keep them.

Your rights, and what they actually mean here

The GDPR gives you the right of access to your data, to have it corrected, to have it erased, to restrict or object to its processing, to receive it in a portable form, and to withdraw consent at any time. All of them apply here. Most of them have very little to bite on, and explaining why is more use to you than a copied list that sounds impressive and helps nobody.

Access and portability. There is no account and no profile, so there is no file with your name on it to send you. If you have made a payment, the record of it lives in Stripe: your receipt already shows most of it, and we can send you what our side records if you write with the payment reference. For everything else — no photograph, no pattern, no browsing history tied to you — there is genuinely nothing to hand over.

Erasure. Your photograph and your pattern are on your device, and you erase them by deleting them; we could not delete them if we wanted to. Your consent choice and your unlock are in your browser and are erased by clearing site data — and clearing the unlock means asking us to reissue it. Payment records are the one thing we cannot erase on request: tax law requires us to keep them, and that is one of the lawful grounds for refusing.

Objection and restriction. The only processing resting on legitimate interest is server logging, which cannot be switched off without also switching off the ability to serve you a page. If you want to object, write and tell us why and we will take it seriously; in most cases the honest answer is that the alternative is not visiting the site.

Withdrawing consent. One click, from the cookies link at the foot of every page. It takes effect immediately and costs you nothing at all, because nothing on this site sits behind analytics.

Complaining. You can go to the Garante per la Protezione dei Dati Personali — https://www.garanteprivacy.it — or to the authority of the EU country you live in, and you do not need to ask us first.

We answer requests within one month, which is what the law requires. Where we cannot identify you, which is most of the time and by design, we will say so plainly and explain what we would need. Demanding proof of identity from somebody whose identity we do not hold would be theatre, and we will not do it.

Children

Fuse beads are a childhood craft and children use this site. Nobody is asked their age, because nothing is collected that would make the answer relevant: no account, no name, no email address on the site itself.

Buying requires a payment card, which in practice means an adult is involved. Analytics runs only after an explicit yes given on that device, and never before.

The part that genuinely matters where a child is concerned is the hot iron, and that is covered in the disclaimer.

Security

Everything is served over HTTPS. The unlock is signed with a secret key held on the server, so a token cannot be forged or edited in a browser, and the check is always done on the server rather than in the page.

The strongest protection here is architectural rather than technical: there is almost nothing to steal. No user database, no password store, no image archive, no card numbers. A breach of this site would expose server logs.

If something did happen that put anyone at risk, it would be reported to the supervisory authority within 72 hours and said publicly on the site — with no mailing list, that is the only way we could tell you.

Changes to this policy

This policy changes when the site changes. The dates below tell you which version you are reading.

A change that widens what is processed is not applied retroactively to something already collected, and a new provider appears on the sub-processors page before it appears on the site.

Contact

Questions, complaints, refund requests and takedown notices: hallo@pixelperlen.com. A person reads that address.

Effective from 9 August 2026. Last updated on 9 August 2026.