Privacy Policy
Last updated: 23 February 2026
1. Introduction
Professional Markdown (“we”, “us”, or “our”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and share your personal data when you use the Professional Markdown web application and related services (the “Service”).
We process personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
2. Data Controller
Professional Markdown is the data controller responsible for your personal data. If you have questions about how we handle your data, contact us at [email protected].
3. Data We Collect
We collect the following categories of personal data:
Account information
- Name and email address (provided via Clerk authentication)
- Profile information from your authentication provider
Payment data
- Billing details processed by Stripe — we do not store your full card number on our servers
- Subscription status and billing history
Usage data
- PDF generation counts and download history
- Documents and templates you create within the Service
- Custom fonts and images you upload
Technical data
- IP address, browser type, and device information
- Pages visited and features used
- Cookies and similar tracking technologies
4. How We Use Your Data
We use your personal data to:
- Provide, maintain, and improve the Service
- Process your documents and generate PDFs
- Manage your account and subscription
- Process payments and prevent fraud
- Send transactional emails (e.g. subscription confirmations)
- Respond to support requests
- Monitor service performance and fix issues
- Comply with legal obligations
5. Legal Basis for Processing
We process your personal data under the following lawful bases under UK GDPR:
- Contract performance — processing necessary to provide the Service you signed up for
- Legitimate interests — improving the Service, preventing abuse, and ensuring security
- Legal obligation — complying with tax, accounting, and regulatory requirements
- Consent — where you have opted in to optional communications
6. Third-Party Services
We share data with the following third-party processors, each acting under data processing agreements:
- Clerk — authentication and user management
- Stripe — payment processing and subscription management
- Vercel — application hosting and serverless functions
- Cloudflare R2 — file storage for generated PDFs, uploaded fonts, and images
- Supabase / Railway — database hosting (PostgreSQL)
We do not sell your personal data to third parties. We only share data as necessary to operate the Service.
7. International Data Transfers
Some of our third-party processors operate outside the UK. Where data is transferred internationally, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses or adequacy decisions recognised by the UK Government.
8. Data Retention
We retain your personal data as follows:
- Account data — retained while your account is active, deleted within 30 days of account closure
- Documents and PDFs — retained while your account is active; you may delete them at any time
- Payment data — retained as required by tax and accounting regulations (typically 6 years)
- Technical logs — retained for up to 90 days for security and debugging purposes
9. Your Rights
Under UK GDPR you have the right to:
- Access — request a copy of the personal data we hold about you
- Rectification — ask us to correct inaccurate data
- Erasure — request deletion of your data (“right to be forgotten”)
- Restrict processing — ask us to limit how we use your data
- Data portability — receive your data in a structured, machine-readable format
- Object — object to processing based on legitimate interests
- Withdraw consent — where processing is based on consent, withdraw it at any time
To exercise any of these rights, email us at [email protected]. We will respond within 30 days.
10. Cookies
We use cookies and similar technologies for:
- Essential cookies — authentication sessions and security (required for the Service to function)
- Analytics cookies — understanding how the Service is used so we can improve it
You can manage cookie preferences through your browser settings. Disabling essential cookies may prevent the Service from functioning correctly.
11. Data Security
We implement appropriate technical and organisational measures to protect your data, including encryption in transit (TLS), secure cloud infrastructure, and access controls limiting who can access personal data.
No system is completely secure. If we become aware of a data breach affecting your personal data, we will notify you and the Information Commissioner’s Office (ICO) as required by law.
12. Children
The Service is not directed at individuals under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
13. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or through the Service. The “Last updated” date at the top indicates the most recent revision.
14. Complaints
If you are unhappy with how we handle your data, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO):
- Website: ico.org.uk
- Phone: 0303 123 1113
15. Contact
For any questions about this Privacy Policy or your personal data, contact us at [email protected].