Plain English summary: We sell printable children's products. We don't sell your data. We collect only what's needed to process orders and improve our content. You can request deletion of your data anytime by emailing support@storyteller-mari.com.
1. Who we are
Storyteller Mari ("we", "our", "us") is operated by Luan Rodrigues. We publish digital printable products for children and parents. Our website is storyteller-mari.com and our products are sold via Stripe, Inc.
Email address — when you purchase a product or subscribe to our newsletter
Billing details — collected and stored by Stripe (our payment processor); we never see your card number
Support messages — content of emails you send us
2.2 Information collected automatically
Cookies and similar technologies — see Section 6
Analytics data — anonymized pageviews, device type, country (via Google Analytics 4)
Pinterest pixel — anonymous conversion events used to measure ad effectiveness; no personal identifiers attached
2.3 Information from third parties
Pinterest — aggregated, anonymized analytics about published Pins, via the Pinterest API scopes we hold. We do not receive individual user profiles. Our TikTok integration does not include any analytics or video-reading capability — its scopes (user.info.basic, video.upload, video.publish) are posting-only.
Stripe — purchase confirmation, customer email, order metadata
3. Platform APIs (Pinterest & TikTok) — specific disclosures
3.1 Pinterest API
We integrate with the Pinterest API to schedule and publish pins, analyze the performance of our own pins and boards, and (with explicit user opt-in) help parents discover our content. In doing so:
We only access data from Pinterest accounts that have explicitly authorized us via OAuth 2.0 (in practice, only our own business account).
We do not collect Pinterest user data of people who simply view our pins.
We store OAuth tokens encrypted at rest and rotate refresh tokens per Pinterest API guidelines.
We delete Pinterest-derived data within 30 days of an authorization being revoked, or upon written request to support@storyteller-mari.com.
We never sell, share, or transfer Pinterest-derived data to third parties.
The Storyteller Mari app integrates with TikTok's Login Kit and Content Posting API to let an authenticated creator connect their TikTok account and publish their own original videos to it. In doing so:
We only access data from TikTok accounts that have explicitly authorized the app via OAuth 2.0.
Through the user.info.basic scope we read basic profile information (display name, avatar, open id) of the authorized account only, so the user can confirm which TikTok account they are posting to.
Through the video.upload scope we send the authorized user's own original video to that user's TikTok inbox (drafts). Nothing is published by this scope — the creator opens the TikTok app and finishes posting it themselves.
Through the video.publish scope we publish the authorized user's own original video directly to that user's own profile (Direct Post), using the privacy level and interaction settings the user selected. The app never posts to any account that has not authorized it, and the user chooses which of the two delivery paths to use on every post.
We do not collect any personal data about TikTok users who view, like, or comment on our content.
We store OAuth tokens encrypted at rest and never share them with third parties.
We delete TikTok-derived data within 30 days of an authorization being revoked, or upon written request to support@storyteller-mari.com. You can revoke the app's access at any time in the TikTok app under Settings → Security → Apps and websites.
We never sell, share, or transfer TikTok-derived data to third parties. Our use of information received from TikTok APIs adheres to the TikTok Developer Terms of Service.
4. How we use information
Purpose
Legal basis (GDPR)
Deliver the product you purchased
Contract
Send order confirmation emails
Contract
Newsletter (only if you opt in)
Consent
Improve our products and site
Legitimate interest
Comply with tax, accounting, fraud laws
Legal obligation
Measure site traffic and Pinterest ad effectiveness
Legitimate interest / Consent
5. Children's privacy (COPPA / GDPR-K)
Although our products are designed for children, the website and purchasing experience are intended for adults (parents, caregivers, teachers). We do not knowingly collect personal information from children under 13. If you believe we have inadvertently collected such data, please contact us at support@storyteller-mari.com and we will delete it within 7 days.
6. Cookies and tracking
We use a small set of cookies. The list below is exhaustive:
Cookie
Set by
Purpose
Duration
_ga, _gid
Google Analytics
Anonymous traffic analytics
2 years / 24h
_pin_unauth
Pinterest
Anonymous conversion attribution
1 year
__stripe_*
Stripe
Cart state during checkout
Session
You can block or delete cookies at any time in your browser settings. The Site remains fully usable without non-essential cookies.
7. How we share information
We never sell personal data. We share it only with the service providers below, strictly to operate the business:
Provider
Role
Stripe, Inc.
Payment processing, receipts, fraud prevention
Vercel, Inc.
Website hosting
Resend
Transactional and newsletter email delivery
Google Analytics 4
Anonymous traffic analytics
We may also disclose information if required by law, court order, or to protect our legal rights.
8. Data retention
Order records — kept as long as tax and accounting law requires (typically 7 years).
Newsletter data — until you unsubscribe; every email contains a one-click unsubscribe link.
Support emails — up to 24 months, then deleted.
Platform API data (Pinterest & TikTok) — deleted within 30 days of an authorization being revoked, as described in Section 3.
9. Your rights (GDPR / CCPA)
Depending on where you live, you have the right to:
Access a copy of the personal data we hold about you.
Correct inaccurate data.
Delete your data ("right to be forgotten").
Object to or restrict processing based on legitimate interest.
Port your data to another service in a machine-readable format.
Opt out of "sale" or "sharing" as defined by the CCPA/CPRA — we do not sell or share personal information as defined by those laws.
To exercise any of these rights, email support@storyteller-mari.com with the subject "Privacy request". We respond within 30 days. EU/UK residents may also lodge a complaint with their local supervisory authority.
10. Security
All traffic to the Site is encrypted in transit (HTTPS/TLS). Payment data is handled entirely by Stripe (PCI-DSS Level 1). API tokens are stored encrypted at rest, and access to production systems is restricted to the operator.
11. International transfers
We are based in Brazil and use service providers located in the United States. Where personal data leaves the EU/UK, transfers rely on Standard Contractual Clauses or an adequacy decision applicable to the provider.
12. Changes to this policy
We may update this policy as our products or the law change. The "Effective date" above always reflects the current version. Material changes will be announced on this page before they take effect.