Privacy and photo processing

How personal information and family photos are handled

This policy explains what we collect, why we need it, who helps us provide the service and how to exercise your privacy rights.

Last updated: 22 July 2026

Who is responsible

Data controller and contact

My Colouring Pad, is the data controller for this service.
Email: data@mycolouringpad.com

This policy also provides information for people shown in a photo uploaded by a customer. The customer may be the person who gives us the photo rather than every person pictured.

Our photo promise

Private, purpose-limited and never used to train AI

Your photos are not used to train AI models. My Colouring Pad has not opted in to OpenAI’s API data-sharing programme. Under OpenAI’s API data policy, API inputs and outputs are not used to train or improve OpenAI models unless the API customer explicitly opts in.

We do not sell your photos, publish them or use them for advertising. We use them only to create your private sample and book, provide support, produce the files you bought and fulfil your order. We share only the information needed by the specialist providers listed below.

Information we use

The data involved in making and delivering a book

  • Contact and account details. Name, email, billing address, UK delivery address, telephone number where supplied and account details managed by WordPress and WooCommerce.
  • Order and payment records. Products, prices, promotion, delivery choice, order status, payment confirmation and refunds. Stripe handles full payment-card details; they are not stored in the personalised project record.
  • Photos and personalisation. Source photos, recipient and book titles, cover choices, page order, generated sample, paid colouring pages, private proof, revision notes and production files.
  • Service and security data. IP address, device and browser details, timestamps, rate-limit and moderation outcomes, permission and policy versions, support messages, deletion records and technical logs.
  • Cookie choices and measurements. Necessary preferences and, only after the relevant choice, analytics or marketing identifiers. Names, emails, titles, photos, media links and proof tokens are not sent in analytics or advertising events.

Why we use it

Purposes and UK data-protection lawful bases

  • Contract. To take steps you request before an order and perform the order: save your chosen draft, create the requested sample, take payment, generate and release the paid proof, produce files, deliver the product and provide order support.
  • Legitimate interests. To secure private media, prevent fraud and repeated free samples, moderate prohibited content, diagnose failures, improve reliability, keep proportionate evidence and establish or defend legal claims. We balance these interests against the privacy rights of customers and people shown in photos.
  • Legal obligations. To keep required tax, accounting, refund and compliance records and respond to lawful requests.
  • Consent. To load optional analytics or marketing technologies and send optional direct marketing. Consent can be withdrawn for future processing at any time.

The service uses automated tools to transform and validate images, but it does not use solely automated processing to make decisions about a person that produce legal or similarly significant effects.

Service providers

Who may process information for the service

  • Hostinger. Hosts the website and private working storage and sends transactional email. Hosting backups and security logs may follow separate rolling retention cycles. Hostinger privacy policy.
  • OpenAI. Receives selected photos and instructions to create line-art pages. The image-edit API does not retain application state. Default abuse-monitoring logs may contain customer content and may be kept for up to 30 days, unless longer retention is required by law or reasonably needed to prevent harm. Image inputs are scanned for child sexual abuse material; a potentially matching image may be retained for manual safety review. OpenAI API data controls.
  • Browserless. Renders guarded proof and production content into PDF files. Browserless states that normal page and session content is not stored or retained. Browserless privacy policy.
  • WooCommerce and Stripe. WooCommerce records checkout and order state; Stripe processes payment and refund transactions. Stripe privacy policy.
  • Lulu. For printed orders, Lulu receives final print-ready PDFs, quantity, recipient and delivery details. Lulu staff and fulfilment providers may access that information to validate, print, support and dispatch the order. Lulu privacy policy and print-file requirements.
  • Google and Meta. May receive analytics or marketing events only after the matching cookie choice and only while the relevant tool is configured. They do not receive customer names, emails, book titles, photos, private media links or proof tokens from our event payloads.

We may also disclose information where required by law, to protect a person or our legal rights, or in connection with a business sale or reorganisation subject to appropriate confidentiality and data-protection safeguards.

Children and family photos

Permission is confirmed after upload and before processing continues

The purchasing journey is for adults. You may select or upload photos before completing the permission confirmation, but a sample cannot be created, photos cannot be saved to a book and checkout cannot continue until you confirm that you are authorised to use every photo and the image of every person shown, including children.

Children’s photos are used to make the requested sample, proof and order. They are not used to profile a child or target advertising to them. We do not use facial recognition or try to identify people shown in photos.

International processing

Some providers process information outside the UK

Where information is transferred outside the UK, we use the protection available for the relevant transfer, such as UK adequacy regulations or an approved contract including the UK International Data Transfer Agreement or UK Addendum, together with any required transfer-risk assessment and additional safeguards. Email data@mycolouringpad.com to ask about the safeguard used for a particular provider.

Retention and security

Working photos are private and time-limited

Unused uploads become eligible for automatic deletion after 24 hours. Unpaid or inactive projects become eligible after 30 days. Paid physical working media becomes eligible 90 days after dispatch and digital working media 90 days after release. Active support, disputes, safeguarding issues or legal obligations may extend these periods. Our Photo and Data Retention Policy gives the full timetable and explains provider copies.

Working files are stored outside the public website and accessed through signed, expiring links. Uploads, private views and provider transfers are encrypted in transit using HTTPS. Access is limited to authorised people and service providers who need it. No online service can guarantee absolute security.

Order, payment, refund, tax, security and compliance records may be kept longer without retaining the working photo files.

Your choices and rights

Contact us about your information

Depending on the circumstances and lawful basis, you may have rights to access, correct or erase personal information, restrict or object to its use and receive information you supplied in a portable format. Where we rely on consent, you may withdraw it for future processing at any time.

You have an absolute right to object to the use of your personal information for direct marketing.

Email data@mycolouringpad.com to make a request. We may need to verify your identity and authority, particularly where a request concerns a child or another person’s photo. Rights are not absolute, and we will explain if a lawful exception applies.

You may complain to the Information Commissioner’s Office. We would appreciate the opportunity to address your concern first, but you do not have to contact us before approaching the ICO.