Legal template · Effective August 7, 2026
Privacy policy
Template requiring professional legal review. This draft is not legal advice and must be reviewed and approved for California, United States before live data collection.
This Privacy Policy explains how Scrollsmith, currently operated by its individual owner ("we," "us," or "our"), handles information when you use Scrollsmith, the website at usescrollsmith.com, related account and billing services, and the Scrollsmith browser extension (together, the "Service").
Summary
Scrollsmith changes the appearance of native website scrollbars. The extension is designed not to collect webpage content, browsing history, passwords, keystrokes, or payment-card information. It stores appearance settings locally and communicates with our server only for account, entitlement, and related operational functions.
Information we handle
| Category | Examples | Purpose |
|---|---|---|
| Account information | Email address, user ID, email-verification state, eligibility confirmation and policy version, profile and plan | Create, authenticate, secure, and administer your account. The eligibility confirmation records that you are 18 or older, or 13 through 17 with parent or legal-guardian permission; it does not include your date of birth. |
| Authentication information | Secure website session cookies; hashed or opaque extension session credentials; expiration and revocation timestamps | Keep you signed in, link the extension to your account, refresh sessions, and prevent unauthorized Premium access. |
| Theme preferences | Selected theme, width, radius, colors, opacity, glow, motion settings, enabled state, and reduced-motion preference | Apply and remember your requested scrollbar appearance. |
| Per-site choices | Hostnames for sites you disable or configure, plus the associated theme settings | Apply the preference you deliberately assign to that hostname. The extension does not need the page's text or browsing history for this feature. |
| Billing and consent records | Stripe customer and subscription identifiers, plan, payment status, billing period, amount, currency, refund status, transaction-event identifiers, the automatic-renewal disclosure accepted, its policy version, and consent timestamp | Process purchases, prove subscription consent, maintain entitlements, prevent duplicate webhook processing, handle cancellations and refunds, and keep required financial and compliance records. |
| Support communications | Email address and the information you choose to send in a support or deletion request | Respond to requests, troubleshoot problems, and maintain a record of the response. |
| Basic technical records | IP address, request time, browser or device information, error and security logs that may be recorded by hosting or infrastructure providers | Deliver and secure the Service, diagnose failures, prevent abuse, and maintain reliability. |
| Anonymous website analytics | Public page path without query strings or fragments, timestamp, referrer, approximate region, browser, operating system, and device category | Understand aggregate website traffic and improve public pages. Account, authentication, password-reset, and billing-result pages are excluded. |
Information we do not intend to collect
- Webpage text, images, form contents, or other page content.
- Your general browsing history or a record of every page you visit.
- Passwords from third-party websites, keystrokes, or clipboard contents.
- Full payment-card numbers, card security codes, or bank-account credentials.
- Data for behavioral advertising, sale to data brokers, or credit decisions.
Please do not send passwords, card details, private webpage content, or other unnecessary sensitive information in a support request.
How the extension uses local storage
The extension uses Chrome extension storage to keep theme settings, the enabled state, disabled hostnames, per-site presets, and an opaque account refresh credential. Short-lived access credentials may use session storage. Content scripts cannot directly read the stored account credential. Local settings remain on your browser installation unless a clearly disclosed cloud-sync feature is later enabled.
Accounts and authentication
Supabase provides authentication and database infrastructure. When you create an account, authentication information is transmitted securely for account creation, verification, login, password reset, and session management. We do not store plaintext passwords in our application database or logs. Supabase may maintain credential hashes and other authentication records as necessary to provide authentication.
Payments
Stripe provides hosted checkout, subscription management, refunds, and the customer billing portal. Payment-card information is entered directly into Stripe's interfaces and is handled under Stripe's own terms and privacy policy. We receive transaction and subscription records needed to determine Premium access, but we do not receive or store complete payment-card details.
Cookies and similar technologies
The website uses strictly necessary HttpOnly cookies for authentication, session refresh, security, and account access. Public marketing and policy pages use Vercel Web Analytics for aggregate page-view statistics without third-party analytics cookies. Scrollsmith does not use advertising cookies or cross-site behavioral tracking. See the Cookie Notice.
Chrome extension storage is not a website cookie. Stripe, Supabase, Vercel, Chrome, and websites you open may use their own cookies or storage under their respective policies.
Where information is stored
- Your browser: extension preferences, per-site hostname settings, and extension session credentials.
- Supabase: authentication records, profiles, preferences, plans, entitlements, subscription references, and extension session records.
- Resend: authentication-email delivery records such as recipient address, message status, timestamps, and provider diagnostics.
- Stripe: checkout, payment method, billing, subscription, refund, and customer-portal information.
- Vercel or the selected host: website and API delivery, operational and security logs, and anonymous aggregate analytics for public pages.
Providers may process information in countries other than your own. Their locations and transfer mechanisms must be confirmed during professional review and production configuration.
How information is shared
We may disclose information to service providers that operate authentication, hosting, payment, email, security, or support functions; when required by law; to protect users, the Service, or legal rights; or in connection with a corporate transaction subject to appropriate safeguards. We do not sell extension data or use it for personalized advertising.
Provider policies: Supabase Privacy Policy, Resend Privacy Policy, Stripe Privacy Policy, and Vercel Privacy Notice.
Analytics and telemetry
Scrollsmith uses Vercel Web Analytics on public website pages to measure anonymous aggregate page views. Before an event is sent, Scrollsmith removes query strings and URL fragments and excludes account, sign-in, signup, authentication callback, password-reset, and billing-result routes. Analytics are not initialized when the browser sends a supported Do Not Track or Global Privacy Control signal.
Vercel may process the public page path, event time, referrer, approximate geographic region, browser, operating system, and device category for these aggregate reports. Scrollsmith does not send names, email addresses, account IDs, payment identifiers, extension settings, webpage content, or browsing history through this integration. The extension contains no analytics tracking. No custom analytics events, advertising analytics, or cross-site profiles are used.
Retention
We retain account information while the account remains active and for only as long afterward as reasonably needed for security, dispute resolution, legal compliance, and financial recordkeeping. Proof of automatic-renewal consent is retained for at least three years after consent or one year after the related subscription terminates, whichever is later. If the account is deleted earlier, the retained consent record uses a pseudonymous account identifier and remains inaccessible to browser users. Authentication codes and access credentials expire on short schedules. Local extension information remains until you reset or remove the extension or clear its storage. Providers may maintain backups and records under their own retention schedules.
Your choices and requests
Depending on applicable law, you may have rights to access, correct, export, restrict, object to, or delete certain personal information. You can change extension settings locally, sign out, cancel billing through the customer portal when available, and request account deletion. See Data Deletion Instructions.
Security and limitations
We use measures intended to protect information, including HTTPS, HttpOnly session cookies, short-lived and rotating extension credentials, server-side entitlement verification, access controls, and database row-level security. No system is completely secure. Browser extensions may also be affected by browser defects, device compromise, malicious software, or changes to third-party websites and browser APIs.
Chrome Web Store Limited Use
The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements. Extension information is used only to provide or improve the extension's disclosed single purpose, operate related account features, maintain security, or comply with law.
Changes to this policy
We may update this Policy when the Service or legal requirements change. We will update the effective date and provide additional notice when required.
Contact
Privacy questions and requests: hello@usescrollsmith.com
Operator: Individual owner of Scrollsmith
Domain: usescrollsmith.com
Jurisdiction for final legal review: California, United States