Privacy Policy

This policy describes what personal data we collect when you buy or request an excerpt of our publication on this website, who processes it for us, and what you can ask us to do with it. It describes this website only.

Effective date
16 August 2026
Published by
ФОП Адамів-Костишин Богдан Олександрович, ІПН 2911110839 · Україна · 79014, м. Львів, вул. Грушева, 1.5
Governing law
the laws of Ukraine

1. Who is responsible for your data

ФОП Адамів-Костишин Богдан Олександрович, ІПН 2911110839 · Україна · 79014, м. Львів, вул. Грушева, 1.5 is the controller of the personal data described in this policy. You can reach us at the support address on our Contact page.

This website sells one digital publication. It hosts no other service, and this policy covers no other activity. Any data handling described by our other websites is separate and does not concern this one.

2. The short version

  • We hold your email address, which edition you bought, and what you paid — plus the notification message Paddle sends our server about the payment, which we keep exactly as Paddle sent it.
  • We never receive or store your card number. We never ask you for your name, and we never use one. But Paddle’s notification message is Paddle’s to compose, and where you paid by card it can carry the cardholder name and the last four digits shown on it — so that name is in the message we keep. Section 3 says where.
  • We use your address to deliver what you paid for, and to answer you if you write to us.
  • Your address goes to a newsletter provider only if you explicitly ask for the newsletter. Buying the book does not sign you up to anything.
  • We run no analytics, no advertising and no cross-site tracking, and this website sets no browser cookies of its own.
  • One thing on these pages is loaded from another company’s servers: the typefaces the site is set in, which come from Google Fonts. Section 6 explains exactly what Google receives.

3. What happens when you buy

  1. You choose an edition. At that point we send Paddle only a price identifier, a quantity of one, the edition and language you chose, and a reference number for the request. No personal data is involved yet, because we do not have any.
  2. You enter your email address and payment details on Paddle’s own checkout. Those details go to Paddle, not to us. We never see, receive or store your card number, and we never ask you for your name or your billing address.
  3. When the payment completes, Paddle notifies our server. That notification identifies you only by a customer reference — it carries no email address.
  4. Our server then asks Paddle, in a second request, for the email address attached to that customer reference, because without it we cannot send you the book you just paid for.
  5. We record the order: your email address, the edition, the amount and currency, the status of the order, the language, and the identifiers Paddle assigned to the transaction. That order record holds no name, no billing address and no card data.
  6. Separately, we store the notification message Paddle sent our server, whole and unedited, as an accounting and troubleshooting record. Its contents are Paddle’s to determine, not ours, and it carries more than the order record does: alongside the transaction and tax figures, a card payment’s message can include the card type, the last four digits, the expiry month and year, and the cardholder name given at Paddle’s checkout. We do not ask for those fields, we do not use them, and they are copied nowhere else — but they are in the stored message, and telling you that is more honest than describing a tidier record than we actually keep.
  7. We create a passwordless account keyed to your email address, so that there is somewhere for you to sign in and download the files. You do not choose or store a password with us.
  8. We email you a receipt-and-delivery message containing a sign-in link that is valid for a short period. Downloads themselves are served over individually signed links that expire, and are re-issued each time you sign in.

4. What happens when you request a free excerpt

If you ask us to email you a free excerpt, we collect your email address, the edition you asked for, and the language of the page you asked from. We do not collect your name, your IP address or your browser details as part of that record.

The newsletter is a separate, explicit choice

Asking for an excerpt and asking for the newsletter are two different things, and our systems treat them as two different things:

  • If you do not tick the newsletter box, we email you the excerpt and nothing else. Your address is never passed to our newsletter provider, and no marketing consent is recorded against it.
  • If you do tick it, we additionally pass your email address and your language — and nothing else — to our newsletter provider, and record the date on which you consented.
  • You can stop the newsletter at any time using the unsubscribe link in any newsletter message. That link is our newsletter provider’s own, and it takes effect there.
  • Unsubscribing stops the messages; it does not by itself remove the consent record we hold against your address. If you want that removed too, write to us and say so — we do it by hand, because nothing here does it automatically.
  • Not ticking the newsletter box on a later visit is not a withdrawal. We treat a missing tick as no answer rather than as a revocation, so it never silently cancels a consent you gave — telling us is what cancels it.

5. Who else processes your data

We use a small number of providers. We do not sell your data, and we do not share it with anyone for their own marketing. The list below is the arrangement in use today, not a list of everyone we might ever use: if a provider on it is replaced, this page is updated to name the replacement before the change takes effect.

  • Paddle.com Market Ltd — takes the payment as merchant of record, holds your payment details, calculates and remits tax, and issues the payment receipt. Paddle also determines its own purposes for some of that data and publishes its own privacy notice, which governs the payment side of your purchase.
  • Amazon Web Services (Simple Email Service) — sends our email: the excerpt message and the receipt-and-delivery message. It processes the recipient address and the content of those messages on our behalf.
  • Amazon Web Services (S3 and CloudFront) — stores the publication files and serves your downloads over time-limited signed links.
  • MailerLite — our newsletter provider. It receives your email address and language only where you have explicitly consented, and never otherwise.
  • Google (Google Fonts) — serves the two typefaces these pages are set in. Your browser fetches them from Google’s servers as the page loads, which means Google receives your IP address, your browser’s user-agent string and the address of the page you are reading. It receives nothing else from us: no email address, no name, no purchase details, and nothing we hold about you. See section 6.

6. Cookies and tracking

This website sets no browser cookies of its own. It loads no analytics product, no advertising pixel, no social media widget and no cross-site tracking script. We do not profile you and we do not follow you to other websites.

There is one exception to "nothing is loaded from outside this domain", and we would rather name it here than leave you to find it in the page source. The typefaces these pages are set in are served by Google Fonts: your browser requests a stylesheet from fonts.googleapis.com and the font files themselves from fonts.gstatic.com, every time you open a page, before you have clicked anything. In making those requests your browser tells Google your IP address, your user-agent string and which page you are on. We receive nothing back from Google, and Google is sent nothing about you by us. If you would rather it did not happen, a content blocker or a privacy-focused browser will stop the request — these pages stay fully readable in whichever typeface your browser falls back to.

When you open the checkout, that checkout is served by Paddle and runs under Paddle’s control. Paddle may set its own browser cookies at that point, for its own purposes, described in its own notice.

7. Why we are allowed to process it

  • To perform our contract with you — delivering the publication you bought, giving you access to your download page, and answering support requests about your purchase.
  • To meet a legal obligation — keeping records of a completed sale for tax and accounting purposes.
  • With your consent — sending you the newsletter, and only where you asked for it.
  • For our legitimate interests in operating the site securely — for example, our servers briefly see your IP address in order to limit the rate of requests and prevent abuse. That address is not kept in our buyer or excerpt-request records.

8. How long we keep it

We would rather tell you what actually happens than quote a period we do not enforce:

  1. Order records — your email address, the edition, the amount, the status and Paddle’s identifiers — are kept as accounting records for as long as we are required to keep records of a completed sale. A completed order deliberately survives the deletion of the account attached to it, because it is a financial record before it is anything else.
  2. The notification messages Paddle sends us are kept as received, as an accounting and troubleshooting record — including the payment-method fields described in section 3, which we neither ask for nor use.
  3. Excerpt-request records, including any newsletter consent recorded against them, are kept until you ask us to remove them and we do so by hand. Unsubscribing from the newsletter stops the newsletter at our newsletter provider; it does not delete the record here, which is why this sentence says write to us.
  4. There is no automatic deletion schedule running today. If you want your data removed, write to us and we will remove what we are not required to keep, and tell you plainly what we must keep and why.

9. Your rights

Depending on where you live, data-protection law gives you rights over the personal data we hold. Those rights ordinarily include:

  • asking for a copy of what we hold about you;
  • asking us to correct something that is wrong;
  • asking us to delete it;
  • asking us to restrict or to stop a particular use;
  • asking for it in a portable form;
  • withdrawing a consent you previously gave, at any time, without affecting what was done before you withdrew it; and
  • complaining to your data-protection supervisory authority.

How this works in practice, stated plainly rather than implied: there is no self-service privacy page on this website, no download-my-data button, and no automated process behind any of the rights above. Every one of them is exercised the same way — you write to the support address on our Contact page, and a person reads that mailbox and carries the request out by hand. That is a smaller machine than most policies describe, and we would rather you knew which one you are dealing with.

We aim to answer within 30 days. We may need to ask you to confirm the email address the request concerns, because that address is usually the only thing that identifies the record.

One honest caveat: where the law requires us to retain a record of a completed sale, we cannot delete that record on request. If that is the case, we will tell you which record it is and why it has to stay.

10. Security

Data is transmitted over TLS, stored encrypted at rest by our hosting provider, and reachable only by the small number of people who operate the site. Download links are individually signed and expire, so a link that leaks stops working. We describe only measures that are actually in place, and we do not claim that any system is immune to compromise.

11. Where your data goes

We are established in Ukraine, and our providers process data in the European Union, the United Kingdom and the United States. Where a transfer leaves your country, it is made under the transfer safeguards our providers publish in their own data-processing terms.

12. Children

This website is not directed at children, and buying here requires you to be at least 18. We do not knowingly collect data from children. If you believe a child has given us their details, write to us and we will remove the record by hand — the same way every other removal request here is carried out.

13. Changes to this policy

If we change how we handle your data, we will change this page and update the effective date shown at the top of it. Where a change is significant and we hold your address, we will tell you directly.

If you have a question about this document, or you want to exercise anything it describes, write to us — a real person answers.

Email support or see our Contact page.