SKIPPER D / PRIVACY
Your workshop is yours.
This notice covers the shared Polywinkle account, Skipper D checkout and private reports. Accounts are free and do not require a purchase. See also the company privacy notice for contact forms and verification checks. Updated 7 October 2026.
What the account service stores
If sign-in is enabled, we use your Google account's stable identifier, email address and display name to create an account. Google verifies your identity. We do not receive your Google password or access to your email messages, contacts or Drive files.
Essential, secure session cookies keep you signed in and protect requests against forgery. Sessions expire after seven days. Short-lived anonymous sessions protect the sign-in flow. Rate-limit records use a hashed network address and expire after one day.
Your profile and desktop sign-in
You can optionally save a display name, first and last name, workshop/company, phone number and profile picture. Uploaded pictures are resized and re-encoded without original metadata. These details are private to your account; we do not publish a member directory.
Changing the linked Google account requires verification of both the existing and replacement identities. Billing history and your profile remain with the same Skipper D account. Desktop sign-in uses explicit browser approval and a device-bound signed access lease. The app stores its encrypted sign-in cache locally and requires monthly verification, limited by the paid subscription period. No hardware serial numbers are collected for this device identifier.
Payments and notifications
Stripe handles payment details through secure embedded payment fields on this website. The account service stores order identifiers, amount, currency, payment status, subscription status, billing period and payment references. Payment method, billing address and invoice details can be managed in Stripe’s billing portal. Successful purchases can generate an email notification to the site owner. The service does not store card numbers or card security codes.
Purchase records are retained for support, refunds and applicable recordkeeping obligations. Contact us to request access, correction or account deletion; records that must be retained for transactions or legal obligations may not be immediately removable.
Bug reports and diagnostic logs
Reports are linked to your signed-in account. Attachments are optional and are only sent when you submit the form with consent. You can inspect and edit the log before sending it; common credentials are redacted, but you should still remove personal or confidential information.
Local application logs are purged each day. Reports and logs that you explicitly submit are retained privately for investigation and are not included in that daily purge. Contact support to request deletion. Download statistics count completed server transfers, not unique people or installations.
Other information
Our hosting provider may retain ordinary access and security logs. Support messages contain whatever you choose to send. Please do not attach private machine credentials or confidential projects unless necessary and agreed.
This section does not use advertising trackers or analytics cookies. Google sign-in is loaded on the account page when configured; Stripe is contacted for checkout. Those services process information under their own privacy policies. Provider processing may occur outside Canada.
Contact
Questions or privacy requests: [email protected]. Include an order reference if relevant, but not payment-card details.
