Privacy Policy
Last updated 20 July 2026
1. Who we are
Coverwright is operated by Aidas Vyšniauskas, a sole trader carrying out individual activity (individuali veikla) under certificate No. 1495712, Lithuania ("Coverwright", "we") — the controller of the personal data described below. Contact: hello@coverwright.com · +370 633 45595. A registered address will be added here once one is set up; see the draft banner above.
2. What we collect
- Intake answers — the questions about your business (industry, headcount, tools you use, data you handle, and similar) that the documents are built from.
- Purchase record — email address, which tier you bought, amount paid, VAT amount and rate, and a Stripe session reference, stored so you can be identified as a paying customer and, if signed in, see past purchases on /dashboard.
- Account info — only if you choose to sign in: your email (and name/avatar if you use Google), handled by our authentication provider, Clerk. Signing in is optional.
We don't run analytics or ad-tracking scripts on the site today. If that changes, this page will say so. The intake has no free-text field except your business name — please don't put anyone's personal details in it.
3. How intake answers are stored
While you're answering questions, your answers live in your browser only (localStorage) — nothing is sent to us until you complete a purchase. Once you pay, a snapshot of your answers is stored against your purchase record so the same document set can be re-downloaded later. Stripe itself never sees your business answers — only payment details.
4. Why we process your data (legal bases)
We process your data on the following legal bases:
- to generate and deliver your documents, provide re-download access, and operate your optional account — performance of a contract (GDPR Art 6(1)(b));
- to keep purchase and invoicing records — legal obligation (Art 6(1)(c), Lithuanian accounting and tax law);
- to prevent fraud and secure the service — legitimate interests (Art 6(1)(f));
- where we ever ask for anything optional beyond this — consent (Art 6(1)(a)), which you can withdraw at any time.
5. Who we share data with
We use a small number of processors to run the service:
- Stripe — payment processing.
- Clerk — optional account sign-in.
- Neon (via Vercel) — database hosting for purchase records.
- Vercel — application hosting.
We don't sell your data, and we don't share it with anyone outside of running the service itself.
6. International transfers
Our processors (Stripe, Clerk, Neon, Vercel) are US companies. Where your data is transferred outside the EEA/UK, the transfer is protected by the EU–US Data Privacy Framework (for certified processors) or the European Commission's Standard Contractual Clauses incorporated into our agreements with them. Our database and hosting are located in [EU region — to be confirmed with engineering before this page leaves draft]; where that's confirmed, document and intake data is stored in the EU.
7. How long we keep it
We keep your purchase record and document snapshot for 3 years from purchase so you can re-download and repurchase updates, then delete the snapshot. Invoicing and accounting data is kept for 10 years as Lithuanian law requires. If you ask us to delete your data sooner, we delete everything except what tax law obliges us to keep.
8. Your rights
You can ask us to access, correct, export, or delete the personal data we hold about you at any time by emailing hello@coverwright.com. If you delete your data, we delete your account, intake snapshot, and generated documents, but must keep the basic purchase and invoicing record (amount, date, VAT details, and the email it was issued to) for 10 years under Lithuanian accounting and tax law — deleting your data ends your ability to re-download your documents. If you're in the EU/UK, this includes the rights available to you under GDPR, including the right to lodge a complaint with a supervisory authority — for us, the State Data Protection Inspectorate of the Republic of Lithuania (VDAI, vdai.lrv.lt) — or the authority where you live or work.
We haven't appointed a data protection officer — the conditions that require one (public-authority processing, or large-scale regular monitoring or special-category processing) don't apply to us. As an EU-established controller, an EU representative isn't applicable. Whether a UK representative is required, given we target UK buyers, is an open item pending a written answer from counsel — see the draft banner above.
9. Health-data intake answers
If your intake answers say your business handles health data, that's information about your business's activities, not health data about an identified person — GDPR's special category rules (Art 9) aren't engaged by that answer.
10. Cookies
We use only the cookies necessary for the site to function — session/authentication cookies set by Clerk when you sign in, and Stripe's checkout session. No advertising or cross-site tracking cookies.
11. Contact
Questions about this policy or your data: hello@coverwright.com.