Legal
Privacy Policy
Last updated 14 August 2026
This Privacy Policy explains how Dino Valley Books (“we”, “us”) collects, uses, and shares information when you visit book.omarhajjoub.site (the “Site”) or request a personalized copy of The Secret of Dino Valley.
Purchases are processed by Etsy, not by this Site. Etsy’s privacy policy applies to payment, checkout, and Etsy account data.
1. Who is responsible
Controller for this Site: Dino Valley Books. Contact: your-real-admin@email.com. Postal correspondence is available on request via that email (see Contact / Imprint).
2. Information we collect
- Parent / purchaser details: name, email address, Etsy order number.
- Personalization details: child’s first name (or chosen explorer name) and a dinosaur companion name. These are story characters, not a child account.
- Technical data: IP address, browser type, date/time, and security logs needed to run the Site and prevent abuse.
- Cookies: essential session and CSRF cookies. See the Cookie Policy.
We do not collect payment card numbers. We do not require a customer account login to read a purchased adventure.
3. Why we use it (legal bases)
- Contract: to match your Etsy order, generate the illustrated PDF, email it, and host the adventure link (GDPR Art. 6(1)(b)).
- Legitimate interests: security, fraud prevention, answering support mail (Art. 6(1)(f)).
- Consent: where required for non-essential cookies. We currently use essential cookies only (Art. 6(1)(a) / ePrivacy).
- Legal obligation: tax, consumer, and child-privacy rules where they apply (Art. 6(1)(c)).
4. Children
This product is intended for children ages 4–9, but it is bought and configured by a parent or guardian. We do not knowingly allow children under 13 (US) or under 16 (EU default) to create an account or submit personal data themselves. Read the dedicated Children’s Privacy page.
5. Sharing
We share data only with:
- Our hosting and email providers (to operate the Site and send your book).
- Etsy, to the extent you already shared data with Etsy at checkout.
- Authorities if required by law.
We do not sell personal information and we do not share it for cross-context behavioral advertising (CCPA/CPRA “sale” / “share”).
6. Retention
Order and personalization records are kept as long as needed to deliver the book, provide support, and meet bookkeeping rules, then deleted or anonymized. Server logs are kept for a short security period.
7. Your rights
EEA/UK (GDPR): access, rectification, erasure, restriction, portability, and objection. You may lodge a complaint with your local supervisory authority.
California (CCPA/CPRA): right to know, delete, correct, and to opt out of sale/share (we do not sell or share). We will not discriminate against you for exercising these rights.
Email your-real-admin@email.com with the subject “Privacy request”. We may need to verify you are the purchaser.
8. International transfers
The Site may be hosted outside your country. Where GDPR applies, we rely on appropriate safeguards used by our processors (such as Standard Contractual Clauses) or a valid adequacy decision.
9. Security
We use HTTPS, access controls on the admin studio, and rate limits on public forms. No method of transmission is 100% secure.
10. Changes
We will update this page when our practices change and revise the “Last updated” date.