The short version
- We collect your email address to create your account, and the details of the book you are making so it is ready for you in the app.
- We never see your card number. Payment happens on Stripe's own checkout page.
- The cover photo you upload while setting up your book never leaves your browser — it is previewed locally and is not sent to us.
- We use Google Analytics to understand how the site is used. You can refuse these cookies.
- We do not sell your personal data, and we do not use your travel writing or photos for advertising.
- You can ask us to show you, correct, or delete your data at any time: hellokikobook@gmail.com.
1. Who we are
kikō ("we," "us," "our") operates the website kikobook.com, the kikō mobile app, and the personalised printed travel books ordered through them. We are the data controller for the personal data described in this policy.
kikō
Dailidžiu St. 4, 5
Vilnius 01210, Lithuania
Email: hellokikobook@gmail.com
Phone: +370 633 83493
This policy is written to meet the EU General Data Protection Regulation (GDPR). It sits alongside our Terms of Use.
2. What we collect
Account details
When you create an account, we collect your email address and a password. The password is handed to Firebase Authentication, which stores it as a salted hash — we never hold or see your password in readable form.
Your book setup
While you set up a book, you tell us the book type, the travel destination, the title, and which cover you picked. This is stored in your browser as you go, and saved to your account once you register so your book is ready when you open the app.
If you upload your own cover photo during setup, that image is previewed inside your browser only and is never uploaded to us. It is discarded when you leave the page, which is why a custom cover has to be chosen again in the app.
Content you create in the app
The kikō app stores the notes, entries, dates, and photos you add to your book, so that we can lay it out and print it. This is your content: we use it to produce the book you ordered, and we do not use it for advertising or sell it to anyone.
Order and payment details
Payments are taken on a Stripe-hosted checkout page. Your card details go directly to Stripe and are never received or stored by us. Stripe passes back the information we need to fulfil and account for your order — typically your name, email, billing and delivery address, the amount, and the outcome of the payment. To send you a physical book, we need a delivery address and recipient name.
Technical and usage data
Our hosting and analytics providers automatically receive your IP address, device and browser type, approximate location (country or city level, derived from IP), referring page, and the pages and steps you view. We also record a small number of product events — that a setup step was viewed, that the pay button was clicked, that an account was created — so we can see where people get stuck.
Messages you send us
If you email us, we keep the message and your address so we can reply and keep a record of the issue.
3. Why we use it, and our legal basis
| What we do | Data used | Legal basis (GDPR Art. 6) |
|---|---|---|
| Create and run your account | Email, password | Performance of a contract |
| Build, print, and deliver your book | Book setup, app content, name, delivery address | Performance of a contract |
| Take payment and prevent fraud | Order and payment data | Performance of a contract; legitimate interests (fraud prevention) |
| Answer your emails | Message, contact details | Legitimate interests (responding to you) |
| Analytics and advertising measurement | Cookies, usage and device data | Consent |
| Keep the service secure and working | Technical logs | Legitimate interests (security, reliability) |
| Keep accounting and tax records | Order and invoice data | Legal obligation |
Where we rely on legitimate interests, we have considered whether our interest is overridden by your rights, and we have concluded it is not — but you can object at any time (see Your rights). Where we rely on consent, you can withdraw it at any time, without affecting anything done before you withdrew it.
4. Cookies and analytics
We use Google Analytics and Google Tag Manager to measure how the site is used, and Google Ads conversion tracking to see which adverts lead to orders. These set cookies and similar identifiers in your browser.
Cookies that are strictly necessary to run the site — for example, keeping your book setup as you move between steps — are used without consent because the site cannot work without them. Analytics and advertising cookies are only used with your consent, which you can give or refuse when you first visit and change at any time.
You can also block or delete cookies in your browser settings, or install Google's Analytics opt-out add-on. Blocking cookies will not stop you buying a book.
Some information — such as your book setup — is kept in your browser's local storage rather than a cookie. Clearing your browser data removes it.
5. Who we share it with
We do not sell your personal data and we do not share it for anyone else's marketing. We share it only with the providers we need to run the service, each of which handles it on our instructions:
- Google (Firebase) — authentication, database, and website hosting.
- Google (Analytics, Tag Manager, Ads) — usage measurement and advertising performance, subject to your consent.
- Stripe — payment processing. Stripe is an independent controller for card and anti-fraud data; see the Stripe Privacy Policy.
- Printing and fulfilment partners, and delivery carriers — the book file plus the name and address needed to print and deliver your order.
- Apple — if you install the app from the App Store, Apple processes that download under its own privacy policy.
We may also disclose data where we are legally required to, or to establish or defend legal claims. If our business is ever sold or reorganised, your data may transfer to the buyer, who would remain bound by this policy.
6. International transfers
Google, Stripe, and Apple are based in the United States and may process your data outside the European Economic Area. Where that happens, the transfer is covered by an approved safeguard — normally the European Commission's Standard Contractual Clauses and/or certification under the EU–US Data Privacy Framework. Write to us if you would like details of the safeguard used for a particular provider.
7. How long we keep it
| Data | Kept for |
|---|---|
| Account and book content | Until you ask us to delete your account, then removed within 30 days |
| Order, invoice, and tax records | 10 years, as Lithuanian accounting law requires |
| Email correspondence | Up to 2 years after the matter is closed |
| Analytics data | Up to 14 months |
| Book setup held in your browser | Until you clear your browser storage |
Deleting your account does not remove records we are legally required to keep, such as invoices.
8. Your rights
If you are in the EEA or the UK, you have the right to:
- Access — get a copy of the personal data we hold about you.
- Rectification — have inaccurate data corrected.
- Erasure — have your data deleted where we have no overriding reason to keep it.
- Restriction — have us pause processing while a dispute is resolved.
- Portability — receive the data you gave us in a machine-readable format.
- Object — object to processing based on legitimate interests, and to direct marketing at any time.
- Withdraw consent — for anything based on consent, such as analytics cookies.
To exercise any of these, email hellokikobook@gmail.com. We will reply within one month. We may ask you to confirm your identity first, and there is no charge unless a request is clearly unfounded or excessive.
If you think we have handled your data badly, please tell us so we can fix it. You also have the right to complain to your national supervisory authority. In Lithuania this is the State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija), L. Sapiegos g. 17, 10312 Vilnius — vdai.lrv.lt.
9. Security
Traffic to our site and app is encrypted with HTTPS. Accounts and data sit in Google Firebase, and passwords are stored only as salted hashes. Card details never reach our systems. Access to customer data is limited to the people who need it to make and send your book.
No system is perfectly secure. If a breach ever puts your rights at serious risk, we will notify you and the supervisory authority as the GDPR requires.
10. Children
Our services are for people aged 18 or over, and we do not knowingly collect data from children. If you believe a child has given us personal data, contact us and we will delete it.
11. Changes to this policy
We may update this policy as the service changes. We will always revise the "Last updated" date above, and for significant changes we will tell you by email or a notice on the site before they take effect.
12. Contact us
For any question about this policy or your personal data:
kikō
Dailidžiu St. 4, 5
Vilnius 01210, Lithuania
hellokikobook@gmail.com