← Back to ISBNFetch

Privacy Policy

Last updated: 24 February 2026

1. Introduction

This Privacy Policy explains how Wong Lung Tak Manson (operating as ISBNFetch) ("we", "us", or "our") collects, uses, and protects your personal data when you use ISBNFetch (https://isbnfetch.com) and its related services (the "Service").

By using the Service, you agree to the collection and use of information as described in this policy. If you do not agree, please stop using the Service.


2. Data We Collect

2.1 Account Data

When you create an account, we collect:

  • Email address
  • Password (stored as a hashed value — we never see your plain-text password)
  • Display name (optional)
  • Preferred language and timezone (optional)

2.2 Usage Data

When you use the Service, we automatically collect:

  • ISBN scan history (books you looked up)
  • Your personal book library (books you saved)
  • Credit usage and transaction history
  • Scan method (camera, manual entry, or batch)
  • Device type and browser (for debugging and improving the Service)
  • IP address and approximate location (country-level)

2.3 Analytics Data

We use PostHog and Vercel Analytics to understand how the Service is used. This may include page views, feature interactions, and session recordings. Analytics are only collected if you consent via our cookie banner.


3. How We Use Your Data

We use your data to:

  • Provide and operate the Service (account management, book lookups, library storage)
  • Process credit purchases and maintain your credit balance
  • Send transactional emails (account confirmation, password reset)
  • Improve the Service through analytics and bug reports
  • Power community activity features — for example, a real-time feed that may display your display name, a recently scanned book title, and your approximate location (country or city derived from your profile or IP address). You can opt out of appearing in this feed at any time in your account settings.
  • Comply with legal obligations

We do not sell your personal data to third parties. We do not use your data for advertising purposes.


4. Legal Basis for Processing (GDPR)

If you are located in the European Economic Area (EEA), we process your data under the following legal bases:

  • Contract performance — processing necessary to provide the Service you signed up for
  • Legitimate interests — service security, fraud prevention, and product improvement
  • Consent — analytics and non-essential cookies (you can withdraw at any time)
  • Legal obligation — where required by applicable law

5. Third-Party Services

We share your personal data only with the following categories of sub-processors, each bound by data protection obligations:

Cloud database & authentication providerStores your account data, book library, and scan history securely
Cloud hosting & infrastructure providerServes the application; processes IP addresses and request logs
Product analytics providerUsage analytics and session insights — only active with your consent

Book metadata lookups (e.g. searching by ISBN) use external book data sources. These requests contain only the ISBN number — no personal data is transmitted.


6. Cookies

We use cookies for two purposes:

  • Essential cookies — required for authentication and session management (Supabase session token). Cannot be disabled.
  • Analytics cookies — PostHog and Vercel Analytics tracking. Only set with your explicit consent via the cookie banner.

You can manage your cookie preferences at any time. See our Cookie Policy for details.


7. Data Retention

  • Account data is retained for as long as your account is active
  • Scan history and library data are retained until you delete your account
  • After account deletion, data is soft-deleted immediately and purged within 30 days
  • Aggregated, anonymised analytics data may be retained indefinitely

8. Your Rights

Depending on your location, you have the following rights regarding your personal data:

  • Access — request a copy of your personal data
  • Rectification — correct inaccurate data
  • Erasure — request deletion of your account and data
  • Portability — export your book library and scan history as CSV
  • Objection — object to processing based on legitimate interests
  • Withdraw consent — revoke cookie/analytics consent at any time
  • Activity feed opt-out — disable your appearance in the community activity feed via account settings
  • CCPA opt-out — we do not sell your data; no separate opt-out needed

To exercise any of these rights, email us at mansonwong0703@gmail.com. We will respond within 30 days.


9. International Data Transfers

Your data may be processed in countries outside your own, including the United States (Supabase, Vercel infrastructure). Where required by law (e.g. GDPR), such transfers are safeguarded by Standard Contractual Clauses or equivalent mechanisms.


10. Children's Privacy

ISBNFetch is not directed at children under the age of 13 (or 16 in the EEA). We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.


11. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email or a prominent notice on the Service. The "Last updated" date at the top of this page indicates when the policy was last revised. Continued use of the Service after changes constitutes acceptance.


12. Contact Us

For privacy-related questions, data requests, or complaints:

Data Controller: Wong Lung Tak Manson (operating as ISBNFetch)

Email: mansonwong0703@gmail.com

Governing Law: Hong Kong SAR

If you are in the EEA and are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority.