← Back

Security & privacy

Last updated: 2026-06-16

This page is maintained by Ambar Blart to answer common security, privacy and data-handling questions about Resin Atelier.

It is informational and describes the seller's current practices. It is not an independent certification or audit.

Sign-in and accounts

Customer accounts use the platform's managed authentication (email + password or Google). Sessions live only in the browser. Each customer can only see their own purchases, receipts and PDFs — access rules are enforced on the server (Row-Level Security).

Payments

Payments are processed by Stripe Payments Europe Ltd. The seller never sees full card data. Stripe handles PCI-DSS compliance and 3-D Secure.

Files and receipts

Ebook PDFs and receipts are stored in a private bucket. Downloads require a signed-in account with a verified purchase; links are short-lived and signed.

Personal data

Only data needed to fulfil the order is processed (email, transaction IDs, billing country). Lawful bases and your rights are detailed in the Privacy Policy.

Sub-processors

Stripe (payments), Supabase / Lovable Cloud (hosting and database), Resend or equivalent (transactional email). All providers operate in the EU/EEA or under Standard Contractual Clauses.

Reporting a security issue

Please report suspected vulnerabilities to ambar.blart@gmail.com. We aim to respond within a few business days.

Ambar Blart
Sign inAccount