Privacy Policy

Last updated: 2026-10-06 · CSV2JSON

CSV2JSON ("we", "us" or "our") respects your privacy. This Privacy Policy explains what personal information we collect when you use CSV2JSON (the "Service"), why we collect it, how long we keep it, who we share it with, and the rights you have over it.

Please read it before you create an account. By using the Service you acknowledge that you have read this policy.

1. Who Is Responsible for Your Data

The data controller for the Service is:

  • Legal entity: CSV2JSON (an individual or sole trader operating under the laws of the People's Republic of China)
  • Postal address:
  • Privacy contact: wyzycao@gmail.com
  • Data protection officer: not appointed — we do not carry out large-scale or sensitive processing that would require one. Data protection enquiries go to wyzycao@gmail.com.

2. Information We Collect

We only collect what the Service actually needs. Concretely, this is what our systems store:

2.1 Information you give us

  • Account details: your display name, email address, and a hashed password if you sign up with email and password.
  • Profile picture URL, if you sign in with Google and your Google account has one.
  • Support correspondence: the content of emails or messages you send us.

2.2 Information we collect automatically

  • Session data: a session token, its expiry time, and the IP address and browser user-agent recorded when a session is created. We use these to keep you signed in and to investigate unauthorised access.
  • Order data: the plan or credit package purchased, the amount and currency, the order status, the credits granted and any refunds processed. We keep this to provide the Service and to meet tax and accounting obligations.
  • Security logs: a record of payment webhook events we have received from our payment provider, used to prevent the same event being processed twice.

2.3 What we do NOT collect

  • We do not store your card number or card security code. Card data is handled entirely by our payment processor (see Section 5).
  • We do not run any analytics, advertising or tracking pixels, and we do not build advertising profiles.
  • We do not use your data to train machine learning models.

3. How We Use Your Information

Each purpose below is paired with the legal basis we rely on for it, as required by the GDPR:

PurposeLegal basis
Creating and operating your accountPerformance of a contract
Processing payments, credits, refunds and invoicesPerformance of a contract
Providing customer supportPerformance of a contract / legitimate interests
Sending service notices (receipts, billing, security alerts, policy changes)Performance of a contract / legal obligation
Preventing fraud, abuse and unauthorised accessLegitimate interests
Keeping tax and accounting recordsLegal obligation
Diagnosing faults and improving the ServiceLegitimate interests

We do not rely on consent for any of the above, and we do not send marketing email. If we ever introduce marketing, we will ask for your consent first and you will be able to withdraw it at any time.

4. Cookies and Local Storage

We use a strictly necessary cookie and one browser storage entry. We do not use analytics, advertising or third-party tracking cookies.

NameTypePurposeCan be disabled
Session cookieCookie, strictly necessaryKeeps you signed in. Without it you cannot use an account.No
themeLocal storage on your deviceRemembers whether you chose light or dark mode. It never leaves your browser.Yes — clearing site data removes it

One further point worth knowing: our pages load web fonts from Google Fonts, which means your browser makes a request to Google's servers and Google therefore sees your IP address and user agent. Because this is a request for a static asset rather than a cookie, we cannot switch it off from within the page.

5. Who We Share Your Information With

We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We share it only with the processors that are needed to run the Service:

RecipientWhat they receiveWhy
CloudflareAll account, session and order data, because it hosts our application and databaseInfrastructure and hosting
Waffo Pancake (merchant of record)Your email address, order details and payment data, including card dataPayment processing, tax determination and remittance, refunds and receipts
ResendYour email address and the content of the messageDelivering transactional email such as address verification, password reset, and receipts
GoogleOnly if you choose to sign in with Google: an authentication exchange that returns your email address, name and profile picture URLOptional single sign-on

We may also disclose your information where we are legally required to, for example in response to a valid court order or a lawful request from a regulator, and to establish or defend legal claims. If we are ever involved in a merger or acquisition, we will give you notice before your data is transferred and remains protected by this policy.

6. How We Protect Your Information

  • All traffic to the Service is encrypted in transit with TLS.
  • Passwords are stored as a salted hash produced by our authentication library, never in plain text.
  • Payment card data never reaches our servers — it is handled solely by our PCI-DSS compliant payment processor.
  • Access to production systems is restricted to the minimum number of people who need it.
  • Payment webhooks are cryptographically verified, and each event is processed only once.

If a personal data breach occurs that is likely to result in a risk to your rights, we will notify the relevant supervisory authority within 72 hours of becoming aware of it, and will tell you directly where the law requires it. Please keep your account credentials to yourself — you are the first line of defence for your own account.

7. How Long We Keep Your Information

DataRetention periodWhat happens at the end
Account information (name, email, password hash, profile picture URL)While your account is open, then 30 days after you close itDeleted
Order and transaction records7 years from the transaction, to meet tax and accounting obligationsDeleted once the statutory period expires
Support correspondence3 years from the last messageDeleted
Session records and security logs12 monthsDeleted

Where we are required to keep transaction records for tax purposes, we retain only the minimum needed to satisfy that obligation and delete the rest.

8. Your Rights

Depending on where you live, you have some or all of the rights below. To exercise any of them, email wyzycao@gmail.com. We will respond within 30 calendar days. We may ask you to verify that you control the account the request relates to, and we will not charge you for a reasonable request.

RightWhat it means
AccessObtain a copy of the personal information we hold about you
RectificationHave inaccurate or incomplete information corrected
ErasureAsk us to delete your personal information in certain circumstances
RestrictionAsk us to pause processing in certain circumstances
PortabilityReceive your information in a structured, machine-readable format
ObjectionObject to processing based on our legitimate interests
Withdraw consentWithdraw any consent you have given, at any time
ComplainLodge a complaint with your local data protection authority

If you believe we have handled your information badly, please contact us first at wyzycao@gmail.com so that we have a chance to put it right. You always have the right to complain to the supervisory authority in your country of residence or place of work.

9. Service Notices

We send transactional email that is necessary to provide the Service: address verification, password reset, receipts and payment confirmations, and notices about changes to these policies. These are part of the Service and cannot be unsubscribed from while your account is open.

We do not currently send marketing or promotional email. If that changes, every marketing message will include a working unsubscribe link and you will be able to opt out from your account settings. Unsubscribing from marketing will never stop service notices such as receipts and security alerts.

10. International Transfers

Our infrastructure and our processors are located in Cloudflare's global network, including the United States. If you access the Service from elsewhere, your information will be transferred to and processed in those locations.

Where personal information is transferred out of the European Economic Area, the United Kingdom or Switzerland, we rely on appropriate safeguards — in particular the European Commission's Standard Contractual Clauses incorporated into our agreements with each processor, together with an assessment of the local law of the destination country. You can request a copy of the relevant safeguards from wyzycao@gmail.com.

11. Children

The Service is intended for people aged 18 and over. We do not knowingly collect personal information from anyone below that age. If you believe a child has provided us with personal information, contact us at wyzycao@gmail.com and we will delete it.

12. Third-Party Services and Links

The Service may contain links to third-party websites, and our pages load third-party assets such as web fonts. This policy applies only to information we collect ourselves. We are not responsible for the privacy practices of those third parties, and we encourage you to read their policies before using their services.

13. Changes to This Policy

We may update this policy. If a change is material — for example a new category of data or a new recipient — we will notify you by email at least 15 days before it takes effect and update the date at the top of this page. Continuing to use the Service after that date means you accept the updated policy.

14. Contact Us

  • Privacy and data rights: wyzycao@gmail.com
  • General support: wyzycao@gmail.com
  • Security reports: wyzycao@gmail.com
  • Legal entity: CSV2JSON
  • Postal address:

← Back to home