Skip to content

Privacy

Privacy information

How BookSway handles account, campaign, payment, and Amazon connection information in the current product.

Who we are

The operating entity is NextPanel Studios LLC d/b/a BookSway. Business address: 1805 Crystal Drive, 908S, Arlington, VA 22202. Privacy contact: privacy@booksway.app.

Information we handle

  • Account and profile information, such as email, password or Google sign-in (stored by the authentication provider), display name, role, bio, country, links, profile visibility, Creator Spotlight opt-in, and avatar image.
  • Book and campaign information authors supply, such as title, synopsis, cover image, ASIN, genres, campaign status, creator reward, and attested marketplace economic terms.
  • Creator participation data, such as which campaign was joined, when, the reserved reward, and the BookSway tracking code for that membership.
  • Payment information needed to operate Author-to-Creator checkout: Stripe customer and connected-account identifiers, checkout and charge identifiers, amounts, fees, receipt last4/brand/url, payout observations, and Connect livemode. Stripe also collects identity information it needs for connected-account verification.
  • Messages sent through the public contact form, including name, email, optional role, subject, and message text, so BookSway can review them.
  • Amazon integration data when an author connects Amazon Ads, as described below.
  • Authentication and session data needed to keep you signed in, named in Cookies and similar storage.
  • Technical and log data such as basic request diagnostics. The hosting provider may see request IP addresses at the edge even though BookSway does not store raw click IP or user-agent. BookSway aims not to log passwords, access tokens, or refresh tokens.

Amazon integration data

When an author chooses to connect Amazon Ads, BookSway stores the author's advertising-profile metadata and an encrypted refresh credential so that author can manage the connection inside BookSway. BookSway may retrieve Amazon Attribution reports for that author. It does not share Amazon credentials with creators or browsers.

How information is used

To create and secure accounts, operate the book library and campaigns, let creators discover and join campaigns, show eligible covers and avatars on public marketplace pages, and — when an author connects Amazon Ads — maintain that Amazon connection and, on a scheduled reporting job, retrieve Attribution reports for that author. Authors do not trigger Attribution retrieve from product UI. BookSway uses Stripe to process Author-to-creator card payments and Creator payouts. BookSway calculates Creator rewards from qualifying Amazon-attributed activity using frozen campaign terms. Settled is not paid. Public tracking links may look up the reader country from the request IP for storefront routing, then discard the IP. BookSway does not store raw IP addresses or derived country on clicks.

If you are in the EEA, UK, or a similar jurisdiction, BookSway uses this information to perform the contract you request (account, campaigns, payments) and, where needed, for security and fraud prevention.

Cookies and similar storage

BookSway uses strictly necessary cookies and similar storage to sign you in and complete the auth flow you requested: Supabase session cookies, booksway_auth_next (return path after sign-in), and booksway_password_recovery (password reset). There are no analytics or advertising cookies today. Stripe Connect and Checkout cookies load only on payout and pay-now flows you start. Google cookies load only if you choose Google sign-in.

Service providers

BookSway uses Supabase for authentication, database, and private cover and avatar storage. Railway hosts the application, scheduled jobs, logs, and TLS. Amazon provides Login with Amazon / Amazon Ads authorization when an author connects. Stripe processes Author-to-creator card payments, connected-account verification, and Creator payouts. Google is an identity provider when you choose Google sign-in. Fonts are served by BookSway, not by Google Fonts. MaxMind GeoLite2 Country data may be used in memory to choose an Amazon storefront for a tracking redirect. This product includes GeoLite Data created by MaxMind, available from https://www.maxmind.com. BookSway does not distribute the GeoLite database, sell GeoLite data, or expose IP-to-country lookup results. Account emails (confirmation and password recovery) are sent by Supabase Auth. BookSway does not currently send product payment emails through a third-party transactional mailer.

Some providers process data in the United States or other countries. Railway currently runs the web replica in Amsterdam. Transfers happen because those providers operate the product features you use.

Retention

Account, book, campaign, and membership records are kept while the product needs them to operate those features. Payment and security records are kept as needed for fraud prevention, accounting, and legal obligations. Contact messages are kept until they are reviewed and no longer needed. Amazon connection metadata remains while the author keeps the connection, and related reporting provenance may be retained after disconnect. You may stop using BookSway at any time. There is no self-serve account wipe. To request deletion, email privacy@booksway.app. BookSway will review the request and remove account access it no longer needs to operate the product. Payment, security, and Amazon-connection records needed for legal, fraud, or accounting purposes may be retained.

Children

BookSway is not directed at children under 18, and we do not knowingly collect personal information from children.

Your choices and rights

You can update your display name and profile, manage your books and campaigns according to product rules, and disconnect Amazon Ads from BookSway. You can ask to access, correct, or delete personal information, or object to processing, by emailing privacy@booksway.app. We may need to keep records described under Retention. If you are in the EEA or UK, you may also contact your local data protection authority.

Security

See Security for a high-level description of authentication, role separation, image serving, and Amazon credential handling.

Contact

Privacy contact: privacy@booksway.app. Also see Contact.