Privacy Policy
This Privacy Policy explains what personal data amCharts Editor (“we”, “us”) collects,
why, who we share it with, how long we keep it, and the rights you have. It is written
to meet the EU/UK GDPR and the California CCPA/CPRA,
and applies to the editor at live.amcharts.com and charts published at chart.amcharts.com.
In short
- We collect the minimum needed to run the service: your account, the charts you save, and basic usage/technical data.
- We don’t sell your personal data.
- Payments are handled by Paddle as merchant of record — we never see your full card details.
- We use Google Analytics, and Google Ads conversion measurement when we run ads, only after you consent.
- Charts you publish are public to anyone with the link.
- You can access, export, correct, or delete your data — self-service tools are coming; until then, email us.
1. Who we are
The data controller is amCharts (Antanas Marcelionis). For any privacy question or to exercise your rights, contact contact@amcharts.com.
2. What we collect
| Category | Examples | Source |
|---|---|---|
| Account | Email, display name, password (hashed) or the identifier from Google/GitHub sign-in | You / your OAuth provider |
| Content | Charts, chart data and settings you create or upload; published charts and their public URL/handle | You |
| Usage | Number of charts, storage used, plan, feature activity | Automatically |
| Billing | Subscription status and plan. Payment details are collected and stored by Paddle, not us | Paddle |
| Technical / log | IP address, browser/device, timestamps, security signals | Automatically (via Cloudflare) |
| Analytics & advertising | Pages viewed, approximate location, interactions (Google Analytics); ad-click identifiers to measure conversions such as upgrades that came from an ad (Google Ads) | Cookies, after you consent |
We don’t intentionally collect special-category data. Please don’t put sensitive personal data into chart data you upload or publish.
3. Why we use it, and our legal bases
| Purpose | GDPR legal basis |
|---|---|
| Create your account and provide the editor, saving, and publishing | Performance of a contract |
| Process subscriptions and payments | Contract; legal obligation (tax/accounting) |
| Secure the service, prevent abuse, debug | Legitimate interests |
| Analytics and product improvement | Consent (EU/UK) / legitimate interests where permitted |
| Send service and, if you opt in, product emails | Contract / consent |
| Comply with the law and respond to lawful requests | Legal obligation |
4. Cookies & similar technologies
We don’t set any cookies of our own. Keeping you signed in and your local drafts uses your browser’s local storage, not cookies. The items below are set by our infrastructure and third parties, plus Google Analytics and Google Ads after you consent. Strictly necessary storage is always on; analytics and advertising cookies load only after you consent where the law requires it, and you’ll be able to change your choice at any time.
| Name / type | Purpose | Category |
|---|---|---|
| Sign-in session & drafts (browser local storage — not a cookie) | Keeps you signed in; holds unsaved drafts | Necessary |
__cf_bm, cf_clearance (Cloudflare) | Bot protection and security | Necessary |
| Cloudflare Turnstile (on forms, e.g. reporting content) | Blocks automated abuse of our forms | Necessary |
| Paddle checkout cookies | Complete a purchase (set by Paddle during checkout only) | Necessary |
| Consent preference (local storage) | Remembers your cookie choice and the policy version you accepted | Necessary |
_ga, _ga_<id> — Google Analytics | Measure usage (loads only after you consent) | Analytics — consent |
_gcl_* — Google Ads | Measure ad conversions, e.g. an upgrade that came from an ad (loads only after you consent) | Advertising — consent |
5. Who we share it with
We use vetted service providers (processors) and don’t sell your data. Key providers:
| Provider | Role | Location |
|---|---|---|
| Supabase | Authentication & database hosting | Sweden (EU) |
| Cloudflare | Hosting, CDN, storage (R2), security | Global edge |
| Paddle | Payments & merchant of record (seller, tax, invoicing) | EU / global |
| Google Analytics | Usage analytics (after consent) | US / global |
| Google Ads | Advertising & conversion measurement (after consent) | US / global |
International transfers. Some providers are outside your country (e.g. the US). Where we transfer personal data out of the EEA/UK, we rely on appropriate safeguards — an adequacy decision where one applies (including the EU–US Data Privacy Framework for certified US providers), and otherwise the European Commission’s Standard Contractual Clauses.
6. How long we keep it
- Account & content: while your account is active.
- Inactive accounts: if you don’t sign in for 24 months, we may delete the account and its charts. We’ll email you two reminders beforehand (about 30 days and 7 days before), so you can keep everything simply by signing in. An active paid subscription counts as activity.
- Published charts: until you unpublish or delete them (public caches may lag briefly).
- Billing/tax records: retained by Paddle as required by law (typically several years).
- Logs: kept for a short period for security and debugging.
- Backups: we keep backups in various forms for up to 12 months for disaster recovery; older backups are overwritten on a rolling basis (see how this affects deletion under Your rights).
7. Your rights
Everyone: access, correct, delete, export (portability), and object to or restrict certain processing; withdraw consent at any time.
EEA/UK: you may lodge a complaint with your local supervisory authority.
California (CCPA/CPRA): the right to know, delete, and correct your personal information, to opt out of “sale”/“sharing” (we do not sell or share for cross-context behavioral advertising), to limit use of sensitive information, and to non-discrimination for exercising these rights.
How to exercise them: self-service data export and account deletion tools are coming to your account settings. Until then, email contact@amcharts.com and we’ll respond within the legally required timeframe (30 days GDPR / 45 days CCPA). We may need to verify your identity.
Backups. When you delete data or your account, we remove it from our active systems promptly. Removing a single record from a backup isn’t feasible, so any residual copies in backups are isolated, not used, and overwritten as backups cycle out (up to 12 months). If we ever restore a backup, we re-apply your deletion.
8. Security
Data is encrypted in transit; access is restricted and rows are isolated per user. No system is perfectly secure, but we take reasonable technical and organizational measures to protect your data and will notify you and regulators of a breach where required.
9. Children
The service isn’t directed to children. We don’t knowingly collect data from anyone under 16 (or the minimum digital-consent age in your country, and under 13 in the US). If you believe a child gave us data, contact us and we’ll delete it.
10. Changes to this policy
We’ll update this policy as the service evolves. The version and date appear at the top; when we make material changes we’ll re-request consent and/or notify you. Continued use after an update means you accept the revised policy.
11. Contact
Questions or requests: contact@amcharts.com.
See also our Terms of Service.