Skip to content

The small print, in plain English

Privacy policy

Last updated 8 October 2026

This policy explains what personal information Mindgrid Kids collects, why, and the choices you have. Mindgrid Kids is a brand ofMindgrid (“we”, “us”), which is responsible for your information. Questions? Emailhello@mindgridkids.com.

We follow the data protection laws that apply to our customers, including the UK GDPR, the EU General Data Protection Regulation, the Australian Privacy Act 1988 (and the Australian Privacy Principles) and Sri Lanka’s Personal Data Protection Act.

Accounts are for adults only

Our books are for children, but our accounts are for parents, teachers and tutors aged 18 or over. We never knowingly collect information about children. If you think a child has created an account, contact us and we’ll delete it.

What we collect

  • Account details: your name, email address, password (stored only as a secure hash), country, preferred currency, whether you’re a parent, teacher, tutor or other, and your confirmation that you’re 18 or over.
  • Orders: what you bought, prices paid, delivery addresses and phone number (for printed books), and order history.
  • Payments: handled by our payment provider. We never see or store your full card details; we receive a payment reference and the result.
  • Marketing choices: whether you agreed to receive our emails, and when.
  • Messages you send us through the contact form or by email.
  • Technical information: your IP address and browser type, used for security (for example limiting login attempts) and to show prices for your country.

Why we use it (and our legal basis)

  • To run your account, take and deliver your orders and give you access to your PDFs (to perform our contract with you).
  • To send emails about your account and orders, such as confirmation codes, receipts and delivery updates (contract).
  • To send puzzles, free packs and news, only if you agreed (consent, which you can withdraw at any time).
  • To keep the shop secure and prevent fraud and spam (legitimate interests).
  • To keep business and tax records (legal obligation).

Who we share it with

We don’t sell your information. We share it only with services that help us run the shop, under contracts that protect it:

  • Cloudflare: website hosting, security and bot protection (Turnstile), and our privacy-friendly visitor statistics.
  • Brevo: sending our emails and managing our mailing list.
  • Our payment provider: processing payments.
  • Google: only if you choose “Sign in with Google”.
  • Printers and delivery companies: your name and delivery address, to send printed books.
  • Amazon: if you buy a printed book on Amazon, that purchase is between you and Amazon under their privacy policy.

Some of these providers process information outside your country. Where that happens, we rely on recognised safeguards such as standard contractual clauses.

Cookies

We use only cookies the shop needs to work. There are no advertising or tracking cookies, and no Google Analytics or Facebook Pixel.

  • Login cookies keep you signed in.
  • A currency cookie remembers the currency you chose.
  • Short-lived sign-up cookies remember which address we just sent a code to (for 30 minutes).

Our visitor statistics (Cloudflare Web Analytics) don’t use cookies or track you across sites.

How long we keep it

  • Account information: while your account is open.
  • Order records: for as long as tax law requires (usually up to 7 years), even if you delete your account; they are no longer linked to it.
  • Marketing consent records: until you unsubscribe, plus a short period as proof of your choice.

Your rights

Depending on where you live, you can ask to see, correct, download or delete your information, object to or restrict how we use it, and withdraw consent. You can do much of this yourself in My account → Privacy & data: download all your data, or delete your account. For anything else, email hello@mindgridkids.com. We’ll reply within one month.

You can also complain to your local data protection authority, for example the Information Commissioner’s Office (UK), your EU country’s supervisory authority, the Office of the Australian Information Commissioner, or Sri Lanka’s Data Protection Authority.

Changes

If we change this policy in an important way, we’ll tell account holders by email before the change takes effect.