ClanCharts.com
Effective date: 18 February 2026
Last updated: 18 February 2026
ClanCharts.com is operated by ADONE SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ, a company incorporated in Poland under Polish company law, with its registered office at:
DRUŻYKOWA 15
42-445 DRUŻYKOWA
Poland
NIP: 6492320014, KRS: 0000862178
For the purposes of the EU General Data Protection Regulation (GDPR/RODO) and UK GDPR, we are the data controller responsible for the personal data we process in connection with the ClanCharts service.
Privacy contact: privacy@clancharts.com
We have not appointed a Data Protection Officer (DPO / Inspektor Ochrony Danych). If you have questions about how we handle your personal data, contact us at the email address above.
We believe you should know what data we collect and why. We follow three principles:
When you register an account, we collect:
| Data | Purpose | Required? |
|---|---|---|
| Email address | Account authentication, order notifications, transactional emails | Yes |
| Phone number | Optional second factor; order SMS notifications | No |
| First name, last name, display name | Personalisation, address on print orders | Partially |
| Password (stored as a cryptographic hash — never in plain text) | Authentication | Yes |
| Locale / language preference | Display language | Yes (auto-detected) |
| Marketing consent flag with timestamp | Sending optional promotional emails | No |
You may use the service as a guest (without registering) for basic preview functionality. A registered account is required to save work, purchase downloads, or order prints.
When you place an order, we collect:
| Data | Purpose |
|---|---|
| Delivery name, address, city, postal code, country | Shipping the physical canvas print |
| Phone number | Courier contact for delivery issues |
| Order details (product, format, size, price, currency, status) | Order fulfilment, accounting |
| Payment confirmation reference from Stripe | Proof of payment; refund processing |
We do not store your credit card number, card verification code, or full payment card data. All payment card handling is performed by Stripe (see Section 7).
When you upload a GEDCOM file, we store the file on our servers. See Section 4 for a full explanation of how this data is handled.
Subject to your cookie preferences, we may collect:
| Data | Tool | What it contains |
|---|---|---|
| Page views, clicks, navigation path, session duration | Google Analytics 4 | Pseudonymous (user ID only, no name or email) |
| Mouse movements, scroll behaviour, session recordings | Microsoft Clarity | Pseudonymous; PII fields masked |
Google Analytics 4 and Microsoft Clarity are not loaded until you have given consent via the cookie banner.
| Data | Purpose | Legal basis |
|---|---|---|
| IP address | Security, fraud prevention, rate limiting | Legitimate interest |
| Approximate country (derived from IP using a local MaxMind GeoLite2 database — your IP is not sent to MaxMind) | Selecting appropriate currency and print provider | Legitimate interest |
| Session ID (stored in a cookie) | Keeping you logged in during a session | Strictly necessary |
| Browser type and version, operating system | Technical troubleshooting | Legitimate interest |
| Timestamps of actions (login, upload, order) | Security logs | Legitimate interest |
| Feature usage events (e.g. “tree generated”, “file uploaded”) | Error monitoring and service stability — routed through our own server; no persistent cookies or local storage set on your device; no personal data sent | Legitimate interest |
Feature event monitoring is provided by PostHog, routed exclusively through our own server proxy. PostHog does not set any cookies or store any data on your device. No email address, name, or other personal data is included in the events — only a pseudonymous session identifier and anonymised event data.
This section explains in detail how we handle GEDCOM files because they deserve special attention.
A GEDCOM (.ged) file is a standard genealogy format exported from services such as Ancestry, MyHeritage, FamilySearch, or genealogy desktop software. It typically contains names, dates of birth and death, places, relationships, and other family history data assembled by the person who built the family tree.
Your GEDCOM file is stored intact and unmodified on our servers. We do not extract, index, or store the names, dates, or other records contained within the file into any separate database. The file is treated as a single opaque object — like a document stored in a folder.
The contents of your GEDCOM file are parsed in your browser (client-side) using JavaScript, not on our servers. This means the raw genealogical records are processed on your device to generate the tree visualisation. Our servers receive only the rendered image output (for download or printing), not a structured extract of the genealogical records.
GEDCOM files commonly contain data about living relatives — people who are alive today and who did not themselves upload or consent to this file being shared with ClanCharts. By uploading a GEDCOM file, you represent that you have a lawful basis to do so (for example, because you are processing data for your own personal or household genealogy research, which is a recognised ground under data protection law).
We process the file solely to render the tree visualisation you have requested. The file is not used for any other purpose, not shared with third parties for data purposes, and not used to contact, profile, or market to the individuals named within it.
Before uploading a GEDCOM file, you are required to confirm (via a checkbox) that:
We do not inspect or verify the contents of uploaded files. We rely on your confirmation and process the file solely to render the visualisation you have requested. If your confirmation is inaccurate, the legal responsibility for any resulting data protection breach rests with you. See also Section 5 of our Terms of Service.
Genealogical records may incidentally contain information that falls into special (sensitive) categories under data protection law, such as:
We do not intentionally process, extract, or analyse this type of information. We process the file as a whole for the purpose of visualisation only.
You may download your uploaded GEDCOM file at any time directly from your account. This satisfies your right to data portability (see Section 10) without requiring a formal request.
Information about deceased individuals is not personal data under the EU GDPR, UK GDPR, or this Privacy Policy (see GDPR Recital 27). The vast majority of entries in typical genealogical files are for persons who have died. Nevertheless, we apply the same care to all data in the file.
We retain your GEDCOM file for 12 months from the date of your last activity (login or order). If your account is deleted, your files are deleted within 30 days. You may also request deletion of a specific file at any time (see Section 10).
| Processing activity | Legal basis | GDPR Article |
|---|---|---|
| Creating and maintaining your user account | Performance of contract | Art. 6(1)(b) |
| Processing orders and payments | Performance of contract | Art. 6(1)(b) |
| Sending transactional emails (order confirmation, download links, shipping updates) | Performance of contract | Art. 6(1)(b) |
| Retaining accounting and order records | Legal obligation (Polish Accounting Act; tax law) | Art. 6(1)© |
| Storing your GEDCOM file to render the requested visualisation | Performance of contract | Art. 6(1)(b) |
| Processing data of living third parties in your GEDCOM file | Legitimate interest (file stored and processed solely for the visualisation purpose you requested; not indexed or used otherwise) | Art. 6(1)(f) |
| IP address logging for security and fraud prevention | Legitimate interest | Art. 6(1)(f) |
| GeoIP country detection to select currency and print provider | Legitimate interest | Art. 6(1)(f) |
| Analytics (GA4, Clarity) | Your consent | Art. 6(1)(a) |
| Feature event monitoring (PostHog via own server proxy) | Legitimate interest (error monitoring, service stability) | Art. 6(1)(f) |
| Sending promotional emails | Your consent | Art. 6(1)(a) |
We use your data exclusively for the following purposes:
We do not:
We share personal data with the following third-party service providers (data processors), only to the extent necessary to provide the service:
| Provider | Data shared | Location | Transfer mechanism |
|---|---|---|---|
| Stripe, Inc. | Order amount, currency, order reference, email for receipt | USA | EU-US Data Privacy Framework; UK-US Data Bridge |
Stripe acts as an independent data controller for your payment card data. We never see, store, or process your card number. See stripe.com/privacy.
| Provider | Data shared | Location | Transfer mechanism |
|---|---|---|---|
| Posterjack | Delivery name, address, phone; print file (rendered tree image) | Canada/USA | Standard Contractual Clauses (SCCs) |
| Fotako | Delivery name, address, phone; print file (rendered tree image) | Poland (EU) | Within EEA — no additional mechanism required |
Your delivery name, address, and phone are passed to the shipping carrier selected at checkout (UPS, DHL, or national postal service) by the print fulfilment provider. These are transferred under standard carrier terms.
| Provider | Data shared | Location | Transfer mechanism |
|---|---|---|---|
| Google LLC (GA4) | Pseudonymous user ID, page interaction events | USA | EU-US Data Privacy Framework |
| Microsoft Corporation (Clarity) | Session recording (masked), pseudonymous session ID | USA | Standard Contractual Clauses (SCCs) |
These tools are only activated after you accept analytics cookies.
Feature usage events (e.g. “tree generated”, “file uploaded”) are collected by PostHog, routed exclusively through our own server proxy. Event data does not leave our infrastructure and is not shared with PostHog’s cloud or any other third party. No cookies or local storage are set on your device for this purpose.
| Provider | Data shared | Location | Transfer mechanism |
|---|---|---|---|
| [Email provider — placeholder] | Recipient email, email content | [TBC] | [TBC — DPA required] |
| Provider | Data shared | Location | Transfer mechanism |
|---|---|---|---|
| [Hosting provider — placeholder] | All data stored on our servers | [TBC] | [TBC — DPA required] |
We do not share your personal data with any other third parties, unless required by law (for example, in response to a valid court order or request from a law enforcement authority). In such cases, we will notify you if legally permitted to do so.
Our primary service infrastructure is located in [country — placeholder]. Some of our service providers are located outside the European Economic Area (EEA) and UK, primarily in the United States. We ensure that transfers to these countries are protected by an appropriate mechanism:
| Destination | Mechanism |
|---|---|
| USA (Stripe, Google GA4) | EU-US Data Privacy Framework (DPF); UK-US Data Bridge |
| USA (Microsoft Clarity, Posterjack) | EU Standard Contractual Clauses (SCCs); UK International Data Transfer Agreement (IDTA) |
| Within Poland / EU (Fotako, internal servers, PostHog via own proxy) | No transfer outside EEA |
We keep your personal data only for as long as necessary for the purposes described in this policy or as required by law.
| Data category | Retention period |
|---|---|
| GEDCOM files | 12 months from your last login or activity, then deleted. Also deleted within 30 days of account deletion. May be deleted earlier on your request. |
| Rendered tree images (download files) | Available for re-download for 12 months after order. |
| Account data (email, name, preferences) | Until you delete your account, then within 30 days. |
| Order records (for accounting and tax purposes) | 5 years from the end of the tax year in which the order was placed (Polish law) / 6 years (UK law) |
| Shipping addresses | Retained as part of the order record (see above) |
| Security logs (IP, login events) | 90 days |
| Analytics data (GA4, Clarity) | Per provider: GA4 — 14 months; Clarity — 13 months |
| Feature event data (PostHog) | 12 months, then deleted from our server |
| Email marketing consent records | Until consent is withdrawn, then 3 years (evidence of consent) |
After the retention period, data is securely deleted or anonymised.
If you are in the EU or UK, you have the following rights under the GDPR/RODO and UK GDPR. Residents of other countries may have similar rights under local law (see Sections 15 and 16).
| Right | What it means |
|---|---|
| Access (Art. 15) | Request a copy of the personal data we hold about you |
| Rectification (Art. 16) | Ask us to correct inaccurate or incomplete data |
| Erasure (Art. 17) | Ask us to delete your data (“right to be forgotten”) — subject to legal retention obligations |
| Restriction (Art. 18) | Ask us to temporarily stop processing your data |
| Data portability (Art. 20) | Receive your data in a machine-readable format (where processing is based on consent or contract). Your uploaded GEDCOM file is available for direct download from your account at any time — no formal request needed. |
| Objection (Art. 21) | Object to processing based on our legitimate interests — we will stop unless we have compelling grounds |
| Withdraw consent (Art. 7(3)) | Withdraw any consent you have given (e.g. for analytics or marketing) at any time — this does not affect the lawfulness of prior processing |
| Not to be subject to automated decisions (Art. 22) | We do not make automated decisions with legal or similarly significant effects about you |
How to exercise your rights: Send an email to privacy@clancharts.com with “Data Rights Request” in the subject line. We will respond within 30 days of receiving your request. For complex or multiple requests, we may extend this period by a further 2 months, in which case we will notify you within the first 30 days and explain the reason for the extension. We may ask you to verify your identity before fulfilling the request.
If you are a living person whose name, date of birth, or other personal information appears in a GEDCOM file uploaded by another user (such as a family member), you have rights under the GDPR/RODO even though you did not interact with ClanCharts directly.
Why we were not able to notify you directly: Under Art. 14(5)(b) of the GDPR, there is an exception to the obligation to inform individuals when providing that information would involve a disproportionate effort. Given that GEDCOM files can contain hundreds or thousands of individuals whose contact details are not available to us, individually notifying each person is not practically possible. We are instead making this notice publicly available.
What you can do:
You may contact us at privacy@clancharts.com to:
To allow us to process your request, please provide sufficient information to identify yourself and the specific file or record concerned (for example, your full name, approximate date of birth, and the family name the tree belongs to).
How we handle deletion requests:
When we receive a valid deletion request from a third party, we will:
The user who uploaded the file is informed of this possibility before uploading and accepts it as a condition of using the service (see Terms of Service §5.2).
We use cookies and similar technologies. These fall into three categories:
These cookies are essential for the website to function. They do not require your consent.
| Cookie | Purpose | Duration |
|---|---|---|
| Session ID cookie | Keeps you logged in during a visit | Session |
| CSRF token | Security — prevents cross-site request forgery | Session |
| Cookie consent preference | Remembers your cookie choices | 12 months |
These cookies help us understand how visitors use the site. They are only set after you accept analytics cookies.
| Tool | What it collects | Duration |
|---|---|---|
| Google Analytics 4 | Page views, navigation, session duration | Up to 14 months |
| Microsoft Clarity | Session recordings (with PII masking), heatmaps | Up to 13 months |
PostHog does not set any cookies or use local storage. Feature event monitoring via PostHog is always active (no consent required) and operates entirely server-side. See Section 3.5 for details.
We do not currently use marketing or advertising cookies. If this changes, we will update this policy and request your consent before setting them.
You can change your cookie preferences at any time by clicking “Cookie Settings” in the footer of any page. You can also control cookies through your browser settings, though this may affect how the website functions.
ClanCharts is not directed at children. You must be at least 18 years old to create an account and make purchases. We do not knowingly collect personal data from individuals under 18 for the purpose of account registration.
GEDCOM files uploaded by adult users may contain data about children who are members of the user’s family. Such data is handled in the same way as all other data in the file (see Section 4), and is not used for any purpose beyond rendering the family tree visualisation requested by the adult user.
If you believe a minor’s data has been processed inappropriately, please contact us at privacy@clancharts.com.
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, accidental loss, or destruction. These measures include:
No system can guarantee absolute security. In the event of a data breach that is likely to result in high risk to individuals, we will notify the relevant supervisory authority within 72 hours and affected individuals without undue delay, as required by law.
This section applies if you are a resident of California, USA.
Under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), you have the right to:
We do not sell your personal information for monetary consideration. We do not share your personal information with third parties for cross-context behavioural advertising purposes. The statement “Do Not Sell or Share My Personal Information” is confirmed here as a permanent commitment.
| Category (CPRA) | Examples | Collected? | Sold/Shared? |
|---|---|---|---|
| Identifiers | Email, name, IP address | Yes | No |
| Personal information (Cal. Civil Code §1798.80) | Name, address, phone, payment reference | Yes | No (shared with fulfilment partners only) |
| Commercial information | Purchase history, order details | Yes | No |
| Internet/electronic network activity | Page views, click interactions (with consent) | Yes (with consent) | No |
| Geolocation data | Country (approximate, from IP) | Yes | No |
| Family tree content (GEDCOM) | Genealogical records | Yes | No |
Submit a request to privacy@clancharts.com with “California Privacy Request” in the subject line, or use our online request form at [URL placeholder]. We will respond within 45 days (extendable to 90 days with notice). We will verify your identity before fulfilling the request.
You may designate an authorised agent to make requests on your behalf by providing signed written permission. We may still require verification of your identity directly.
The CPRA defines “sensitive personal information” (SPI) as a specific subset of personal data. Family tree content (GEDCOM files) could potentially fall within SPI categories (e.g. racial or ethnic origin, health information). We do not use or disclose such information for the purpose of inferring characteristics about individuals, and we do not use SPI to target you with advertising. You therefore have the right to limit the use of your SPI under CPRA, and we commit to the minimum necessary use of any SPI categories.
California residents may also request information about disclosure of personal data to third parties for direct marketing purposes under California Civil Code § 1798.83. We do not disclose personal data to third parties for their direct marketing purposes.
This section applies if you are located in the United Kingdom.
Our processing of personal data of UK residents is governed by UK GDPR and the Data Protection Act 2018. The lawful bases, rights, and protections described elsewhere in this policy apply equally under UK GDPR.
UK Representative: In accordance with Art. 27 UK GDPR, we have designated the following entity as our UK Representative, which can be contacted by UK residents and by the ICO on matters relating to this Privacy Policy and the processing of UK residents’ personal data:
Magowie LTD
71-75 Shelton Street, Covent Garden
London, WC2H 9JQ
United Kingdom
For data protection enquiries from UK residents, you may contact our UK Representative at the address above, or contact us directly at privacy@clancharts.com.
UK supervisory authority: You have the right to lodge a complaint with the Information Commissioner’s Office (ICO):
ICO
Wycliffe House
Water Lane
Wilmslow
Cheshire SK9 5AF
Tel: 0303 123 1113
Website: ico.org.uk
ICO registration: Magowie LTD is registered with the ICO. Registration number: [ICO REGISTRATION NUMBER — to be completed after registration].
International transfers from the UK: Transfers of your data outside the UK are covered by UK adequacy regulations (for EEA countries) or UK International Data Transfer Agreements (IDTA) / addenda to EU SCCs (for other countries, including the USA via the UK-US Data Bridge).
If you are located in Canada, your personal data is processed in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy legislation. The principles of PIPEDA — accountability, identifying purpose, consent, limiting collection, limiting use, safeguards, openness, individual access, and challenging compliance — are reflected in this policy.
You may submit privacy complaints or enquiries to:
Office of the Privacy Commissioner of Canada (OPC)
30 Victoria Street, Gatineau, Quebec K1A 1H3
Tel: 1-800-282-1376
Website: priv.gc.ca
If you are located in Australia, your personal data is processed in accordance with the Australian Privacy Act 1988 and the Australian Privacy Principles (APPs). You may submit a complaint to:
Office of the Australian Information Commissioner (OAIC)
Website: oaic.gov.au
Email: enquiries@oaic.gov.au
If you have a concern about how we handle your personal data, we encourage you to contact us first at privacy@clancharts.com. We will try to resolve your concern promptly.
You also have the right to lodge a complaint with a supervisory authority:
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by:
The updated policy will be effective from the date shown at the top of this document. We encourage you to review this policy periodically.
For any questions, requests, or concerns about this Privacy Policy or your personal data:
Email: privacy@clancharts.com
Postal address:
ADONE SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ
DRUŻYKOWA 15
42-445 DRUŻYKOWA, Poland
NIP: 6492320014, KRS: 0000862178
We aim to respond to all enquiries within 5 business days and to fulfil data rights requests within 30 days (or 45 days for California residents).
This Privacy Policy was drafted based on the requirements of EU Regulation 2016/679 (GDPR/RODO), UK GDPR and Data Protection Act 2018, and the California Consumer Privacy Act (CCPA/CPRA). It is provided for informational purposes. For legal advice specific to your situation, consult a qualified data protection solicitor or attorney.