BookAuth

Privacy Policy

Last updated: June 15, 2026

Version 2.0

1. Introduction

BookAuth ("BookAuth," "we," "our," or "us") is a product of Vuxtra LLC, a Florida, U.S.A. company, and operates a platform at bookauth.com (and related subdomains and author sites) connecting authors, readers, publishing professionals, and newsletter subscribers (collectively, the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard personal information when you use our Service.

This Privacy Policy applies to all of our services, including: the book-selling marketplace, Advance Reader Copy (ARC) campaigns, author websites, reader reviews and reputation, book clubs, the professional services marketplace, the newsletter sending service, our aggregated book/author information hub, and any AI-assisted features.

Controller and processor roles. BookAuth is the controller of the personal information we collect directly from you to operate the platform. Where you are an author or professional who collects your own readers' or clients' data through our tools (for example, newsletter subscribers or buyer shipping addresses), you are the controller of that data and BookAuth acts as your processor under our Data Processing Addendum.

By using the Service, you agree to the collection and use of information described here. If you do not agree, do not use the Service. This policy is incorporated into our Terms of Service and applicable service agreements.

Not legal advice. This Privacy Policy describes our practices; it is not legal advice. Capitalized terms not defined here have the meanings given in our Terms of Service.

2. Information We Collect

2.1 Information You Provide

  • Account Information: Name, email address, password (hashed), username/slug, and profile information when you create an account.
  • Author / Professional Profile Data: Biography, social media and retailer links, genres, profile photos, portfolio samples, professional credentials, and identity-verification information (which may include government ID details collected by our identity provider).
  • Book & Content Information: Book titles, descriptions, cover images, manuscripts and uploaded files (EPUB/PDF/MOBI), pricing, and publication details.
  • Buyer & Shipping Information: When you buy a physical product, your shipping name, address, phone, and order details are collected to fulfill the order. Shipping address data is encrypted at rest and is shared with the selling author solely for fulfillment.
  • Payment Information: Payment details are handled by our payment processor, Stripe. We do not store full card numbers on our servers; we store limited transaction references (e.g., charge/payment-intent identifiers).
  • Communications & User Content: Messages, reviews, book-club posts, support requests, and other content you submit.
  • Newsletter Subscribers: When you subscribe to an author's newsletter, the email address (and any data the author asks you to provide) is collected on the author's behalf. The author is the controller of their subscriber list; BookAuth processes it for them.

2.2 Information Collected Automatically

  • Usage Data: Pages visited, features used, interactions, search queries, and reading progress.
  • Device & Technical Information: Browser type, operating system, device type, screen size, and IP address.
  • Cookies and Similar Technologies: Used to maintain sessions, remember preferences, and analyze usage. See our Cookie Policy for details.

2.3 Information From Other Sources

Our public book and author discovery hub enriches listings using publicly available data from third-party sources (for example, open book metadata, news, video, and knowledge-base providers, and public web sources via our data partners). We use this information to improve discovery and display useful summaries. If you are an author whose public information appears in the hub, you may request removal of certain aggregated data as described in Section 5.

3. How We Use Your Information & Legal Bases

We process personal information for the following purposes:

  • Providing the Service (accounts, books, orders, payouts, websites, ARC, newsletters, marketplace) — contractual necessity.
  • Processing transactions and sending related receipts and confirmations — contractual necessity.
  • Fraud prevention and security, including automated fraud scoring on purchases (see Section 9) — our legitimate interests and legal obligations.
  • Communications, including transactional messages, support replies, and (with your consent) marketing — contract, legitimate interests, and your consent.
  • Improving and analyzing the Service, debugging, and product development — our legitimate interests.
  • Complying with legal obligations, including tax, sanctions (OFAC), recordkeeping, and law-enforcement responses — legal obligation.
  • AI-assisted features (e.g., review insights, content suggestions) operate on your inputs and content. We do not use your content to train foundational AI models. See our AI Features Terms.

Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.

4. Information Sharing and Disclosure

4.1 Public Information

Author and professional profiles, book listings, reviews, book-club posts, and reputation indicators are visible to other users and, where applicable, the public.

4.2 Between Users

When you buy a physical product, your shipping information is shared with the selling author for fulfillment. When an author sends a newsletter, subscriber email addresses are processed on the author's behalf. In the professional marketplace, project briefs, files, and messages are shared between the author and the professional they engage.

4.3 Service Providers & Sub-Processors

We share personal information with third-party service providers who perform services on our behalf. Our current categories and representative providers include:

  • Payments: Stripe (payment processing, Connect payouts, sales-tax calculation).
  • Authentication & Identity: WorkOS (authentication).
  • Email & Newsletters: our self-hosted email platform and delivery providers (transactional and newsletter email).
  • Cloud Hosting & Infrastructure: our cloud hosting, database, cache, search, and analytics providers.
  • Shipping & Print: our shipping carrier and label providers (for rates and shipping labels) and print-on-demand providers.
  • Data Enrichment: book/author information sources used by the discovery hub.
  • AI Providers: third-party AI model providers used for AI-assisted features.

An up-to-date list of sub-processors is maintained in our Data Processing Addendum. These providers process data on our instructions under written agreements that require confidentiality and appropriate safeguards.

4.4 Legal Requirements

We may disclose information if required by law or in response to valid legal requests (subpoenas, court orders, government regulations), to enforce our agreements, to protect rights or safety, or to investigate and prevent fraud, security issues, or violations of law or our policies.

4.5 Business Transfers

In connection with a merger, acquisition, financing, reorganization, or sale of all or part of our assets, your information may be transferred as an asset of the business, subject to the confidentiality and other commitments of this policy.

5. Your Privacy Rights

Depending on where you live, you may have some or all of the following rights. You can exercise most rights through your account settings or by contacting [email protected]. We will verify your identity before acting on a request.

5.1 General Rights

  • Access & portability: request a copy of your personal data and receive it in a portable format.
  • Correction: update or correct inaccurate information.
  • Deletion: request deletion of your account and associated data. Some data may be retained for legal, accounting, or security purposes.
  • Restriction / objection: ask us to limit processing or object to processing based on legitimate interests.
  • Withdraw consent: withdraw consent for processing we carry out on the basis of consent.
  • Marketing opt-out: unsubscribe from marketing emails using the link in any email or your account settings. Transactional messages may still be sent.

5.2 California Privacy Rights (CCPA / CPRA)

If you are a California resident, the California Consumer Privacy Act as amended by the California Privacy Rights Act gives you additional rights:

  • Know: the categories and specific pieces of personal information we collect, the sources, purposes, and categories of third parties to which we disclose it.
  • Delete: your personal information (subject to exceptions).
  • Correct: inaccurate personal information.
  • Sensitive personal information: request that we limit the use of your sensitive personal information to what is necessary to provide the Service.
  • Opt out of "sale" or "sharing": BookAuth does not sell personal information. "Sharing" under California law can include making personal information available to third parties for cross-context behavioral advertising. If we begin any such practice, we will provide a clear "Do Not Sell or Share My Personal Information" link and honor opt-out requests.
  • Non-discrimination: we will not discriminate against you for exercising your rights.

Authorized agents may submit requests on your behalf with proof of authorization. We verify requests as permitted by law.

5.3 U.S. State Privacy Rights

Residents of other U.S. states with comprehensive privacy laws (such as Virginia, Colorado, Connecticut, Utah, and others) may have comparable rights of access, correction, deletion, opt-out of certain processing, and appeal. To the extent those laws apply, the rights above apply to you. Submit requests to [email protected].

5.4 European, UK & Swiss Rights (GDPR / UK GDPR)

If you are in the European Economic Area, the United Kingdom, or Switzerland, you have the rights listed in Section 5.1, plus the right to lodge a complaint with your local data-protection authority. We process personal data on the legal bases set out in Section 3. To the extent we rely on legitimate interests, you may object to that processing. Our representative contact and lawful-basis details are in Section 10.

5.5 Canada Anti-Spam & PIPEDA

Canadian users receive commercial electronic messages only with express or implied consent under Canada's Anti-Spam Legislation (CASL) and may unsubscribe at any time. Personal information is handled in accordance with PIPEDA.

6. Data Retention

We retain personal information only as long as necessary:

  • Active accounts: for the life of the account, plus any applicable cooling-off period.
  • Transaction & financial records: typically 7 years to meet tax, accounting, and recordkeeping obligations.
  • Newsletters & subscriber data: retained for as long as the subscriber remains subscribed (controller = author) and then per the author's instructions and legal obligations.
  • Usage & log data: generally retained for up to 13 months, except where longer retention is required for security or legal reasons.
  • Published content: books, reviews, and public posts may remain after account deletion, with personally identifying information removed or anonymized where appropriate.

When data is no longer needed, we delete it or anonymize it so it can no longer be associated with you.

7. Data Security

We use appropriate technical, administrative, and physical safeguards designed to protect personal information, including encryption in transit (HTTPS/TLS) and at rest, access controls, secure authentication, encryption of buyer shipping addresses, network policies, and regular security assessments. Despite these measures, no system is 100% secure, and we cannot guarantee absolute security.

Breach notification. In the event of a personal-data breach affecting your rights, we will notify affected users and, where required (including under GDPR within 72 hours to controllers and/or regulators as applicable), the relevant supervisory authorities, and take reasonable steps to mitigate harm.

8. International Data Transfers

BookAuth is based in the United States and your information may be transferred to and processed in the U.S. and other countries where we or our service providers operate. Where we transfer personal data from the EEA, UK, or Switzerland to a country that has not received an adequacy decision, we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses (SCCs), the UK International Data Transfer Addendum/Agreement, or another valid transfer mechanism, and complete transfer-impact assessments where required.

9. Automated Decision-Making & Fraud Scoring

We use automated processing to help operate and protect the Service. For example, we automatically score purchases for fraud risk and may automatically block, hold, or flag high-risk transactions. These automated decisions help prevent fraud and abuse and are based on legitimate interests; they may affect whether an order is accepted. If an automated decision produces legal or similarly significant effects concerning you (for example, blocking your funds or account), you have the right to request human review by contacting [email protected].

10. Controller Details & How to Contact Us

The operator of the Service and the controller of your personal data is BookAuth, a product of Vuxtra LLC, a Florida, U.S.A. company, with a principal place of business in Royal Palm Beach, Florida. For privacy questions or to exercise your rights, contact us:

Email: [email protected]

Legal: [email protected]

Data Protection Officer / privacy inquiries: [email protected]

EU/UK representative: where required by GDPR Article 27, BookAuth designates a representative in the EU/UK for data-protection matters. The current representative's contact details are available on request to [email protected] and will be provided directly to EU/UK data subjects upon request.

11. Children's Privacy

The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13 in compliance with the Children's Online Privacy Protection Act (COPPA). If we learn we have collected such information, we will delete it. Use of the selling and professional marketplace features, and the sending of payments, is limited to users 18 and older; users aged 13–17 may use age-appropriate features with parental or guardian consent. If you believe a child has provided us personal information, contact [email protected].

12. Cookies and Tracking Technologies

We use cookies and similar technologies to operate the Service, keep you signed in, remember preferences, measure performance, and (where used) improve our services. Full details — including categories, purposes, retention, and how to manage or disable cookies — are in our Cookie Policy.

Where we use non-essential cookies or trackers that require consent under applicable law (e.g., EU ePrivacy, certain U.S. state laws), we obtain your consent before setting them. You can withdraw consent at any time.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will post the updated policy on this page and revise the "Last updated" date. For material changes, we will also provide notice through the Service or by email where appropriate. Your continued use of the Service after changes take effect constitutes acceptance of the updated policy.

14. Related Documents