Last Updated: 12-Jul-2026
Effective Date: 12-Jul-2026
Privacy Policy
1. Introduction and Scope
This Privacy Policy ("Policy") is provided by Don Nguyen, operating as "Widget-Hub" ("Company," "we," "our," or "us"), and governs the collection, use, disclosure, and protection of personal data and information in relation to your access and use of our website, web applications, and services (collectively, the "Service").
This Policy applies to all users, visitors, and individuals who interact with our Services, regardless of how they access them (web browser, mobile device, API, etc.). By accessing or using our Service, you acknowledge that you have read, understood, and agree to be bound by the terms of this Privacy Policy. If you do not agree with any part of this Policy, you should discontinue use of our Service immediately.
This Policy complies with applicable data protection regulations, including but not limited to the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and other relevant privacy laws.
2. Information We Collect
2.1 Information We Do NOT Actively Collect
Our web applications are designed with privacy-first architecture and run primarily in your browser. We have implemented technical and organizational measures to minimize data collection:
- We do not request or collect personal information such as your name, email address, postal address, telephone number, date of birth, or other personally identifiable information (PII)
- We do not store any user-generated content or personal data on our servers
- We do not use tracking cookies designed to identify individuals across sessions or across websites
- We do not employ user-tracking analytics that collect personally identifiable behavior patterns
- We do not require user registration or authentication to access most of our Services
- We do not collect payment information directly (if payments are required, they are processed through secure third-party payment processors)
2.2 Automatically Collected Information (Server Logs)
When you access our website, your browser automatically transmits certain technical information. Because our applications run on Cloudflare Workers (a third-party infrastructure provider), we do not directly collect, store, or maintain server logs ourselves. Instead, Cloudflare may automatically collect technical metadata as part of their platform operations, including:
- IP Address: Your Internet Protocol (IP) address
- Request Metadata: Information about your HTTP request, including the URL accessed, time of access, HTTP method, and response status code
- User-Agent String: Information about your browser type, version, and operating system
- Referrer Information: The webpage from which you accessed our Service
- Approximate Geolocation: General geographic location derived from your IP address (country/region level, not precise coordinates)
Important: We do not actively retain or manage server logs on our infrastructure. Any logging that occurs is handled by Cloudflare as part of their third-party infrastructure services. The retention, processing, and security of such data is governed by Cloudflare's privacy practices and terms of service, not by us. For details on what Cloudflare may collect and how they handle data, please consult their Privacy Policy at https://www.cloudflare.com/privacy/
2.3 Client-Side Local Storage
Some of our applications utilize your browser's client-side storage mechanisms to enhance user experience:
- Browser Local Storage: We may store user preferences, application settings, and application state data in your browser's localStorage API
- Browser Cookies: Functional cookies may be used for session management and preference persistence
- IndexedDB/Web Storage: Client-side databases may be used for caching and performance optimization
Critically, this locally-stored data:
- Remains entirely on your device and is never transmitted to our servers (unless you explicitly export/sync data)
- Is inaccessible to us unless you manually export or share it
- Can be cleared at any time through your browser settings, developer tools, or by clearing your browsing data
- Is not shared with third parties
- Persists only until you clear it or until the configured expiration time (set to your browser's defaults or application-specific durations)
2.4 Information You Voluntarily Provide
In certain scenarios, you may voluntarily provide information to us:
- Contact Forms: If you complete a contact form or send us an email, we receive any information you include in your message
- Support Requests: Information provided when requesting technical support or reporting issues
- Feedback and Surveys: Voluntary participation in user surveys or feedback submissions
- User-Generated Content: Any text, files, or data you create or upload within our applications
This information is collected only when you voluntarily submit it and is used solely for the purposes stated at the time of collection.
3. How We Use Your Information
We use the information we collect for the following legitimate purposes:
- Service Delivery: To provide, maintain, and improve our Services
- Security and Fraud Prevention: To detect, prevent, and address fraudulent activity, security incidents, and technical problems
- Legal Compliance: To comply with applicable laws, regulations, legal processes, and governmental requests
- Performance Monitoring: To monitor and analyze website performance, usage patterns, and user engagement (in aggregate, non-identifying form)
- User Support: To respond to your inquiries and provide customer support
- Service Improvement: To identify areas for improvement and develop new features and services
- Marketing (if applicable): To send you updates about our Services, only if you have explicitly opted in
We do not use your information for purposes incompatible with those stated in this Policy without obtaining your prior explicit consent.
4. Third-Party Service Providers and Data Sharing
Our Service integrates with third-party services. Your interaction with these services is governed by their respective privacy policies:
4.1 Content Delivery and Hosting
- Cloudflare: Provides Content Delivery Network (CDN), DDoS protection, and web security services. When you access our website, your request may be routed through Cloudflare's infrastructure, including Cloudflare Workers (a serverless computing platform). We use Cloudflare Workers to deploy our applications and handle edge computing tasks. Cloudflare is a third-party service provider and may collect and process certain technical data (such as IP addresses, request headers, and usage metadata) as part of their platform operations. The collection and retention of such data by Cloudflare is governed by their own privacy practices and infrastructure, not directly by us. We do not actively control or retain these logs on our own servers. Please review Cloudflare's Privacy Policy at https://www.cloudflare.com/privacy/ and their specific data retention practices for Workers at https://developers.cloudflare.com/workers/
4.2 Advertising Networks
- Google AdSense: If we display advertisements through Google AdSense, Google may collect and use data about your browsing activity for ad personalization. This includes the use of cookies and similar tracking technologies. Google's use of data is subject to the Google Ads Privacy Policy (https://policies.google.com/privacy) and their ad technology providers' policies. You can opt out of personalized advertising through Google's Ads Settings (https://adssettings.google.com/)
4.3 Third-Party APIs and Services
- Our applications may utilize third-party APIs to provide certain functionality. Data transmitted to these services is governed by their respective privacy policies. We recommend reviewing these policies before using features that rely on third-party services
4.4 Analytics and Performance Monitoring
- We may use privacy-respecting analytics tools that do not personally identify users. Any analytics data collected is aggregated and anonymized
4.5 Payment Processing
- If our Services require payment, we do not directly collect payment information. Payment processing is handled exclusively by certified third-party payment processors (e.g., Stripe, PayPal). These processors are PCI DSS compliant and their data practices are governed by their respective privacy policies
4.6 Legal Disclosures
Notwithstanding any other provision in this Policy, we may disclose your information when required by law, court order, or legal process, or when we reasonably believe disclosure is necessary to:
- Comply with applicable laws, regulations, or legal obligations
- Enforce our Terms of Service and other agreements
- Protect the safety, rights, or property of our company, users, or the public
- Detect, prevent, or address fraudulent activity or security incidents
- Respond to claims of illegal activity
5. Data Retention
We retain information for the minimum period necessary to fulfill the purposes for which it was collected:
- Server Logs: We do not directly retain or manage server logs on our own infrastructure. Any technical data collected through Cloudflare's infrastructure is subject to Cloudflare's retention policies. For information on Cloudflare's data retention practices, please see their Privacy Policy at https://www.cloudflare.com/privacy/
- Contact Information: Retained until you request deletion or for as long as necessary to respond to your inquiry
- Local Storage Data: Retained on your device indefinitely until you manually clear it
- User-Generated Content: Retained as long as your account is active, or as directed by you
When data is no longer needed and is within our control, we securely delete or anonymize it to prevent unauthorized access or recovery.
6. Data Security
We implement comprehensive technical and organizational security measures to protect your information against unauthorized access, alteration, disclosure, or destruction:
- HTTPS Encryption: All data transmitted between your browser and our servers is encrypted using TLS/SSL protocols
- Server Security: Our web servers are secured with firewalls, intrusion detection systems, and regular security patching
- DDoS Protection: Our infrastructure is protected against distributed denial-of-service (DDoS) attacks
However, no security measure is completely foolproof. While we strive to protect your information, we cannot guarantee absolute security against all possible threats. You use our Service at your own risk. We encourage you to use strong passwords and practice good cybersecurity hygiene.
7. Your Privacy Rights and Choices
7.1 Right to Access and Portability (GDPR & CCPA)
You have the right to request access to the personal data we hold about you, in a portable and machine-readable format. Since we do not actively collect personal data, this right has limited application. However, if we hold any information about you, you may request it by contacting us.
7.2 Right to Rectification (GDPR)
You have the right to request correction of inaccurate data held about you.
7.3 Right to Erasure ("Right to be Forgotten") (GDPR & CCPA)
You have the right to request deletion of personal data we hold about you, subject to certain exceptions (such as where data is necessary for legal compliance or fraud prevention).
7.4 Right to Restrict Processing (GDPR)
You have the right to request that we limit the processing of your data while we investigate your requests or when processing is no longer necessary.
7.5 Right to Opt-Out (CCPA & GDPR)
You have the right to opt-out of certain data processing activities, including targeted advertising and sales of personal information (we do not sell data, so this right is largely inapplicable).
7.6 Cookie and Tracking Preferences
- You can disable cookies in your browser settings
- You can clear local storage through your browser's settings or developer tools
- You can opt-out of personalized ads through Google Ads Settings
- You can use "Do Not Track" (DNT) signals, though we note that not all services honor this signal
7.7 Marketing Communications
If you receive marketing communications from us and wish to unsubscribe, you can do so by clicking the unsubscribe link in the email or by contacting us directly.
8. Children's Privacy
Our Services are not intended for children under the age of 13 (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect personal information from children. If we become aware that a child has provided us with personal information, we will take steps to delete such information and terminate the child's access to our Services. If you are aware that a child has provided us with information, please contact us immediately.
9. International Data Transfers
Our servers may be located in various jurisdictions. If you are located outside the jurisdiction where our servers operate, by using our Service, you consent to the transfer of your information to countries that may have different data protection laws than your home country. We implement appropriate safeguards for such transfers, including Standard Contractual Clauses (SCCs) as required by applicable law.
10. Data Protection Impact Assessment
Due to our privacy-first architecture (minimal data collection, no tracking), a full Data Protection Impact Assessment (DPIA) is not required. However, we remain vigilant and will conduct a DPIA if we introduce new services that pose elevated privacy risks.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of any material changes by posting the revised Privacy Policy on this page and updating the "Last Updated" date. If the changes are significant, we will provide additional notice (e.g., via email or a prominent notification on our website). Your continued use of our Service after changes become effective constitutes your acceptance of the updated Policy. We encourage you to review this Policy periodically to stay informed about how we protect your information.
12. Dispute Resolution and Governing Law
This Privacy Policy is governed by the laws of the jurisdiction where we operate, without regard to conflicts of law principles. For users subject to GDPR, disputes regarding data protection may be escalated to the relevant Data Protection Authority in your jurisdiction. For CCPA-related disputes, you have the right to lodge a complaint with the California Attorney General.
13. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy, our data practices, or wish to exercise your privacy rights, please contact us at the email provided below, or by using the "contact" page on the bottom of the site and subsites:
Email: Don_Nguyen11@proton.meWe will respond to your request as soon as possible, or as required by applicable law.
14. Accessibility
We are committed to ensuring this Privacy Policy is accessible to all individuals, including those with disabilities. If you experience difficulty accessing this policy, please contact us, and we will provide the information in an alternative format.
15. Limitation of Liability and Damages Waiver
By using our Services, you agree that we are not liable for any damages, losses, or injuries arising from your use of our Services. This limitation applies to all forms of damages, whether direct, indirect, incidental, special, consequential, or punitive, including but not limited to:
- Loss of data, files, or information
- Loss of business, revenue, or profits
- Loss of time or opportunity
- Damage to devices, hardware, or software
- Any other economic loss or damage
- Personal injury or harm
- Emotional distress or psychological harm
- Third-party claims against you
You use our Services "as is" and at your own risk. We make no warranties or representations regarding the accuracy, functionality, availability, or non-infringement of our Services. We shall not be held responsible for:
- Service interruptions, downtime, or unavailability
- Data loss or corruption
- Unauthorized access or security breaches (to the extent not resulting from our gross negligence)
- Malware, viruses, or other malicious code
- Misuse of our Services by third parties
- Your misuse or misunderstanding of our Services
- Third-party content or links accessed through our Services
Indemnification: You agree to indemnify, defend, and hold harmless Don Nguyen (operating as Widget-Hub), its officers, directors, employees, relatives, and agents from any and all claims, damages, liabilities, costs, and expenses (including reasonable attorney's fees) arising from or related to your use of the Services, your violation of this Policy, or your violation of any applicable laws or regulations.
This limitation of liability applies to the maximum extent permitted by applicable law. Some jurisdictions do not allow the exclusion or limitation of certain damages, so this provision may not fully apply to you depending on your location. However, to the greatest extent allowed by your local laws, you agree to limit your recourse against us to the amount you paid to use our Services (if any).
16. Acknowledgment
By using our Services, you acknowledge that you have read, understood, and agree to the terms of this Privacy Policy, including the Limitation of Liability section. If you do not agree with any aspect of this policy, you should discontinue use of our Services immediately.