Select Page

Privacy

**PRIVACY POLICY**
**One-File Prompt Builder Secret**
**Website:** https://onefileprompts.com/

**Effective Date:** August 20, 2026
**Last Updated:** August 20, 2026

This Privacy Policy describes how C.A. Staffel / CAS Designs Networks (“we,” “us,” or “our”), operating the website https://onefileprompts.com/ (the “Site”) and related digital product offerings, including the digital report “One-File Prompt Builder Secret” (collectively, the “Services”), collects, uses, discloses, and protects personal information.

By accessing or using the Site or purchasing our digital products, you acknowledge that you have read, understood, and agree to the practices described in this Privacy Policy. If you do not agree, please do not use the Site or Services.

We are committed to transparency and compliance with applicable privacy laws, including the California Consumer Privacy Act (CCPA/CPRA), the General Data Protection Regulation (GDPR) where applicable to EU/EEA/UK users, and other relevant U.S. state and federal laws.

### 1. Categories of Personal Information We Collect

We collect limited personal information in connection with the Site and digital product sales. Categories include:

– **Identifiers**: Name, email address, billing/shipping address (if provided), IP address, and unique device or browser identifiers.
– **Commercial Information**: Purchase history, order details, payment status, and product access information related to the digital report.
– **Internet or Other Electronic Network Activity**: Browser type and version, device type, operating system, referring/exit pages, pages viewed, time spent on pages, clickstream data, and interaction with the Site.
– **Geolocation Data**: Approximate location derived from IP address (city/region/country level).
– **Inferences**: Limited inferences drawn from the above for service improvement or fraud prevention (we do not create detailed consumer profiles for advertising).

We do **not** intentionally collect sensitive personal information (e.g., precise geolocation, biometric data, health data, Social Security numbers, or financial account numbers beyond what is processed transiently by our payment processor). Payment card details are collected and processed exclusively by Stripe and are never stored on our systems.

We do not knowingly collect personal information from children under 16 (or under 13 in certain jurisdictions). If we become aware of such collection, we will delete it promptly.

### 2. Sources of Personal Information

– Directly from you (e.g., when you complete a purchase, contact us, or submit a form).
– Automatically through cookies, pixels, and similar technologies when you visit the Site.
– From third-party service providers (e.g., Stripe for payment processing and transaction confirmation; analytics providers if used).

### 3. Legal Bases for Processing (GDPR and Similar Laws)

Where the GDPR or equivalent laws apply, we process personal information on the following legal bases:

– **Performance of a contract**: To process purchases, deliver the digital product, provide access, and fulfill related obligations.
– **Legitimate interests**: To operate and improve the Site, prevent fraud/abuse, ensure security, respond to inquiries, and analyze usage in a non-intrusive manner.
– **Consent**: For non-essential cookies, marketing communications (if any), or other processing where required. You may withdraw consent at any time.
– **Legal obligation**: To comply with applicable laws, tax requirements, or lawful requests from authorities.

### 4. How We Use Personal Information

We use personal information to:
– Process and fulfill orders for the digital report.
– Deliver product access (typically via email or download link).
– Respond to customer service inquiries.
– Operate, maintain, and improve the Site and Services.
– Detect, prevent, and address fraud, security issues, or technical problems.
– Comply with legal obligations.
– Send transactional emails related to your purchase (these are not marketing).

We do not sell personal information. We do not use personal information for targeted advertising or cross-context behavioral advertising in a manner that constitutes a “sale” or “sharing” under CCPA/CPRA.

### 5. Cookies and Similar Technologies

The Site may use cookies, local storage, pixels, and similar technologies.

– **Essential/Strictly Necessary Cookies**: Required for basic Site functionality, security, and purchase processing. These do not require consent in most jurisdictions.
– **Analytics/Performance Cookies** (if used): To understand how visitors interact with the Site (e.g., page views, traffic sources). We aim to use privacy-respecting tools and limit data retention.
– **Marketing/Advertising Cookies**: We do not currently use third-party advertising cookies for behavioral targeting.

You can control cookies through your browser settings. Disabling certain cookies may affect Site functionality. For more information on managing cookies, consult your browser’s help documentation.

### 6. Third-Party Sharing and Disclosure

We share personal information only as necessary and with the following categories of recipients:

– **Payment Processors**: Stripe processes payments. Stripe’s privacy practices are governed by its own privacy policy (available at stripe.com/privacy). We receive limited transaction confirmation data.
– **Service Providers / Processors**: Hosting providers, email delivery services, and analytics tools that assist in operating the Site under contractual obligations to protect data and use it only for specified purposes.
– **Legal and Safety**: When required by law, court order, or governmental request; to protect our rights, property, or safety, or that of users or the public; or in connection with a merger, acquisition, or asset sale (with notice where required).

We do not sell or rent personal information to third parties for their marketing purposes. We require service providers to implement appropriate safeguards.

### 7. International Data Transfers

The Site is operated from the United States. If you access the Site from outside the United States (including the European Economic Area, United Kingdom, or other regions with data protection laws), your information may be transferred to, stored, and processed in the United States or other countries that may have different data protection standards.

Where required (e.g., under GDPR), we rely on appropriate safeguards such as Standard Contractual Clauses (SCCs) approved by the European Commission, adequacy decisions, or other lawful transfer mechanisms. By using the Services, you acknowledge these transfers.

### 8. Data Retention

We retain personal information only as long as necessary for the purposes described in this Policy, including:
– Transaction and order records: generally for the period required by tax, accounting, or legal obligations (typically 3–7 years, depending on jurisdiction).
– Customer service communications: for a reasonable period to resolve inquiries and improve service.
– Website logs and analytics data: typically 12–24 months, or shorter where feasible.
– Marketing consent records (if any): until consent is withdrawn plus a short period for evidentiary purposes.

When retention is no longer necessary, we securely delete or anonymize the data.

### 9. Security Measures

We implement reasonable administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, loss, misuse, alteration, or destruction. These include encryption in transit (HTTPS), access controls, and secure payment processing via Stripe.

No method of transmission over the Internet or electronic storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security. You are responsible for maintaining the confidentiality of any access credentials or download links provided to you.

### 10. Data Breach Notification

In the event of a security incident involving personal information that poses a risk of harm, we will investigate promptly and, where required by applicable law (including GDPR and certain U.S. state laws), notify affected individuals and relevant supervisory authorities without undue delay, and in any event within the timeframes mandated by law. Notifications will include available details about the nature of the incident, data involved, and recommended steps.

### 11. Your Rights

Depending on your location, you may have the following rights:

**Under CCPA/CPRA (California residents and certain other U.S. states):**
– Right to know/access the categories and specific pieces of personal information collected.
– Right to delete personal information (subject to exceptions).
– Right to correct inaccurate personal information.
– Right to opt-out of the “sale” or “sharing” of personal information (we do not sell or share for cross-context behavioral advertising).
– Right to limit use of sensitive personal information (we do not collect sensitive PI for such purposes).
– Right to non-discrimination for exercising privacy rights.

**Under GDPR (EU/EEA/UK residents):**
– Right of access, rectification, erasure (“right to be forgotten”), restriction of processing, data portability, and objection to processing.
– Right to withdraw consent at any time.
– Right to lodge a complaint with a supervisory authority.

To exercise these rights, contact us using the details in Section 13. We will verify your identity as required by law and respond within the applicable statutory timeframe (generally 45 days under CCPA, or one month under GDPR, subject to extensions). Authorized agents may submit requests on behalf of California residents with proper documentation.

### 12. Children’s Privacy

The Services are not directed to individuals under the age of 16 (or 13 where applicable). We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us so we can delete it.

### 13. Contact Information

For questions, requests regarding this Privacy Policy, or to exercise your privacy rights, contact us at:

**Email:** carlstaff@icloud.com
**Postal Address:**
C.A. Staffel
5 Hillcrest Court
Trophy Club, Texas 76262
United States

We will respond to legitimate requests in accordance with applicable law.

### 14. Severability

If any provision of this Privacy Policy is held to be invalid, illegal, or unenforceable by a court of competent jurisdiction, such provision shall be modified to the minimum extent necessary to make it valid and enforceable, or if modification is not possible, severed. The remaining provisions shall continue in full force and effect.

### 15. Governing Law and Jurisdiction

This Privacy Policy shall be governed by and construed in accordance with the laws of the State of Texas, United States, without regard to its conflict of laws principles. Any disputes arising out of or relating to this Privacy Policy or the Services shall be resolved exclusively in the state or federal courts located in Tarrant County or Denton County, Texas, and you consent to the personal jurisdiction of such courts.

For users in the European Economic Area or United Kingdom, nothing in this section limits mandatory consumer protection rights under applicable local law.

### 16. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. The “Last Updated” date at the top will indicate the most recent revision. Material changes will be posted on this page, and where required by law, we will provide additional notice (e.g., via email or a prominent Site notice).

Your continued use of the Site or Services after the effective date of any updated Policy constitutes acceptance of the changes. We encourage you to review this Policy periodically.

### 17. Revision History

– **August 20, 2026**: Initial Privacy Policy published (Effective Date).

—