Privacy Policy
firsthorseman.world · The First Horseman Multi-Language Digital Reader
Last updated: June 2, 2026
1. Who we are
This website is operated by ZXQS, Inc. ("we", "us", "our"), 2929 Vista Blvd. Box 50342, Sparks, NV 89435, United States, on behalf of the author Kelly Smith. ZXQS, Inc. is the data controller for personal data collected through firsthorseman.world.
For privacy questions, contact us at:
2. What we collect
We try to collect as little as possible. Specifically:
- Account data: the email address you used at checkout, and optionally a display name.
- Purchase data: we receive a notification from our payment processor (HighLevel, with Stripe or PayPal for card processing) confirming that you bought access. We do not store your card number, billing address, or payment details on our servers.
- Reading activity: which chapter you opened, in which language, and when. This is logged for two reasons: to remember where you left off, and to detect automated scraping or copying of the book.
- Technical data: your IP address and browser user-agent string are recorded against each chapter view for the same anti-piracy purpose.
- Terms acceptance: the date and version of the terms you accepted.
- Translation feedback: if you submit feedback, we keep the text you sent along with the chapter and language it concerned.
We do not use Google Analytics, Meta Pixel, advertising trackers, third-party fingerprinting, or any cross-site tracking technology.
3. Why we use it (legal basis)
- Performance of a contract — to give you the access you paid for, remember your last chapter, and let you sign in.
- Legitimate interest — to protect the author's copyright against automated scraping, mass downloading, and account sharing. This is why we keep the reading-activity log and rate-limit access.
- Legal obligation — to keep purchase records for tax and consumer-protection requirements.
4. Who we share it with
We do not sell your personal data, ever. We share it only with the service providers that make the site work, each acting as a data processor under contract:
- Hosting and database: Lovable Cloud (Supabase / Amazon Web Services), which stores your account, reading state, and activity log.
- Payment and customer record: HighLevel (LeadConnector), and Stripe or PayPal for card processing.
- Email delivery: GoHighLevel (LeadConnector), which uses Mailgun to send your sign-in links.
We may also disclose data when required by law, court order, or to enforce our Terms of Sale and Use against piracy.
5. International transfers
The site is operated from the United States, and our hosting is provided from the United States. If you access the site from the European Economic Area, the United Kingdom, or elsewhere, your personal data is transferred to the United States under Standard Contractual Clauses or equivalent safeguards offered by our processors.
6. How long we keep it
- Account, profile, reading state: for as long as you keep your account. Deleted on request.
- Reading access log: retained for up to 24 months, then automatically purged. Used only for anti-piracy and rate-limit enforcement.
- Purchase / tax records: retained for the period required by applicable tax law (typically 6–7 years).
7. Your rights
You can:
- Access & export a copy of your personal data — one click in your Account page.
- Delete your account and all personal data we hold — also one click in your Account page. (Anonymous purchase records required by tax law may be retained.)
- Correct inaccurate information — email us.
- Object to a particular use, or restrict processing — email us.
- Complain to a supervisory authority (in the EU, your national Data Protection Authority; in the UK, the ICO).
California residents have equivalent rights under the CCPA / CPRA, including the right to know and the right to delete. We do not sell personal information.
8. Cookies
We only use cookies and local storage that are strictly necessary to keep you signed in and to remember your reading position and language. We do not set any advertising, analytics, or tracking cookies, so we do not display a cookie banner.
9. Children
The reader is intended for an adult audience and is not directed at children. We do not knowingly collect personal data from anyone under the age of 16. If you believe a minor has signed up, please contact us and we will delete the account.
10. Security
Connections to the site are encrypted with TLS. Sign-in is by single-use magic link — we never store your password (there isn't one). Access to the database is restricted to the author and the platform operators.
In the unlikely event of a personal-data breach affecting your account, we will notify you and the relevant supervisory authority within 72 hours, as required by the GDPR.
11. Changes to this policy
If we make a material change, we will update the date at the top of this page and, if the change affects you, notify you the next time you sign in.
