Legal
Privacy Policy
Effective April 7, 2026 · Last updated October 7, 2026
1. Who we are and what this covers
SMJ AI LLC, a Delaware limited liability company based in Wilmington, Delaware ("SMJ AI", "we", "us"), owns and operates Printless and is the data controller for the personal data described here, except where a business that issues prints is the controller of its own customer data. This policy covers the Printless and Printless Printer apps, the Business Portal (printer.printless.app), the Printless API and button, printless.app and our other websites, and delivery of prints over WhatsApp. Questions and requests go to [email protected].
2. Information we collect
2.1 Account
- ·Mobile number — required; it identifies your account and is where prints are addressed
- ·Optional profile details: name, email address and a profile picture
- ·Sign-in codes, session tokens and the time and device of each sign-in
2.2 Prints and records
- ·The content of each print issued to you or by you: type, title, amounts, line items, dates, seats, vehicle numbers, notes and any document or image the issuing business attached
- ·Identifiers that let a print be verified: print IDs, public verification tokens and the issuing business
- ·Your own organisation of prints: categories, archive and read state
2.3 Business accounts
- ·Business profile: legal and display name, category, address, contact details, logo, brand colours, website and business hours
- ·Operational data: lists (your items and any custom lists you create with your own columns, such as materials or students), queues, templates, team members, subscription and usage counts
- ·The mobile numbers of the customers you send prints to, and API request logs (key used, endpoint, time, outcome)
2.4 Device and usage
- ·Device type, operating system and app version; a push-notification token from Apple or Google if you allow notifications
- ·IP address, approximate country derived from it, language preference and request logs used for security and troubleshooting
- ·Crash and error reports from the apps and the API
2.5 Website
- ·What you type into the contact or waitlist forms: name, email, business, phone, topic and message
- ·A bot-check token from Cloudflare Turnstile when you submit a form
- ·Functional cookies: pl_lang remembers the language you chose; pl_src remembers for 90 days how you first reached the site (for example a flyer, a social network, a search engine, another website or "direct")
- ·An anonymous visitor cookie, pl_vid: a random id, kept for a year, so we can count a visitor once. It is not linked to your name, email or phone number
- ·For each page you view and each app-store, Business Portal or docs link you follow: the page, the kind of link, the source above, your country (from Cloudflare), whether you are on a phone or a computer and the site language. We do not store your IP address or browser details with it
2.6 Subscriptions
- ·Your plan, renewal state and usage against its allowance
- ·Transaction and receipt identifiers from Apple or Google used to verify a purchase
- ·We never see or store your card or bank details; Apple and Google process payments
2.7 What we do not collect
- ·Precise location
- ·Your contacts or photo library
- ·Advertising identifiers or cross-site tracking data
3. How and why we use it
Where the GDPR or a similar law applies, the legal basis is shown in brackets.
- ·Create and secure your account, verify your number and sign you in (contract; legitimate interest in security)
- ·Deliver, store, display, search and let you verify prints, and add cards to wallets (contract)
- ·Send prints and status updates by push notification and, on eligible business plans, over WhatsApp (contract; consent where the law requires it)
- ·Run business tools: queues, lists, analytics about the prints a business issues, API keys and usage limits (contract)
- ·Bill subscriptions and confirm purchases with Apple or Google (contract; legal obligation)
- ·Answer support and contact requests, and see which source a request came from (legitimate interest; contract)
- ·Measure, on our own systems, which flyers, posts, searches and websites bring visitors, installs and sign-ups (legitimate interest)
- ·Keep the Service safe: detect fraud, abuse, forged prints and unauthorised access, and keep logs and backups (legitimate interest; legal obligation)
- ·Improve the Service using aggregated, de-identified usage information (legitimate interest)
- ·Comply with law, tax and accounting rules and lawful requests (legal obligation)
4. Who we share it with
We do not sell personal data and do not share it for advertising. We share it only:
- ·Between the business that issues a print and the customer who receives it — the business sees the number it sent the print to and the print's status; the customer sees the business's name, logo and contact details
- ·With the service providers listed in section 5, who process data only on our instructions
- ·When the law, a court order or a regulator requires it, or to protect the rights, safety or property of users, the public or SMJ AI
- ·With a buyer or successor if the Printless business is sold or merged, under this policy
- ·With your consent, or at your direction — for example when you share a print with someone
5. Service providers
- ·Amazon Web Services — application hosting and file storage (Mumbai, India region) and the connection to WhatsApp
- ·PlanetScale — database hosting (Mumbai, India)
- ·Cloudflare — websites, DNS, content delivery, bot protection (Turnstile), contact-form storage and security
- ·Google — Firebase Cloud Messaging for push notifications, Google Play for Android distribution and billing
- ·Apple — App Store distribution, billing and Apple Push Notification service, and Apple Wallet if you add a card
- ·Meta Platforms — WhatsApp Business Platform, for verification messages and delivery of prints over WhatsApp
6. International transfers
Our servers are in India and our providers operate in the United States, the European Union and other countries, so your data may be processed outside the country where you live. Where the law requires safeguards for such transfers we rely on the providers' contractual commitments, including standard contractual clauses, and on the protections described in section 7.
7. Security
Data travels over TLS and is stored encrypted. The content of each print is encrypted with its own key, access to production systems is restricted and logged, and we take daily backups. We test and review our security regularly. No system is perfectly secure; if a breach affects your data we will notify you and the relevant authorities as the law requires.
8. How long we keep it
- ·Account and profile data: while your account is open, then deleted within 30 days of closure
- ·Prints: for as long as the recipient or the issuing business keeps them. When a customer closes an account, the profile is deleted and the prints are no longer accessible to that person; the issuing business keeps its copy as a business record. When a business closes its account, the business is deactivated but the prints it issued stay verifiable for the customers who hold them, with the business name attached
- ·Contact and waitlist submissions: up to 24 months, or until handled and no longer needed
- ·Security, API and request logs: up to 12 months; backups: up to 6 months
- ·Billing records: as long as tax and accounting law requires
9. Your rights
Depending on where you live you may have the right to access, correct, delete or receive a copy of your personal data, to restrict or object to how we use it, to withdraw consent, and to complain to a data-protection authority. To exercise them:
- ·Delete your account and data at https://printless.app/account or in the app under Settings → Delete Account
- ·Export or correct your details in the app, or email [email protected] for anything else
- ·We verify requests using your registered number and respond within 30 days (or sooner where the law requires)
- ·We will not treat you differently for exercising a right
10. Regional notices
10.1 European Economic Area, United Kingdom and Switzerland
10.2 United States (California and other states)
10.3 India
10.4 Other countries
11. Children
Printless is not directed at children. Customers must be at least 16, or the age of digital consent where they live, and business accounts require an adult. We do not knowingly collect data from anyone younger; if you believe we have, email [email protected] and we will delete it.
12. Cookies and measurement
printless.app sets two functional cookies — pl_lang (your language) and pl_src (how you first found us, kept 90 days) — and one anonymous measurement cookie, pl_vid (a random id, kept one year). We use them only to count, in our own database, which flyers, posts, searches and websites bring visitors and sign-ups. When you follow a link from the site to the App Store, Google Play or the Business Portal, we add that source name (for example "flyer" or "instagram") to the link, so installs and sign-ups can be counted per source too; nothing that identifies you is added. This is first-party measurement only: no third-party analytics or advertising scripts run on our websites, nothing is shared with advertisers, and you are not tracked across other sites. You can delete or block these cookies in your browser at any time and the site works the same without them. Cloudflare Turnstile protects forms from bots. The apps contain no advertising or third-party analytics SDKs, and because we do not track you across other sites there is nothing for "Do Not Track" signals to switch off.
13. Notifications and WhatsApp
Push notifications can be turned off in your phone's settings at any time. WhatsApp messages from Printless are transactional — verification codes and the prints a business sends you; you can stop them by blocking the number in WhatsApp, and we do not send marketing over WhatsApp.
14. Changes to this policy
We may update this policy as the Service or the law changes. For material changes we give at least 30 days' notice in the app or on the website before they take effect. The date at the top shows when it was last revised.
15. Contact
SMJ AI LLC, Wilmington, Delaware, United States.
- ·Privacy and Grievance Officer: [email protected]
- ·Support: [email protected]
- ·General: [email protected]
- ·Website: https://printless.app