Privacy

Last updated: 4 October 2026

This policy explains how Ginger Cat Works handles personal data for the Ginger Cat Works account, which signs you in to our apps, such as TasteMate and TulipTv, and for this website. Each app also has its own privacy policy for the data that app keeps.

Who we are

Ginger Cat Works is an independent studio in the Netherlands building digital apps and products. Ginger Cat Works is responsible for the processing described here. Our address is Verdunplein 17, G9053, 5627 SZ Eindhoven, Netherlands. We are registered with the Dutch Chamber of Commerce (KvK) under number 42139363. Questions and requests: contact@gingercatworks.com. Our other contact details are on the contact page.

One account for our apps

Our apps share one Ginger Cat Works account per email address within the same environment. If you join a second app with the same email address, it uses the same account and sign-in methods. You still sign in to each app separately. Development and test accounts are kept separately from production accounts.

The account holds only what all apps need to sign you in:

  • your email address;
  • your sign-in details: stored password-verification material, rather than the password itself, and, if you use Google Sign-In, the identifier that links your Google account, its email verification status and technical provider identity records;
  • technical account records, such as when the account was created and last used;
  • which of our apps you use, and any role you have in each of them.

App-specific records are kept separately: your profile, content, settings, devices and licences belong to that app. Sharing the account does not give another app access to your private app data. Information an app makes public remains public under that app's settings and privacy policy.

Signing in with Google

Where Google Sign-In is offered, we request only basic sign-in information through the openid, email and profile permissions. Google can send your email address, email verification status, a stable Google account identifier, your name and your profile picture. We use the email, identifier and verification/provider records to authenticate you and connect the sign-in to your shared account. We do not request your Gmail messages, Drive files, contacts or access to other Google services.

Our account database removes Google name and picture fields from saved account and provider-identity metadata. Those fields may still be present in the sign-in response or browser session. An app may ask you to choose its own display name and picture.

We do not sell Google user data or use it for advertising. Our account infrastructure processes it for sign-in, and the email address is also used for the account service emails described below. You can revoke our Google access in your Google Account settings; that does not delete the shared account or its already saved records.

Development services are used to test this shared account. Google's Testing status alone does not limit basic Google Sign-In to a named list of testers. Signing in can create an account record even if you do not finish joining an app; that record can remain until account deletion is requested.

Emails about your account

Sign-up confirmations, sign-in links, password resets and email-change confirmations are sent from no-reply@gingercatworks.com through Resend. They are service emails about your account.

Leaving an app or deleting your account

  • Leave one app. Use the account deletion option in that app, or email us. This removes the app membership and deletes the app data covered by that deletion. Your account and data in other apps stay. The limited records described below can be retained for their separate purpose.
  • Leaving the last joined app also deletes the maintained shared account, including its email address and sign-in details. A sign-in-only account that never joined an app needs an account deletion request.
  • Delete the whole account. Email contact@gingercatworks.com from the account's email address. We remove you from every app and delete the account. We may need to confirm that you control the address.

When deletion is completed, the account and app data covered by that deletion are removed from active systems. Earlier backup copies can still contain that data. Development rolling backups are configured to remove snapshots older than 30 days on each backup run; removal depends on that process running. Other archived copies are outside that cleanup process. This development setting does not establish an automatic expiry guarantee for every backup or a production retention period. Contact us about data retained in backup or archive copies.

An app may retain limited accounting or licensing records separately where required by law or justified, for example to stop a licence key from being reused. Its own privacy policy explains which records it retains, why, and for how long.

An app can also keep a minimal ban record tied to the shared account to prevent a banned account from rejoining that app. This restriction does not ban the account from other apps. The record is removed when the shared account is deleted.

Service providers

  • Supabase: account sign-in, and the apps' databases and file storage;
  • Vercel: hosting for this website and our web apps;
  • Resend: account emails and delivery of contact-form messages;
  • Zoho Mail: receiving and storing email sent to our contact address;
  • Google: Google Sign-In, only if you choose it;
  • Cloudflare Turnstile: spam protection on the contact form.

These providers receive only the information needed for their role and process it under their own terms and safeguards. Hosting and account services also process standard connection data, such as IP addresses, to deliver and secure the service. Providers may process data outside your country; where required, transfers rely on the providers' contractual commitments or other lawful safeguards. We do not sell personal data.

This website

This website uses no analytics or advertising cookies. On the contact form, Cloudflare Turnstile checks that a message comes from a person rather than a bot. For that check it processes signals such as your IP address and browser details, and it may set cookies that are strictly necessary for this security purpose. If you use the contact form, your name, email address and message are used only to answer you. Contact-form messages, direct emails and deletion or rights requests sent to our contact address are received and stored in our Zoho Mail mailbox so we can respond.

Why we process data

  • to provide the account and the apps you sign up for (contract);
  • to keep the account and the apps secure and prevent abuse (legitimate interests);
  • to meet legal obligations.

Account data is kept while the account exists and is deleted as described above.

Your rights

Depending on where you live, you may have the right to access, correct or delete your data, to restrict or object to its processing, to receive a portable copy, and to complain to a data protection authority. Send requests to contact@gingercatworks.com. We may need to confirm that you control the account.

Changes

We update this policy when our apps, providers or the law change. The date at the top shows the current version.