Little Big Tool

Privacy Notice

Last updated: 7 October 2026 (version 2026-10-07)

This notice explains what personal information Little Big Tool collects, why, and what your choices are. We keep it short because we collect very little. It should be read with our Terms of Service and Refund Policy.

Operator details

Email
t.r-c@outlook.com

Operator details are provided at the time of purchase.

1. Who is responsible

1.1The operator identified in the Operator details above (we, us) runs Little Big Tool and is responsible for the personal information described in this notice.

1.2We aim to handle personal information in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), whether or not we are legally required to.

2. What we collect and why

Technical logs

Each request to the Service is recorded in server logs at the AWS load balancer, the web application firewall (WAF) and the application. A log entry has your IP address, your browser's user agent, the address (URL) requested and the time. We use logs to keep the Service secure, to find and fix faults, to block abuse and to apply rate limits. Pages that carry a payment reference in their address (the confirmation page) therefore also record that reference in the logs.

Session cookie and your work

Little Big Tool sets a session cookie (hb_sid) that links your browser to your work. The data you enter is held in the server's memory for your session only. It is used only to run Little Big Tool and generate your exports, and it is not stored long term.

Pass cookie

If you buy an Export Pass, we set a signed cookie (hb_pass) that proves the purchase and its expiry. It holds a reference to your Stripe checkout, the pass type and its times. It does not contain your name or card details.

Settings stored in your browser

Your accessibility settings (text size, contrast, motion) and a reminder preference are stored in your browser's local storage. They stay on your device and are not sent to us.

Payments

Payment details are collected by Stripe, not by us. We never see your card number. Stripe shares with us the information about a purchase that we need to run the pass and to deal with refunds and tax, such as the checkout reference, amount, date and status, and the email address you gave Stripe. We also ask Stripe whether a purchase has been refunded or disputed.

If you email us

If you contact us, we receive your email address and the content of your message, and we use them to reply and to keep a record of the request.

3. What we do not do

4. Cookies and local storage

These are all the cookies and browser storage entries the Service uses. All of them are strictly necessary to provide what you asked for, so there is nothing to opt in to.

Cookies and local storage used by Little Big Tool
NamePurposeDurationStrictly necessary
hb_sid (cookie, HttpOnly)Links your browser to your in-memory session.About 2 hours; the design is discarded after a period of inactivity.Yes
hb_pass (cookie, HttpOnly)Proves your Export Pass so that paid exports work. Set only after a purchase or a restore.Until the pass expires.Yes
hb_prefs (local storage)Remembers your accessibility settings.Until you reset the settings or clear your browser data.Yes
Reminder preference (local storage)Remembers whether you asked to be reminded about your pass.Until you change it or clear your browser data.Yes

The cookies are set with SameSite=Lax, and with the Secure flag on https. Stripe may set its own cookies on its Checkout pages; those are governed by Stripe's notices.

5. How long we keep things

Retention periods
WhatHow long
Design dataIn memory until the session ends or expires, or until the server restarts, whichever comes first.
Server logs (IP address, user agent, URL, time)About 30 days.
Stripe payment and tax recordsAs required by tax law, typically 7 years. Stripe holds the payment details.
Support emailsAs long as needed to deal with your request and any follow-up.

6. Where data is processed and who receives it

6.1The Service is hosted on Amazon Web Services (AWS) in Sydney, Australia. Logs and the in-memory design data are processed there.

6.2Payments are processed by Stripe, which may handle your information outside Australia. By paying you accept that we disclose the information needed to process the payment to Stripe. Under APP 8, when we disclose personal information to an overseas recipient we take reasonable steps to make sure it is handled consistently with the APPs; Stripe's own privacy notice governs its processing. Please read it at stripe.com/privacy before paying.

6.3We do not disclose personal information to anyone else, except where the law requires it.

7. Security

7.1We protect information with encryption in transit (TLS), restricted access to the systems and logs, signed and HttpOnly cookies, and by keeping very little and keeping it for a short time. No system is perfectly secure, so please keep your pass link private.

7.2If a data breach is likely to cause serious harm to you, we will notify you and the Office of the Australian Information Commissioner (OAIC) as required by the Notifiable Data Breaches scheme.

8. Your rights, access, correction and complaints

8.1You can ask us for access to the personal information we hold about you and ask us to correct it. Email t.r-c@outlook.com. Because we hold little, and design data lives only in memory, we may need you to tell us the approximate time and your IP address to find log entries. We will respond within a reasonable time, normally within 30 days.

8.2If you are unhappy with how we handled your information, please contact us first so we can try to put it right. If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner: www.oaic.gov.au.

9. Children

9.1The Service is not aimed at children, and we do not knowingly collect personal information from children. Paid passes are for adults, or for under 18s with a parent or guardian's involvement. If you think a child has given us personal information, please contact us and we will delete it.

10. Visitors from the EU, the UK and other regions

10.1If the GDPR or UK GDPR applies to you, our lawful bases are contract (to provide the pass you bought and the service you asked to use) and legitimate interests (security, preventing abuse and fixing faults). Where the law requires, you may ask us to erase, restrict or stop processing your personal information, or to give you a copy, and you may complain to your local data protection authority. We make no decisions about you by automated means that have legal or similarly significant effects.

10.2Your information is processed in Australia and, for payments, by Stripe, which may process it elsewhere.

11. Changes and contact

11.1We may update this notice. The date and version at the top show the current one.

11.2Privacy questions or requests: t.r-c@outlook.com.