PRIVACY POLICY

Your privacy matters. Learn how we protect your personal data

Effective Date: May 22, 2025 | Last Updated: May 23, 2026


Data Security

Secure payment processing through PCI-compliant providers

GDPR Compliant

Full compliance with EU protection regulations

Minimal Collection

We only collect data necessary for service

Your Rights

Access, rectify, erase, and securely port your data





Who We Are and What This Notice Covers




Personal Data We Collect


Payment Data Security

Card payments are processed through a PCI DSS Level 1-compliant payment provider. Card data does not pass through or get stored on our servers. We receive only payment tokens, transaction references, masked card details, and authentication metadata needed for order processing, fraud prevention, refunds, and dispute handling. We do not store full card numbers, CVC codes, or sensitive card authentication data.



Sources of Personal Data




Purposes and Lawful Bases (GDPR)


We process personal data for:

  • Contractual necessity – Create and manage your account, process orders, deliver digital products, provide customer support, handle refunds, and maintain account balance records
  • Legitimate interests – Fraud prevention, payment authentication, service security, delivery verification, support ticket read status, abuse prevention, troubleshooting, analytics, chargeback defense, and payment dispute response
  • Legal obligations – Tax, accounting, audit records, sanctions compliance, regulatory screening, responding to lawful requests, and maintaining transaction records
  • Consent – Where required, including marketing emails, non-essential cookies, and checkout consent for immediate digital delivery
  • Establishment, exercise, or defense of legal claims – Preparing and submitting evidence for refunds, chargebacks, payment disputes, fraud claims, and legal or regulatory matters


Cookies and Similar Technologies




Disclosures and Processors




International Transfers




Security Measures



Encryption

Enforced TLS (1.2+) for web/API traffic, encryption of sensitive data at rest

Access Control

MFA for administrative/sensitive access, salted cryptographic password hashing

Monitoring

Centralized logging and monitoring, vulnerability management


Testing

Quarterly external ASV scans, annual penetration testing

Backup

Encrypted off-site backups with documented restore tests

Data Protection

We never log sensitive card authentication data



Data Retention


Data Type
Retention Period
Customer account data (name/email/phone)
Active period + 24 months, unless longer retention is required or permitted by law
Order, transaction, payment reference, and delivery records (no full PAN)
7 years for tax, accounting, audit, fraud prevention, and payment record purposes
Support tickets, ticket read status, verification requests, refund requests, and customer communications
24 months, or longer if connected to an active dispute, fraud review, or legal matter
Security logs, IP address, device/browser records, and access logs
12 months, unless needed longer for fraud prevention, dispute response, security investigation, or legal compliance
Checkout consent records, 3D Secure metadata, ECI value, payment authentication metadata, delivery evidence, support verification evidence, ticket read records, supplier fulfillment status, and dispute materials
As reasonably necessary for payment disputes, fraud prevention, chargeback defense, legal compliance, tax, and accounting records


Your Rights



Access

Request a copy of your personal data

Rectification

Correct inaccurate personal data

Erasure

Request deletion of your data


Restriction

Limit processing of your data

Portability

Receive your data in a portable format

Object/Withdraw

Object to processing or withdraw consent


How to Exercise Your Rights

To exercise your rights, contact [email protected]. We verify identity before fulfilling requests and respond within statutory timeframes (typically ≤30 days in the EU; ≤45 days under CCPA). We may request additional information to verify your identity and to secure your account.



Children’s Privacy




Complaints




Updates to This Policy




Contact Our Privacy Team


General Inquiries
24-48 hours response
Partnership
B2B opportunities
Security
24/7 monitored