Política de privacidad

What we store

  • Your email address. Required, because it is where the licence key goes. Kept with the order.
  • Your account, if you create one: email address and a hashed password. The password itself is never stored and cannot be recovered from the hash. Signing in sets a cookie called “session” that lasts 90 days and does nothing but keep you signed in.
  • Your orders: what was bought, when, for how much, and whether it was paid, refunded or cancelled.
  • Download records: when a file was downloaded, from which IP address and with which browser. This exists to stop one purchase being shared with a hundred people.
  • Your network address at checkout, kept in two forms for two reasons. As a one-way hash, which only counts how many keys one caller is holding unpaid at the same time. And as the address itself, because a bank that calls a purchase fraudulent asks us to name the address the order came from, and a hash is no answer to that question.
  • How the site gets used. The first page you open sets a cookie called “tid”: a random ID with no name attached, valid for a year, set before you sign in and whether or not you ever do. Against that ID we record the pages you open and how far you get through a purchase, where you arrived from (the referring site and any utm tags in the link), your country, and whether you are on a phone or a computer, with which browser and which operating system. It answers one question: which pages and products people actually reach, and where they give up. Your IP address is not stored with any of it — it is used to stop that endpoint being flooded, and the country comes from a header the network in front of this site adds.
  • A partner referral, if you arrived through a partner link. It sets a second cookie, “aff”, holding the partner’s code for 30 days, so that a purchase can be credited to them. The visit itself is logged with the page you landed on and a hash of your address and browser — enough not to count you twice, not enough to name you.


What we do not do

We run no advertising pixels, no third-party tracking cookies and no cross-site profiling, and we sell nothing to data brokers. The measurement described above is our own: it runs on our own server, the data stays in our own database, and no analytics company gets a copy of it.

We never see your card details. Payment runs through Stripe, and what comes back to us is whether it worked.

Who else gets your data

  • Stripe: payment processing.
  • Cloudflare: the “are you human” check on the sign-in, registration, password-reset and checkout forms. Your browser loads it from challenges.cloudflare.com, and when we verify the result we send your IP address along — that is how the check works. Cloudflare also sits in front of this site, so every request passes through it, and the country field in our own measurement comes from a header it adds.
  • Elastic Email: delivery of the key and account emails.
  • AlexHost SRL: operates the servers this site runs on.

How long we keep it

Orders and invoices are kept as long as tax law requires. Download records are deleted after [RETENTION PERIOD]. The checkout address is kept while a payment can still be disputed and is deleted after [RETENTION PERIOD]; the hash stays, because it is not you, it is a counter. Usage events are deleted once they are older than 90 days, and the visitor row goes with them once no event points at it any more and no account is attached; that cleanup runs off ordinary traffic rather than a nightly job, so a row can outlive the mark by a little. Partner click records are kept for [RETENTION PERIOD]. Delete your account and the rest goes with it, except what we must keep for accounting.