01
Data Controller
02
Scope.
This Privacy Policy explains how we collect, use, share, and protect personal data when you visit our website, create an account, purchase our digital software products/tweaks, use our services, or contact support.
03
Who this applies to.
Visitors, account holders, and customers worldwide. If you are in the EEA/UK, this notice is provided under GDPR/UK GDPR.
04
Categories of Data We Process
- Identity & contact data — name, email, billing address, country, company (optional), VAT ID (if applicable).
- Account & order data — username, password (one-way hashed), order history, licence keys, support tickets, and the version and server timestamp of checkout terms accepted.
- Payment data — payment status and identifiers from our payment provider; we do not receive or store full card numbers.
- Lifecycle support data — whether a download, installation, successful first action, purchase, refund or review occurred; preferred language; and whether a related help email was scheduled, sent, failed or disabled. Email identities in the event ledger are stored as keyed pseudonyms.
- Device & usage data — timestamps, pages viewed, referrers, browser/OS information, country and error or security events. A connection IP may be processed transiently by our edge/server, but normal web access logs are disabled and the application keeps only a keyed, one-way IP pseudonym where anti-abuse or attribution requires it.
- Hardware identifier (HWID/SID) — used for licence enforcement and anti-abuse. The application converts it to a keyed, one-way pseudonym before persistent storage; the original identifier is not kept in the application database.
- Cookies and browser storage — consent, language, cart, country/currency, authentication, and analytics data as described in our Cookie Policy.
- No special categories. We do not intentionally collect data revealing racial/ethnic origin, health, biometrics, religious beliefs, etc.
- Children. Our services are not directed to children under 16. If you are under the applicable age of consent in your country, use requires parental/guardian consent. We delete data if we learn we collected it in error.
05
Purposes and Legal Bases
We process personal data only where a legal basis applies:
- Performing a contract (Art. 6(1)(b) GDPR):
- creating and managing your account;
- processing orders, recording purchase/refund status, and delivering digital content;
- providing support and handling non-conformity remedies;
- recording your express request for immediate delivery and acknowledgement concerning the 14-day withdrawal right where applicable.
- Legal obligations (Art. 6(1)(c)): tax/accounting records and lawful authority requests.
- Legitimate interests (Art. 6(1)(f)):
- licence enforcement, fraud and abuse prevention;
- service security, diagnostics, and incident response;
- attributing an expressly supplied creator/referral code so commissions can be audited;
- communicating about purchases and defending legal claims.
- Consent (Art. 6(1)(a)): optional first-party funnel measurement, campaign parameters, Google Analytics, and marketing communications where consent is required. You can withdraw consent at any time without affecting earlier processing.
06
How We Use Data
Orders & delivery: to take payment, issue invoices, deliver/activate digital content, and manage licences.
Lifecycle support: to send relevant setup help after a requested download, installation or activation, purchase onboarding, and one later review request. Anonymous visitors provide their email voluntarily for this purpose; downloading is never conditional on providing it. Every lifecycle email includes an unsubscribe link and is stopped when no longer relevant, including after a refund where applicable.
Support: to verify identity, diagnose issues, and respond to requests.
Security & compliance: to detect/prevent fraud or misuse, secure accounts, and meet legal duties.
Service improvement: to analyse performance and fix usability issues.
Marketing: to send product updates and offers where permitted; you can opt-out any time (unsubscribe link in email).
We do not engage in automated decision-making that produces legal or similarly significant effects under GDPR Article 22.
Lifecycle support: to send relevant setup help after a requested download, installation or activation, purchase onboarding, and one later review request. Anonymous visitors provide their email voluntarily for this purpose; downloading is never conditional on providing it. Every lifecycle email includes an unsubscribe link and is stopped when no longer relevant, including after a refund where applicable.
Support: to verify identity, diagnose issues, and respond to requests.
Security & compliance: to detect/prevent fraud or misuse, secure accounts, and meet legal duties.
Service improvement: to analyse performance and fix usability issues.
Marketing: to send product updates and offers where permitted; you can opt-out any time (unsubscribe link in email).
We do not engage in automated decision-making that produces legal or similarly significant effects under GDPR Article 22.
07
Disclosures & Recipients
We do not sell your personal data. We share it only as needed:
- Payment processors for secure payments (e.g., card networks, PSPs).
- Hosting, storage, and security providers; anti-abuse/fraud tools; content delivery networks.
- Customer support & communication tools (ticketing/emailing).
- Professional advisers (legal, accounting) and authorities when legally required.
- Business transfers: in a merger, acquisition, or asset sale, data may transfer subject to this Policy’s protections.
08
International Transfers
We may process/store data outside your country (including outside the EEA/UK). Where we transfer EEA/UK personal data internationally, we rely on:
- an adequacy decision (where available), or
- Standard Contractual Clauses (and, for UK, the UK IDTA/Addendum) with supplementary safeguards as needed.
09
Retention
We keep data only as long as necessary, then delete or irreversibly anonymise it. Automated cleanup runs at least daily.
- Account data: while the account is active; a verified self-service deletion removes it without an additional 24-month waiting period, except records we must retain.
- Orders, invoices and purchase/refund records: up to 10 years where required for tax, accounting, fraud prevention or disputes; account identifiers are minimised or anonymised where possible.
- Lifecycle support: milestone and delivery records are retained for up to 24 months. A standalone contact email with no pending message is minimised after 180 days; a minimal suppression record may remain so an unsubscribe is respected.
- Licence/device pseudonyms: while needed for an active licence; inactive device-tracking records are deleted after 24 months.
- Closed support tickets: 3 years from submission/last activity.
- Logs: normal web access logs are disabled. Application operational/error logs are rotated and deleted after 14 days. Dedicated high-risk security trap logs are retained for 30 days; account security audit records may be retained for 12 months, or longer for an active incident/legal claim.
- First-party funnel analytics: 14 months. Campaign visit pseudonyms: 90 days. Webhook replay protection: 180 days. Consent evidence: 24 months.
- Marketing data: until you unsubscribe/withdraw consent; a minimal suppression record may be retained to honour the opt-out.
- Cookies: per our Cookie Policy schedule.
10
Your Data Rights
Subject to applicable law, you may request access, correction, deletion, restriction, portability, or object to processing based on legitimate interests. Signed-in customers can download a machine-readable account export or submit a verified account-deletion request directly in the dashboard. You may also email [email protected], withdraw consent at any time, and complain to the Czech Office for Personal Data Protection or your local supervisory authority. We may verify your identity and normally respond within one month.
11
Security
We apply appropriate technical and organisational measures, including encryption in transit, restricted access, hardened infrastructure, backups, central password controls, revocable sessions and provider review. IP and HWID/SID values retained by the application are converted to keyed one-way HMAC pseudonyms. No system is completely secure.
12
Third-Party Links
Our site may link to third-party services. Their privacy practices are governed by their own notices.
13
Changes to This Policy
Effective date: 10 August 2026. We may update this Policy to reflect legal, technical, or business changes. The current version and effective date are published on this page.
14
How to Contact Us
Questions or requests about this Policy or your data: [email protected]