Skip to document
crazikktweaks
AgreementPrivacyCookiesRefunds
Log in

LEGAL · CURRENT DOCUMENT

Privacy Policy

How we collect, use, protect, retain, and share personal data when you use crazikktweaks.

Structured for easier readingEffective 10 August 202614 sections

On this page

01Data Controller02Scope.03Who this applies to.04Categories of Data We Process05Purposes and Legal Bases06How We Use Data07Disclosures & Recipients08International Transfers09Retention10Your Data Rights11Security12Third-Party Links13Changes to This Policy14How to Contact Us
Questions?Contact support ↗
01

Data Controller

Ben Barkai, ID No. 22073264
V Kapslovně 2770/5, 130 00 Prague 3
E-mail: [email protected]
02

Scope.

This Privacy Policy explains how we collect, use, share, and protect personal data when you visit our website, create an account, purchase our digital software products/tweaks, use our services, or contact support.
03

Who this applies to.

Visitors, account holders, and customers worldwide. If you are in the EEA/UK, this notice is provided under GDPR/UK GDPR.
04

Categories of Data We Process

  • Identity & contact data — name, email, billing address, country, company (optional), VAT ID (if applicable).
  • Account & order data — username, password (one-way hashed), order history, licence keys, support tickets, and the version and server timestamp of checkout terms accepted.
  • Payment data — payment status and identifiers from our payment provider; we do not receive or store full card numbers.
  • Lifecycle support data — whether a download, installation, successful first action, purchase, refund or review occurred; preferred language; and whether a related help email was scheduled, sent, failed or disabled. Email identities in the event ledger are stored as keyed pseudonyms.
  • Device & usage data — timestamps, pages viewed, referrers, browser/OS information, country and error or security events. A connection IP may be processed transiently by our edge/server, but normal web access logs are disabled and the application keeps only a keyed, one-way IP pseudonym where anti-abuse or attribution requires it.
  • Hardware identifier (HWID/SID) — used for licence enforcement and anti-abuse. The application converts it to a keyed, one-way pseudonym before persistent storage; the original identifier is not kept in the application database.
  • Cookies and browser storage — consent, language, cart, country/currency, authentication, and analytics data as described in our Cookie Policy.
  • No special categories. We do not intentionally collect data revealing racial/ethnic origin, health, biometrics, religious beliefs, etc.
  • Children. Our services are not directed to children under 16. If you are under the applicable age of consent in your country, use requires parental/guardian consent. We delete data if we learn we collected it in error.
05

Purposes and Legal Bases

We process personal data only where a legal basis applies:
  • Performing a contract (Art. 6(1)(b) GDPR):
    • creating and managing your account;
    • processing orders, recording purchase/refund status, and delivering digital content;
    • providing support and handling non-conformity remedies;
    • recording your express request for immediate delivery and acknowledgement concerning the 14-day withdrawal right where applicable.
  • Legal obligations (Art. 6(1)(c)): tax/accounting records and lawful authority requests.
  • Legitimate interests (Art. 6(1)(f)):
    • licence enforcement, fraud and abuse prevention;
    • service security, diagnostics, and incident response;
    • attributing an expressly supplied creator/referral code so commissions can be audited;
    • communicating about purchases and defending legal claims.
    You may object as described in the Rights section.
  • Consent (Art. 6(1)(a)): optional first-party funnel measurement, campaign parameters, Google Analytics, and marketing communications where consent is required. You can withdraw consent at any time without affecting earlier processing.
06

How We Use Data

Orders & delivery: to take payment, issue invoices, deliver/activate digital content, and manage licences.
Lifecycle support: to send relevant setup help after a requested download, installation or activation, purchase onboarding, and one later review request. Anonymous visitors provide their email voluntarily for this purpose; downloading is never conditional on providing it. Every lifecycle email includes an unsubscribe link and is stopped when no longer relevant, including after a refund where applicable.
Support: to verify identity, diagnose issues, and respond to requests.
Security & compliance: to detect/prevent fraud or misuse, secure accounts, and meet legal duties.
Service improvement: to analyse performance and fix usability issues.
Marketing: to send product updates and offers where permitted; you can opt-out any time (unsubscribe link in email).
We do not engage in automated decision-making that produces legal or similarly significant effects under GDPR Article 22.
07

Disclosures & Recipients

We do not sell your personal data. We share it only as needed:
  • Payment processors for secure payments (e.g., card networks, PSPs).
  • Hosting, storage, and security providers; anti-abuse/fraud tools; content delivery networks.
  • Customer support & communication tools (ticketing/emailing).
  • Professional advisers (legal, accounting) and authorities when legally required.
  • Business transfers: in a merger, acquisition, or asset sale, data may transfer subject to this Policy’s protections.
Each provider is bound by contract to protect your data and use it only for the instructed purpose.
08

International Transfers

We may process/store data outside your country (including outside the EEA/UK). Where we transfer EEA/UK personal data internationally, we rely on:
  • an adequacy decision (where available), or
  • Standard Contractual Clauses (and, for UK, the UK IDTA/Addendum) with supplementary safeguards as needed.
09

Retention

We keep data only as long as necessary, then delete or irreversibly anonymise it. Automated cleanup runs at least daily.
  • Account data: while the account is active; a verified self-service deletion removes it without an additional 24-month waiting period, except records we must retain.
  • Orders, invoices and purchase/refund records: up to 10 years where required for tax, accounting, fraud prevention or disputes; account identifiers are minimised or anonymised where possible.
  • Lifecycle support: milestone and delivery records are retained for up to 24 months. A standalone contact email with no pending message is minimised after 180 days; a minimal suppression record may remain so an unsubscribe is respected.
  • Licence/device pseudonyms: while needed for an active licence; inactive device-tracking records are deleted after 24 months.
  • Closed support tickets: 3 years from submission/last activity.
  • Logs: normal web access logs are disabled. Application operational/error logs are rotated and deleted after 14 days. Dedicated high-risk security trap logs are retained for 30 days; account security audit records may be retained for 12 months, or longer for an active incident/legal claim.
  • First-party funnel analytics: 14 months. Campaign visit pseudonyms: 90 days. Webhook replay protection: 180 days. Consent evidence: 24 months.
  • Marketing data: until you unsubscribe/withdraw consent; a minimal suppression record may be retained to honour the opt-out.
  • Cookies: per our Cookie Policy schedule.
10

Your Data Rights

Subject to applicable law, you may request access, correction, deletion, restriction, portability, or object to processing based on legitimate interests. Signed-in customers can download a machine-readable account export or submit a verified account-deletion request directly in the dashboard. You may also email [email protected], withdraw consent at any time, and complain to the Czech Office for Personal Data Protection or your local supervisory authority. We may verify your identity and normally respond within one month.
11

Security

We apply appropriate technical and organisational measures, including encryption in transit, restricted access, hardened infrastructure, backups, central password controls, revocable sessions and provider review. IP and HWID/SID values retained by the application are converted to keyed one-way HMAC pseudonyms. No system is completely secure.
12

Third-Party Links

Our site may link to third-party services. Their privacy practices are governed by their own notices.
13

Changes to This Policy

Effective date: 10 August 2026. We may update this Policy to reflect legal, technical, or business changes. The current version and effective date are published on this page.
14

How to Contact Us

Questions or requests about this Policy or your data: [email protected]

NEED A HAND?

Legal should be understandable.

If something is unclear, ask us before purchasing or changing your account.

Contact support ↗
crazikktweaks
FAQAgreementCookiesRefunds

© 2026 crazikktweaks. All rights reserved.