Legal

Privacy
policy

Last updated · Version 1.0

The short version

This shop has no analytics, no advertising pixels, no social widgets and no tracking cookies. Nothing on these pages is loaded from another company's server, including the fonts. We collect what is needed to sell you a licence and issue it, and nothing beyond that.

Who is responsible

Controller
Prime Entity, Heer Arnoudstraat 49, 4902 BR Oosterhout, the Netherlands
Chamber of Commerce (KvK)
91972655
Contact for privacy questions
privacy@prime-entity.nl

What we collect, and why

When you buy something

Your name, email address and the country used for tax. These create your account and go into the licence the plug-in receives, which is what makes it yours.

Legal basis: performance of the contract. We cannot issue a licence without them.

Your account

A hash of your password, never the password itself. We use PHP's own password_hash(), which is one-way: we cannot read your password, and neither can anyone who steals the database.

When you activate the plug-in we also store an identifier for that computer and the name it reports, so your account page can show you which machine your licence is on and let you release it. The identifier comes from the plug-in and means nothing outside our system.

Legal basis: performance of the contract, and our legitimate interest in the licence limit being enforceable.

Sign-in attempts

Each attempt to sign in records the email address used, the IP address and whether it worked. This is how the rate limit works, and it is the first thing we look at if somebody reports their account being attacked. Entries older than a couple of hours are deleted automatically.

Legal basis: legitimate interest in preventing password guessing.

Payment details

Handled entirely by Paddle, who act as the merchant of record. Card numbers never reach this website and we never see them. Paddle processes your payment as an independent controller under its own privacy policy, and passes us back only your name, email, country and whether the payment succeeded.

Order records

We keep a record of each order: date, product, amount, name and email. Dutch tax law requires us to retain business records, so these are kept for seven years.

Legal basis: legal obligation.

If you ask to be notified about a product

Only your email address and which product you asked about. It is used for one message when that product is released, and then deleted. We do not add you to a newsletter.

Legal basis: your consent, which you can withdraw at any time by emailing us.

Server logs

Our web server records requests, including IP addresses, in the ordinary way. These are used to keep the site running and to investigate abuse, and are kept for a short period.

Legal basis: legitimate interest in operating and securing the site.

Cookies and local storage

We set one cookie, and only once you sign in: a session cookie that keeps you signed in while you are on the site. It holds no personal data, only a random identifier, and it disappears when you close your browser. There is no way to refuse it and still have an account page, which is why it needs no consent banner: it is strictly necessary for something you asked for.

The site also stores a single value in your browser's local storage recording whether you chose light or dark mode. It never leaves your device, is not an identifier, and is not used to recognise you. Clearing your browser data removes it.

Paddle may set cookies on its own checkout overlay for fraud prevention. That happens under Paddle's policy.

Who else sees your data

Paddle
Payment processing, tax calculation and merchant of record. Independent controller.
Our email provider
Sends your licence and download link. Processor, acting only on our instructions.
Our hosting provider
Runs the server the site and the order records live on. Processor.

We do not sell personal data, and we do not share it for advertising. Some of these providers may process data outside the European Economic Area; where they do, that transfer relies on the European Commission's standard contractual clauses or an adequacy decision.

How long we keep things

  • Order records: seven years, as Dutch tax law requires.
  • Your account: for as long as you have it. Ask us and we delete it, keeping only the order record the tax rules oblige us to keep.
  • Activated machines: until you release them, or until the account is deleted.
  • Sign-in attempts: a couple of hours.
  • Notify-me addresses: until the product ships, or until you ask us to remove yours.
  • Support email: as long as it is useful for supporting you, then deleted.

Your rights

Under the GDPR you can ask us to:

  • tell you what we hold about you, and give you a copy;
  • correct anything that is wrong;
  • delete it, where we are not legally required to keep it;
  • restrict or object to how we use it;
  • hand it to you in a portable format.

Email privacy@prime-entity.nl and we will respond within a month. There is no charge.

One honest limit: we cannot delete an order record inside the seven-year retention period, because keeping it is a legal obligation rather than a choice. We can delete everything else.

If you are not happy with how we handle it, you can complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens, or to the authority in the EU country where you live.

Changes

If this policy changes, the date at the top changes with it. Material changes affecting people who have already bought will be sent by email.

Read the terms of sale