Privacy Policy
What we collect, why we collect it, how long we keep it, and the controls you have.
We collect what we need to sell, license, and support our software — nothing more. We don't sell your data, and the plugin itself does not phone home except to verify your license and check for updates (both can be disabled).
01Who we are
The data controller is SaneSounds Acoustic Instruments GmbH, [registered address], Berlin, Germany. Email: privacy@sanesounds.com.
02Data we collect
You give us
- Account & purchase — name, email, billing address, license key, order history
- Support — emails, attachments, system info you submit with bug reports
- Newsletter — email address (only if you opt in)
Collected automatically
- Website analytics — anonymized page views, referrer, device type, country (no IP stored)
- License activation — machine fingerprint hash, OS, plugin version (only at activation/update)
- Crash reports — stack trace, plugin state (only if you opt in via the plugin)
03How we use data
- Fulfilling orders, delivering downloads, and issuing license keys
- Authenticating your license and providing software updates
- Responding to support requests and bug reports
- Sending optional product news (only if you opt in; unsubscribe anytime)
- Detecting fraud and enforcing the Terms
- Complying with tax, accounting, and legal obligations
04Legal basis (GDPR)
- Contract (Art. 6(1)(b)) — order processing, license delivery, support
- Legal obligation (Art. 6(1)(c)) — tax records, anti-fraud
- Legitimate interest (Art. 6(1)(f)) — security, anonymized analytics, fraud prevention
- Consent (Art. 6(1)(a)) — newsletter, optional crash reports, non-essential cookies
05Sharing & processors
We do not sell or rent personal data. We share it only with vetted processors under data-processing agreements:
- Payment processor — checkout, refunds (e.g., Stripe / Paddle / Lemon Squeezy)
- Email provider — transactional and newsletter delivery
- Hosting & CDN — website and download delivery
- Analytics — privacy-friendly, cookieless analytics provider
- Authorities — only when legally required
A current list is available on request from privacy@sanesounds.com.
06Cookies & tracking
We use only essential cookies (e.g., session, CSRF) by default. Any non-essential cookies require your explicit consent via the cookie banner. You may withdraw consent at any time by clearing your browser cookies or using the in-banner controls.
07Retention
- Order & invoice records — 10 years (German tax law)
- Account data — until you request deletion or 3 years of inactivity
- Newsletter subscription — until you unsubscribe
- Support tickets — 3 years after resolution
- Anonymized analytics — 24 months
08Your rights
Under GDPR (and equivalent rights under CCPA, UK GDPR, etc.), you have the right to:
- Access — request a copy of your data
- Rectification — correct inaccurate data
- Erasure — request deletion ("right to be forgotten")
- Restriction — limit how we process your data
- Portability — receive your data in a machine-readable format
- Object — to processing based on legitimate interest
- Withdraw consent — at any time, without affecting prior processing
- Lodge a complaint — with your local supervisory authority
To exercise any of these, email privacy@sanesounds.com. We respond within 30 days.
09Security
We use TLS encryption in transit, encrypted storage at rest for sensitive fields, and restricted access controls. No system is perfectly secure; we will notify affected users and the relevant authority within 72 hours of any qualifying breach.
10International transfers
Some processors may be based outside the EEA. Where this occurs we rely on Standard Contractual Clauses (SCCs) or other approved transfer mechanisms.
11Children
The service is not directed at children under 16. We do not knowingly collect their data; if you believe we have, contact us and we will delete it.
12Contact
Privacy questions: privacy@sanesounds.com