What we store, why, who else sees it, and how to make us delete it. Short, because we collect very little.
Last updated 30 August 2026
We sell files. To do that we need to know where to email your download link, and we need a record of what you bought so you can get it again later. That is very nearly the whole list.
There are no analytics, no advertising pixels and no third-party trackers of any kind on this site. Nobody is following you here, and nothing about your visit is sold or shared for marketing.
We never see your card. Payment happens on PayPal, and the number never touches our servers.
Everything below lives in our own database. It is the complete list.
That is all. We do not ask for your name, your address, your age, your date of birth or your phone number, because we do not need any of them to send you a file.
For UK and EU visitors, the legal bases are:
If you are in the UK or EU you have the right to see what we hold about you, correct it, have it deleted, object to how we use it, or take it elsewhere. We extend the same to everybody, because running two standards would be more work than doing it properly once.
Email [email protected] from the address you bought with and say what you want. We will do it within 30 days and usually much sooner. There is no charge and no form.
One honest limitation: if you ask us to delete everything, we must keep the bare sales record for tax purposes, and you will lose access to your downloads, because the record of what you bought is the access. We will say so before we do it, not after.
If you think we have handled your data badly, please tell us first — but you can also complain to your data protection regulator, which in the UK is the Information Commissioner’s Office.
Passwords are hashed with PBKDF2 and a per-account salt, never stored or transmitted in a form we could read. Session cookies are HttpOnly, Secure and SameSite, so a script cannot read your session and it is never sent over an unencrypted connection. Repeated failed sign-ins lock an account rather than allowing an endless guessing run. Download links are cryptographically signed, so one cannot be edited into a link for something you did not buy. Every page is served over HTTPS.
What we will not claim is that any of this is unbreakable. If we ever do suffer a breach affecting your data, we will tell you what happened and what to do about it, and we will do it promptly rather than quietly.
This shop is not intended for children, and we do not knowingly collect anything from them. If you believe a child has given us their details, email us and we will remove it.
If we change it, the date at the top changes. If we ever change it in a way that materially affects what we do with data we already hold, we will email people on the list and say so plainly rather than relying on you noticing a date.
Something here unclear, or think we have got it wrong? Write to [email protected] and a person will answer.