Legal

Privacy

What we store, why, who else sees it, and how to make us delete it. Short, because we collect very little.

Last updated 30 August 2026

On this page

The short version

We sell files. To do that we need to know where to email your download link, and we need a record of what you bought so you can get it again later. That is very nearly the whole list.

There are no analytics, no advertising pixels and no third-party trackers of any kind on this site. Nobody is following you here, and nothing about your visit is sold or shared for marketing.

We never see your card. Payment happens on PayPal, and the number never touches our servers.

What we actually store

Everything below lives in our own database. It is the complete list.

  • Your email address. Where download links go, and how a purchase finds you if you make an account later.
  • Your password, hashed. Stored as a PBKDF2 hash with a per-account salt. We cannot read it, and neither can anyone who steals the database. We never email you a password and never ask for it.
  • What you bought — the product, the price paid, the date, and PayPal’s reference for the payment, so we can match a payment to an order if you ever ask us to.
  • A record of downloads — which file, when, and a hashed form of your IP address. The hash lets us see that one permanent link is being used by hundreds of different machines, which is how we notice a link has been posted publicly. It cannot be turned back into an address.
  • Sign-in events and failed attempts, so an account can be locked after repeated wrong passwords and so we can tell you what happened if something looks wrong.
  • Your address on the mailing list, if you asked to be on it, along with the date and where you signed up. It is used for new releases, sales and updates, and nothing else.

That is all. We do not ask for your name, your address, your age, your date of birth or your phone number, because we do not need any of them to send you a file.

Why we are allowed to hold it

For UK and EU visitors, the legal bases are:

  • Performing our contract with you — your email and your purchase record. We cannot deliver a file we have no address for.
  • Our legitimate interests — the hashed download log and the sign-in events, which exist to protect the shop from abuse and to let us answer a support question honestly.
  • Your consent — the mailing list, and nothing else. You can withdraw it with one click in any email we send.
  • A legal obligation — records of what was sold and for how much, which tax law requires us to keep whatever else you ask us to delete.

Who else sees it

Three companies, each for one job, and none of them for advertising:

  • PayPal handles payment. You deal with them directly; we are told only that a payment succeeded, for how much, and PayPal’s reference for it. They are their own data controller and their privacy policy governs what they do — including the card details we never receive.
  • Cloudflare hosts the site, the database, the files and the email we send. They process this data on our behalf and under our instructions.
  • Nobody else. We do not sell, rent, share or trade your data, and there is no analytics provider, ad network or data broker in the picture.

Our Discord server is Discord’s own service under their terms — joining it is a separate decision you make, and nothing links your Discord account to your purchase unless you tell us it does. The member count shown on our Support page is a total; it identifies nobody.

Cookies

Two, both strictly necessary, neither used for tracking:

  • ri_acct — proves you are signed in. Set only when you sign in, and cleared when you sign out.
  • ri_gate — remembers that you entered the access code, while the site is still private before launch. It will disappear once the shop opens.

Your browser also keeps a few things locally that never reach us at all: your cart, whether you chose light or dark mode, whether you have already seen the latest “what’s new” note and whether you asked not to be shown it again, and a copy of your own sign-in state so the account menu does not flicker on every page. Those are not cookies, they are not sent anywhere, and clearing your browser data removes them.

Because we set no analytics or advertising cookies, there is nothing here that requires a consent banner, which is why you have not been shown one.

How long we keep it

  • Your account and purchases: for as long as you have an account, because the whole point is that you can come back years later for an updated file.
  • Download logs: they carry only a hashed IP and exist for abuse detection.
  • Mailing list: until you unsubscribe. We then keep a record that you unsubscribed — deliberately, because it is the only reliable way to make sure you are never added again by mistake.
  • Sales records: kept as long as tax law requires, even after an account is deleted.

Your rights, and how to use them

If you are in the UK or EU you have the right to see what we hold about you, correct it, have it deleted, object to how we use it, or take it elsewhere. We extend the same to everybody, because running two standards would be more work than doing it properly once.

Email [email protected] from the address you bought with and say what you want. We will do it within 30 days and usually much sooner. There is no charge and no form.

One honest limitation: if you ask us to delete everything, we must keep the bare sales record for tax purposes, and you will lose access to your downloads, because the record of what you bought is the access. We will say so before we do it, not after.

If you think we have handled your data badly, please tell us first — but you can also complain to your data protection regulator, which in the UK is the Information Commissioner’s Office.

Security, without the marketing

Passwords are hashed with PBKDF2 and a per-account salt, never stored or transmitted in a form we could read. Session cookies are HttpOnly, Secure and SameSite, so a script cannot read your session and it is never sent over an unencrypted connection. Repeated failed sign-ins lock an account rather than allowing an endless guessing run. Download links are cryptographically signed, so one cannot be edited into a link for something you did not buy. Every page is served over HTTPS.

What we will not claim is that any of this is unbreakable. If we ever do suffer a breach affecting your data, we will tell you what happened and what to do about it, and we will do it promptly rather than quietly.

Children

This shop is not intended for children, and we do not knowingly collect anything from them. If you believe a child has given us their details, email us and we will remove it.

Changes to this policy

If we change it, the date at the top changes. If we ever change it in a way that materially affects what we do with data we already hold, we will email people on the list and say so plainly rather than relying on you noticing a date.

Something here unclear, or think we have got it wrong? Write to [email protected] and a person will answer.

Respawn IconsRespawn Icons Respawn Icons
© 2026 Respawn Icons