Home Legal

Privacy Policy

Last updated: · Revision 0.1 draft

Unreviewed draft

This document is a draft. It has not been reviewed by a lawyer, it is not legal advice, and it may be incomplete or wrong on points that matter. It must be checked by a Dutch lawyer before it governs a real sale. If you are reading this on a live store page, please tell us at TODO_SUPPORT_EMAIL.

On this page

This policy covers smokingmedia.com, our store, our audio plugins and the emails we send you. It is written to be read, not to be survived, so it says plainly what we hold and why.

In short

  • We store the minimum we need to sell you a plugin, deliver a licence, and let that licence work on up to 3 of your machines.
  • We never see your card details. Paddle handles payments as merchant of record.
  • The plugin sends us a hashed machine fingerprint. The raw machine identifier never leaves your computer.
  • Our website analytics are cookieless and cannot identify you, which is why there is no cookie banner on this site.
  • We never sell, rent or share your data for anyone else’s marketing.
  • Buying something never subscribes you to a mailing list.

1. Who is responsible for your data

The controller for the personal data described here is TODO_REGISTERED_LEGAL_NAME, trading as Smoking Media, registered address TODO_STREET_AND_NUMBER, TODO_POSTAL_CODE TODO_CITY, TODO_COUNTRY, KvK number TODO_KVK_NUMBER.

For any privacy question or request, email TODO_PRIVACY_EMAIL.

2. When you buy a plugin

Our checkout is operated by Paddle, which acts as merchant of record and is the seller of record for the transaction. Your card number, expiry date and security code go to Paddle and its payment processors. They never reach our servers, and we could not retrieve them if we wanted to. Paddle’s own privacy notice governs that part of the transaction.

What Paddle passes on to us, and what we then store, is:

DataWhy we store it
Your email addressTo send your licence key, to identify your account when you sign in later, and it is shown inside the plugin on your licensed machines, so a shared key is visibly someone else’s
The products you boughtTo create the right entitlement
The amount, the currency and the list price at the timeAccounting, and calculating upgrade credit later
Paddle’s transaction identifierSo a payment, a licence and a refund can be matched to each other
The date and timeSame

Legal basis: performance of our contract with you (Article 6(1)(b) GDPR), and our legal obligation to keep business records (Article 6(1)(c) GDPR).

3. When you activate a plugin

This is the part people most want to know about, so here is the complete list. When you enter your licence key in the plugin, the plugin sends us, and we store:

DataWhat it actually is
Licence keyThe key you entered, which identifies your entitlement
Machine fingerprintA SHA-256 hash of a stable machine identifier combined with a product specific value. The raw machine identifier is hashed on your computer and never leaves it. We cannot reverse the hash back into a hardware identifier
Machine nameThe name your computer reports, for example “Studio iMac”, so you can tell your machines apart on the account page when you need to deactivate one
Operating system stringFor example “macos-15.2-arm64”, so support can reproduce a problem
Plugin versionWhich build is running, for the same reason
IP addressThe address the request came from, used for rate limiting and to detect key sharing and brute force attempts
User agentThe client string sent with the request, for the same reason
TimestampsWhen the activation was created, when it was last seen, and when it was deactivated

That is the whole list. We do not receive your audio, your projects, your presets, your file names, your MIDI, your plugin settings, or any usage telemetry. The plugin does not phone home while you work: after activation it verifies its licence file locally and only contacts us to refresh the lease or when you activate or deactivate a machine.

Data minimisation is a design requirement here, not a slogan. Each field above exists because a specific feature would break without it: the machine limit, the deactivate button, support, or abuse prevention.

Legal basis: performance of our contract with you (Article 6(1)(b) GDPR) for the activation itself, and our legitimate interest in preventing licence abuse (Article 6(1)(f) GDPR) for the IP address, the user agent and the abuse counters.

4. When you sign in to the account page

The account page has no passwords. You enter your email address, we email you a single use sign-in link that expires after 15 minutes, and clicking it creates a session.

We store the email address you entered, a hash of the sign-in token, the expiry and whether it has been used, and, for the session itself, your user agent and the times it was created and expires. Rate limiting counters keyed on your email address and IP address are held briefly so nobody can use the form to hammer our mail sender or to find out which addresses have accounts.

Legal basis: performance of our contract (Article 6(1)(b) GDPR) and legitimate interest in securing the service (Article 6(1)(f) GDPR).

5. Emails we send you

Transactional emails, meaning your licence key, your sign-in link and a redemption confirmation, are sent through Scaleway Transactional Email, a European email provider, acting as our processor. They receive your email address and the content of the message so they can deliver it.

We do not put tracking pixels in these emails, and we do not track whether you opened them.

6. The mailing list

Our mailing list is completely separate from everything above.

  • It runs on mail818, our own mailing list service.
  • It is opt-in and double opt-in: you enter your address, you receive a confirmation email, and nothing is sent to you until you click the link in it.
  • Buying a plugin never subscribes you. There is no pre-ticked box anywhere in the checkout, and the purchase pipeline has no path into the list.
  • Every message has an unsubscribe link, and unsubscribing removes your address.

Legal basis: your consent (Article 6(1)(a) GDPR), which you can withdraw at any time.

7. Website analytics

We use Umami, a privacy preserving analytics tool, running on our own infrastructure at track.exquex.com.

Umami is cookieless. It sets no cookie, stores nothing in your browser, and assigns no persistent identifier. It records aggregate page views, referrers and coarse country and device information, and it cannot follow you across sites or across sessions. We use it to see which product pages people reach and which links to us actually work.

Because no cookies or similar identifiers are stored on your device and no individual is identified, this site does not need, and does not show, a cookie consent banner.

We show no advertising on this site and we run no advertising trackers.

8. Cookies

We use exactly one cookie, and only if you sign in to the account page: a session cookie that keeps you signed in for about 30 days. It is HttpOnly, Secure and SameSite=Lax, it contains no personal data, and it exists solely to remember that you completed a sign-in. That is a strictly necessary cookie under the ePrivacy rules, so it needs no consent.

If you never sign in, this site sets no cookies at all.

9. When you contact support

If you email us, we hold your message, your email address and anything you chose to put in the message, for as long as we need it to help you and to keep a record of the case.

10. How long we keep things

DataKept for
Activation records: hashed fingerprint, machine name, OS, plugin version, IP address, timestampsTODO_ACTIVATION_RETENTION_PERIOD
Sign-in sessions and used or expired sign-in tokensTODO_SESSION_RETENTION_PERIOD
Customer and licence records, after the last sign of activityTODO_ACCOUNT_RETENTION_PERIOD
Orders, entitlements, invoices and the records our accountant needsTODO_ORDER_RECORD_RETENTION_PERIOD
Support correspondenceTODO_SUPPORT_MESSAGE_RETENTION_PERIOD
Mailing list subscriptionUntil you unsubscribe

Some of this is not ours to shorten. Dutch tax law sets a minimum retention period for business and invoice records, and that minimum governs the orders row above.

When a period expires the data is deleted or irreversibly anonymised. Deleting a licence record ends your ability to reactivate that licence, which is why the period for licence records is longer than the period for activation records.

11. Who processes data for us

We keep this list short on purpose.

ProcessorWhat they do for us
PaddleCheckout, payment, tax and invoicing, as merchant of record. Paddle is a controller in its own right for the payment transaction
Cloudflare, Inc.Hosting, CDN, database and file storage for the site and the licensing service
ScalewayTransactional email delivery
mail818Mailing list, operated by us
UmamiWebsite analytics, self hosted by us on our own infrastructure

We do not sell, rent or trade your personal data, and we do not share it for anyone else’s marketing.

12. Where your data is processed

Our infrastructure is chosen with European processing in mind. Some providers, notably Cloudflare and Paddle, operate globally and may process data outside the European Economic Area. Where that happens, the transfer relies on the safeguards in their data processing terms, such as the European Commission’s standard contractual clauses or an adequacy decision.

13. Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you and get a copy;
  • have inaccurate data corrected;
  • have your data erased, where we have no overriding obligation to keep it;
  • restrict or object to processing based on our legitimate interests;
  • receive your data in a portable format;
  • withdraw consent at any time, for anything based on consent, such as the mailing list.

To exercise any of these, email TODO_PRIVACY_EMAIL. We will respond within one month. We may ask you to confirm the email address on the account, because otherwise anyone could ask for someone else’s data.

Note that erasing your customer record also destroys your licence and its activation history. If you ask us to erase everything, we will tell you exactly what you are giving up before we do it.

If you think we have handled your data badly, please tell us first so we can fix it. You also have the right to complain to a supervisory authority: the data protection authority in the country where you live, or TODO_SUPERVISORY_AUTHORITY, which supervises us.

14. Security

Passwords are not a risk here because there are none: sign-in is by single use email link. Sessions are stored as hashes, sign-in tokens are stored as hashes, and machine fingerprints arrive already hashed. Traffic is encrypted in transit. Licence signing keys are held as secrets that no part of the website can read. Access to production data is limited to the people who operate the service.

No system is perfect. If you find a security problem, please report it to TODO_SUPPORT_EMAIL before publishing it, and we will work with you.

15. Children

Our products are not aimed at children, and we do not knowingly collect data from anyone under 16.

16. Changes to this policy

We will update this page when what we do changes, and the “last updated” date at the top tells you when we last did. If a change materially affects how we use data you have already given us, we will contact the customers concerned by email.

17. Contact

Privacy questions and requests: TODO_PRIVACY_EMAIL. Everything else: TODO_SUPPORT_EMAIL. Our full registered details are in the business details block below.

Business details

Registered name
TODO_REGISTERED_LEGAL_NAME
Trading as
Smoking Media
Legal form
besloten vennootschap (B.V.)
Registered address
TODO_STREET_AND_NUMBER, TODO_POSTAL_CODE TODO_CITY, TODO_COUNTRY
KvK number
TODO_KVK_NUMBER
VAT number
TODO_VAT_NUMBER
Email
TODO_SUPPORT_EMAIL
Website
smokingmedia.com
Terms and EULA Privacy policy Refund policy Support