This policy covers smokingmedia.com, our store, our audio plugins and the emails we send you. It is written to be read, not to be survived, so it says plainly what we hold and why.
In short
- We store the minimum we need to sell you a plugin, deliver a licence, and let that licence work on up to 3 of your machines.
- We never see your card details. Paddle handles payments as merchant of record.
- The plugin sends us a hashed machine fingerprint. The raw machine identifier never leaves your computer.
- Our website analytics are cookieless and cannot identify you, which is why there is no cookie banner on this site.
- We never sell, rent or share your data for anyone else’s marketing.
- Buying something never subscribes you to a mailing list.
1. Who is responsible for your data
The controller for the personal data described here is TODO_REGISTERED_LEGAL_NAME, trading as Smoking Media, registered address TODO_STREET_AND_NUMBER, TODO_POSTAL_CODE TODO_CITY, TODO_COUNTRY, KvK number TODO_KVK_NUMBER.
For any privacy question or request, email TODO_PRIVACY_EMAIL.
2. When you buy a plugin
Our checkout is operated by Paddle, which acts as merchant of record and is the seller of record for the transaction. Your card number, expiry date and security code go to Paddle and its payment processors. They never reach our servers, and we could not retrieve them if we wanted to. Paddle’s own privacy notice governs that part of the transaction.
What Paddle passes on to us, and what we then store, is:
| Data | Why we store it |
|---|---|
| Your email address | To send your licence key, to identify your account when you sign in later, and it is shown inside the plugin on your licensed machines, so a shared key is visibly someone else’s |
| The products you bought | To create the right entitlement |
| The amount, the currency and the list price at the time | Accounting, and calculating upgrade credit later |
| Paddle’s transaction identifier | So a payment, a licence and a refund can be matched to each other |
| The date and time | Same |
Legal basis: performance of our contract with you (Article 6(1)(b) GDPR), and our legal obligation to keep business records (Article 6(1)(c) GDPR).
3. When you activate a plugin
This is the part people most want to know about, so here is the complete list. When you enter your licence key in the plugin, the plugin sends us, and we store:
| Data | What it actually is |
|---|---|
| Licence key | The key you entered, which identifies your entitlement |
| Machine fingerprint | A SHA-256 hash of a stable machine identifier combined with a product specific value. The raw machine identifier is hashed on your computer and never leaves it. We cannot reverse the hash back into a hardware identifier |
| Machine name | The name your computer reports, for example “Studio iMac”, so you can tell your machines apart on the account page when you need to deactivate one |
| Operating system string | For example “macos-15.2-arm64”, so support can reproduce a problem |
| Plugin version | Which build is running, for the same reason |
| IP address | The address the request came from, used for rate limiting and to detect key sharing and brute force attempts |
| User agent | The client string sent with the request, for the same reason |
| Timestamps | When the activation was created, when it was last seen, and when it was deactivated |
That is the whole list. We do not receive your audio, your projects, your presets, your file names, your MIDI, your plugin settings, or any usage telemetry. The plugin does not phone home while you work: after activation it verifies its licence file locally and only contacts us to refresh the lease or when you activate or deactivate a machine.
Data minimisation is a design requirement here, not a slogan. Each field above exists because a specific feature would break without it: the machine limit, the deactivate button, support, or abuse prevention.
Legal basis: performance of our contract with you (Article 6(1)(b) GDPR) for the activation itself, and our legitimate interest in preventing licence abuse (Article 6(1)(f) GDPR) for the IP address, the user agent and the abuse counters.
4. When you sign in to the account page
The account page has no passwords. You enter your email address, we email you a single use sign-in link that expires after 15 minutes, and clicking it creates a session.
We store the email address you entered, a hash of the sign-in token, the expiry and whether it has been used, and, for the session itself, your user agent and the times it was created and expires. Rate limiting counters keyed on your email address and IP address are held briefly so nobody can use the form to hammer our mail sender or to find out which addresses have accounts.
Legal basis: performance of our contract (Article 6(1)(b) GDPR) and legitimate interest in securing the service (Article 6(1)(f) GDPR).
5. Emails we send you
Transactional emails, meaning your licence key, your sign-in link and a redemption confirmation, are sent through Scaleway Transactional Email, a European email provider, acting as our processor. They receive your email address and the content of the message so they can deliver it.
We do not put tracking pixels in these emails, and we do not track whether you opened them.
6. The mailing list
Our mailing list is completely separate from everything above.
- It runs on mail818, our own mailing list service.
- It is opt-in and double opt-in: you enter your address, you receive a confirmation email, and nothing is sent to you until you click the link in it.
- Buying a plugin never subscribes you. There is no pre-ticked box anywhere in the checkout, and the purchase pipeline has no path into the list.
- Every message has an unsubscribe link, and unsubscribing removes your address.
Legal basis: your consent (Article 6(1)(a) GDPR), which you can withdraw at any time.
7. Website analytics
We use Umami, a privacy preserving analytics tool, running on our own infrastructure at track.exquex.com.
Umami is cookieless. It sets no cookie, stores nothing in your browser, and assigns no persistent identifier. It records aggregate page views, referrers and coarse country and device information, and it cannot follow you across sites or across sessions. We use it to see which product pages people reach and which links to us actually work.
Because no cookies or similar identifiers are stored on your device and no individual is identified, this site does not need, and does not show, a cookie consent banner.
We show no advertising on this site and we run no advertising trackers.
8. Cookies
We use exactly one cookie, and only if you sign in to the account page: a
session cookie that keeps you signed in for about 30 days. It is HttpOnly,
Secure and SameSite=Lax, it contains no personal data, and it exists solely
to remember that you completed a sign-in. That is a strictly necessary cookie
under the ePrivacy rules, so it needs no consent.
If you never sign in, this site sets no cookies at all.
9. When you contact support
If you email us, we hold your message, your email address and anything you chose to put in the message, for as long as we need it to help you and to keep a record of the case.
10. How long we keep things
| Data | Kept for |
|---|---|
| Activation records: hashed fingerprint, machine name, OS, plugin version, IP address, timestamps | TODO_ACTIVATION_RETENTION_PERIOD |
| Sign-in sessions and used or expired sign-in tokens | TODO_SESSION_RETENTION_PERIOD |
| Customer and licence records, after the last sign of activity | TODO_ACCOUNT_RETENTION_PERIOD |
| Orders, entitlements, invoices and the records our accountant needs | TODO_ORDER_RECORD_RETENTION_PERIOD |
| Support correspondence | TODO_SUPPORT_MESSAGE_RETENTION_PERIOD |
| Mailing list subscription | Until you unsubscribe |
Some of this is not ours to shorten. Dutch tax law sets a minimum retention period for business and invoice records, and that minimum governs the orders row above.
When a period expires the data is deleted or irreversibly anonymised. Deleting a licence record ends your ability to reactivate that licence, which is why the period for licence records is longer than the period for activation records.
11. Who processes data for us
We keep this list short on purpose.
| Processor | What they do for us |
|---|---|
| Paddle | Checkout, payment, tax and invoicing, as merchant of record. Paddle is a controller in its own right for the payment transaction |
| Cloudflare, Inc. | Hosting, CDN, database and file storage for the site and the licensing service |
| Scaleway | Transactional email delivery |
| mail818 | Mailing list, operated by us |
| Umami | Website analytics, self hosted by us on our own infrastructure |
We do not sell, rent or trade your personal data, and we do not share it for anyone else’s marketing.
12. Where your data is processed
Our infrastructure is chosen with European processing in mind. Some providers, notably Cloudflare and Paddle, operate globally and may process data outside the European Economic Area. Where that happens, the transfer relies on the safeguards in their data processing terms, such as the European Commission’s standard contractual clauses or an adequacy decision.
13. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you and get a copy;
- have inaccurate data corrected;
- have your data erased, where we have no overriding obligation to keep it;
- restrict or object to processing based on our legitimate interests;
- receive your data in a portable format;
- withdraw consent at any time, for anything based on consent, such as the mailing list.
To exercise any of these, email TODO_PRIVACY_EMAIL. We will respond within one month. We may ask you to confirm the email address on the account, because otherwise anyone could ask for someone else’s data.
Note that erasing your customer record also destroys your licence and its activation history. If you ask us to erase everything, we will tell you exactly what you are giving up before we do it.
If you think we have handled your data badly, please tell us first so we can fix it. You also have the right to complain to a supervisory authority: the data protection authority in the country where you live, or TODO_SUPERVISORY_AUTHORITY, which supervises us.
14. Security
Passwords are not a risk here because there are none: sign-in is by single use email link. Sessions are stored as hashes, sign-in tokens are stored as hashes, and machine fingerprints arrive already hashed. Traffic is encrypted in transit. Licence signing keys are held as secrets that no part of the website can read. Access to production data is limited to the people who operate the service.
No system is perfect. If you find a security problem, please report it to TODO_SUPPORT_EMAIL before publishing it, and we will work with you.
15. Children
Our products are not aimed at children, and we do not knowingly collect data from anyone under 16.
16. Changes to this policy
We will update this page when what we do changes, and the “last updated” date at the top tells you when we last did. If a change materially affects how we use data you have already given us, we will contact the customers concerned by email.
17. Contact
Privacy questions and requests: TODO_PRIVACY_EMAIL. Everything else: TODO_SUPPORT_EMAIL. Our full registered details are in the business details block below.