1. Controller
The controller responsible for the processing described in this policy is:
Jochen Abitz Webdesign
Owner: Jochen Abitz
Alstrupvej 20
9700 Brønderslev
Denmark
CVR: 44189348
Email: support@stackswork.com
2. Scope and principles
This policy applies when you visit stackswork.com, buy or download a product, use a stackswork licence-enabled product, request a download list, subscribe to the newsletter, submit a review, or contact support.
We process only data needed to operate the website, deliver products, manage licences, communicate with you, prevent abuse, and meet legal obligations. We do not sell personal data and do not use it for third-party advertising.
3. Website delivery and server logs
When you request a page, the web server necessarily processes technical data such as your IP address, the requested URL, date and time, response status, referrer, and browser or user-agent information. This is used to deliver the website, maintain security, diagnose errors, and prevent misuse.
The legal basis is our legitimate interest in providing a secure and reliable website (Article 6(1)(f) GDPR). Log data is deleted or anonymised when it is no longer needed for security and error analysis, unless a specific incident requires longer retention.
4. Cookie-free website statistics
We use a self-hosted Rybbit instance to understand how the website is used. The analytics service runs on infrastructure controlled by us. It does not use analytics cookies or browser local storage and does not track visitors across unrelated websites.
For anonymous usage statistics, Rybbit processes information such as visited URLs and page titles, referrer, browser and device category, operating system, screen size, approximate country or region, entry and exit pages, session duration, and campaign parameters. The IP address is used temporarily to derive approximate location and a pseudonymous visitor or session identifier; the raw IP address is not stored in the analytics database. Visitor identifiers are salted daily so that visitors are not recognised across different days.
We use Rybbit only for ordinary website statistics. We do not use its identify-user function or session replay on stackswork.com. Analytics data remains in our self-hosted installation and is retained only for as long as needed to evaluate website use and technical performance, after which it is deleted or aggregated. The legal basis is our legitimate interest in improving the website and identifying technical problems (Article 6(1)(f) GDPR). Further technical information is available in Rybbit's privacy documentation.
5. Shopping cart, prices, and Paddle checkout
The shopping cart is stored in your browser's local storage so that your selection remains available while you navigate the site. You can remove it by emptying the cart or clearing the website data in your browser.
We use Paddle.js to show localised prices and provide checkout. Paddle is the authorised reseller and Merchant of Record for purchases. When Paddle.js loads or you request a price preview or checkout, Paddle may process technical request data, cart and product identifiers, and the information you enter during checkout.
Paddle handles payment details, taxes, invoices, refunds, and the purchase transaction under its own terms and privacy notice. We do not receive your complete card or payment-account details. Paddle provides us with fulfilment data such as your email address, customer and transaction identifiers, purchased products, transaction status, and any marketing consent required to deliver and support your purchase.
Processing for delivery, licensing, and purchase support is based on performance of the product agreement (Article 6(1)(b) GDPR). Accounting or compliance records are processed where required by law (Article 6(1)(c) GDPR), and fraud prevention and operational records are based on legitimate interests (Article 6(1)(f) GDPR). See Paddle's Privacy Notice.
6. Downloads and product licensing
For purchased downloads, we store the purchase email, Paddle customer and transaction identifiers, product identifiers, an encrypted download token and its hash, download limits and counts, status, and delivery timestamps. This lets us deliver the purchase, restore active download links, and disable access after refunds or chargebacks.
For products that use licence activation, we may additionally process the licence key, product or app identifier, device identifier and device name, app version, seat limit, activation status, and first and last activation times. This is required to issue, validate, restore, and deactivate the licence.
These records are kept for the active life of the purchase or licence and afterwards where needed for statutory records, refund or chargeback handling, security, and the establishment or defence of legal claims.
7. Download recovery
If you request a download list on the Support page, we use the email address you enter to look up active purchase entitlements and send the requested message. The public response never confirms whether an address is linked to a purchase.
For abuse prevention, rate limits use hashed identifiers derived from the email address and IP address. The request is also protected with Cloudflare Turnstile as described below. The legal basis is performance of the product agreement and your request (Article 6(1)(b) GDPR), together with our legitimate interest in preventing misuse (Article 6(1)(f) GDPR).
8. Newsletter
When you subscribe, we process your email address, consent, confirmation status, and subscription history in our self-hosted Sendy newsletter system. We use double opt-in: the subscription is activated only after you confirm the link sent to your email address. If you expressly opt in during Paddle checkout, Paddle may pass that consent and email address to us for the same purpose.
The legal basis is your consent (Article 6(1)(a) GDPR). You can withdraw it at any time through the unsubscribe link in every newsletter. The email address is then removed from active mailing and may remain on a suppression list only to ensure that no further newsletter is sent against your choice. Other purchase records remain unaffected.
9. Product reviews
When you submit a review, we process your name, email address, rating, review text, selected product, and moderation status. Reviews are saved as drafts and reviewed before publication. If approved, the name, rating, and review text are published; the email address is never displayed publicly. We also send a submission confirmation and an internal moderation notice.
We process the review based on your request and our legitimate interest in publishing authentic product feedback and preventing abuse (Article 6(1)(f) GDPR). Published reviews are retained while they remain relevant. You may ask us to remove or anonymise your review.
10. Cloudflare Turnstile
Review and download-recovery forms use Cloudflare Turnstile to distinguish legitimate submissions from automated abuse. The Turnstile script is loaded when you open one of these forms. Cloudflare receives the challenge data and, during server-side validation, the token and your IP address. Tokens are short-lived and single-use.
The legal basis is our legitimate interest in protecting public forms and customer data from spam and abuse (Article 6(1)(f) GDPR). See Cloudflare's Privacy Policy.
11. Support and email communication
If you contact us, we process your email address, name if supplied, message, attachments, and any information required to answer the request. Messages sent to support@stackswork.com are routed directly to ThriveDesk, the help-desk service we use to organise and answer support conversations.
Purchase-related support is processed for contract performance (Article 6(1)(b) GDPR); other enquiries are processed on the basis of our legitimate interest in responding efficiently (Article 6(1)(f) GDPR). Messages are retained until the request is resolved and then only as long as needed for follow-up, statutory obligations, or legal claims. See ThriveDesk's Privacy Policy.
12. Recipients and international processing
Data is disclosed only where necessary to service providers involved in hosting, email delivery, customer support, security, or payment and purchase fulfilment, and to public authorities where legally required. Paddle, Cloudflare, and ThriveDesk may process data outside the European Economic Area. Their privacy notices describe the relevant locations and transfer safeguards. Rybbit analytics data remains in our self-hosted installation.
13. Your rights
Subject to the conditions in applicable data-protection law, you may request access, correction, deletion, restriction, or portability of your personal data. You may object to processing based on legitimate interests and withdraw consent at any time for future processing.
To exercise a right, email support@stackswork.com. We may need enough information to verify that the request concerns your data. You may also lodge a complaint with the Danish supervisory authority, Datatilsynet.
14. Security and policy updates
We use technical and organisational measures appropriate to the nature of the data, including encrypted connections, access controls, protected download links, hashed rate-limit identifiers, and server-side form validation. No internet service can guarantee absolute security.
We update this policy when services or processing activities change. The review date shown at the top identifies the current version.