Privacy Policy
This Privacy Policy explains how Stranis Audio ("Stranis", "we", "us") collects, uses, and shares personal data when you visit our website, create an account, or purchase our products. We are the data controller for the purposes of the EU/UK General Data Protection Regulation (GDPR). If you do not agree with this policy, please do not use our services.
1. Data we collect
- Account data — your email address and an encrypted (hashed) password, managed through our authentication provider (Supabase).
- Order & transaction data — products purchased, order references, amounts, promo codes, and payment-processor identifiers. We never see or store your full card number; card payments are handled directly by Stripe.
- License data — license keys issued to your account and your download history.
- Technical data — IP address, browser type, and server logs, processed by our hosting provider (Vercel) for security and operation.
- Communications — messages you send us through the contact form, email, or your account.
2. How we use your data
- To create and manage your account and deliver license keys and downloads;
- To process payments and issue receipts (via Stripe);
- To provide customer support and respond to your messages;
- To prevent fraud, abuse, and unauthorized access, and to enforce our terms;
- To comply with legal, tax, and accounting obligations;
- To send service messages (e.g., purchase confirmations). Marketing emails are sent only with your consent, and you can opt out at any time.
3. Legal bases for processing (GDPR)
- Performance of a contract — to provide the products and account you purchase;
- Legitimate interests — to secure our services, prevent fraud, and improve our products;
- Legal obligation — to meet tax and accounting requirements;
- Consent — for optional marketing communications, which you may withdraw at any time.
4. Who we share data with
We do not sell your personal data. We share it only with service providers ("processors") that help us operate, under appropriate data-processing agreements:
- Stripe — payment processing;
- Supabase — database, authentication, and storage;
- Vercel — website hosting and delivery;
- Authorities or advisors where required by law, or to protect our legal rights.
5. International data transfers
Our providers may process data in the United States and other countries. Where personal data of EU/UK residents is transferred outside the EEA/UK, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses.
6. Data retention
We keep account and license data for as long as your account is active and the license is valid. Transaction records are retained as required by tax and accounting law (typically several years). When data is no longer needed, we delete or anonymize it.
7. Your rights
Depending on where you live, you may have the right to:
- GDPR (EU/UK): access, correct, delete, restrict, or port your data; object to processing; withdraw consent; and lodge a complaint with your local data-protection authority.
- CCPA/CPRA (California): know what personal information we collect, request its deletion, and opt out of any "sale" or "sharing" of personal information. We do not sell or share your personal information. We will not discriminate against you for exercising these rights.
To exercise any right, contact us at support@stranis.com. We will respond within the timeframe required by law.
8. Cookies & local storage
We use strictly necessary cookies and browser local storage to keep you signed in and to operate the checkout. Stripe may set cookies needed for payment processing and fraud prevention. We do not use advertising cookies.
9. Security
We use industry-standard measures to protect your data, including encryption in transit, hashed passwords, and access controls. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
10. Children
Our services are not directed to children under 16, and we do not knowingly collect their personal data. If you believe a child has provided us data, contact us and we will delete it.
11. Changes to this policy
We may update this policy from time to time. We will post the new version here and update the "Last updated" date. Material changes will be communicated where required.
12. Contact
Data controller: Stranis Audio, 1907 Hendrickson St, New York, NY, USA. Privacy enquiries: support@stranis.com.