GDPR & Privacy Policy

Use of private information policy (GDPR)

Last updated

Summary

We respect the EU’s General Data Protection Regulations (GDPR) and this policy explains how we collect and treat any information you give us. This policy also applies to all US based customers as our general privacy policy. You won’t find any complicated legal terms or long passages of unreadable text. We’ve no desire to trick you into agreeing to something you might later regret.

Our policy covers

  1. Why we value your privacy
  2. How we collect information
  3. What information we hold
  4. Where we store your information
  5. What we use your information for
  6. Who’s responsible for your information at our company
  7. Who has access to information about you
  8. The steps we take to keep your information private
  9. Our apps, store & support
  10. How to complain
  11. Changes to the policy

Why we value your privacy

We value your privacy as much as we do our own, so we’re committed to keeping your personal and business information safe. We’re uncomfortable with the information companies, governments, and other organisations keep on file, so we ask for only the bare minimum from our customers. We’ll never use your personal information for any reason other than why you gave it, and we’ll never give anyone access to it unless we’re forced to by law.

How we collect information

We ask for contact information including your name, email address, and phone number, on our website so that we can reply to your enquiry. Our website doesn’t use cookies or scripts that were designed to track the websites you visit. We don’t use analytics or native social media ‘like’ or ‘sharing’ buttons which also build profiles of your internet activity. We ask for your account and contact information when you hire or buy something from us. Occasionally, we might receive your contact information from one of our partners. If we do, we protect it in exactly the same way as if you give it to us directly.

What information we hold

  • When you contact us by email or through our website, we collect your name, email address, phone number, and the company you work for, if you’ve given us that.
  • When you buy something from us, we collect your name, email address, phone number, and a delivery address.
  • If you do business with us, we also collect your business name and bank details and keep records of the invoices we send you and the payments you make.
  • All purchases are processed by Stripe, via our ecommerce platforms over https and we never have access to your credit card information.

Where we store your information

When you contact us by email or through our website, we store your information in Statamic CMS, our Customer Relationship Management (CRM) software. When you buy one of our apps, your order is handled by Stripe and your license is recorded on our own license server (see Our apps, store & support), and if we do business, we store your information in our accounts software, QuickBooks. We chose these systems partly for their commitment to security.

What we use your information for

We occasionally use your contact information to send you details of our products and services. When we do, you have the option to unsubscribe from these communications and we won’t send them to you again. We might also email or phone you about our products and services, but if you tell us not to, we won’t get in touch again. We will use your information to send you invoices, statements, or reminders. We never sell or give your information to 3rd parties for marketing or promotional purposes.

Who’s responsible for your information at our company

Me, your friendly website stuff developer, is responsible for the security of your information. You can contact me by email at blake.myers@xenoplexus.com or by phone at +1.614.417.1544 (USA) / +420.734.755.511 (EU) if you have any concerns about the information we store.

Who has access to information about you

When we store information in our own systems, only the people who need it have access. Our management team (me) have access to everything you’ve provided, but individual employees (there are none) have access to only what they need to do their job.

The steps we take to keep your information private

Where we store your information in third-party services, we restrict access only to people who need it (again, that’s just me). We store passwords in Keychain, an encrypted password manager, use a different, randomly generated password for each service, and never use the same password twice.

The computers we use are all protected by a passcode or fingerprint access. These computers ask for authentication whenever they’re started or after 5 minutes of inactivity. Our mobile devices are also protected by passcodes, fingerprint or facial recognition.

Our apps, store & support

Our Mac apps, our store and our support system use a few more services. This section explains what each one sees, why, and for how long we keep it.

License checks in our apps

Our paid apps check their license with our own license server at licenses.xenoplexus.com. When you activate a license, and again from time to time to renew it (about once a day while the app is open and online), the app sends:

  • your license key, and the app’s name and version;
  • a one-way coded identifier for your Mac, so a reinstall doesn’t use up a second seat (it is not your Mac’s serial number);
  • your Mac’s name, model and macOS version, so you can tell your Macs apart when you manage your seats.

A license check never includes your files or what you do in the app. The license server keeps your name, email address and organisation (if you gave one) from your purchase, your licenses and keys (stored encrypted), the Macs activated on each license with the dates they were activated and last checked in, and the license emails we’ve sent you. We use this only to provide and support your license, and we keep it for as long as your license exists, so you can reinstall, move and recover it. You can recover a lost key at licenses.xenoplexus.com/recover. What each app collects on its own is described on its page; Classroom Diaries has its own privacy policy.

Buying from our store

Our store sells our apps. Payment, and sales tax or VAT, are handled by Stripe, which acts as the merchant of record. At checkout Stripe collects your name, email address, billing address and payment details; we never see your card details. Stripe then tells our license server who bought what, so it can create your license and email you your key. Until you check out, your cart is kept in the store’s session cookie (see Cookies).

Email

We send email through Postmark: license keys, replies to support tickets and messages from our website. Email you send to support@xenoplexus.com also reaches us through Postmark.

Support tickets

When you open a ticket on our support page or email support@xenoplexus.com, we store your name, email address, the product and the app and macOS versions you tell us, your messages and any files you attach, in our own support database on our web server. If your question is about a license, we look up the licenses registered to your email address on our license server. We use all of this only to answer you. We keep resolved tickets for two years and then delete them; backups of the support database are kept for 30 days.

Notify me and beta sign-ups

When you ask us to tell you when an app is available, or to join a beta, we store your email address, the app and the time you asked, with your consent. We use it only to email you about that app’s release or beta. We delete it once we’ve sent that email, or after 12 months at the latest. You can withdraw your consent at any time by emailing blake.myers@xenoplexus.com, and we’ll delete your address.

Hosting

Our website and store are hosted by DreamHost in the United States. Messages from our contact form, notify-me sign-ups and support tickets are stored on that server. Stripe and Postmark are also based in the United States.

Cookies

Our website and store set only the two cookies they need to work: a session cookie and an XSRF-TOKEN cookie. Together they protect our forms from forgery, remember what’s in your store cart and show you the result after you send a form. They expire after a short period of inactivity. We don’t use analytics, advertising or tracking cookies.

How to complain

We take complaints very seriously. If you’ve any reason to complain about the ways we handle your privacy, please contact me by email at blake.myers@xenoplexus.com or by phone at +1.614.417.1544 (USA) / +420.734.755.511 (EU). If you’re the letter writing type, send your envelope to Xenoplexus Studios, 4061 Pepperwell Cir., Dayton, OH 45440.

Changes to the policy

If we change the contents of this policy, those changes will become effective the moment we publish them on our website.

Let’s make something.

Tell us about your website or app and we’ll get back to you within 24 hours.

Need help with an app or a license? Open a support ticket →

We reply within 24 hours on business days.