Privacy Policy
Effective date: 24 August 2026
Data controller: Mark Julien Hahn / Softdrive Foundry Görlitzer Straße 52, 10997 Berlin, Germany Email: privacy@softdrivefoundry.com
We are not required to appoint a Data Protection Officer under Art. 37 GDPR. For all privacy-related inquiries, please contact us at privacy@softdrivefoundry.com.
This Privacy Policy explains how Softdrive Foundry ("we", "us", or "our") collects, uses, shares, and protects your personal data when you use our website and services. It applies to all users, including visitors, customers, and newsletter subscribers.
We are committed to privacy by design and comply with the General Data Protection Regulation (GDPR, EU 2016/679) and the German Telekommunikation-Digitale-Dienste-Datenschutz-Gesetz (TDDDG).
1. What data we collect
Personal data you provide directly
We collect the following data when you actively provide it to us:
Name, email, billing/shipping address
- Purpose: Order fulfillment, license delivery, and customer support
- Legal basis: Contract (Art. 6(1)(b) GDPR)
- Retention: 10 years (tax and accounting obligations)
Payment information (via Stripe)
- Purpose: Payment processing
- Legal basis: Contract (Art. 6(1)(b) GDPR)
- Retention: Not stored by us — Stripe retains this according to their own policy
Account registration details
- Purpose: User account management
- Legal basis: Contract (Art. 6(1)(b) GDPR)
- Retention: Until account deletion
Newsletter signup (email)
- Purpose: Sending newsletters and updates
- Legal basis: Consent (Art. 6(1)(a) GDPR)
- Retention: Until consent is withdrawn
Note: We never receive or retain full card numbers. Payment data is processed entirely by Stripe Payments Europe, Ltd. under a signed Data Processing Agreement (DPA) with EU Standard Contractual Clauses (SCCs).
Data collected automatically
Server logs (IP address, browser/device info, request timestamp)
- Purpose: Security monitoring, abuse prevention, and troubleshooting
- Legal basis: Legitimate interest (Art. 6(1)(f) GDPR)
- Retention: 7 days (automatically deleted)
session cookie
- Purpose: Maintains your logged-in state
- Legal basis: Strictly necessary (§ 25(2) TDDDG)
- Retention: 7 days
admin_session cookie
- Purpose: Maintains the site owner's admin access
- Legal basis: Strictly necessary (§ 25(2) TDDDG)
- Retention: Until sign-out
Local storage (shopping cart)
- Purpose: Stores cart contents between visits
- Legal basis: Strictly necessary (§ 25(2) TDDDG)
- Retention: Until checkout or manual clearance
Why we collect this:
- Server logs help us detect and prevent attacks, monitor performance, and debug issues. We retain them for 7 days — the minimum necessary for security purposes — and then permanently delete them.
- Cookies and local storage are strictly necessary for core functionality (login, cart). No other cookies or trackers are used.
Analytics data (Umami)
We use Umami, a privacy-focused analytics tool that does not use cookies and does not store IP addresses. Umami is hosted in the EU and covered by a signed DPA with SCCs.
Umami collects the following aggregate, non-personal data:
- Pages visited and referral source
- Approximate country (derived from IP, then discarded)
- Browser, operating system, device type, and screen size
- Page loading performance metrics
- Aggregate interactions (e.g. cart additions, checkout starts, purchases, trial font requests)
How Umami works:
- Your IP address is used only in passing to generate a short-lived, random hash (to count unique visits).
- The hash cannot identify you across days or websites.
- No cookies are set, no profiles are built, and no data is shared with advertisers.
- Sensitive URL parameters (e.g. email verification tokens) are stripped in your browser before any data is sent.
- We honor your browser's "Do Not Track" setting.
Your control: You can opt out of analytics at any time via /analytics-opt-out. This stores one value in your browser's local storage to remember your choice (no cookies are used).
Legal basis: Legitimate interest (Art. 6(1)(f) GDPR). Our interest is in understanding site usage to improve our services, without compromising your privacy. You may object at any time via the opt-out link above.
Data from third parties
We receive data from the following trusted processors under signed DPAs with SCCs where applicable:
Stripe Payments Europe, Ltd.
- Data received: Payment details (no full card numbers)
- Purpose: Payment processing
- Location: Ireland / USA
Resend, Inc.
- Data received: Email delivery status
- Purpose: Transactional emails and newsletters
- Location: USA
Vercel Inc.
- Data received: Hosting logs
- Purpose: Website hosting
- Location: USA / EU
Sanity AS
- Data received: Site content and associated metadata
- Purpose: CMS hosting
- Location: Norway / USA
Umami Software, Inc.
- Data received: Analytics data (as described above)
- Purpose: Website analytics
- Location: EU (hosting region)
Note: All transfers to non-EU/EEA providers are covered by signed Data Processing Agreements (DPAs) incorporating the EU Standard Contractual Clauses (Art. 46 GDPR).
2. How we use your data
Order fulfillment (licenses, deliveries)
- Data used: Name, email, address, payment info
- Legal basis: Contract (Art. 6(1)(b) GDPR)
Customer account management
- Data used: Registration details
- Legal basis: Contract (Art. 6(1)(b) GDPR)
Newsletter delivery
- Data used: Email address
- Legal basis: Consent (Art. 6(1)(a) GDPR)
Website analytics (Umami)
- Data used: Aggregate usage data (no personal data)
- Legal basis: Legitimate interest (Art. 6(1)(f) GDPR)
Security and abuse prevention
- Data used: Server logs (IP, browser, etc.)
- Legal basis: Legitimate interest (Art. 6(1)(f) GDPR)
Tax and accounting compliance
- Data used: Purchase data
- Legal basis: Legal obligation (Art. 6(1)(c) GDPR)
3. Legal basis for processing
We process your data only when we have a lawful basis under GDPR:
- Contract (Art. 6(1)(b)): Processing necessary to fulfill orders, deliver licenses, or manage your account.
- Consent (Art. 6(1)(a)): For newsletter subscriptions. You can withdraw at any time via the unsubscribe link.
- Legal obligation (Art. 6(1)(c)): For tax, accounting, and regulatory compliance (e.g. retaining purchase records for 10 years).
- Legitimate interest (Art. 6(1)(f)): For cookieless analytics (Umami) and server security. Our interest is in understanding how the site is used, so we can improve it, and in protecting the site from abuse and attacks.
We pursue these interests without:
- Cookies, except strictly necessary ones
- Cross-site tracking
- Storing IP addresses in analytics
- Building user profiles
You may object to this processing at any time — via /analytics-opt-out for analytics, or by contacting us at privacy@softdrivefoundry.com for server logs.
4. Sharing data with third parties
We never sell your personal data to third parties. Data is shared only with the processors below, who act under our instructions and signed DPAs with SCCs where applicable:
- Stripe Payments Europe, Ltd. — Payment processing. Ireland / USA. DPA + SCCs in place.
- Resend, Inc. — Transactional emails and newsletters. USA. DPA + SCCs in place.
- Vercel Inc. — Website hosting. USA / EU. DPA + SCCs in place.
- Sanity AS — Content management, including images served via cdn.sanity.io. Norway / USA. DPA + SCCs in place.
- Umami Software, Inc. — Website analytics. EU hosting. DPA + SCCs in place.
Additional safeguards:
- Our typefaces are self-hosted. We use no Google Fonts and no third-party CDNs for fonts.
- We do not load any advertising, social media, or external tracking scripts.
- All processors are contractually obligated to protect your data and to assist us with your rights requests (e.g. access, deletion).
5. Cookies and tracking technologies
What we do not use
- No tracking cookies (e.g. for ads or analytics)
- No advertising cookies (e.g. Google Ads, Facebook Pixel)
- No analytics cookies — Umami uses zero cookies
- No third-party trackers (e.g. Google Analytics, social media widgets)
Result: This website does not display a cookie banner, because nothing we use requires your consent under § 25 TDDDG or the GDPR. All cookies we use are strictly necessary for functionality you have requested (§ 25(2) TDDDG).
Cookies we use
session
- Purpose: Keeps you signed in to your customer account
- Duration: 7 days
- Legal basis: Strictly necessary (§ 25(2) TDDDG)
admin_session
- Purpose: Keeps the site owner signed in to the admin area
- Duration: Until sign-out
- Legal basis: Strictly necessary (§ 25(2) TDDDG)
Other local storage
- Shopping cart: Stored in your browser's local storage (not a cookie) and not transmitted to us until you start checkout.
- Analytics opt-out: If you disable analytics via /analytics-opt-out, one value is stored in your browser's local storage to remember your choice.
6. Data retention
We retain your data only for as long as necessary for the purposes described in this policy:
- Server logs — 7 days. Kept for security monitoring and abuse prevention.
- Purchase records — 10 years. Required by German tax and accounting law.
- Customer accounts — Until you delete the account. Kept for account management.
- Newsletter subscribers — Until you withdraw consent. Consent-based processing.
- Analytics data (Umami) — 30 days for raw data, aggregated data indefinitely. Raw data is anonymized.
Automatic deletion: Server logs and session cookies are automatically deleted after their retention periods. You can delete your account or unsubscribe from newsletters at any time.
7. Your rights under GDPR
You have the following rights regarding your personal data. To exercise any of them, contact us at privacy@softdrivefoundry.com. We will respond within one month, extendable to three months for complex requests.
Right to access (Art. 15 GDPR)
Request a copy of the personal data we hold about you, including:
- The purposes of processing
- The categories of data concerned
- The recipients or categories of recipients to whom your data has been disclosed
- The envisaged retention period
Right to rectification (Art. 16 GDPR)
Request correction of inaccurate or incomplete data about you.
Right to erasure — "right to be forgotten" (Art. 17 GDPR)
Request deletion of your data if:
- It is no longer necessary for the purposes for which it was collected
- You withdraw consent and there is no other legal basis
- You object to processing and there are no overriding legitimate grounds
- The data was processed unlawfully
Exceptions: we may retain data to comply with legal obligations, such as tax records, or to establish, exercise, or defend legal claims.
Right to restriction of processing (Art. 18 GDPR)
Request that we temporarily restrict processing of your data while we verify the accuracy of contested data, or determine whether we have overriding legitimate grounds for processing after you object.
Right to data portability (Art. 20 GDPR)
Request your data in a structured, commonly used, machine-readable format such as JSON or CSV. This covers data you provided to us — for example account details and purchase history — that we process under consent or contract.
Right to object (Art. 21 GDPR)
Object to processing based on legitimate interest, such as analytics and server logs. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests.
- For Umami analytics: object instantly via /analytics-opt-out.
- For server logs: contact us at privacy@softdrivefoundry.com. We will review your request and comply unless retention is legally required.
Right to withdraw consent (Art. 7(3) GDPR)
Withdraw your consent for newsletter subscriptions at any time via the unsubscribe link in any email, or by contacting us.
Rights related to automated decision-making (Art. 22 GDPR)
You have the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal effects or significantly affects you. We do not use automated decision-making in this way.
8. Data security
We implement technical and organizational measures to protect your data from unauthorized access, disclosure, alteration, or destruction.
Technical measures
- Encryption: All data in transit (HTTPS/TLS) and at rest where applicable.
- Access controls: Strict role-based access to personal data.
- Regular reviews: Periodic reviews of data processing activities and security practices.
- Secure hosting: Website hosted on Vercel with industry-standard security.
Organizational measures
- Data minimization: We collect only what is necessary.
- Processor contracts: All third parties operate under signed DPAs with SCCs where applicable.
- Incident response: We will notify you without undue delay, and within 72 hours where required, if a data breach is likely to result in a high risk to your rights and freedoms.
9. International data transfers
Some of our processors — Stripe, Resend, Vercel, Sanity — may process data outside the EU/EEA. All such transfers are protected by signed Data Processing Agreements incorporating the EU Standard Contractual Clauses (Art. 46 GDPR). Where required, we assess the risk of transfers to countries without an EU adequacy decision, such as the USA, and implement supplementary measures.
- Stripe Payments Europe, Ltd. — SCCs, contracting via the Irish entity. Low risk: primary processing takes place in the EU.
- Resend, Inc. — SCCs. Medium risk: USA-based.
- Vercel Inc. — SCCs, with EU hosting option. Low risk: data can be hosted in the EU.
- Sanity AS — SCCs, contracting via the Norwegian entity. Low risk: primary processing takes place in the EU/Norway.
- Umami Software, Inc. — SCCs, with EU hosting. Low risk: hosted in the EU.
10. Children's privacy
Our services are not directed at children under 16. We do not knowingly collect personal data from children. If you are a parent or guardian and believe we have collected data from your child, contact us at privacy@softdrivefoundry.com and we will promptly delete it.
11. Changes to this policy
We may update this Privacy Policy to reflect changes in our practices or legal requirements. If we make material changes, we will post the updated policy on this page with a new effective date, and notify you by email if you have an account, or via a prominent notice on our website.
Your continued use of our services after the effective date constitutes acceptance of the changes.
12. Contact
For questions, requests, or complaints regarding this policy or your data:
Mark Julien Hahn / Softdrive Foundry
Görlitzer Straße 52, 10997 Berlin, Germany
privacy@softdrivefoundry.com
Supervisory authority
You have the right to lodge a complaint with a data protection authority, in particular in the EU member state of your habitual residence, place of work, or place of the alleged infringement. The authority responsible for us is the Berliner Beauftragte für Datenschutz und Informationsfreiheit, Alt-Moabit 59–61, 10555 Berlin.