Legal

Privacy Notice

Effective 27 July 2026  ·  Last updated 27 July 2026

The short version

This summary is here to be helpful, not to replace the notice below.

Contents

  1. Who is responsible for your data
  2. What this notice covers
  3. What we collect, and when
  4. What we deliberately don't do
  5. Why we use it, and our legal bases
  6. Who we share it with
  7. International transfers
  8. How long we keep it
  9. How we protect it
  10. Your rights
  11. How to exercise your rights
  12. Rights in the EEA and UK
  13. Rights in US states
  14. Children
  15. Do Not Track and Global Privacy Control
  16. Security incidents
  17. Changes to this notice
  18. How to contact us

1Who is responsible for your data

Alex Ward, an individual doing business as Award Audio Tools, based in Texas, United States, is the controller of the personal information described here. That means we decide what is collected and why.

Contact for anything privacy-related: support@awardaudiotools.com. That address reaches a person, not a queue.

2What this notice covers

This notice applies to awardaudiotools.com, to buying our plugins, and to emailing us for support. It's written to be accurate about what actually happens rather than to cover every hypothetical, and we'll update it if that changes.

It does not cover the plugins themselves. Our plugins do not connect to the internet. They contain no telemetry, no usage analytics, no licence phone-home and no update checker. Once installed, they never send us anything, and we have no way to know how, when, or whether you use them.

It also doesn't cover third-party sites. When you click through to Stripe to pay, or to a storefront such as Gumroad, that company's own privacy policy governs what happens there.

3What we collect, and when

When you just browse the site

We collect nothing that identifies you, and we set no cookies. There is no analytics package, no visitor counter, no advertising pixel, no session storage and no fingerprinting.

Our host, Cloudflare, processes technical request data on our behalf so the site can be delivered and protected — your IP address, the page requested, your browser's user-agent string, timestamps, and network error reports. This is standard server infrastructure data. We use it only in aggregate, for security and to keep the site running; we don't use it to build a profile of you, and in the ordinary course we don't look at it at all.

When you buy a plugin

Checkout happens on Stripe's hosted pages, not ours. Stripe collects the payment details directly and acts as the payment processor.

DataWho collects itDo we see it?
Card number, expiry, CVCStripeNo — never. It does not touch our servers.
NameStripeYes, in the Stripe dashboard
Email addressStripeYes, in the Stripe dashboard
Billing address and countryStripeYes — needed for tax
Card brand and last four digitsStripeYes — for matching refunds and disputes
What you bought, the amount, the timeStripeYes
Fraud and risk signalsStripeOnly Stripe's summary score

We don't keep a customer database of our own. Stripe's dashboard is our record of sales.

When you download

After payment, our server asks Stripe whether that checkout session was paid, and if so issues a short-lived signed download link. That link contains only a product identifier and an expiry time — no personal information, no name and no email. We don't log who downloaded what.

When you email us

We receive your email address, your name if you give it, and whatever you write — typically a purchase reference and a description of a problem. We keep the thread so we can help you and so we have a record of the exchange.

What we never ask for

We don't ask for and don't want your date of birth, government ID, social security number, precise location, biometric or health data, racial or ethnic origin, religious or political beliefs, sexual orientation, or any other special-category or sensitive personal information. We do not knowingly process sensitive personal data at all, and we never sell it.

4What we deliberately don't do

Some of the strongest privacy statements are about absences, so here they are plainly. We do not:

• sell your personal information, and never have  • share it for cross-context behavioural advertising  • run advertising or retargeting of any kind  • use analytics or tracking cookies  • load third-party scripts, fonts or embeds  • build profiles or make automated decisions with legal or similarly significant effects  • run a marketing mailing list  • require an account  • put telemetry in our plugins.

If any of that ever changes, we'll update this notice before it does, and where the law requires your consent we'll ask for it first.

5Why we use it, and our legal bases

If you're in the EEA or UK, the GDPR requires us to name a legal basis for each use. Here they are.

What we doData involvedLegal basis
Take payment and deliver your downloadOrder and contact dataPerformance of a contract (Art. 6(1)(b))
Answer your support emailsEmail correspondencePerformance of a contract, or our legitimate interest in helping people who write to us (Art. 6(1)(b), (f))
Issue refunds and handle disputesOrder dataPerformance of a contract and legal obligation (Art. 6(1)(b), (c))
Keep the site up and block abuseTechnical request dataLegitimate interest in the security and availability of our service (Art. 6(1)(f))
Prevent payment fraudOrder and risk dataLegitimate interest in preventing fraud; legal obligation (Art. 6(1)(f), (c))
Keep tax and accounting recordsTransaction recordsLegal obligation (Art. 6(1)(c))
Establish or defend a legal claimWhatever is relevantLegitimate interest in defending ourselves (Art. 6(1)(f))

Where we rely on legitimate interests, we've considered whether our interest is overridden by your rights and concluded it isn't, given how little data is involved and how narrowly it's used. You can object at any time — see section 12.

We don't currently rely on consent for anything, because we don't do the things that would require it.

6Who we share it with

We don't sell, rent or trade personal information. We share it only with the small number of service providers needed to run the business, each of which is contractually bound to use it only on our instructions:

ProviderWhat they doWhat they handle
Stripe, Inc. (USA)Payment processing, fraud prevention, refundsPayment and contact details. Stripe is also an independent controller for fraud prevention and legal compliance, under its own privacy policy.
Cloudflare, Inc. (USA)Hosting, CDN, DDoS protection, file storage and delivery, email routingTechnical request data; inbound support email in transit
Google LLC (USA)The mailbox where support email is readSupport correspondence
Gumroad, Inc. (USA)Alternative storefront for some products, where usedOrder and contact data for purchases made there, under its own policy

Beyond that, we may disclose information only where we're legally required to — a valid subpoena, court order or lawful government request — or where we need to establish, exercise or defend a legal claim, or to prevent fraud or harm. If our business is ever sold, merged, or reorganised (including being incorporated into a limited liability company), records may transfer to the successor, which would remain bound by this notice.

We'll tell you about a legal demand for your data unless we're prohibited from doing so.

7International transfers

We're based in the United States, and our providers are US companies, so if you're outside the US your information will be processed in the US and possibly other countries where those providers operate. Privacy laws there differ from your own.

For customers in the EEA, UK or Switzerland: when you buy from us, the transfer is necessary to perform the contract you asked us to enter into (GDPR Art. 49(1)(b)) — we can't deliver you software without it. Separately, our processors maintain their own transfer safeguards, including the European Commission's Standard Contractual Clauses and, where applicable, certification under the EU–US, UK and Swiss–US Data Privacy Frameworks. You can ask us for details of the safeguards that apply to you.

8How long we keep it

RecordKept forWhy
Transaction records in StripeUp to 7 years from the transactionTax, accounting and audit obligations, and the window for chargebacks and claims
Support email threadsNormally up to 3 years, then deletedSo we can pick up where we left off, and to evidence what was agreed
Technical request data at CloudflareShort-term, per Cloudflare's own retention scheduleSecurity and diagnostics
Download linksMinutes. They expire and are never storedThey hold no personal data in the first place

Where we're required to keep something for tax or legal reasons, we keep it for that period even if you ask us to delete it — but we'll restrict it to that purpose and tell you when we do.

9How we protect it

The site is served over HTTPS only. Payment data goes directly to Stripe, a PCI-DSS Level 1 certified provider, and never reaches our systems. Download links are cryptographically signed, single-purpose and short-lived, so a leaked link can't be reused or altered to fetch a different file. Access to the Stripe dashboard and the support mailbox is limited to the owner and protected by multi-factor authentication.

No system is perfectly secure, and we can't guarantee absolute security — but we hold very little about you in the first place, which is the most effective protection there is.

10Your rights

Wherever you live, you can ask us to:

  • Tell you what personal information we hold about you and give you a copy;
  • Correct anything that's wrong;
  • Delete what we hold, subject to records we must keep by law;
  • Restrict or object to how we use it;
  • Port it — receive it in a portable, machine-readable format;
  • Complain to us or to a regulator.

We extend these to every customer, not just those whose law requires it. Exercising them costs nothing and we won't discriminate against you for it — no price change, no reduced support, no loss of access.

11How to exercise your rights

Email support@awardaudiotools.com and say what you want. If you can, write from the address you used at checkout — it's the simplest way for us to find your records and to be confident you are who you say you are. We may ask one or two follow-up questions to verify that, and we won't use anything you send for verification for any other purpose.

We'll respond within 45 days, and within 30 days for requests under the GDPR or UK GDPR. If a request is genuinely complex we may extend that once, and we'll tell you why before we do. An authorised agent may act for you if you give them written permission we can verify.

Appeals. If we refuse your request, we'll explain why, and you may appeal by replying with the word "Appeal" in the subject line. We'll review it and give you a written decision within 60 days. If we deny the appeal, we'll tell you how to complain to your regulator — for Texas residents, the Office of the Texas Attorney General.

12Rights in the EEA and UK

If the GDPR or UK GDPR applies to you, you have the rights in section 10 plus the right to withdraw consent where we rely on it (we currently don't), and the right not to be subject to automated decision-making producing legal or similarly significant effects (we don't do that either).

Right to object. Where we process on legitimate interests, you can object at any time and we'll stop unless we can show compelling grounds that override your rights.

Complaints. You may lodge a complaint with your local supervisory authority — in the UK, the Information Commissioner's Office (ico.org.uk); in the EEA, your national data protection authority. We'd appreciate the chance to put it right first.

We are a very small business with no EU or UK establishment, and given the limited scale and nature of our processing we have not appointed an Article 27 representative or a Data Protection Officer. Write to us directly and we'll deal with it ourselves.

13Rights in US states

Several US states — including Texas, California, Colorado, Connecticut, Virginia, Utah, Oregon, Montana and others — give residents privacy rights. Most of those laws apply only to businesses above a size or revenue threshold, and as a small sole proprietorship we fall below them; the Texas Data Privacy and Security Act, for example, exempts small businesses as defined by the US Small Business Administration.

We honour these requests anyway, from residents of any state, as a matter of policy rather than obligation. Use section 11 to make one.

Statements these laws ask for, all of which are true of us:

We do not sell personal data, and have not in the preceding 12 months. • We do not share personal data for cross-context behavioural advertising or targeted advertising. • We do not sell sensitive personal data — we don't collect any. • We do not profile you in furtherance of decisions producing legal or similarly significant effects. • There is therefore no "Do Not Sell or Share My Personal Information" mechanism to offer you, because there is nothing to opt out of.

California residents: the categories in section 3 correspond to CCPA categories A (identifiers), B (customer records), D (commercial information) and F (internet activity), collected for the business purposes in section 5, disclosed only to the service providers in section 6, and retained per section 8. You also have the right to know, delete, correct, and to be free from retaliation, all of which we honour. We do not offer financial incentives for personal information.

14Children

The site isn't directed to children under 13 and we don't knowingly collect their personal information. If you believe a child under 13 has provided us with personal information, email us and we'll delete it promptly. Buyers must meet the age requirement in our Terms of Use.

15Do Not Track and Global Privacy Control

Some browsers send a "Do Not Track" or Global Privacy Control signal. There's no industry consensus on DNT, but the point is moot here: we don't track you, set cookies, or sell or share data, so both signals are effectively honoured by default no matter what your browser sends.

16Security incidents

If a breach affects your personal information, we'll notify you and the relevant authorities as required by law — including under Texas Business & Commerce Code § 521.053 and, where the GDPR applies, within 72 hours of becoming aware of it. We'll tell you what happened, what was affected, and what to do about it, without unreasonable delay.

17Changes to this notice

If our practices change, we'll update this page and change the "Last updated" date. For a material change — particularly one that expands what we collect or how we use it — we'll make it prominent, and where the law requires consent we'll ask before the change takes effect rather than after.

18How to contact us

Award Audio Tools
Alex Ward, sole proprietor
Texas, United States
support@awardaudiotools.com

Privacy questions, data requests and complaints all go to that address. If you need our full mailing address for a formal notice, ask and we'll provide it.