1Who is responsible for your data
Alex Ward, an individual doing business as Award Audio Tools, based in Texas, United States, is the controller of the personal information described here. That means we decide what is collected and why.
Contact for anything privacy-related: support@awardaudiotools.com. That address reaches a person, not a queue.
2What this notice covers
This notice applies to awardaudiotools.com, to buying our plugins, and to emailing us for support. It's written to be accurate about what actually happens rather than to cover every hypothetical, and we'll update it if that changes.
It does not cover the plugins themselves. Our plugins do not connect to the internet. They contain no telemetry, no usage analytics, no licence phone-home and no update checker. Once installed, they never send us anything, and we have no way to know how, when, or whether you use them.
It also doesn't cover third-party sites. When you click through to Stripe to pay, or to a storefront such as Gumroad, that company's own privacy policy governs what happens there.
3What we collect, and when
When you just browse the site
We collect nothing that identifies you, and we set no cookies. There is no analytics package, no visitor counter, no advertising pixel, no session storage and no fingerprinting.
Our host, Cloudflare, processes technical request data on our behalf so the site can be delivered and protected — your IP address, the page requested, your browser's user-agent string, timestamps, and network error reports. This is standard server infrastructure data. We use it only in aggregate, for security and to keep the site running; we don't use it to build a profile of you, and in the ordinary course we don't look at it at all.
When you buy a plugin
Checkout happens on Stripe's hosted pages, not ours. Stripe collects the payment details directly and acts as the payment processor.
| Data | Who collects it | Do we see it? |
|---|---|---|
| Card number, expiry, CVC | Stripe | No — never. It does not touch our servers. |
| Name | Stripe | Yes, in the Stripe dashboard |
| Email address | Stripe | Yes, in the Stripe dashboard |
| Billing address and country | Stripe | Yes — needed for tax |
| Card brand and last four digits | Stripe | Yes — for matching refunds and disputes |
| What you bought, the amount, the time | Stripe | Yes |
| Fraud and risk signals | Stripe | Only Stripe's summary score |
We don't keep a customer database of our own. Stripe's dashboard is our record of sales.
When you download
After payment, our server asks Stripe whether that checkout session was paid, and if so issues a short-lived signed download link. That link contains only a product identifier and an expiry time — no personal information, no name and no email. We don't log who downloaded what.
When you email us
We receive your email address, your name if you give it, and whatever you write — typically a purchase reference and a description of a problem. We keep the thread so we can help you and so we have a record of the exchange.
What we never ask for
We don't ask for and don't want your date of birth, government ID, social security number, precise location, biometric or health data, racial or ethnic origin, religious or political beliefs, sexual orientation, or any other special-category or sensitive personal information. We do not knowingly process sensitive personal data at all, and we never sell it.
4What we deliberately don't do
Some of the strongest privacy statements are about absences, so here they are plainly. We do not:
• sell your personal information, and never have • share it for cross-context behavioural advertising • run advertising or retargeting of any kind • use analytics or tracking cookies • load third-party scripts, fonts or embeds • build profiles or make automated decisions with legal or similarly significant effects • run a marketing mailing list • require an account • put telemetry in our plugins.
If any of that ever changes, we'll update this notice before it does, and where the law requires your consent we'll ask for it first.
5Why we use it, and our legal bases
If you're in the EEA or UK, the GDPR requires us to name a legal basis for each use. Here they are.
| What we do | Data involved | Legal basis |
|---|---|---|
| Take payment and deliver your download | Order and contact data | Performance of a contract (Art. 6(1)(b)) |
| Answer your support emails | Email correspondence | Performance of a contract, or our legitimate interest in helping people who write to us (Art. 6(1)(b), (f)) |
| Issue refunds and handle disputes | Order data | Performance of a contract and legal obligation (Art. 6(1)(b), (c)) |
| Keep the site up and block abuse | Technical request data | Legitimate interest in the security and availability of our service (Art. 6(1)(f)) |
| Prevent payment fraud | Order and risk data | Legitimate interest in preventing fraud; legal obligation (Art. 6(1)(f), (c)) |
| Keep tax and accounting records | Transaction records | Legal obligation (Art. 6(1)(c)) |
| Establish or defend a legal claim | Whatever is relevant | Legitimate interest in defending ourselves (Art. 6(1)(f)) |
Where we rely on legitimate interests, we've considered whether our interest is overridden by your rights and concluded it isn't, given how little data is involved and how narrowly it's used. You can object at any time — see section 12.
We don't currently rely on consent for anything, because we don't do the things that would require it.
6Who we share it with
We don't sell, rent or trade personal information. We share it only with the small number of service providers needed to run the business, each of which is contractually bound to use it only on our instructions:
| Provider | What they do | What they handle |
|---|---|---|
| Stripe, Inc. (USA) | Payment processing, fraud prevention, refunds | Payment and contact details. Stripe is also an independent controller for fraud prevention and legal compliance, under its own privacy policy. |
| Cloudflare, Inc. (USA) | Hosting, CDN, DDoS protection, file storage and delivery, email routing | Technical request data; inbound support email in transit |
| Google LLC (USA) | The mailbox where support email is read | Support correspondence |
| Gumroad, Inc. (USA) | Alternative storefront for some products, where used | Order and contact data for purchases made there, under its own policy |
Beyond that, we may disclose information only where we're legally required to — a valid subpoena, court order or lawful government request — or where we need to establish, exercise or defend a legal claim, or to prevent fraud or harm. If our business is ever sold, merged, or reorganised (including being incorporated into a limited liability company), records may transfer to the successor, which would remain bound by this notice.
We'll tell you about a legal demand for your data unless we're prohibited from doing so.
7International transfers
We're based in the United States, and our providers are US companies, so if you're outside the US your information will be processed in the US and possibly other countries where those providers operate. Privacy laws there differ from your own.
For customers in the EEA, UK or Switzerland: when you buy from us, the transfer is necessary to perform the contract you asked us to enter into (GDPR Art. 49(1)(b)) — we can't deliver you software without it. Separately, our processors maintain their own transfer safeguards, including the European Commission's Standard Contractual Clauses and, where applicable, certification under the EU–US, UK and Swiss–US Data Privacy Frameworks. You can ask us for details of the safeguards that apply to you.
8How long we keep it
| Record | Kept for | Why |
|---|---|---|
| Transaction records in Stripe | Up to 7 years from the transaction | Tax, accounting and audit obligations, and the window for chargebacks and claims |
| Support email threads | Normally up to 3 years, then deleted | So we can pick up where we left off, and to evidence what was agreed |
| Technical request data at Cloudflare | Short-term, per Cloudflare's own retention schedule | Security and diagnostics |
| Download links | Minutes. They expire and are never stored | They hold no personal data in the first place |
Where we're required to keep something for tax or legal reasons, we keep it for that period even if you ask us to delete it — but we'll restrict it to that purpose and tell you when we do.
9How we protect it
The site is served over HTTPS only. Payment data goes directly to Stripe, a PCI-DSS Level 1 certified provider, and never reaches our systems. Download links are cryptographically signed, single-purpose and short-lived, so a leaked link can't be reused or altered to fetch a different file. Access to the Stripe dashboard and the support mailbox is limited to the owner and protected by multi-factor authentication.
No system is perfectly secure, and we can't guarantee absolute security — but we hold very little about you in the first place, which is the most effective protection there is.
10Your rights
Wherever you live, you can ask us to:
- Tell you what personal information we hold about you and give you a copy;
- Correct anything that's wrong;
- Delete what we hold, subject to records we must keep by law;
- Restrict or object to how we use it;
- Port it — receive it in a portable, machine-readable format;
- Complain to us or to a regulator.
We extend these to every customer, not just those whose law requires it. Exercising them costs nothing and we won't discriminate against you for it — no price change, no reduced support, no loss of access.
11How to exercise your rights
Email support@awardaudiotools.com and say what you want. If you can, write from the address you used at checkout — it's the simplest way for us to find your records and to be confident you are who you say you are. We may ask one or two follow-up questions to verify that, and we won't use anything you send for verification for any other purpose.
We'll respond within 45 days, and within 30 days for requests under the GDPR or UK GDPR. If a request is genuinely complex we may extend that once, and we'll tell you why before we do. An authorised agent may act for you if you give them written permission we can verify.
Appeals. If we refuse your request, we'll explain why, and you may appeal by replying with the word "Appeal" in the subject line. We'll review it and give you a written decision within 60 days. If we deny the appeal, we'll tell you how to complain to your regulator — for Texas residents, the Office of the Texas Attorney General.
12Rights in the EEA and UK
If the GDPR or UK GDPR applies to you, you have the rights in section 10 plus the right to withdraw consent where we rely on it (we currently don't), and the right not to be subject to automated decision-making producing legal or similarly significant effects (we don't do that either).
Right to object. Where we process on legitimate interests, you can object at any time and we'll stop unless we can show compelling grounds that override your rights.
Complaints. You may lodge a complaint with your local supervisory authority — in the UK, the Information Commissioner's Office (ico.org.uk); in the EEA, your national data protection authority. We'd appreciate the chance to put it right first.
We are a very small business with no EU or UK establishment, and given the limited scale and nature of our processing we have not appointed an Article 27 representative or a Data Protection Officer. Write to us directly and we'll deal with it ourselves.
13Rights in US states
Several US states — including Texas, California, Colorado, Connecticut, Virginia, Utah, Oregon, Montana and others — give residents privacy rights. Most of those laws apply only to businesses above a size or revenue threshold, and as a small sole proprietorship we fall below them; the Texas Data Privacy and Security Act, for example, exempts small businesses as defined by the US Small Business Administration.
We honour these requests anyway, from residents of any state, as a matter of policy rather than obligation. Use section 11 to make one.
Statements these laws ask for, all of which are true of us:
• We do not sell personal data, and have not in the preceding 12 months. • We do not share personal data for cross-context behavioural advertising or targeted advertising. • We do not sell sensitive personal data — we don't collect any. • We do not profile you in furtherance of decisions producing legal or similarly significant effects. • There is therefore no "Do Not Sell or Share My Personal Information" mechanism to offer you, because there is nothing to opt out of.
California residents: the categories in section 3 correspond to CCPA categories A (identifiers), B (customer records), D (commercial information) and F (internet activity), collected for the business purposes in section 5, disclosed only to the service providers in section 6, and retained per section 8. You also have the right to know, delete, correct, and to be free from retaliation, all of which we honour. We do not offer financial incentives for personal information.
14Children
The site isn't directed to children under 13 and we don't knowingly collect their personal information. If you believe a child under 13 has provided us with personal information, email us and we'll delete it promptly. Buyers must meet the age requirement in our Terms of Use.
15Do Not Track and Global Privacy Control
Some browsers send a "Do Not Track" or Global Privacy Control signal. There's no industry consensus on DNT, but the point is moot here: we don't track you, set cookies, or sell or share data, so both signals are effectively honoured by default no matter what your browser sends.
16Security incidents
If a breach affects your personal information, we'll notify you and the relevant authorities as required by law — including under Texas Business & Commerce Code § 521.053 and, where the GDPR applies, within 72 hours of becoming aware of it. We'll tell you what happened, what was affected, and what to do about it, without unreasonable delay.
17Changes to this notice
If our practices change, we'll update this page and change the "Last updated" date. For a material change — particularly one that expands what we collect or how we use it — we'll make it prominent, and where the law requires consent we'll ask before the change takes effect rather than after.
18How to contact us
Award Audio Tools
Alex Ward, sole proprietor
Texas, United States
support@awardaudiotools.com
Privacy questions, data requests and complaints all go to that address. If you need our full mailing address for a formal notice, ask and we'll provide it.