Skip to content

PRIVACY POLICY

LAST UPDATED: FEBRUARY 2026

PRIVACY COMMITMENT

Vectis adheres to GDPR and CCPA standards. We minimize data collection to strictly necessary functional requirements.

TRACKINGZero. No Pixels. No Analytics.
COOKIESStrictly Functional Only.
DATAEncrypted & Minimized.

1INTRODUCTION

This Privacy Policy outlines the data we collect, why we collect it, and your rights under GDPR/CCPA. We prioritize data minimization and security.

2. LEGAL BASIS FOR PROCESSING (Rechtsgrundlagen)

In accordance with Art. 13 DSGVO and international standards, we explicitly inform you of the legal basis for our data processing:

2.1. Contractual Necessity (Art. 6 Abs. 1 lit. b DSGVO)

Processing of your Order ID, Payment Confirmation, and License Key is strictly necessary to fulfill the software license agreement between you and us. Without this data, we cannot deliver the product.

2.2. Legitimate Interest (Art. 6 Abs. 1 lit. f DSGVO)

We have a legitimate interest in protecting our software from piracy ("cracking") and our infrastructure from attacks ("DDoS"). Therefore, we process:

  • HWID Hashes: To prevent license sharing and unauthorized distribution.
  • IP Addresses (Short-term): Handled by Cloudflare to ensure network security and availability.

2.3. Legal Obligation (Art. 6 Abs. 1 lit. c DSGVO)

We are legally required to retain certain financial data (invoice records) by German tax law (§ 147 AO, Abgabenordnung).

3. THIRD-PARTY INFRASTRUCTURE

We use specialized third-party providers. Where required by Art. 28 DSGVO, we have concluded or are in the process of concluding Data Processing Agreements (Auftragsverarbeitungsverträge, AVV) with these providers.

ProviderFunctionData Accessed
Sellhub.cxMerchant of Record / PaymentsPayment details, Email, Order Metadata.
Stripe / PayPalFinancial ProcessingCredit Card Numbers, Billing Address (Directly Input by User).
CloudflareCDN & DDoS ProtectionIP Address, Request Properties, geographic region (Optimization).
SupabaseDatabase HostingHashed HWIDs, License Keys, Encrypted User Records.
DiscordCommunity SupportMessages sent within our guild, Discord User ID.

Important: We never see, store, or have access to your credit card number, CVV, or full billing details. All payment information is entered directly into the secure forms of our payment processors (Stripe, PayPal) and is never transmitted to or stored on our servers.

4. NO TRACKING / COOKIE POLICY

4.1. No Tracking Cookies. We do not use Google Analytics, Facebook Pixel, Hotjar, or any other marketing analysis tool. We do not track your browsing behavior for advertising purposes.

4.2. Strictly Necessary Storage. Our website uses only technically necessary session data (stored in Local Storage / Session Storage) to maintain the functionality of your shopping cart and session state. This is explicitly permitted under § 25 Abs. 2 Nr. 2 TTDSG (Telekommunikation-Telemedien-Datenschutz-Gesetz) and does not require your consent.

4.3. Provider Information (DDG). In accordance with § 5 DDG (Digitale-Dienste-Gesetz), the information about the responsible party is provided in our Impressum.

5. GRANULAR DATA INVENTORY

Transparency is trust. We believe you have the right to know exactly what byte of data is sent to our servers. Here is the complete inventory of collected telemetry:

Data PointTechnical DetailPurpose
Hardware ID (HWID)SHA-256 Hash of Mainboard Serial + CPU ID.Locks your license key to your specific machine to prevent sharing.
Session TokenJWT (JSON Web Token).Maintains your login state during a session. Expires automatically.
Discord IDSnowflake ID (Numerical).Grants you access to the "Customer Only" channels in our support server.

Note on Telemetry: We do NOT collect screenshots, process lists, or file system contents. Our software runs in a strictly isolated environment.

6. DATA RETENTION & DELETION

We strictly adhere to a "Storage Limitation" policy. We do not hoard data.

6.1. Retention Periods

  • Active License Holders: We retain your hashed HWID and email for the lifespan of your license to ensure continued service availability.
  • Server Logs: Automatically rotated and purged every 10-30 days unless required for an active security investigation.
  • Financial Records: Retained for a minimum of 10 years in accordance with strict tax auditing laws (e.g., German HGB/AO, EU VAT Directive). This is a legal requirement we cannot bypass.

6.2. Account Deletion

You have the right to request the deletion of your user profile at any time. Upon request, we will purge your HWID association and Discord linkage. Please note that deleting your account will permanently revoke your access to the software, as we will no longer be able to validate your license.

7. GDPR & DATA SOVEREIGNTY

Vectis Development operates with a privacy-first mindset compliant with the General Data Protection Regulation (EU 2016/679).

7.1. Data Sovereignty. Your data is primarily processed within the European Union (EU). However, our global CDN (Cloudflare) and Payment Processors may legally transfer limited encrypted data fragments strictly for security and billing purposes.

7.2. Your Rights (Art. 15-22 DSGVO). As a user, you possess the following inalienable rights:

  • Right to Access (Art. 15): Request a copy of all data we hold on you.
  • Right to Rectification (Art. 16): Correct any inaccuracies in your email or account details.
  • Right to Erasure (Art. 17): "The Right to be Forgotten" (Subject to tax law retention periods).
  • Right to Restriction (Art. 18): Halt processing of your data during a dispute.
  • Right to Data Portability (Art. 20): Receive your data in a structured, commonly used, machine-readable format.
  • Right to Object (Art. 21): Object to processing based on legitimate interests.

7.3. Supervisory Authority. You have the right to lodge a complaint with a supervisory authority. The competent authority for Germany is the Berliner Beauftragte für Datenschutz und Informationsfreiheit or the data protection authority of your federal state.

8. INTERNATIONAL COMPLIANCE

Global Neighbors: No matter where you live, we respect your digital borders. Here is how we comply with your local laws.

While our primary jurisdiction is Germany/EU, we acknowledge our global user base and strictly adhere to international privacy frameworks.

8.1. United States (CCPA / CPRA)

For residents of California and other US states with specific privacy statutes:

  • No Sale of Data: We do not "sell" your personal information as defined by the CCPA/CPRA.
  • Non-Discrimination: We will not discriminate against you for exercising your privacy rights.
  • Designated Agent: You may designate an authorized agent to make a request on your behalf.

8.2. United Kingdom (UK-GDPR)

Following Brexit, we adhere to the Data Protection Act 2018 and the UK-GDPR. Your rights remain identical to those under the EU-GDPR. If required under UK-GDPR Art. 27, we will designate a UK representative; please contact us at [email protected] for details.

8.3. Canada (PIPEDA)

We comply with the Personal Information Protection and Electronic Documents Act (PIPEDA). We rely on "implied consent" for the collection of transactional data necessary to deliver our product, and "express consent" for any optional communications.

8.4. Brazil (LGPD)

Users in Brazil are protected under the Lei Geral de Proteção de Dados. You have the right to confirmation of the existence of processing and access to your data, which we fully grant via our support channels.

9. DATA BREACH NOTIFICATION

In the unlikely event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you without undue delay. We will provide:

  • A description of the nature of the personal data breach.
  • The likely consequences of the breach.
  • The measures taken or proposed to address the breach.

We will also report the breach to the relevant supervisory authority (e.g., the Berliner Beauftragte für Datenschutz) within 72 hours of becoming aware of it, in accordance with Art. 33 DSGVO.

10. CHILDREN'S PRIVACY

Our Service is not directed to individuals under the age of 18. We do not knowingly collect personal information from children under 18. If you become aware that a child has provided us with personal data without parental consent, please contact us at [email protected] so that we may take steps to delete such information.

11. CONTACT & SECURITY REPORTING

If you have identified a potential security vulnerability in our infrastructure, or if you wish to exercise your GDPR/CCPA/PIPEDA rights, we encourage you to contact us immediately.

Data Protection Officer (DPO): [email protected]

For general inquiries, you may also open a confidential ticket in our Discord community.