1. Who we are (data controller)
EditsPack (“EditsPack”, “we”, “us”, “our”) operates the website https://editspack.onrender.com and sells the EditsPack Signature digital pack for DaVinci Resolve. The data controller responsible for the personal data described in this policy is EditsPack, operated from Tbilisi, Georgia.
You can reach us at any time about privacy matters at tfiruvtr@gmail.com. If you contact us from an account email address, we may use that address to verify your identity before acting on your request.
2. Scope of this policy
This policy covers the EditsPack website, the storefront and checkout flow (hosted with our payment provider Payhip), the customer account area, and the gated download service. It does not cover the internal privacy practices of third-party services such as Google or Payhip when you interact with them directly; those are governed by the third parties’ own privacy policies, which we link to in section 14.
3. What we collect
We deliberately collect as little personal data as the service allows. Specifically:
- Google sign-in data (via Google OAuth 2.0): your Google account name, your Google email address, your Google profile picture URL, your Google account identifier, and timestamps for when your EditsPack account was created and last signed in. Your Google email address is the identity of your EditsPack account. We receive only basic profile scope information — we never see your Google password, and we never post to or read your Google services.
- Purchase records supplied by our payment provider Payhip: a transaction identifier, the email address used at checkout, the product purchased, and the amount charged (including any VAT or sales tax breakdown Payhip calculates). We never receive or store card numbers, card details or bank credentials.
- Download audit records: each gated download of the product is logged against your account with the file name, the number of bytes transferred, your IP address, your browser user-agent string, and the date and time. This is an anti-piracy and abuse-prevention record and is described openly here — it is not hidden logging.
- First-party visit counts: we keep a simple per-day aggregate counter of site visits. It contains no personal identifiers, builds no visitor profiles and performs no cross-site tracking.
- Advertising data (only if Google AdSense ad slots are enabled sitewide): Google and its advertising partners may use cookies or similar identifiers to serve and measure ads, as described in section 9.
4. What we do not collect
We do not collect passwords (sign-in is Google-only), payment card data (checkout runs entirely on Payhip), precise location or device GPS data, contacts, biometric data, special-category data (such as health, religion or political opinions), or the content of any video you edit with the product. We do not build behavioral profiles of our customers and we do not sell personal data, as described in section 15.
5. Purposes and legal bases
Where the GDPR applies, we process personal data only on one of the following legal bases, matched to the purpose:
- 1.Contract performance (GDPR Art. 6(1)(b)): creating your account, identifying you at sign-in, showing your purchase, and delivering the .drfx file you paid for through gated downloads.
- 2.Legitimate interests (GDPR Art. 6(1)(f)): anti-piracy enforcement and download audit logging, daily download limits, abuse and fraud prevention, service security, and keeping basic operational server logs. We have weighed these interests against your rights and keep the data proportionate and time-limited.
- 3.Consent (GDPR Art. 6(1)(a)): serving advertising through Google AdSense where personalized ads are involved, and any optional cookies that are not strictly necessary. You may withdraw consent at any time via the mechanisms in section 10.
- 4.Legal obligation (GDPR Art. 6(1)(c)): retaining purchase and sales records for tax, accounting and audit purposes where law requires it.
6. Cookies overview
A cookie is a small text file a website stores in your browser. EditsPack uses a very small number of first-party cookies that are strictly necessary for the site to function, one anonymous first-party counting mechanism, and — only if and when ad slots are enabled — third-party advertising cookies placed by Google. We do not run social-media pixels or other cross-site trackers of our own.
7. Strictly necessary cookies
These cookies are strictly necessary: the store cannot deliver purchases securely without them, so they are not subject to an opt-out. Clearing them simply signs you out.
- kfx_session — a signed, httpOnly session cookie that keeps you signed in to your account after Google authentication. It is essential for the gated download system to know who is downloading, to enforce the daily download limit, and to protect the account area. It is not readable by JavaScript and expires when you sign out or when the session ends.
- OAuth state cookie — a short-lived cookie set when you start Google sign-in and consumed when you finish. It protects the sign-in flow against cross-site request forgery (CSRF) attacks and carries no personal data.
8. First-party analytics: daily visit counts
We count visits ourselves, in our own database, as a single number per calendar day. There is no individual identifier attached to the count, no session stitching, no fingerprinting, no heatmaps and no cross-site or cross-device tracking. This counter tells us things like “how many visits did the homepage get on Tuesday” and nothing about you as an individual. Because it is non-identifying aggregate data, it is not personal data under the GDPR and not “personal information” under the CCPA.
9. Advertising and Google AdSense
EditsPack may display advertising through Google AdSense. If and when ad slots are enabled sitewide, the following applies honestly and in plain terms:
- Google and its certified partners may set and read cookies or use similar identifiers (such as mobile advertising IDs) in your browser or device to serve ads on EditsPack and other sites.
- Where personalized advertising is enabled, those identifiers may be used to select ads based on your prior visits to this and other websites, and to measure ad performance.
- Where personalized advertising is not enabled (for example in the EEA, the UK and Switzerland, where we do not serve personalized ads without a valid consent signal), Google serves non-personalized ads based on contextual factors such as the page content, and uses cookies only for frequency capping, aggregated ad reporting and fraud detection.
- Third-party vendors and ad networks may also serve ads on EditsPack under Google’s certified-partner program; their use of cookies is subject to their own privacy policies.
- We do not control and cannot read the cookies Google places; they are governed by Google’s policies at https://policies.google.com/technologies/ads.
10. Opting out of personalized advertising
You are always in control of ad personalization. You can:
- Turn off ad personalization in Google’s Ad Settings at https://adssettings.google.com, which applies to ads Google serves in your signed-in browser.
- Opt out of many third-party vendors’ advertising cookies at the industry opt-out portals https://www.aboutads.info/choices and https://optout.networkadvertising.org.
- Use your browser’s private/incognito mode, clear cookies, or block third-party cookies in your browser settings; EditsPack will continue to work normally, because none of our strictly necessary cookies are advertising-related.
- Send a legally recognized opt-out preference signal (such as Global Privacy Control) where your browser supports it — we treat recognized signals as an opt-out from any personalized-advertising cookies on our pages.
11. Payments and Payhip
All payments for EditsPack Signature are processed by Payhip (payhip.com), which acts as the merchant of record for the transaction, including the calculation, collection and remittance of VAT, GST and sales tax where applicable. When you check out, you pay on Payhip’s infrastructure; your card or payment details go directly to Payhip and its payment processors and are never transmitted to or stored on EditsPack servers.
We receive from Payhip only what we need to recognize your purchase and deliver the file: a transaction identifier, the checkout email address, the product and the amount paid. If you pay while signed in, we link the purchase to your EditsPack account; if you buy before creating an account, we keep the purchase queued against your checkout email and it attaches to your account when a Google sign-in matches that email.
12. Download audit logging and anti-piracy
Because EditsPack Signature is a downloadable file, some logging is necessary to keep the product from being stolen at scale. We say this plainly rather than burying it: every gated download is logged with your account, the file name, the byte count, your IP address, your user-agent string and a timestamp. We use this record to prove a genuine license, to detect mass-downloading, link-sharing, scraping and credential sharing, to investigate suspected piracy, and to protect the bandwidth of the service for paying customers.
Download records are kept for a maximum of 90 days and are then pruned, except where a specific record must be preserved for an active abuse investigation, a chargeback dispute, or a legal requirement.
13. Daily download limit
To deter automated scraping and unauthorized redistribution, each account may download the product 3 to 5 times in any rolling 24-hour period. The limit is enforced per account using the session established by your strictly necessary cookie. Reaching the limit is not a breach and is not recorded against you; the counter simply resets. Attempts to circumvent the limit (for example through mass-created accounts) are treated as abuse under our Terms of Service.
14. Sharing of data
We share personal data only with the following categories of recipients, only to the extent necessary:
- Google — for account authentication (OAuth 2.0) and, where ad slots are enabled, as the advertising vendor. Google’s own privacy policy is at https://policies.google.com/privacy and its ad technologies policy at https://policies.google.com/technologies/ads.
- Payhip — as the payment processor and merchant of record for your purchase. Payhip’s privacy policy is available at https://payhip.com/privacy.
- Our hosting provider (Render) — which runs the application and stores the database; it processes data on our instructions as a processor.
- Professional advisers, and law enforcement, regulators or courts — only where we are legally required to disclose, or where strictly necessary to establish, exercise or defend legal claims (for example a fraud or copyright-infringement investigation).
15. We do not sell personal data
We do not sell, rent or trade your personal data, and we do not disclose it for cross-context behavioral advertising in exchange for money or other valuable consideration. The advertising described in section 9 is limited to Google AdSense slots on our own pages; we do not share your account data, purchase records or download logs with any advertising network. If this ever changes, we will update this policy and, where required (including under the CCPA), honor opt-out signals such as Global Privacy Control.
16. International data transfers
EditsPack is operated from Tbilisi, Georgia, and the service is hosted on infrastructure that may be located in the United States or the European Union. Where personal data is transferred out of the EEA or the UK — for example when you sign in with Google, pay through Payhip, or when our hosting provider processes data — the transfer relies on appropriate safeguards such as the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum adopted by the receiving provider. You can request details of the safeguards that apply to your data by emailing tfiruvtr@gmail.com.
17. Data retention
We keep personal data only as long as necessary for the purpose it was collected:
- Download audit logs — pruned after 90 days (longer only where needed for an active investigation, chargeback or legal claim).
- Purchase and sales records — retained for tax, accounting and audit purposes for the statutory retention period applicable in Georgia and, where applicable, the records required by our payment provider; these are the proof of your license, so they normally last as long as your license.
- Account data (Google name, email, profile picture URL, account identifier, timestamps) — kept until you request deletion of your account.
- Daily aggregate visit counts — kept long-term, but they contain no personal data.
- Server security logs — short-lived operational logs, typically rotated within 30 days.
18. Your rights under the GDPR and UK GDPR
If you are in the EEA or the UK, you have the following rights over your personal data:
- Access — to ask whether we process your data and to receive a copy of it.
- Rectification — to have inaccurate data corrected (for example your displayed name).
- Erasure — to have your account data deleted; note that this ends your ability to re-download the pack from that account.
- Restriction and objection — to restrict or object to processing, including any processing based on legitimate interests.
- Portability — to receive your account and purchase data in a structured, commonly used, machine-readable format.
- Withdrawal of consent — for any processing based on consent, such as personalized advertising.
- Complaint — to lodge a complaint with your local supervisory authority. We would, however, appreciate the chance to deal with your concern first.
19. Exercising your rights
To exercise any right, email tfiruvtr@gmail.com from your account email address (or include the transaction ID from your purchase) and describe what you want. We will verify your identity through your account or purchase details, respond without undue delay and in any event within one month of a GDPR request, and tell you promptly if we need an extension. Requests are free of charge; we may charge a reasonable fee or decline requests that are manifestly unfounded or excessive, as the law allows.
20. Your rights under the CCPA (California)
If you are a California resident, the California Consumer Privacy Act gives you the right to know what personal information we collect and how it is used, the right to request deletion of your personal information, the right to correct inaccurate personal information, the right to opt out of the sale or sharing of personal information, and the right not to be discriminated against for exercising any of these rights.
As stated in section 15, we do not sell or share personal information as those terms are defined by the CCPA, so there is nothing to opt out of in practice; recognized opt-out preference signals are nevertheless honored. To make a know, delete or correct request, email tfiruvtr@gmail.com. We will verify your request through your account or purchase details and respond within the timeframes the CCPA requires.
21. Children’s privacy
EditsPack is intended for people aged 13 and over, and the service is not directed to children under 13. We do not knowingly collect personal data from anyone under 13, and where the applicable age of digital consent is 16 or higher (as in parts of the EEA), we rely on consent mechanisms appropriate to that age before serving personalized advertising. If you believe a child under the applicable age has created an account or purchased the product, contact us at tfiruvtr@gmail.com and we will delete the account and associated personal data. Purchases made by minors should be made with the involvement and payment instrument of a parent or guardian.
22. Security measures
We protect personal data with technical and organizational measures appropriate to a small digital storefront, including:
- Session cookies that are signed and httpOnly, so they cannot be tampered with from the browser or stolen by client-side scripts.
- Transport encryption (TLS/HTTPS) for all site traffic.
- A short-lived OAuth state cookie that protects the Google sign-in flow against CSRF attacks.
- Parameterized database queries throughout the application to prevent SQL injection.
- Least-privilege, account-gated file delivery: the product file is never publicly exposed; it is served only to signed-in accounts with a verified purchase.
- Signature verification on payment webhooks, and server-side enforcement of download limits.
- Data minimization by design: we collect the smallest set of fields the service needs, and download logs expire automatically.
23. Data breach notification
If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority without undue delay and, where the GDPR requires it, within 72 hours of becoming aware of the breach. Where a breach is likely to result in a high risk to you, we will also inform you directly, describing what happened, what data was involved and what you can do. If you ever notice suspicious activity on your account, report it immediately to tfiruvtr@gmail.com.
24. Changes to this policy
We may update this Privacy Policy to reflect changes in the service (for example enabling AdSense slots), changes in law or improvements in our practices. The “last updated” date at the top of this page always shows the current version. Material changes that affect how we use previously collected data will be announced on the site before they take effect, and where consent is the legal basis for a new use, we will ask for it at that time.
25. Contact and escalation
Questions, requests or complaints about privacy: email tfiruvtr@gmail.com and include “Privacy” in the subject line. We answer every privacy email. If you are unsatisfied with our response and you are in the EEA or the UK, you may escalate to your local data-protection supervisory authority; if you are in California, you may escalate to the California Attorney General. Nothing in this policy limits any non-waivable statutory right you may have.