VANILLA.AC / Legal
Privacy Policy
Updated 11 October 2026 · Germany
Pre-release draft. Seller identification and privacy contact are pending. These documents require completion and legal review before live sales or customer data collection.
1. Scope and controller
This policy describes the planned handling of personal data for the vanilla.ac website, software, licensing and support. The seller is based in Germany. The legal controller name, business address and dedicated privacy contact have not yet been supplied. These details must be completed before customer data collection or live sales begin.
The current website is a frontend preview: its product and plan selections do not process payments or validate licenses. References below to account, HWID and checkout processing describe the intended service, not proof that these features are active. Hosting providers may still process requests to serve and secure this website.
2. Information we process
The intended account and licensing records contain your Discord username, email address, IP address and hardware identifier (HWID). We use only the information needed for the relevant service. An IP address can indicate approximate location; an HWID identifies a licensed device and can be personal data when linked to you.
- Discord username: to associate community support and access with your account. If Discord authorization is enabled, a Discord user ID and authorized profile fields may also be received; we do not receive your Discord password.
- Email: for order delivery, account communication and support.
- IP address: received when you connect to a website or service and used for security and abuse prevention. We do not assume a payment provider shares its own IP or risk records with us.
- HWID: collected by the licensing software when activation is implemented, not automatically obtained by an ordinary web checkout. Its exact derivation and whether a hash is stored must be disclosed before activation is enabled.
- Support records and order references: messages and transaction information you provide or that a configured checkout makes available.
3. Stripe and PayPal payments
The intended payment methods include Stripe and PayPal. When enabled, their hosted payment services collect payment information directly under their own privacy notices. With a standard hosted checkout, vanilla.ac does not receive or store full card numbers, CVC codes, online-banking passwords or PayPal login credentials.
Depending on the chosen integration and fields collected, Stripe can make available the transaction, customer or payment reference, amount, currency, status, refunds, billing name, email and address, and limited card information such as brand, last four digits and expiration. PayPal can make available order and transaction references, amount, currency, status, payer name, email and payer identifier, and address information where applicable. Not every field is automatically received or stored by vanilla.ac.
The providers may separately process device, IP, fraud-prevention, financial and identity-verification information. Information held by a provider is not necessarily shared with the seller. The final checkout configuration and actual received fields must be reviewed before live payments start.
4. SellAuth and cryptocurrency
Cryptocurrency checkout is intended to use SellAuth. Depending on the configured checkout, SellAuth may process and expose customer email, IP, order and invoice references, selected currency, amount, payment status and transaction confirmations. Discord data is relevant only if that integration is enabled. Cryptocurrency network, wallet address and transaction hash may be visible in the payment record or on the network. The exact fields and any underlying payment providers depend on the configured gateway.
Transactions on public blockchains can expose addresses, amounts, timestamps and transaction identifiers. Some networks or payment arrangements have different visibility. Public blockchain records cannot be erased or altered by vanilla.ac; deleting our internal records does not delete the network transaction. Never provide us with a wallet seed phrase or private key.
SellAuth checkout does not inherently obtain your HWID from your computer. Any HWID collection belongs to the separately implemented license activation service. SellAuth and any configured underlying gateway have their own privacy and retention practices; their contractual roles and transfer safeguards must be checked before launch.
5. Purposes and legal bases
Where necessary to deliver purchased access, orders and license activation are processed to perform a contract (GDPR Article 6(1)(b)). Necessary accounting and lawful disclosure records are processed to comply with legal obligations (Article 6(1)(c)). Proportionate IP and HWID-based security checks may rely on legitimate interests in protecting accounts and preventing fraud (Article 6(1)(f)), subject to a documented balancing assessment and your right to object.
Optional marketing and non-essential tracking require consent where applicable (Article 6(1)(a)). We will not treat use of the website as consent to optional tracking or make optional marketing a condition of purchasing access.
6. Recipients and transfers
Information is shared only as needed with the configured payment and checkout services (Stripe, PayPal and SellAuth), hosting and security services, support or licensing providers, and Discord if authorization is enabled. The actual providers and their roles must be confirmed before launch. Competent authorities may receive information where legally required.
We do not sell personal data. Where data is transferred outside the EEA, the relevant transfer must have a lawful safeguard, such as an applicable adequacy decision or standard contractual clauses and any necessary supplementary measures. We do not claim these agreements are in place until they have been verified.
7. Cookies and local storage
We do not currently implement advertising tracking or a customer authentication cookie in this frontend preview. Infrastructure providers may use necessary security technologies. If account sessions, checkout cookies or optional analytics are introduced, we will disclose their providers, purposes and duration. Non-essential storage or access on your device will require consent where applicable under German law. Third-party checkout pages have their own cookie notices.
8. Retention and security
Personal information should be kept only for its stated purpose. Account and licensing records are retained while needed for access; proportionate security records may be kept for a limited period where justified; statutory financial records follow the applicable German retention requirements. Exact deletion schedules have not yet been set and must be documented before launch. We do not adopt another website's fixed retention period or keep HWID records indefinitely by default.
Appropriate access controls, secure transport and data minimization must protect the implemented service. No online system can guarantee complete security. We do not claim specific audits, certifications or encryption-at-rest arrangements that have not been verified.
9. Your rights
Subject to applicable conditions, you can request access, correction, erasure, restriction and portability, and object to processing based on legitimate interests. You can withdraw consent without affecting prior lawful processing. You may complain to a supervisory authority, including the competent German data protection authority. Statutory retention and the rights of others can limit erasure.
A dedicated privacy contact is still required. Until it is supplied, use the official vanilla.ac Discord support link to request that the operator establish a private contact channel. Do not send identity documents or sensitive information in public channels. This temporary channel does not replace the controller identification required by law.
10. Changes
We will revise this draft to reflect the actual service before launch, including seller identification, active providers, checkout fields, retention periods and contact details. Material changes will be communicated as required. This draft was updated on 11 October 2026.