Privacy Policy
Last updated: 2026-05-03
Quick navigation
- 1. Your Rights
- 2. Information We Collect
- 3. How We Use Your Information
- 4. How We Share Your Information
- 5. Cookies, Tracking & Analytics
- 6. License Activation & Device Information
- 7. Communications Preferences
- 8. Data Retention
- 9. Data Security
- 10. International Users
- 11. Children's Privacy
- 12. Changes to This Policy
- 13. Contact Us
1. Your Rights
You have many rights regarding the data we hold about you. Most of these can be exercised directly from your account page:
- Access (GDPR Article 15) — view the personal data we hold about you on your account page, or request a structured export via the "Download my data" button.
- Rectification (Article 16) — update your display name, address, marketing preferences, and email directly on your account.
- Erasure / "right to be forgotten" (Article 17) — permanently delete your account and associated personal data via the "Delete account" control. We process deletion within 30 days, subject to retention requirements imposed by tax and financial compliance law (e.g., past invoices may be retained without your name attached, as permitted by Article 17 §3(b)).
- Portability (Article 20) — request a JSON copy of your account data, addresses, orders, and license keys.
- Object / Withdraw consent — opt out of marketing communications at any time. We will not use your data for marketing purposes unless you have opted in (or are an existing customer consented under "legitimate interest" — see below).
These rights are extended to all users worldwide, regardless of where you live.
2. Information We Collect
A. Information you provide
We collect information you provide directly when you:
- Create a Strangebad Effects account.
- Sign in with email + password or via Google.
- Place an order or use a license key.
- Sign up for our newsletter or product updates.
- Contact us with questions or feedback.
This may include:
- Contact information — email address, display name, postal address.
- Account credentials — a salted, one-way-hashed password (we never store the plain password).
- Payment information — billing address, country, and card metadata (last 4 digits, expiration). We never see or store your full card number; payment is processed by Stripe and PayPal.
- Communications preferences (e.g., marketing opt-in).
- Correspondence and any other information you choose to send us.
Information that personally identifies you (alone or in combination) is referred to as "Personal Information". Personal Information once de-identified or aggregated is no longer subject to this Privacy Policy.
B. Information collected automatically
When you visit our website or use our software, we automatically collect:
- Browser type and operating system.
- IP address (used for security, fraud prevention, and rate limiting).
- Approximate geo-location derived from IP, used only for tax compliance and fraud signals — never stored at street level.
- Pages you view, links you click, and the order in which you visit them.
- Information collected through cookies and similar technologies (see Section 5).
- Standard server log information (request timestamps, status codes, referrer header).
- Software usage signals from our plug-ins, such as host DAW and plug-in version, used to improve product quality.
- Email engagement metadata such as whether a transactional email opened or its links were clicked. You can disable this in our email-delivery preferences.
We do not consider this "Usage Information" to be Personal Information on its own, but if it is combined with information that identifies you, we treat the combined data as Personal Information.
C. Information from other sources
We may receive information about you from third-party services, such as identity-verification responses from Google when you sign in with Google, payment-network responses from Stripe and PayPal, and deliverability reports from our email provider. To the extent we combine that information with Personal Information, we treat the combined record as Personal Information.
3. How We Use Your Information
We use the information we collect to:
- Provide our products and the website, including authentication, order fulfilment, license issuance, downloads, and support.
- Send you transactional communications — order receipts, license deliveries, password resets, security alerts, change notifications. These are always delivered, regardless of marketing preferences.
- Detect, investigate, and prevent fraudulent or abusive activity (e.g., chargeback risk, license-key sharing, sign-in lockout).
- Comply with tax, accounting, and other legal requirements.
- Improve our products and the website through aggregated analytics, A/B tests, and error reports.
- Tell you about new releases, tutorials, and offers — only when you have opted in to marketing communications.
- Honour your privacy-rights requests under Section 1.
Where we rely on "legitimate interest" as the legal basis for processing (e.g., delivering the products you ordered, protecting against fraud, basic analytics), no opt-in is required. For everything else — particularly marketing — we rely on your explicit opt-in.
4. How We Share Your Information
We never sell your personal data. We share it only with the categories of recipients below, and only to the extent necessary.
Service providers (sub-processors)
We rely on the following providers to operate Strangebad Effects. Each is contractually bound to process your data only on our instructions and to keep it secure:
- Supabase — authentication, database, storage (US).
- Stripe — credit/debit card payment processing (US).
- PayPal — alternative payment processing (US).
- Resend — transactional and marketing email delivery (US).
- Vercel — website hosting and CDN (US).
- Sentry — error tracking and performance monitoring, with PII scrubbing applied before events leave your browser (US).
- Upstash — Redis-backed rate limiting, session caching, and CSRF token storage (US).
Legal process and safety
We may disclose your information when we have a good-faith belief that disclosure is necessary to (a) comply with a subpoena, court order, or other legal process; (b) enforce our Terms of Service; (c) protect the rights, property, or safety of Strangebad Effects, our users, or the public; or (d) prevent or investigate fraud or security incidents.
Business transfers
If Strangebad Effects is involved in a merger, acquisition, financing, bankruptcy, or sale of all or part of our assets, your information may be transferred as part of that transaction. We will notify you and give you the opportunity to opt out of any such transfer if the new entity's planned processing differs materially from this Privacy Policy.
Aggregate or de-identified information
We may share aggregate statistics or de-identified information that does not identify any individual user (for example, total install counts, cumulative usage trends).
With your consent
We will share your information for any other purpose disclosed to you with your consent at the point of collection.
5. Cookies, Tracking & Analytics
Cookies and similar technologies
Cookies are small data files stored on your device by your browser. We use them to keep you signed in, remember your cart, protect against cross-site request forgery (CSRF), and measure how the site is used. Most browsers allow you to refuse cookies via their settings — note that disabling cookies will break sign-in, checkout, and other site features.
Anonymous-visitor identifier (sbe_anon_id)
We set an HTTP-only, SameSite=Lax cookie named sbe_anon_id on your first visit. It contains a random UUID with a 2-year lifetime; it is never linked to your name, email, or any third-party identifier. We use it to (a) keep your cart consistent across page loads while you are signed out, (b) detect abusive request patterns alongside our IP-hash rate limits, and (c) attribute first-touch marketing context (where you came from, which campaign brought you in) so we can measure which channels work. When you sign in, we link prior pageviews recorded under this cookie to your account so your data export and account history are complete; when you sign out, we rotate the cookie so a shared browser does not bleed your activity into the next user's session. When you delete your account, the per-event user link is anonymized to a sentinel value (the underlying audit trail is preserved for fraud / chargeback investigation; the personal link is removed). A future consent banner will let you opt OUT of marketing-attribution capture while keeping the functional uses (cart consistency, fraud signal); marketing-attribution capture is currently on by default in the EU and worldwide.
Embedded scripts
We use small JavaScript snippets to power dynamic features (cart, sign-in, error capture). These scripts run only while you are on our site and do not persist on your device.
Analytics
We use first-party analytics derived from server logs, the sbe_anon_id capture pipeline above, and Sentry's opt-in performance traces. We do not use Google Analytics, Facebook Pixel, or other third-party advertising trackers. Captured pageview rows are retained for 13 months and then deleted automatically by a scheduled cleanup.
Do-Not-Track
Because there is currently no industry standard governing how websites should respond to "Do-Not-Track" browser signals, we do not take action on them. We instead rely on the explicit opt-out mechanisms described in this policy and on your account page.
6. License Activation & Device Information
Our software uses device-locked licensing. When you activate a plug-in on a computer, we generate a one-way hashed "machine ID" derived from stable hardware identifiers (e.g., serial numbers exposed by your operating system) and bind your license to it. We collect this only to:
- Enforce the activation limit on your license.
- Allow you to deactivate a device when you no longer use it.
- Detect license-key sharing across many machines.
The machine ID is a one-way hash; we cannot reverse it back to the original hardware identifiers. We do not collect contents of your files, audio recordings, project sessions, or anything else from your computer.
7. Communications Preferences
We send two categories of email:
- Transactional — order receipts, license deliveries, password resets, sign-in alerts, account-deletion confirmations. These are always sent, regardless of your marketing preference, and cannot be unsubscribed from while you have an active account.
- Marketing — product news, tutorials, and occasional offers. New accounts are subscribed by default. You can opt out at any time on your account page or via the "unsubscribe" link in any marketing email (RFC 8058 one-click unsubscribe is supported).
Opt-out requests typically take effect immediately and may take up to 24 hours to propagate across our systems.
8. Data Retention
We keep your account information indefinitely while your account is active. When you delete your account, we erase your personal data within 30 days, except where retention is mandated by law:
- Past invoices and tax records are retained for the period required by tax authorities (typically 7 years), but we de-identify the customer name/address attached to them where possible.
- Audit-log entries that reference your account are pseudonymised (your user ID is replaced with an opaque token) so the audit trail remains intact without your identity attached.
- Active license keys are revoked at deletion time but the revocation record is retained for fraud-prevention purposes.
9. Data Security
We protect your data with industry-standard safeguards including:
- HTTPS/TLS for all data in transit.
- Salted bcrypt hashing for passwords.
- HTTP-only, SameSite session cookies; CSRF token validation on every state-changing request.
- IP-hashed rate limiting and lockouts on sign-in and password endpoints.
- PII-scrubbing on error reports before they leave your browser.
- Principle-of-least-privilege access for staff and sub-processors.
Despite our efforts, no system is 100% secure. You are responsible for keeping your password confidential and for any activity that occurs under your account. Please notify us immediately at support@strangebadeffects.com if you suspect unauthorised access.
10. International Users
Strangebad Effects is based in the United States. If you access our website or use our software from outside the United States, your information will be transferred to, stored on, and processed by servers located in the United States and other countries where our sub-processors operate. Some of these countries may not offer the same level of privacy protection as your own. Where required by law (for example, the EU's GDPR), we rely on Standard Contractual Clauses or other approved transfer mechanisms.
11. Children's Privacy
Strangebad Effects does not knowingly collect, use, or disclose personal information from children under the age of 13 in the United States (or under 16 in the European Economic Area) without verified parental consent, except as permitted by the Children's Online Privacy Protection Act ("COPPA"). If you believe we have inadvertently collected information about a child, please contact us at support@strangebadeffects.com and we will delete it promptly.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, our services, or applicable law. When we make material changes, we will notify you via the email address on file and update the "Last updated" date at the top of this page. Your continued use of the website or software after a change constitutes your acceptance of the new policy.
13. Contact Us
For questions about this Privacy Policy or to exercise any of the rights described in Section 1, please contact us at: