Privacy Policy
What personal data this shop actually processes, why, how long it is kept, and your rights over it.
Who we are
This shop is operated by an individual photographer/videographer (no registered company). The operator's legal identity and contact details will appear in the Legal Notice once published; until then you can reach the operator through the contact page.
What we collect — the complete inventory
There are no buyer accounts here: checkout is guest-only, with no passwords and no profiles. The complete list of personal data this system processes is:
- Your order email address — collected at checkout, used to deliver your order confirmation, license record, and download links, and to let you look your order up later. Legal basis: performance of the purchase contract.
- Order records — the items you licensed, amounts, currency, order status, and order timestamps. Legal basis: contract performance and the legal obligation to keep financial records.
- Payment provider references — an opaque customer/transaction reference from our payment provider, used to reconcile your payment. We never see or store your card number, bank details, or billing credentials — payment runs entirely inside the payment provider's checkout (see below).
- Payment provider event data — the payment provider sends us signed webhook notifications about your transaction, which we archive verbatim as the proof behind every amount in our books. Depending on what the provider includes, these can contain your name, country, and tax-related data. We treat this archive as a personal-data store and it is covered by the erasure process below.
- Download delivery logs — when you download a purchased file, we log the request (timestamp, byte ranges, and your IP address and browser user-agent). IP and user-agent are recorded as soft fraud-review signals only: they are looked at by a human if something looks abusive, and they are never used as an automatic gate — a changing IP will not block your download. Legal basis: legitimate interest (abuse and fraud review).
- Administrator accounts — staff email/name for the people who run the shop (not buyer data; listed for completeness).
What we deliberately do not collect
- No buyer accounts, passwords, or profiles — guest checkout only.
- No analytics or advertising trackers, no tracking pixels, no fingerprinting. None are built into this site.
- No photo-capture dates or GPS data: this project strips date and location metadata from image files at ingest as a design rule, so we cannot leak what we do not store.
- Your personal data is never sent to any AI/LLM service. The AI assistance used to prepare catalog text works on catalog content only — that is a standing project rule.
Cookies
This site itself uses at most session-strength cookies needed to operate (for example, keeping an admin signed in). It sets no advertising or analytics cookies. During checkout, the payment provider's embedded checkout sets its own cookies under its own policy — that happens inside their checkout component and is disclosed here so you are not surprised by it.
Payments — merchant of record
Payments are handled by Paddle as merchant of record: Paddle is the seller of record for your purchase, processes your payment data, computes and remits applicable tax, and issues the buyer-facing tax invoice. Paddle is an independent controller of the personal data it processes for those purposes, under its own privacy policy. This shop receives only the references and event notifications described above — never your payment credentials.
How long we keep things
- Download-log IP addresses and user-agents: nulled 90 days after your download token reaches its final state. The log rows themselves (byte counts, timestamps) are kept for statistics — with the personal columns removed.
- Server logs containing IPs: rotated away after 90 days.
- Order and payment records: kept for as long as financial-record law requires of the operator. The exact statutory period for an individual seller in Bosnia & Herzegovina is currently under legal confirmation; until it is confirmed with a citable source, these records are retained and never auto-deleted. This draft will state the exact period once legal review (team 25) settles it.
- Email addresses from checkouts that never completed: if a checkout is started and the payment provider never confirms it (no payment notification ever arrives about it, at all), there is no financial record to preserve, so the order and its associated email address are deleted outright 30 days after the checkout was started. A dedicated cleanup tool enforces this rule; it never touches a completed purchase.
Your rights, and how erasure actually works here
You can request access to, correction of, or erasure of your personal data via the contact page, from the email address you ordered with (that is how we verify the request is yours).
Erasure is honest about its limits: when you ask to be erased, your email address is replaced with an anonymous tombstone, payment-provider customer references are removed, IP/user-agent entries in the download logs are nulled immediately, and personal fields inside the archived payment notifications (name, email, address values) are redacted in place. What remains is the accounting skeleton the law requires us to keep: amounts, currencies, order references and order-record numbers, statuses, timestamps, and the payment provider's transaction references — numbers, not you. The erasure itself is written to a tamper-evident audit log (as reference IDs, not personal data). For data Paddle holds as merchant of record, Paddle is an independent controller — we will point you to Paddle's privacy contact for that part rather than pretend we can delete it for them.
Where data lives
The shop database (orders, emails, logs described above) runs on this site's hosting. Full-size originals are not stored on the web host at all; purchased files are delivered from the operator's own equipment through one-time, time-limited download links. Encrypted backups of business records are kept as part of normal operations.
Complaints
If you believe your data has been handled improperly, contact the operator first via the contact page. You also have the right to complain to your data-protection supervisory authority. (The operator's competent authority will be named here together with the legal identity in the finished document.)