Skip to content
QevixLabs
Menu

QevixLabs

Privacy policy

What data QevixLabs collects, why we collect it, who processes it and how to have it removed.

Last updated

This policy explains what QevixLabs collects, why, and what you can do about it. It covers this website and the licensed software we distribute.

We collect the minimum needed to sell you a licence, keep it working and answer your questions. We do not sell or rent personal data to anyone, and we do not run advertising or tracking networks on this site.

What we collect

When you buy. Your name, email address and billing details. Your card number never reaches our servers - payment is handled entirely by Stripe on their own hosted checkout, and we only ever see the card brand and last four digits that Stripe reports back to us.

When you create an account. Your email address and a hashed password. If you sign in with Google, GitHub, LinkedIn or Microsoft instead, we receive your verified email address and name from that provider and store a link to that account - never your password there.

When licensed software checks in. Licensed installs verify their licence with us periodically. That check-in sends the licence key, a one-way SHA-256 hash of the site or install URL, the product version and a self-reported file-integrity status. We store the hash rather than the URL, and we use it only to count and manage the seats you paid for.

When you contact us. Your message, your email address, and - if you opened a ticket from inside your install - a read-only snapshot of that install's configuration, which our software redacts of secrets before sending. That snapshot exists so we can diagnose your problem without asking you to describe it.

In our server logs. Your IP address, briefly, for rate limiting and abuse prevention.

Why we are allowed to hold it

Account, licence and payment data we hold to perform the contract you entered into when you bought a licence. Logs and rate-limiting data we hold on the basis of our legitimate interest in keeping the service available and unabused. Support messages we hold to answer them.

Who else processes it

  • Stripe - payments, subscriptions and receipts. Stripe is the controller of your card data; we never hold it.
  • Cloudflare - DNS, network protection, and the email routing that carries mail to and from our support address.
  • Google, GitHub, LinkedIn and Microsoft - only if you choose to sign in with one of them, and only to confirm you control the email address you are signing in with.
  • Our hosting provider, which stores the database this site runs on.

We use no analytics or advertising processors.

How long we keep it

Account, licence and purchase records are kept while your account exists and afterwards for as long as tax and accounting law requires us to keep the transaction. Support tickets are kept while they are useful for supporting you. Server logs are kept for a short operational window and then discarded.

Your rights

You can ask us for a copy of what we hold about you, ask us to correct it, or ask us to delete it. Deleting an account also ends the licences attached to it, because the licence is what the account is for. Email [email protected] and a person will answer - there is no form and no queue.

Your email address is the identity your licences, purchases and downloads hang off, so it is the one field you cannot change yourself. Ask us and we will move it for you.

Cookies

We set a session cookie so you stay signed in, and a CSRF cookie so forms submitted to us can be proven to have come from you. That is all. Neither follows you anywhere, and we set no cookie at all until you interact with something that needs one.

Changes

If this policy changes materially we will say so on this page, and the date below will move.

Contact

Questions about this policy, or about data we hold: [email protected].

Anything here unclear?

A person reads every message - ask and you'll get a straight answer.

Contact us