Who We Are
This Privacy Policy explains how Stéphane Berger ("MousePlugins", "we", "us") processes personal data.
If you are in the EEA/UK, we process personal data in accordance with the GDPR and applicable local laws.
Zero Telemetry Policy (Software)
MousePlugins software products are designed to run as a closed system. We do not collect telemetry, usage analytics, audio content, or session data from your DAW.
What We Collect
A) Purchases & Licensing
To sell and deliver products (including license keys), we may process:
- Contact data: email address.
- Transaction metadata: order/reference IDs, product, price, currency, timestamps, refund status.
- License data: license key and its status (active/revoked), plus optional "seat" or entitlement metadata.
- Tax data (if required): VAT ID and invoicing fields you provide for billing purposes.
We do not store your full card details. Payments are handled by our payment processor(s) (e.g., Stripe).
Activation is performed locally by entering a license key. We do not contact a server to validate it and we do not receive activation events.
B) Customer Dashboard (Magic Link)
If you use our customer dashboard, we process your email to send a sign-in link and keep security logs (e.g., sign-in timestamps, IP/UA) to prevent abuse.
C) Newsletter (Optional)
If you subscribe, we process:
- Email address.
- Your opt-ins (separate toggles): (1) event discounts (country-based), (2) product updates, (3) new releases.
- Country (only if you opt into event discounts).
- Subscription/unsubscribe timestamps (for compliance).
D) Support (Optional)
If you contact support, we process what you send us (messages, attachments). If you choose to provide diagnostics, it may include device/OS/DAW details and software version. Do not send audio projects or sensitive personal data unless you truly want to.
E) Website Technical Data
Like every website on Earth (sadly), our servers may receive technical data such as IP address, user-agent, referring URL, and request logs for security and troubleshooting. We also use Plausible Analytics to understand aggregate website traffic (e.g., page views and referral sources). Plausible is designed to be cookie-less and to avoid tracking you across sites; we use it for high-level metrics, not to profile individuals.
fonts.bunny.net, and we may serve static assets or product downloads via Bunny.net CDN. These providers can receive your IP address and user-agent as part of normal web requests. If you prefer, we can self-host fonts and reduce third-party delivery.
Why We Use Data (and Legal Bases)
Who We Share Data With
We do not sell your personal data. We share it only with service providers who help us run MousePlugins:
- Payment processing: e.g., Stripe (processes payments and related fraud checks; we receive confirmation and transaction metadata).
- Hosting/infrastructure: to serve the website and downloads.
- Email delivery: for transactional emails (magic links, receipts) and, if you opt in, newsletters.
- Content delivery (CDN) & downloads: e.g., Bunny.net to serve files quickly and reliably (receives IP/user-agent as part of delivery).
- Website analytics (aggregate): Plausible Analytics (cookie-less, used to measure overall traffic and site performance).
Service Providers (Processors)
We use the following providers to operate MousePlugins. They may process limited technical data (e.g., IP address and user-agent) as part of delivering these services.
Some providers may process data outside the EEA/UK. Where required, we rely on appropriate safeguards (e.g., adequacy decisions and/or Standard Contractual Clauses).
How Long We Keep Data
- Purchase/accounting records: typically kept for 6 years from the last entry for business documentation, unless a longer period is required by law or to handle disputes.
- Licensing records: kept while the license remains active, plus reasonable time for audits, dispute resolution, and legal obligations.
- Newsletter: until you unsubscribe.
- Support tickets: kept as long as necessary to resolve your issue and for reasonable follow-up.
- Server security logs: typically short retention (e.g., days to weeks), unless needed for incident response.
Your Rights
Depending on your location (especially within the EEA/UK), you may have rights to access, correct, delete, restrict, object to processing, and request portability of your personal data.
Security
We use reasonable technical and organizational measures to protect personal data (TLS encryption in transit, access controls, and minimal data collection by design). No system is perfect, but we try harder than average.
Cookies
We use only what we need to make the website and dashboard work (e.g., session cookies, CSRF protection, and security/rate-limiting where applicable). We may also store your interface preferences (such as theme: light/dark and accent color) in a cookie or local storage so the site remembers your choice. We do not use tracking cookies for advertising. Our website analytics (Plausible) is designed to be cookie-less.
Changes to This Policy
If we change this policy, we'll update the "Last updated" date and, where appropriate, provide a notice on the website.