Privacy Policy
This privacy policy describes how MX36 Suite ("we", "us") collects and uses your personal data when you visit mx36suite.cc or use MX36 Suite software.
MX36 Suite is operated as a sole trader. We are not affiliated with XTA Audio Ltd.
1. Data we collect
When you create an account
- Email address — used to deliver your license key, send transactional emails, and log into your account.
- Password — stored as a salted bcrypt hash. We never store your plaintext password.
When you purchase
- Order reference and amount — received from Gumroad to link your purchase to your account.
- Buyer email — provided by Gumroad to deliver your license key. Payment data (card details, billing address) is handled exclusively by Gumroad and is never sent to us.
When you activate a license
- Hardware ID (HWID) — a one-way hash derived from your machine. Used solely to enforce single-seat activation.
- IP address — logged during activation and emergency deactivation for security purposes. Retained for 90 days.
Server logs
Our web server logs standard HTTP request data (IP address, timestamp, requested URL, HTTP status code) for security and diagnostics. Logs are retained for 30 days and then deleted.
2. How we use your data
- To deliver and manage your license keys.
- To send transactional emails (purchase confirmation, email verification, password reset).
- To enforce one-seat-per-license-key activation.
- To investigate suspected abuse or fraud.
We do not sell your data, use it for advertising, or share it with third parties except as described below.
3. Third-party services
- Gumroad — payment processing. Your payment data is subject to Gumroad's privacy policy.
- Resend / SMTP provider — transactional email delivery.
- Hetzner Online GmbH — server hosting (Germany, EU). Data is stored in the European Union.
4. Legal basis (GDPR)
We process your data on the following legal bases:
- Contract performance (Art. 6(1)(b) GDPR) — processing necessary to deliver the software and license you purchased.
- Legitimate interests (Art. 6(1)(f) GDPR) — server logs and security logging.
5. Data retention
- Account data is retained until you delete your account.
- Order and license data is retained for 7 years for legal/tax compliance, even after account deletion.
- Server logs: 30 days. Activation IP logs: 90 days.
6. Your rights
Under GDPR, you have the right to access, rectify, erase, restrict, or export your personal data. You may exercise these rights by contacting us at privacy@mx36suite.cc. You can delete your account at any time from your profile settings.
7. Cookies
We use one first-party session cookie (session) to keep you logged in. No third-party tracking cookies are used. No analytics services are active.
8. Contact
Questions about this policy? Email privacy@mx36suite.cc.