Privacy Policy
Data Collection and Processing
1. Demo Request Form
When you submit a demo request through our website, the following information is collected:
- Personal Information: Name (optional), email address, Raspberry Pi model selection
- Processing: Demo requests are processed through Netlify Functions (serverless backend) and Resend (email delivery service)
- Email Verification: You must verify your email address by clicking a verification link sent to your email. Verification tokens are stored temporarily in Netlify Blobs for 24 hours, then automatically deleted
- Data Storage: After email verification, your email address, name, Pi model selection, subscription status, and request timestamps are stored indefinitely in Netlify Blobs (secure cloud storage) until you request deletion
- Purpose: To verify email ownership, send personalised demo download links with SHA256 checksums, and maintain mailing list subscriptions
2. Licence Purchases and Payment Information (via Stripe)
When you purchase a licence through our Stripe checkout links, the following information is collected:
- Personal Information: Name, email address, billing address
- Payment Information: Credit/debit card details, payment method information (processed securely by Stripe)
- Third-Party Processor: All payment processing is handled by Stripe
- Data Location: Stripe stores payment data on their secure servers
- Purpose: To process licence purchases and payments
3. Mailing List
By submitting a demo request, you agree that your email address will be added to the Intuition Subsynth mailing list. We send:
- Demo download instructions
- Occasional product updates
- New sound pack announcements
- Raspberry Pi compatibility updates
You can unsubscribe at any time using the unsubscribe link included in every email we send.
Third-Party Services
Netlify (Serverless Functions & Blob Storage)
- Service: Serverless backend functions and persistent data storage (Netlify Blobs)
- Data Shared: Name (optional), email address, Pi model selection, subscription status, request timestamps, verification tokens
- Purpose: Demo request processing, email verification, mailing list management, and persistent subscriber data storage
- Data Retention: Verification tokens are automatically deleted after use or 24-hour expiration. Verified email addresses and associated data are stored indefinitely in Netlify Blobs until you request deletion
- Privacy Policy: netlify.com/privacy
Resend (Email Delivery Service)
- Service: Transactional email delivery
- Data Shared: Email address, name (optional), Pi model selection
- Purpose: Send verification emails and demo download links
- Email Types: Email verification requests and demo delivery emails with download links
- Privacy Policy: resend.com/legal/privacy-policy
Stripe (Payment Processing)
- Service: Secure payment processing for licence purchases
- Data Shared: Name, email, billing address, payment information
- Purpose: Process licence payments securely
- Privacy Policy: stripe.com/privacy
- Security: PCI-DSS Level 1 certified, highest security standard
- Data Processing: United States and globally via Stripe's infrastructure
- Card Data Storage: We never see or store your full card details - handled entirely by Stripe
YouTube Embeds
- Service: Video playback via youtube-nocookie.com
- Data Collection: We use YouTube's privacy-enhanced mode which does not set cookies until you interact with the video player
- Privacy Policy: policies.google.com/privacy
Google Fonts
- Service: Web font delivery
- Data Collection: Google may collect usage statistics
- Privacy Policy: policies.google.com/privacy
Plausible Analytics
- Service: Privacy-friendly analytics (no cookies, no personal data)
- Data Collected: Aggregated page views, referrers, country-level location, device/OS/browser, and custom event counts (e.g. demo form clicks)
- Purpose: Understand which parts of the site are used so we can improve content and fix issues
- Retention: Aggregated metrics only; no personal identifiers or IP addresses are stored
- Privacy Policy: plausible.io/data-policy
Browser Storage
Local Storage
- Theme Preference: Stores your light/dark mode preference
- Data Stored: Single value (
'light'or'dark') - Retention: Until you clear browser data
Session Storage
- Buy Bar State: Stores whether you've dismissed the sticky purchase bar
- Data Stored: Single value (
'1'if dismissed) - Retention: Until you close the browser tab
No personal data is stored in browser storage. These preferences are stored locally on your device only.
Cookies
We do not use first-party cookies for tracking or analytics.
Stripe may set cookies during checkout to prevent fraud and ensure secure payment processing.
Data Security
- HTTPS: All connections use HTTPS encryption
- Content Security Policy: Restricts which external resources can be loaded
- Security Headers: X-Frame-Options, X-Content-Type-Options protect against common attacks
- Permissions Policy: Restricts access to sensitive browser APIs
- Privacy-Enhanced YouTube: Uses youtube-nocookie.com to minimize tracking
Your Rights
You have the right to:
- Access: Request a copy of the data we hold about you
- Rectification: Request correction of inaccurate data
- Erasure: Request deletion of your data
- Unsubscribe: Stop receiving marketing emails at any time
- Portability: Receive your data in a machine-readable format
To exercise these rights, contact us at: privacy@intuitionsubsynth.com
Data Retention
- Demo Requests & Mailing List: Email addresses, names, Pi model selections, and subscription status are retained indefinitely in Netlify Blobs until you unsubscribe or request deletion. Verification tokens expire and are automatically deleted after 24 hours
- Purchase Records: Retained as required for accounting and tax purposes (typically 7 years)
- Browser Storage: Retained until you clear browser data
International Data Transfers
Netlify & Resend (United States)
- Demo request data is processed via Netlify Functions and Resend in the United States
- Verified email addresses and subscriber data are stored indefinitely in Netlify Blobs until deletion is requested
- Verification tokens are stored in Netlify Blobs temporarily (maximum 24 hours), then automatically deleted
- Both services comply with applicable data protection regulations including GDPR
Stripe (Global)
- Payment data is processed in the United States and globally via Stripe's secure infrastructure
- Stripe is PCI-DSS Level 1 certified
- Stripe complies with GDPR and other international data protection laws
- Standard contractual clauses and adequate safeguards in place
GDPR Compliance
For users in the European Economic Area (EEA):
- Legal Basis: Consent (by submitting forms or making purchases)
- Data Controller: Intuition Subsynth
- Data Processors: Netlify (serverless functions & storage), Resend (email delivery), Stripe (payment processing)
Children's Privacy
Our website is not directed at children under 13. We do not knowingly collect personal information from children.
Changes to This Policy
We may update this privacy policy from time to time. The "Last Updated" date at the top indicates when changes were last made.
Contact
Email: privacy@intuitionsubsynth.com
Subject Line: "Privacy Inquiry"
Summary
What we collect:
- Demo request details (name, email, Pi model, subscription status, timestamps) stored indefinitely in Netlify Blobs until deletion requested
- Purchase and payment information via Stripe checkout
- UI preferences in browser storage (no personal data)
- Anonymous site usage metrics (page views, clicks, referrers) via Plausible Analytics
How we use it:
- Send demo downloads and respond to requests
- Process secure licence purchases and payments
- Send occasional product updates (you can unsubscribe anytime)
Your data is:
- ✅ Encrypted in transit (HTTPS)
- ✅ Stored indefinitely in Netlify Blobs until you request deletion
- ✅ Processed by Netlify and Resend for demos, and Stripe for payments
- ✅ Payment card details never stored by us (handled securely by Stripe)
- ✅ Not sold or shared with advertisers
- ✅ Protected by security headers and policies
- ✅ Deletable upon request via automated GDPR deletion function
For questions or data requests: privacy@intuitionsubsynth.com