Privacy Policy

Last updated: — · Draft

This policy explains what soundweekends.com collects when you visit the site, buy a sound library or join the mailing list, why it is collected and how long it is kept. I run this site myself, I do not sell anyone’s data, and I collect as little of it as a shop can get away with.

Draft. The processors listed below (payments, e‑mail, hosting, analytics) are the ones planned for the shop and must be replaced with the services actually used before this page goes live. Company details and retention periods are placeholders.

1. Who is responsible:

The data controller for this site is [legal name of the business], [address], [VAT / company number], trading as Sound Weekends. For anything to do with your data, write to [privacy e‑mail] — it comes to me directly, there is no support department in between.

2. What is collected:

Nothing is asked of you just for reading the site. Data appears in three situations only: when you buy, when you subscribe, and when you write to me.

When What
You open a page Technical data your browser sends: IP address, browser and version, operating system, referring page, time of the request, and the pages viewed. Stored in the web server log.
You buy a library Name, e‑mail address, billing address and country, company name and VAT number if you buy as a business, the order itself (libraries, price, currency, tax rate and amount), and the payment reference returned by the payment provider.
You join the mailing list E‑mail address, the date and IP of the sign‑up as proof of consent, and whether the mails are opened.
You use the contact form Name, e‑mail address and whatever you write in the message.

Card numbers never reach this site. Payment details are entered on the payment provider’s own page or in their hosted field, and I only ever see the last four digits, the card brand and whether the payment went through.

3. Why, and on what legal basis:

Under the GDPR each purpose needs a legal basis. Mine are:

4. Who else sees the data:

Only the companies that are needed to run the shop, and only the part of the data each of them needs. Nothing is sold, rented or passed on for anyone else’s advertising.

Processor What it handles
[hosting provider] Runs the server, holds the site files, the database and the access logs.
[payment provider] Takes the payment, holds the card data, returns the result and the payout reports.
[e‑mail / newsletter provider] Sends order and download e‑mails and the mailing list.
[analytics] Aggregated visit statistics.
[accountant] Invoices, bookkeeping and tax filings.

Data may also be disclosed where the law requires it — a lawful request from an authority, or defending a legal claim.

5. Payments and VAT records:

Selling digital goods inside the EU means tax is charged according to where the buyer is, so the law requires me to record and keep two independent pieces of evidence of your location — usually your billing address and the country of your IP address or of your payment method.

If you buy as a business with a valid EU VAT number, the number is checked against the VIES database and the result of that check is stored with the order. Invoices, evidence of location and VAT returns are kept for the retention period set by tax law and cannot be deleted on request before it expires.

6. Mailing list:

The list is opt‑in and it is used for one thing: telling you when a new library is out and sending a few free sounds from it. No partner offers, no rented lists, no selling of addresses.

Every mail has an unsubscribe link, and one click is enough. After you unsubscribe your address is removed from the active list; a minimal record of the unsubscribe is kept so you are not accidentally added again.

7. Cookies and analytics:

Cookies are small files a site stores in your browser. This site uses as few as it can:

Type What for Consent
Essential Keeping the cart, the session and the checkout working, and remembering your cookie choice. Not required
Analytics Counting visits and seeing which pages are read, in aggregate. Required
Marketing Not used at the moment. Required if introduced

You can refuse or delete cookies in your browser settings at any time. Blocking essential cookies will break the cart and the checkout. Because there is no agreed industry standard for it, Do Not Track browser signals are not acted upon.

8. How long it is kept:

Data Kept for
Server access logs [N] days, then deleted automatically
Orders, invoices, VAT evidence [N] years — the period required by tax law
Customer account and licence record As long as the account exists, so download links can be re‑issued
Mailing list Until you unsubscribe
Contact form correspondence [N] months after the conversation ends

9. Transfers outside the EEA:

Some of the services above are run by companies based outside the European Economic Area, mainly in the United States. Where that happens the transfer is covered by the European Commission’s Standard Contractual Clauses or by an adequacy decision, and the processor is bound by a data processing agreement. The current list of processors and their locations is in section 4.

10. Your rights:

Wherever you live, you can ask me for any of the following, and I will answer within one month:

Residents of California have equivalent rights under the CCPA, including the right to know what is collected and to ask for deletion. I do not sell personal information, in the CCPA sense or any other.

To use any of these rights, write to [privacy e‑mail] from the address the data is connected to.

11. Children:

The shop is not aimed at children and I do not knowingly collect data from anyone under 16. If you are a parent or guardian and think your child has given me their data, write to me and I will delete it.

12. Security:

The site runs over HTTPS, administrative access is limited to me, backups are encrypted, and payment data is handled entirely by the payment provider. No system is perfectly secure, but if a breach ever affects your data I will notify you and the supervisory authority as the GDPR requires.

13. Automated decision‑making:

There is no profiling and no automated decision that has a legal or similarly significant effect on you. The payment provider runs automated fraud checks on transactions — for example temporarily blocking a card or an IP address after repeated failed attempts — and those checks are part of their own service.

14. Changes and complaints:

This policy will be updated when the shop changes — a new payment provider, a new tool, a new legal requirement. The date at the top always shows the current version.

If you are unhappy with how your data is handled, tell me first — it is usually a misunderstanding I can fix. You also have the right to complain to the data protection authority in the country you live in, or to [the supervisory authority of the country of establishment].

Questions about this policy: get in touch. See also the Licensing agreement.