SHOPRECEIPTSBRAND
52X
BAG LOG IN
52X

Privacy & Cookie Policy

This Privacy & Cookie Policy explains how 52X LTD ("52X", "we", "us") collects, uses, stores, and shares personal data when you use 52x.store, create an account, purchase products, activate software, or join our mailing list.

Who we are

Data controller: 52X LTD

Registered address: 134 N 4th St., Brooklyn, NY 11249

Website: https://52x.store

Contact: hello@52x.store

We sell digital music production tools (including VST plugins) and may offer related services. This policy describes how we handle personal data for those activities.

Data we collect

We collect the following categories of data, depending on how you use the Site:

Account and identity: name, email address, password (stored hashed; we never store plain-text passwords), optional profile image (if you sign in with Google), account creation and update timestamps.

Authentication and session: session tokens (in cookies), session expiry, and optionally your IP address and browser user agent stored with active sessions.

Orders and commerce: order identifiers, products purchased, amounts paid, order timestamps, Stripe checkout session references, and licence keys issued to your account.

Licence and activation: licence key identifiers, product ID, machine/device identifiers submitted by the plugin during activation, signed licence files, and last-seen timestamps for activations.

Legal and consent records: which version of our Terms and Privacy Policy you accepted, timestamps of acceptance, whether you acknowledged immediate digital delivery, and the IP address recorded at checkout (where available).

Mailing list: email address and signup timestamp if you join the waitlist/mailing list.

Technical and security: IP addresses used for API rate limiting (stored temporarily in rolling hourly windows), Cloudflare request metadata as part of hosting, and Turnstile verification tokens on the mailing list form (processed by Cloudflare, not stored long-term by us).

Communications: email addresses and message content for transactional emails we send (order confirmations, password resets). In development or when email is not configured, copies may be stored in our database outbox for testing.

We do not currently run advertising pixels or third-party analytics on the Site. We do not store payment card numbers. Stripe handles payment data.

Why we process your data

We process personal data for these purposes and legal bases:

Purpose Typical data Legal basis (where GDPR applies)
Provide accounts and authentication Email, name, password hash, session data Contract; legitimate interests (security)
Process orders and deliver digital products Order data, licence keys, user ID Contract
Activate and enforce software licences Licence key, machine ID, email in signed licence file Contract; legitimate interests (fraud prevention)
Send transactional emails Email, order/licence details Contract; legitimate interests
Operate and secure the Site IP for rate limits, logs via Cloudflare Legitimate interests
Mailing list Email Consent (when you submit the form)
Record legal acceptances Consent timestamps, terms version, IP at checkout Legal obligation; contract
Comply with law Relevant records Legal obligation

We do not sell your personal data.

Accounts

When you create an account, we collect the information you provide (name, email, password) or receive from Google if you use Google sign-in (name, email, profile image, and OAuth tokens stored in our database).

We store session data including optional IP address and user agent to keep you logged in and to help detect abuse.

You can log out at any time. Password reset links are sent to your email address on request. Resetting your password revokes existing sessions.

Email address verification at sign-up is not currently required, but we may enable it in the future.

Purchases and payment information

Purchases require a logged-in account. At checkout we send your email and order details to Stripe for payment processing. Stripe collects and processes payment card and billing information under its own privacy policy.

We store in our database: order ID, products purchased, price paid, order status, Stripe session ID, and links to your user account. We do not store full card numbers or CVV codes.

If you use promotion codes, Stripe processes them as part of checkout.

Plugin activation and licensing data

When you activate a plugin, the software sends your licence key, a machine identifier generated on your device, and the product ID to our activation API. An optional plugin version field may be sent but is not currently stored.

We verify the licence key, check activation limits (currently up to 3 devices per licence), and return a cryptographically signed licence file that includes your email address, product ID, machine ID, and expiry information for offline use (including a limited offline grace period, currently up to 30 days).

We store activation records to enforce device limits and allow deactivation/revalidation. We do not currently store your IP address on licence API requests.

Uploaded audio and music

We do not currently offer a customer-facing upload service for mastering or other audio processing on the Site. No audio files are collected through the storefront today.

If we launch upload-based services in the future, we will update this policy to describe what is uploaded, how long it is kept, and who can access it.

Analytics

We do not use third-party analytics services (such as Google Analytics or similar) on the Site at this time.

Our cookie consent tool allows you to accept or reject non-essential cookies for future analytics or marketing, but no analytics scripts are loaded based on those choices today.

Cookies and tracking

Essential cookies and similar technologies

  • Authentication cookies: set by our auth system (for example session tokens) so you can stay logged in. These are necessary for account features and checkout.
  • OAuth cookies: short-lived cookies may be set during Google sign-in if that option is enabled.

Functional storage (browser, not cookies)

  • Shopping cart: we store product IDs and quantities in your browser's localStorage under the key plugin-website.cart. This does not contain personal information.
  • Cookie preferences: we store your cookie banner choice in localStorage under 52x.cookieConsent.

Third-party cookies on the mailing list

  • Cloudflare Turnstile: used only on the mailing list signup form to reduce spam. Turnstile may set cookies or use similar technologies as described in Cloudflare's documentation.

Non-essential cookies

We do not currently set analytics or marketing cookies. If we add them in the future, we will update this policy and honour your choices made through the cookie banner or Cookie Settings link in the footer.

You can control cookies through your browser settings. Blocking essential cookies may prevent login and checkout.

Marketing

If you join our mailing list at /mailinglist, we store your email address to send updates about 52X products and news. You must complete the Turnstile check to submit the form.

We do not send marketing email to purchasers automatically unless you separately opt in. Order confirmation emails are transactional, not marketing.

You can ask to be removed from the mailing list by contacting hello@52x.store.

Service providers and processors

We use the following categories of service providers who process data on our behalf:

Provider Role Data typically processed
Cloudflare Hosting, CDN, D1 database, R2 file storage, Turnstile Site traffic, stored account/order/licence data, download files, rate-limit IPs
Stripe Payment processing Email at checkout, payment information, order metadata
Brevo Transactional email delivery Recipient email, email subject and body
Google Optional OAuth sign-in Profile information and tokens if you choose Google login

We require processors to protect data under their terms and applicable law. Processor privacy policies:

  • Cloudflare
  • Stripe
  • Brevo
  • Google

International transfers

We and our processors may process data in the United States and other countries where they operate. If you are in the UK, EEA, or another region with transfer restrictions, we rely on appropriate safeguards where required (such as standard contractual clauses offered by processors, or your explicit consent where applicable).

Contact us if you need more information about transfers relevant to your location.

Data retention

We keep personal data only as long as needed for the purposes described in this policy:

  • Account data: while your account is active and for a reasonable period after deletion requests or inactivity, unless longer retention is required by law.
  • Order and licence records: for the life of your licence and as needed for tax, accounting, fraud prevention, and legal claims (typically several years).
  • Legal acceptance records: associated with your orders for as long as needed to demonstrate what terms applied to each purchase.
  • Mailing list: until you unsubscribe or ask for deletion.
  • Rate-limit data: rolling hourly windows; not kept as a long-term log of your activity.
  • Password reset tokens: until used or expired.
  • Development email outbox: in non-production environments, emails may be stored in a database table for testing and are not used in production when Brevo is configured.

Uploaded audio deletion and retention

Not applicable today. We do not collect uploaded audio from customers. This section will be updated if we launch upload-based services.

Security

We use technical and organisational measures appropriate to the risk, including encrypted connections (HTTPS), hashed passwords, signed licence files, access controls on infrastructure, and rate limiting on sensitive APIs.

No method of transmission or storage is 100% secure. Please use a strong unique password and keep your licence keys confidential.

If we become aware of a personal data breach likely to affect your rights, we will notify you and relevant authorities as required by applicable law (for example, within 72 hours under GDPR where applicable).

Report security concerns to hello@52x.store.

Your privacy rights

Depending on where you live, you may have rights to:

  • Access a copy of personal data we hold about you
  • Correct inaccurate data
  • Delete data in certain circumstances
  • Restrict or object to certain processing
  • Data portability where applicable
  • Withdraw consent where processing is based on consent (for example mailing list)
  • Lodge a complaint with your local data protection authority

To exercise rights, email hello@52x.store. We may need to verify your identity. We will respond within timeframes required by applicable law.

Children's privacy

The Site is not directed at children under 13 (or the minimum age in your country). We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it.

Changes to this policy

We may update this Privacy & Cookie Policy from time to time. The current version is always published at /legal/privacy with an effective date in our version records.

Material changes may be communicated by email or a notice on the Site where appropriate. Order-related processing remains governed by the privacy information that applied when you purchased, where required by law.

Contact details

52X LTD

Registered address: 134 N 4th St., Brooklyn, NY 11249

Email: hello@52x.store

Website: https://52x.store

For terms of purchase and software licensing, see Terms of Service.

Terms Privacy Withdrawal Contact

© 2026 52X LTD. 134 N 4th St., Brooklyn, NY 11249