← Back to store

Privacy Policy

Last updated: September 8, 2026

This policy describes how NextByte AB ("we", "us", "our") collects and uses information when you buy or use a license through NextByte Commerce (nextbytecommerce.com). We're a Swedish company based in Norrköping, and this policy is written to comply with the EU General Data Protection Regulation (GDPR).

Who we are

NextByte AB, Norrköping, Sweden. For anything privacy-related, contact us.

What we collect

  • Account data — your name, email address, and a hashed (never plain-text) password.
  • Purchase & license data — which modules you've licensed, the term you bought, and your license key.
  • Payment data — we never see or store your card details. Payments are processed entirely by Stripe, our payment processor; we only receive confirmation that a payment succeeded and the email address Stripe collected.
  • Reviews & bug reports — anything you submit through those forms, tied to your account.
  • Cookies — a session cookie (keeps you logged in and your cart intact) and a CSRF token (blocks a class of attack on forms). Both are strictly functional — we don't use advertising or third-party tracking cookies.

Why we process it (legal basis)

  • Contract — creating your account, issuing your license, and providing support and updates for the term you bought.
  • Legitimate interest — preventing fraud, moderating reviews before they're published, and keeping the store secure.
  • Legal obligation — Swedish bookkeeping law requires us to retain accounting records (which include purchase records) for 7 years.

Who we share it with

Only the processors we need to run the store: Stripe (payments) and our email provider (sending your license key and account emails). We don't sell or rent your data to anyone, and we don't share it for advertising purposes.

How long we keep it

Account and license data for as long as your account exists, plus the 7-year retention Swedish accounting law requires for purchase records. You can ask us to delete your account at any time (see your rights, below) — we'll remove what we're not legally required to keep.

Your rights

Under GDPR, you can ask us to:

  • Give you a copy of the data we hold about you (access)
  • Correct anything that's wrong (rectification)
  • Delete your account and data, subject to our legal retention obligations (erasure)
  • Export your data in a portable format (portability)
  • Object to how we're processing it (objection)

Contact us for any of the above.

Changes to this policy

If we make a material change, we'll update the date at the top of this page. Continued use of the store after a change means you accept the updated policy.

We use cookies to improve your experience on our site — mainly to keep your cart and sign-in working. By continuing, you agree to our use of cookies. Read our Privacy Policy.