Privacy Policy
Last updated: September 8, 2026
This policy describes how NextByte AB ("we", "us", "our") collects and uses information when you buy or use a license through NextByte Commerce (nextbytecommerce.com). We're a Swedish company based in Norrköping, and this policy is written to comply with the EU General Data Protection Regulation (GDPR).
Who we are
NextByte AB, Norrköping, Sweden. For anything privacy-related, contact us.
What we collect
- Account data — your name, email address, and a hashed (never plain-text) password.
- Purchase & license data — which modules you've licensed, the term you bought, and your license key.
- Payment data — we never see or store your card details. Payments are processed entirely by Stripe, our payment processor; we only receive confirmation that a payment succeeded and the email address Stripe collected.
- Reviews & bug reports — anything you submit through those forms, tied to your account.
- Cookies — a session cookie (keeps you logged in and your cart intact) and a CSRF token (blocks a class of attack on forms). Both are strictly functional — we don't use advertising or third-party tracking cookies.
Why we process it (legal basis)
- Contract — creating your account, issuing your license, and providing support and updates for the term you bought.
- Legitimate interest — preventing fraud, moderating reviews before they're published, and keeping the store secure.
- Legal obligation — Swedish bookkeeping law requires us to retain accounting records (which include purchase records) for 7 years.
Who we share it with
Only the processors we need to run the store: Stripe (payments) and our email provider (sending your license key and account emails). We don't sell or rent your data to anyone, and we don't share it for advertising purposes.
How long we keep it
Account and license data for as long as your account exists, plus the 7-year retention Swedish accounting law requires for purchase records. You can ask us to delete your account at any time (see your rights, below) — we'll remove what we're not legally required to keep.
Your rights
Under GDPR, you can ask us to:
- Give you a copy of the data we hold about you (access)
- Correct anything that's wrong (rectification)
- Delete your account and data, subject to our legal retention obligations (erasure)
- Export your data in a portable format (portability)
- Object to how we're processing it (objection)
Contact us for any of the above.
Changes to this policy
If we make a material change, we'll update the date at the top of this page. Continued use of the store after a change means you accept the updated policy.