Legal · Privacy policy

Your data, our discipline.

What we collect, why we collect it, and what you can do about it. Frame Station is GDPR-compliant and we sell zero data, ever.

Last updatedMay 3, 2026
Server room with dark drives and cables
◇ doc.3028
EU data residency · Frankfurt / Paris
§01

What we collect

  • Account: name, email, hashed password, locale.
  • Orders: billing address, VAT number, purchased items. Payment data is held by PayPal, never by us.
  • Usage: page views, downloads, device type. Aggregated for product decisions.
  • Communications: any email or message you send the studio.
§02

Why we collect it

To deliver the service: process orders, host downloads, prevent fraud, send transactional emails, and improve the product. No targeted advertising, no third-party trackers, no resale.

§03

Cookies

We use first-party cookies for authentication and locale. We also use a single privacy-respecting analytics provider (Plausible, EU) that sets no tracking cookies and does not fingerprint visitors.

§04

Where data lives

All personal data is hosted in the European Union (Hetzner Frankfurt, OVH Roubaix). Backups are encrypted at rest and retained for 30 days. PayPal holds payment data under its own terms.

§05

Your rights

Under GDPR you have the right to access, rectify, port, or delete your data. Submit any request via studio/contact; we respond within 30 days, no questions asked.

  • Right of access · article 15
  • Right to rectification · article 16
  • Right to erasure · article 17
  • Right to portability · article 20
  • Right to object · article 21
§06

Retention

Account data is retained while your account is active. Orders are retained for 10 years (French commercial law). Logs are rotated every 90 days.

§07

Contact the DPO

Data protection officer: dpo@frame-station.com. You may also lodge a complaint with the CNIL (France) or your local supervisory authority.