Privacy

How we handle your data.

The plain version: we collect what the store needs to work, we don't sell it, and you can ask to see, correct, or delete it. The full account, with lawful bases and processors, follows.

Last updated 4 June 2026

  1. 01

    Who controls your data

    The data controller for Runciter Store is Eurisko Workshop SL (CIF B01801869), incorporated in Spain. This policy explains what personal data we collect, why, the lawful basis we rely on, who we share it with, and the rights you have under the EU General Data Protection Regulation (GDPR) and Spanish data-protection law.

    For any privacy question or to exercise your rights, write to [email protected].

  2. 02

    What we collect

    We collect only what we need to run the store and serve your account:

    • Account data: your name, email address, hashed password, and email-verification status.
    • Purchase and entitlement data: what you have bought, subscribed to, redeemed, or claimed, and your rune balance and ledger.
    • Payment data, handled by Stripe. We receive a customer reference and the status of payments; we never see or store your full card number.
    • Technical data: minimal logs needed for security and abuse prevention. For rate-limiting we store a one-way hash of your IP address, never the raw IP.
    • Communications: if you join the newsletter or a pre-campaign list, your email and the consent you gave.
  3. 03

    Why we use it, and our lawful basis

    We use your data for clearly defined purposes, each with a lawful basis under Article 6 GDPR:

    • To perform our contract with you (creating your account, taking payment, delivering downloads, running your subscription and runes) (Art. 6(1)(b)).
    • To meet legal obligations, such as tax and accounting records for purchases (Art. 6(1)(c)).
    • For our legitimate interests: security, fraud and abuse prevention, and keeping the service working (Art. 6(1)(f)).
    • With your consent, for marketing emails and newsletter, which you can withdraw at any time (Art. 6(1)(a)).
  4. 04

    Who we share it with

    We do not sell your data. We share it only with the processors that make the store work, each bound to handle it on our instructions:

    • Stripe, for payment processing and subscription billing.
    • Resend, for transactional and (where you consented) newsletter email delivery.
    • Backblaze B2, for storage of the model files you download and serving your downloads.
    • Our hosting and database provider, for running the application and storing your account record.
    • Meta Platforms, for advertising measurement via the Meta Pixel, only if you consent.
  5. 05

    International transfers

    Some processors operate outside the European Economic Area. Where that is the case, transfers are protected by appropriate safeguards such as the European Commission's Standard Contractual Clauses or an adequacy decision. You can ask us for details of the safeguards that apply.

  6. 06

    How long we keep it

    We keep personal data only as long as we need it:

    • Account and entitlement data: for as long as your account exists, so your library stays available to you.
    • Purchase and invoice records: for the period required by tax and accounting law (generally several years), even after an account is closed.
    • Rate-limit and security logs: short-lived; old windows are purged on a rolling basis.
    • Newsletter and marketing consent: until you unsubscribe or withdraw consent.
  7. 07

    Your rights

    Under the GDPR you have the right to:

    • Access the personal data we hold about you, and receive a copy.
    • Rectify data that is inaccurate or incomplete.
    • Erase your data where there is no overriding legal reason to keep it.
    • Restrict or object to certain processing, including direct marketing.
    • Port your data to another service in a structured, machine-readable form.
    • Withdraw consent at any time, without affecting processing already carried out.
  8. 08

    Cookies and tracking

    We use cookies strictly necessary to run the store, chiefly to keep you signed in and to protect against cross-site request forgery. Being strictly necessary, these always run and do not require consent under the ePrivacy rules.

    With your explicit consent we also load the Meta (Facebook) Pixel to measure how well our advertising performs. It is off by default; a banner lets you accept or decline, and you can withdraw consent at any time by declining or clearing the consent cookie. We use no other behavioural tracking, and never load the pixel until you opt in.

  9. 09

    Security

    We protect your data with measures appropriate to the risk: passwords are stored only as salted hashes, downloads are served through short-lived signed links tied to your entitlement, payment details never touch our servers, and access to administrative tools is restricted. No system is perfectly secure, but we take reasonable steps to keep yours safe and will notify you and the authorities of a breach where the law requires.

  10. 10

    Complaints and contact

    To exercise any right above, or if you have a concern about how we handle your data, contact [email protected] and we will respond within the time the law allows. You also have the right to lodge a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos, www.aepd.es) or your local supervisory authority.

    We may update this policy; the version in force is the one published here, dated at the top of the page.