CLOUD RIFTStore

Privacy

No advertising, no trackers, no accounts. What is collected is what it takes to sell you a product and to check its licence.

Last changed 9 October 2026

Who is responsible

Andrii Osypenko, a sole proprietor (FOP) registered in Ukraine, trading as CLOUD RIFT. Everything below is decided and done by one person, who can be reached at hello@cloudrift.team.

In the language of the GDPR that makes the seller the data controller for what this shop holds.

Reading the shop

Browsing the shop collects nothing from you. There are no accounts, no cookies, no advertising or analytics tags, and no scripts from anyone else on the pages while you read.

One thing is kept on your own device: whether you chose the light or the dark theme. It never leaves your browser.

The pages are static files served by Cloudflare, which keeps its own operational logs, including IP addresses, as any host does. That is covered by its privacy terms rather than by this page.

When you press Buy

Only when you press Buy does the page load the checkout, a script from the payment provider. From that moment the provider sees your browser, as any site you open does. The checkout is theirs, on their pages: your card details are typed into it and never reach this shop. Nobody here sees them, at any point.

When an order goes through, the provider passes on what is needed to stand behind it: your name, your email address, your country, what you bought and the order number.

We use it for three things: to get you the product, to answer you when you write about it, and to tell you about updates to products you own. A new build of something you paid for is part of what you paid for. It does not put you on any mailing list.

The basis is Article 6(1)(b) of the GDPR, the contract you entered by buying, and Article 6(1)(c) for the records that tax and accounting law requires to be kept.

The payment provider is not a processor of ours. It is an independent controller of the payment and of what it needs to take one: the card, the billing address, its fraud checks and the tax records it is obliged to keep. That is covered by its own privacy policy, which is available at the checkout.

Your key and your download

After you pay, the page you are sent to asks our licence server for your key and download link. The server creates the key, stores it with your order number and the product, and, if an email service is connected, emails it to the address you gave at checkout.

The files themselves sit in private storage with no public address. The link you are given works for fifteen minutes, and a new one is made each time you open your order page.

The licence server is a Cloudflare Worker with a Cloudflare D1 database. Email goes through Resend.

Licence checks

Some products ask for a licence key the first time they run, and check it again about once a day. Each check is a small request from your computer to license.cloudrift.team.

What is sent: the licence key, the name of the product, and an installation ID that is given to that computer when the key is first used. On first use there is also a short label for the installation, such as win-3fa91c07b2d4e865. It is worked out on your computer from the product, the computer's name and the name of the account you are logged in to, and only the result leaves it, never the names themselves. It is a code, not a name, but it is derived from yours, so it counts as pseudonymous rather than anonymous.

The server stores, for each key, the installations that have used it: the installation ID, the label, and the dates it was first and last seen. That is how it knows a key is not used on more computers than the licence allows, and how one of your machines can be told from another when a place has to be freed.

Nothing else is read from your machine, and nothing is sent about what you make with the product.

The basis is Article 6(1)(b) of the GDPR: checking the licence is part of delivering what you bought. If you are offline, the product keeps working for seven days before it needs to check again. A product with no licence key makes none of these requests.

Who else sees it

Cloudflare (hosting, the licence server and its database, private file storage) and Resend (the email that carries your key) handle your data as processors: on instruction and for no purpose of their own. Both are in the United States, so your data leaves the European Economic Area. The transfer rests on the Standard Contractual Clauses in their own data processing terms.

It is not sold, not shared with anyone else, and never used to send you anything you did not ask for.

How long it is kept

Order and licence records are kept for as long as tax and accounting law requires, and for as long as the licence they record is valid. That record is what lets you download a product again, or get a lost key back, long after you bought it.

Ask for any of it to go sooner and it goes, except what the law requires us to keep.

What you can ask for

A copy of what is held. A correction. Deletion. A pause on using it. A machine-readable export. Or an objection to it being held at all under legitimate interest.

Write to hello@cloudrift.team and say which. It is one person reading, so the answer comes from a person, within a month.

If the answer does not satisfy you, you can complain to a data protection authority: in Ukraine the Ombudsman's office, and in the EU the authority where you live.

Children

This shop sells tools for professionals. It is not aimed at children and nothing here is knowingly collected from them.

If this changes

The date at the top is when this page was last changed. Anything that changes what happens to data already collected will be told to the people it concerns, not quietly edited in here.

Questions about this page

Write to hello@cloudrift.team. One person reads it and answers within three business days.