What we store — and what we don't.
This shop was built to hold as little as possible. Here is the complete list, so you can check it against the behaviour instead of trusting a paragraph.
What we store
- Your account number and its balance, orders, invoices and ledger entries.
- Shipping details — name, address and an optional contact — but only for phone orders that were actually placed, and only attached to that order.
- A session token, stored server-side as a salted hash; it expires after 12 idle hours.
- Short-lived technical logs (IP address, request time) kept for security and abuse prevention.
What we never store
- No email, no name, no phone number — unless you choose to leave a contact for a tracking note.
- No card data, no bank details, no payment processor account.
- No analytics, no advertising pixels, no third-party trackers.
- No cookies beyond the session cookie and your currency choice.
- Nothing about what you do on the phone itself: the OS sends no telemetry, and the dashboard never receives data from your device beyond license activation.
Things that are public by nature
Crypto payments are on-chain: whoever looks can see that an address received an amount. Your account number itself is random and carries no identity — but anyone who has it can spend the balance, so treat it like cash.
Your rights
Under the GDPR you can ask what we hold about your account and ask us to delete it. Because there is no identity attached, the account number is what identifies the data — write to support@nopwn.example and we act on the account that number points to. Deleting an account deletes its orders, licenses, balance and shipping details.
Shipping data retention
Shipping details are kept while the order is open and for as long as the warranty and returns windows require; after that they are deleted on request or with the account.