Last updated: August 09, 2026
Chiranjeev Singh, trading as RunicDevs, Delhi, India. Contact: [email protected].
Email address — entered at checkout, used to identify your subscription and to sign you in. If you begin checkout and do not complete payment, your email is retained as a sales enquiry so I can follow up.
Subscription data — your PayPal subscription ID, plan, status, and next billing date, received from PayPal.
Login codes — a hashed one-time code, stored for ten minutes and deleted on use or expiry. No passwords are collected or stored.
Session — a signed, HTTP-only cookie identifying your subscription, valid for 30 days. It is strictly necessary for the billing area to function.
Correspondence — anything you send by email, retained in my mailbox.
I do not collect card or bank details. Payment information is handled entirely by PayPal and never reaches this site. I do not use advertising or analytics cookies.
Providing the service and billing you — performance of a contract. Signing you in and keeping accounts secure — legitimate interests. Following up on incomplete checkouts — legitimate interests, and you may object at any time. Retaining transaction records — legal obligation.
PayPal (payment processing and subscription management), Resend (sending login codes), Cloudflare (hosting, storage, email routing). Each processes data only to deliver those functions. Nothing is sold or shared for advertising.
Data is stored in Cloudflare Workers KV, which replicates globally, and is accessed from India. Where you are in the UK or EEA, transfers rely on Standard Contractual Clauses or equivalent safeguards operated by these providers.
Subscription records: for the life of the subscription and up to eight years afterwards, for tax and accounting purposes. Incomplete checkout enquiries: up to 12 months, or until you ask for deletion. Login codes: ten minutes. Sessions: 30 days.
You may request access to your data, correction, deletion, restriction, portability, or object to processing based on legitimate interests — including the follow-up on incomplete checkouts. Email [email protected] and I will respond within 30 days. Deletion requests are honoured except where records must be kept for tax purposes. UK and EEA residents may complain to their local supervisory authority.
Login codes are stored hashed with a limited number of attempts. Sessions are cryptographically signed. Credentials for third-party services are held as encrypted secrets. No system is perfectly secure; I will notify affected clients without undue delay if a breach occurs.
The service is intended for businesses and is not directed at anyone under 18.
Material changes will be notified by email to active subscribers.