Legal
Privacy policy
Last updated August 3, 2026
Keyplar is a delivery platform used by merchants to run customer portals for their digital products. Two different relationships are covered here, and it matters which one you're in:
- Merchants — you operate a Keyplar store. For your account data, Keyplar is the data controller.
- Store customers — you bought something from a store that runs on Keyplar. For your data, the merchant is the controller and Keyplar is a processor acting on their instructions. Requests about your data are best directed to the store you bought from; we support them in fulfilling every request.
Every store is isolated: your data at one store is never shared with, or visible to, any other store — even if you use the same email at both.
1. What we collect
From merchants
- Account details: name, email, store name and domain settings;
- Billing details, processed by Stripe (we store the subscription status and a Stripe customer reference — never card numbers);
- Encrypted credentials for the payment gateways you connect;
- The catalog, files, and benefit configuration you upload.
About store customers (on the merchant's behalf)
- Identity: email address and name, as provided by the payment gateway at checkout or at sign-in;
- Order records: products, amounts, currency, timestamps, refund status, and subscription state received from the merchant's gateway;
- Delivery records: license keys and activations, download entitlements and file metadata, and — if a GitHub benefit is claimed — the claimed GitHub username;
- Sign-in data: session records and, where used, OAuth identifiers from Google or GitHub. Passwords, where set, are stored only as hashes.
We do not sell personal data, we do not use it for advertising, and we collect no more than delivery requires.
2. How we use it
To operate the service: fulfilling orders, issuing and validating license keys, serving downloads over signed URLs, granting and revoking repository access, sending transactional email (magic links, receipts of access, quota notices), preventing abuse, and billing merchants. We use service providers — hosting, object storage, email delivery, and payment processing — bound to process data only on our instructions.
3. Customer rights: export and erasure
Exporting your data. Store customers can download everything a store holds about them as a JSON file from their account page at any time.
Deleting your account. Store customers can delete their account from their account page. Deletion immediately and permanently removes sign-in credentials, sessions, license keys, download entitlements, and any repository access granted — and strips the name, email address, and avatar from our records.
What must be kept. The record of purchases — order date, products, amounts, tax and currency — is retained because tax and accounting law requires merchants to keep transaction records, typically for 6–10 years depending on jurisdiction. After account deletion these records no longer identify you: they are linked to an anonymous placeholder, not to your name or email.
4. Merchant offboarding
When a merchant deletes their store, it goes offline immediately and all of its data — files, orders, customer records, credentials — is permanently deleted after a 30-day recovery window. Merchants closing a store should notify their customers beforehand so they can export their data while the store is still reachable.
5. Security
- Gateway credentials and secrets are encrypted at rest;
- Files are served only through signed, expiring URLs;
- License API keys are stored hashed and compared in constant time;
- Webhooks are signature-verified; sessions are revocable server-side;
- Access to production systems is restricted and audited.
6. Cookies
Keyplar uses only the cookies the service needs to function: session cookies for signed-in users and a short-lived, HttpOnly cookie that lets a buyer access their order immediately after checkout. This marketing site sets no analytics or advertising cookies.
7. International transfers
Data is hosted with cloud infrastructure providers and may be processed outside your country. Where EU/UK data is transferred internationally, we rely on appropriate safeguards such as standard contractual clauses with our providers.
8. Changes and contact
We will post updates to this policy here and, for material changes affecting merchants, give notice by email. Questions, requests, or complaints: support@keyplar.com. See also our terms of service.