Files delivered as downloads — on screen and by email, as soon as payment is confirmed.

Privacy Policy

This explains what we do with personal data on digitalskylight.com. It describes what the site actually does — not a generic list of things a shop might do.

Short version: we take an email address so we can send you what you bought, we keep an order record because tax law says we must, we answer messages you send us, and that is essentially it. We do not run analytics, we do not use advertising trackers, and we do not have a mailing list.

Contents

1. Who is responsible for your data

(owner review needed — registered legal name — set BUSINESS_LEGAL_NAME), seat at Janáčkova 3392/17, 702 00 Moravská Ostrava a Přívoz, Czechia, IČO (owner review needed — IČO, the company identification number — set BUSINESS_ICO), is the controller of the personal data described here.

Contact for anything about privacy: support@digitalskylight.com

We are a small operation and we are not required to appoint a data protection officer, so we have not appointed one. Your message goes to the people who actually run the store.

When you buy something

WhatWhyLegal basis
Your email address (collected by Stripe at checkout and passed to us)To send your download link and your order confirmation, and to help you if something goes wrongPerforming our contract with you — GDPR Art. 6(1)(b)
Order record: order number, Stripe payment references, which products, amount, currency, your billing country, payment and delivery status, datesTo fulfil the order, and to keep the accounting and tax records the law requiresContract — Art. 6(1)(b); legal obligation — Art. 6(1)(c)
A one-way hash of your download linkSo we can check your download link is valid without storing a usable copy of itContract — Art. 6(1)(b)
A record that you ticked the immediate-delivery confirmation, the exact wording shown, and the date and timeCzech consumer law requires us to be able to show this, and it protects both of us if there is a disputeLegal obligation — Art. 6(1)(c); and our legitimate interest in establishing or defending legal claims — Art. 6(1)(f)

We never receive your card number, expiry date or security code. Payment happens on Stripe's own page. Card details go from you to Stripe and never touch our servers.

When you use the contact form

WhatWhyLegal basis
Your name, email address and messageTo read your message and reply to itIf your message is about buying or an existing order: steps at your request before or under a contract — Art. 6(1)(b). Otherwise: our legitimate interest in answering someone who contacted us — Art. 6(1)(f)

Your message is emailed to our support inbox. We do not store contact-form messages in a database, and we do not add you to any list.

Please don't send card details or other sensitive personal information through the form — it is ordinary email, and there are better ways for us to help you.

Automatically, when you use the site

WhatWhyLegal basis
A salted, one-way hash of your IP address, with a timestamp, when you submit the contact formTo stop the form being flooded with spam. We do not store your actual IP address for thisLegitimate interest in keeping the form usable — Art. 6(1)(f)
Server access logs kept by our hosting provider: IP address, browser user agent, page requested, timeSecurity, spotting abuse, and diagnosing errorsLegitimate interest in running the site securely — Art. 6(1)(f)

What we do not collect

No passwords or accounts. No postal address (beyond the billing country Stripe gives us for tax purposes). No phone number, unless you choose to put one in a message. No marketing preferences, because there is no marketing. No analytics or advertising identifiers. No uploaded files. No location data. No special-category data — health, beliefs, biometrics and so on. We do not profile you and we do not make automated decisions about you.

3. Cookies

We use two cookies. Both are strictly necessary, and there is nothing to consent to — which is why you will not see a cookie banner here.

CookieWhat it doesHow long
Session cookieRemembers what is in your basket, and links your browser to the security token that protects your checkoutDeleted when you close your browser
Security (CSRF) tokenStops someone else's website submitting our checkout or contact form as youDeleted when you close your browser

Both are set by us, on our own domain. Neither is used to track you, build a profile, or share anything with anyone.

Under Czech law (Act No. 127/2005 Sb., § 89(3), which has required opt-in consent for cookies since 1 January 2022), consent is not needed for storage that is strictly necessary to provide a service you have asked for. A basket that remembers your items and a token that protects your own checkout are exactly that.

We also don't set these cookies until you need them — browsing the catalogue sets nothing. The session starts when you add something to your basket, open the checkout, or use the contact form.

What we deliberately do not use: Google Analytics or any other analytics, Google Tag Manager, Meta/Facebook Pixel, TikTok or any advertising pixel, Hotjar, Microsoft Clarity, heatmaps, fingerprinting, Google Fonts or any external font or script CDN, embedded maps, embedded video, social media widgets, chat widgets, captcha services, or affiliate tracking.

Our fonts and scripts are served from our own server, so loading a page on this site does not send your IP address to any third party.

If we ever add anything that isn't strictly necessary, we will ask for your consent properly first — meaning it will not load until you agree, and refusing will be as easy as accepting.

4. Who else sees your data

We do not sell your data, rent it, or share it for anyone else's marketing. These are the only parties involved, and each is there because the site cannot work without them:

Stripe — payment processing

Payments are handled by Stripe Payments Europe, Ltd. (Ireland) and its group companies.

Stripe has two roles, and it matters which is which:

  • For the parts of the service it provides on our instructions, Stripe acts as our processor under a data processing agreement.
  • For its own regulated purposes — running the payment network, fraud and risk monitoring, anti-money-laundering and know-your-customer checks, and its own legal obligations — Stripe acts as an independent controller. That processing is governed by Stripe's own privacy policy, not ours, and your rights in respect of it are against Stripe.

Stripe receives your payment details, your email address and your billing country. It passes your email address, billing country and payment status back to us. Stripe's privacy policy: https://stripe.com/privacy

Stripe is part of a US-headquartered group. Where data reaches the United States, Stripe relies on the European Commission's Standard Contractual Clauses through its Data Transfers Addendum, and is certified under the EU–US Data Privacy Framework.

Our hosting provider

(owner review needed — hosting provider and country — set BUSINESS_HOSTING_PROVIDER). They host the site and the order database, and keep the server access logs described above. They act as our processor. Namecheap is established in the United States, so hosting your order data involves a transfer outside the EEA. That transfer is covered by the European Commission's Standard Contractual Clauses, which form part of Namecheap's Data Processing Addendum.

Our email provider

(owner review needed — email provider and country — set BUSINESS_EMAIL_PROVIDER). They deliver your order confirmation and carry contact-form messages to our inbox. They act as our processor. This is the same provider, and the same safeguard applies: the transfer to the United States is made under the European Commission's Standard Contractual Clauses in Namecheap's Data Processing Addendum.

We do not use open tracking or click tracking in our emails. Opening your order confirmation tells us nothing.

Others

We may share data with our accountant or tax advisers, or with an authority or court where the law requires it. Nothing else.

5. How long we keep things

DataKept for
Order records, including your email address and billing country5 years from the end of the accounting period in which the order was placed, as required by Act No. 563/1991 Sb. on accounting
Your immediate-delivery confirmation recordKept with the order record, for the same period
Download link hashes and delivery metadataLinks are valid for 30 days; the hash is deleted 30 days after that. Re-issued links follow the same rule
Contact-form messages in our support inbox12 months
Anti-spam IP hashesUp to 24 hours, then automatically deleted
Server access logs(owner review needed — server log retention — set BUSINESS_LOG_RETENTION)

The long retention on order records is not our choice — Czech accounting and tax law requires it. It is also why we cannot always delete an order record on request (see below).

6. Your rights

If you are in the EU or EEA, the GDPR gives you the right to:

  • Get a copy of the personal data we hold about you;
  • Correct anything that is wrong;
  • Have data deleted — though not where we are legally required to keep it, which applies to the accounting and tax parts of an order record;
  • Restrict how we use your data while a question about it is being resolved;
  • Receive your data in a portable, machine-readable format, for the data we hold in order to perform our contract with you;
  • Object to the processing we do on the basis of legitimate interests — our server logs and the anti-spam hashes;
  • Complain to a supervisory authority.

We do not rely on consent for any of the processing described here, so there is no consent for you to withdraw. (The box you tick at checkout is a request under consumer law for immediate delivery — it is not data protection consent, and it does not affect these rights.)

To exercise any of these: email support@digitalskylight.com. We will reply within one month. We may need to check you are the person the data relates to — usually by confirming you can use the email address the order was placed with.

To complain, in Czechia:

Úřad pro ochranu osobních údajů Pplk. Sochora 27, 170 00 Praha 7, Czechia https://uoou.gov.cz/

You can also complain to the supervisory authority in the EU country where you live or work.

7. Security

We take reasonable technical and organisational measures to protect your data. In practice that means: the site is served over HTTPS; product files are stored outside the public web root and can only be reached through a token check; download tokens are stored as hashes, not as usable links; card details never reach us at all; access to the order database is restricted; and we deliberately collect and keep as little as we can.

No system is completely secure, and we are not going to tell you otherwise. If a breach happens that puts your rights at risk, we will notify the supervisory authority and, where required, you.

8. Children

This store is aimed at adults and we do not knowingly collect personal data from children. If you believe a child has given us personal data, email support@digitalskylight.com and we will remove it.

Product pages may mention or link to other companies' tools. Those sites have their own privacy practices and we are not responsible for them. This policy covers only digitalskylight.com and the payment step on Stripe's checkout page that we send you to.

10. Changes

If we change how we handle personal data, we will update this page and change the version and date at the top. If a change is significant — for example if we ever introduce analytics — we will make that clear rather than quietly editing the text.