Privacy Policy
Effective date: September 1, 2026
Busticated LLC ("Busticated", "we", "us", "our") makes audio software. This policy explains what
personal information we collect, why we collect it, who we share it with, how long we keep it, and
what you can ask us to do about it.
We are the data controller for the information described here.
Busticated LLC, 5441 S Macadam Ave #6369, Portland, OR 97239, United States
The short version
- We collect the account details you give us, the order records our store sends us, and the server-side records our own systems create when you use the Service.
- We never see your payment card details. Checkout happens on Shopify's systems, not ours.
- Our plugins make no network calls. They contain no license check, no activation, no product registration, and no usage reporting. Once a plugin is installed, it never contacts us, and it works whether or not you are signed in, online, or still a customer.
- There is no session recording, no advertising tracking, no cross-site tracking, no profiling, and no automated decision-making anywhere in the Service.
- We do not sell your personal information, and we do not share it for targeted advertising.
- Every cookie we set is strictly necessary to make the site work. We do not use advertising or analytics cookies, which is why you are not asked to dismiss a cookie banner.
- You can ask us for a copy of your data, ask us to correct it, or ask us to delete it, by emailing support@busticated.co.
The rest of this document is the detail behind those statements.
1. What this policy covers
Throughout this policy, the Service means all three of the following:
| Part | What it is |
|---|---|
| The website | busticated.co, including your account and the customer portal |
| Softboss | Our desktop application, which installs and updates plugins |
| The plugins | The audio plugins themselves (CLAP, VST3, AU) once installed on your computer |
Buying from us involves one system we do not operate: checkout is hosted by Shopify. When you
click through to buy, you are on Shopify's systems and Shopify's privacy policy governs what happens
there. We receive a record of the completed order afterward, described in section 2.3.
This policy does not cover third-party websites we link to. Once you follow a link away from the
Service, the privacy policy of wherever you land applies instead.
2. What we collect
2.1 Information you give us
Account information. When you create an account we collect your name and email address.
If you sign up with a password, we store a salted one-way hash of it and never the password itself.
If you sign in with Google instead, we receive your name, email address, and profile image from
Google, along with the tokens that let us verify your session. We never receive your Google
password.
Newsletter consent. If you opt in to our newsletter, we record that you did and when. The
checkbox on the sign-up form is unticked by default and never affects whether you can create an
account.
Support correspondence. If you email us, we keep the message and our reply so we can help you and
so we have a record of what was agreed.
Diagnostic reports you choose to send. Softboss may offer to send us a diagnostic report when you
are troubleshooting a problem. This is always optional, always initiated by you, and never automatic.
See section 2.4.
2.2 Information we collect automatically when you use the website
Session records. When you sign in we create a session record containing a session token, its
expiry, your IP address, your browser user-agent string, and a label identifying which client
you signed in from (a browser or Softboss). This is what keeps you signed in and what lets you review
and revoke your own sessions.
Server logs. Our servers write a log line for the requests they handle. Those lines carry
technical detail — the route, the outcome, timing — along with identifiers for the account, session,
and where relevant the order involved. Email addresses are masked in log fields before they are
written. Logs are written to one destination, our hosting provider's log stream, and are not
forwarded anywhere else.
IP address, for rate limiting. We resolve your IP address on authentication requests so that a
limit on sign-in attempts applies per visitor rather than to everyone at once. This is a security
measure, not analytics.
Error reports. When something in the Service throws an error, we send a report about that error to
PostHog so we can fix it. We capture errors and nothing else — page views, clicks, scrolling,
session replay, surveys, and user profiles are all switched off, and our test suite fails if anyone
turns one on. PostHog is configured to keep no identifier in your browser between page loads.
2.3 Information we receive about your orders
When you complete a purchase, Shopify sends us a record of it. What we store is deliberately narrow:
| We store | We do not store |
|---|---|
| Your email address | Your payment card details |
| Shopify's order id | Your billing address |
| The products and quantities ordered | Your shipping address |
| The payment status (paid, refunded, and so on) | Any part of the transaction Shopify handles itself |
| The date the order was placed |
Your card details never reach our systems in any form. If you buy physical merchandise, the shipping
address you enter stays with Shopify, who fulfill the order; it is not copied into our database.
2.4 Information we collect through Softboss
Requests Softboss makes on your behalf. Softboss signs you in and then asks our API what you own
and what is available to download. Those requests identify you the same way a browser would, and they
produce the same session records and server logs described in section 2.2. Softboss stores its
sign-in token in your operating system's keychain.
Records of what you install. When you install, update, or remove software through Softboss, it
records that action with us, so that we can support you, so that your account can show what you have,
and so we know which versions are actually in use before we change or retire one.
Optional diagnostic reports. Softboss may offer to send us a diagnostic report — local application
logs, your operating system and version, and details of your Softboss installation — when you are
reporting a problem. This never happens unless you choose it, it is off by default, and you are
told what the report contains before it is sent. We use these reports only to investigate the issue
you raised. Because logs can incidentally contain file paths, please review a report before sending
it if that concerns you.
What Softboss does not do. It runs no background agent, does not start itself at login unless you
ask it to, and collects nothing while you are not using it. Closing it never disables software you
have already installed.
2.5 What we never collect, anywhere
To be explicit, because some of these are common in our industry and we have decided against all of
them:
- No copy protection of any kind. No license keys, no activation, no serial numbers, no seat counting, no machine fingerprinting, and no dongle. There is nothing to lose and nothing to transfer.
- No network activity from a plugin. A plugin never calls home, never checks a license, never reports its usage, and never identifies your computer. It does not know or care whether you have an account.
- No audio, no projects, no session data. We never receive what you are working on.
- No advertising or cross-site tracking, no advertising pixels, no data brokers, and no fingerprinting scripts.
- No session replay and no recording of how you move through the site.
- No sensitive categories of personal information — we do not collect health, biometric, precise geolocation, racial or ethnic origin, religious belief, sexual orientation, union membership, government identifiers, or financial account numbers.
3. Why we collect it, and our legal basis
If you are in the European Economic Area or the United Kingdom, the GDPR requires us to name a lawful
basis for each purpose. Here they are.
| Purpose | What it uses | Lawful basis |
|---|---|---|
| Creating and running your account; keeping you signed in | Account details, session records | Contract — we cannot give you an account without it |
| Fulfilling your order and giving you access to what you bought | Order records, account details | Contract |
| Sending transactional email — verification, password reset, receipts, your download link | Email address, order records | Contract |
| Delivering and updating software through Softboss | Account details, install records | Contract |
| Customer support | Anything you send us, order records | Contract, and legitimate interests in running a supportable product |
| Security, abuse prevention, and rate limiting | IP address, session records, logs | Legitimate interests in keeping the Service available and accounts safe |
| Fixing bugs and crashes | Error reports, logs | Legitimate interests in a working product |
| Knowing which software versions are in use before changing or retiring one | Install records | Legitimate interests in not breaking working setups |
| Investigating a problem you reported | Optional diagnostic reports | Consent — you choose to send each one |
| Sending the newsletter | Email address, name, opt-in record | Consent — you opt in and can withdraw at any time |
| Meeting tax, accounting, and VAT obligations | Order records | Legal obligation |
| Responding to lawful requests and defending legal claims | Whatever the request concerns | Legal obligation, and legitimate interests |
Where we rely on legitimate interests, we have considered whether our interest is overridden by your
rights, and you can object at any time (section 8).
Withdrawing consent. You can unsubscribe from the newsletter using the link in any newsletter
email, or by emailing us. You can decline to send a diagnostic report, and declining costs you
nothing beyond making a problem harder for us to diagnose. Withdrawing consent does not affect
processing that already happened.
4. Cookies and similar technologies
Every cookie the Service sets is strictly necessary. We use no advertising cookies, no analytics
cookies, and no third-party tracking cookies, which is why the site does not ask you to accept
cookies before you can read it.
| Cookie | Purpose | Lifetime |
|---|---|---|
| Session cookie | Keeps you signed in and identifies your session to our server | Until it expires or you sign out |
| Sign-in state cookies | Carry the short-lived state needed to complete a sign-in securely, including Google sign-in | Minutes |
Our error-reporting tool is configured to keep its state in memory only, so it sets no cookie and
writes nothing to your browser's storage that survives a page load.
You can block or delete cookies in your browser settings. Blocking the session cookie will prevent
you from signing in, because it is the mechanism by which being signed in works.
Do Not Track and Global Privacy Control. There is no consistent standard for how sites should
respond to a Do Not Track header, so we do not act on it. We do honor Global Privacy Control signals
— though since we do not sell or share personal information or serve targeted advertising, there is
nothing for the signal to switch off.
5. Who we share it with
We do not sell your personal information, and we never have. We share it in three situations: with
the service providers who help us run the Service, when the law requires it, and if the business
itself changes hands.
5.1 Service providers
Each of these processes personal information on our instructions and is contractually bound to use it
only for the purpose we engaged them for.
| Provider | What it does for us | What it receives |
|---|---|---|
| Shopify | Hosts our store and processes checkout | Everything you enter at checkout, including payment details, which are handled by Shopify and its payment processors under PCI-DSS |
| Render | Hosts our application, database, and logs | Everything the Service stores, since it is the infrastructure the Service runs on |
| Brevo | Sends transactional email and the newsletter | Your email address and name, plus the contents of the messages we send you |
| PostHog | Receives error and crash reports | Technical error detail; where an error occurred inside a signed-in session, the identifiers on that report |
| Cloudflare | Stores the software archives you download | The download request itself; the archives contain no personal information |
| Provides "Sign in with Google", if you use it | The sign-in request. Google tells us your name, email, and profile image; we tell Google nothing about you | |
| Slack | Notifies us internally when an order or account is created | A short notification. Email addresses in these notifications are masked |
We have data processing agreements in place with these providers where the GDPR requires one.
5.2 Legal disclosures
We may disclose personal information where we are legally required to — in response to a subpoena,
court order, or other lawful request — or where disclosure is necessary to investigate suspected
fraud, enforce our Terms of Service, or protect the rights or safety of a person. We will not
volunteer your data to anyone who has not established a legal right to it.
5.3 Business transfers
If Busticated LLC is sold, merged, or reorganized, customer information may transfer with the
business, because your account and your purchases would need to keep working. Any acquirer would be
bound by this policy in respect of information collected under it until you are notified otherwise
and given a chance to object.
6. Where your information is stored
We are based in the United States and your information is stored in the United States. If you use
the Service from the European Economic Area, the United Kingdom, or anywhere else outside the US,
your personal information is transferred to and processed in the US, where data protection law
differs from your own.
For transfers of EEA and UK personal information, we rely on the European Commission's Standard
Contractual Clauses and the UK International Data Transfer Addendum, incorporated into our
agreements with the service providers listed in section 5.1. You can ask us for more detail on the
safeguards that apply.
7. How long we keep it
| Information | Retention |
|---|---|
| Account details | For as long as you have an account. Deleted when you ask us to delete your account |
| Session records | Until the session expires or you revoke it, whichever is first |
| Order records | 10 years from the date of the order. Required to meet tax, accounting, and EU/UK VAT record-keeping obligations, so these survive account deletion — see section 9 |
| Server logs | 90 days, after which they are deleted by our hosting provider on a rolling basis |
| Error reports | 12 months |
| Install and update records | For as long as you have an account |
| Optional diagnostic reports | 12 months, or sooner if you ask us to delete a report you sent |
| Newsletter subscription | Until you unsubscribe |
| Unsubscribe records | Indefinitely. We must remember that you unsubscribed in order to honor it |
| Support correspondence | 3 years from the last message in the conversation |
Where we are required to keep something for longer by law, or need it to establish or defend a legal
claim, we keep it for that period instead.
8. Your rights
8.1 If you are in the EEA or the UK
Under the GDPR and the UK GDPR you have the right to:
- Access — get a copy of the personal information we hold about you
- Rectification — have inaccurate or incomplete information corrected
- Erasure — have your information deleted, subject to the legal obligations in section 7
- Restriction — have us pause processing while a dispute about it is resolved
- Portability — receive the information you gave us in a structured, commonly used, machine-readable format, and have it sent to another controller where technically feasible
- Object — object to processing we base on legitimate interests, including at any time and for any reason where the processing is for direct marketing
- Withdraw consent — at any time, for anything we do on the basis of consent
You also have the right to lodge a complaint with a supervisory authority — your national data
protection authority in the EEA, or the Information Commissioner's Office in the UK. We would ask you
to raise it with us first, but that is a preference and not a precondition.
8.2 If you are in California or another US state with a privacy law
Depending on your state, you may have the right to know what personal information we collect and why,
to access a copy of it, to correct it, to delete it, to obtain it in a portable form, to opt out of
its sale, sharing, or use for targeted advertising or profiling, and to be free from discrimination
for exercising any of these rights.
We do not sell personal information, we do not share it for cross-context behavioral advertising,
we do not use it for targeted advertising, and we do not profile you. We have not done any of these
things in the preceding twelve months, including with respect to anyone under 16. There is therefore
no opt-out for you to exercise, but the other rights are available to you and we honor them
regardless of whether a given state's law strictly applies to a business our size.
The categories of personal information we have collected, the sources, the purposes, and the
recipients are set out in sections 2, 3, and 5 of this policy.
Authorized agents. You may use an authorized agent to make a request. We will ask for proof of
their authority and may ask you to confirm it directly.
Appeals. If we decline your request, you may appeal by replying to our response or emailing
support@busticated.co with "Appeal" in the subject line. We will
respond to an appeal within 45 days, in writing, with our reasons. If we deny the appeal, your state
attorney general's office can hear a complaint.
8.3 How to exercise any of these rights
Email support@busticated.co. Tell us what you want and, if you
have an account, write from the address on it — that is usually all the verification we need. If we
cannot match your request to an account, we may need to ask you for more information to confirm who
you are, and we will use anything you send for that purpose and no other.
We will respond within 30 days, or within 45 days for requests under a US state law. If a request
is genuinely complex we may extend that once and will tell you why before the original deadline
passes. Exercising your rights is free unless a request is manifestly unfounded or repetitive.
Some of this you can do yourself without asking us: your account page shows the details we hold and
lists every session signed in to your account, and you can revoke any of them there. You can
unsubscribe from the newsletter using the link in any newsletter email.
9. Deleting your account
You can ask us to delete your account by emailing
support@busticated.co.
What deletion removes: your name, email address, password credentials or linked Google account,
profile image, sessions, install records, newsletter subscription, and any diagnostic reports you
sent.
What survives, and why: the order records described in section 2.3 remain, detached from your
deleted account. Tax and VAT law requires us to keep a record of what was sold, to whom, and when,
for the period in section 7, and a deletion request cannot override a statutory retention duty. We
also keep an unsubscribe record so we do not email you again by mistake.
Server logs are deleted by expiry, not by purge. Logs written before your request roll off on the
90-day cycle in section 7. We do not selectively rewrite historical logs, because doing so would
undermine the security and audit purpose they exist for. They contain no email address, and after 90
days they contain nothing about you at all.
Deleting your account also ends your access to downloads and updates. Because we use no copy
protection, plugins you have already installed keep working — deleting your account does not
disable, expire, or remove any software on your computer.
10. Security
We protect your information with measures appropriate to its sensitivity:
- All traffic to and from the Service is encrypted in transit with TLS.
- Passwords are stored as salted one-way hashes and are never recoverable, by us or by anyone else.
- We never handle payment card data at all, which removes the single most valuable target from our systems.
- Access to production systems is restricted to those who need it and protected by two-factor authentication.
- Secrets, credentials, and email addresses are masked or redacted before anything is written to a log.
- Sign-in endpoints are rate-limited per visitor to frustrate credential-stuffing attacks.
- Downloads are served through short-lived, single-purpose links issued only to entitled accounts.
No system is perfectly secure, and we will not claim otherwise. If we become aware of a breach
affecting your personal information, we will notify you and the relevant supervisory authority as the
law requires, without undue delay.
11. Children
The Service is not directed at anyone under 16, and we do not knowingly collect personal
information from children under 16. If you are a parent or guardian and believe a child has given us
personal information, email support@busticated.co and we will delete
it.
12. Automated decision-making
We do not make decisions about you by automated means that produce legal or similarly significant
effects, and we do not profile you.
13. Changes to this policy
We may update this policy to reflect changes in what we do, in the services we use, or in the law.
When we do, we will change the effective date at the top and post the new version here.
If a change materially affects how we handle your personal information, we will tell you before it
takes effect — by email to account holders, or by a prominent notice on the site. Continuing to use
the Service after a change takes effect means the updated policy applies to you.
14. Contact us
For anything in this policy, including any request under section 8, contact:
Busticated LLC, 5441 S Macadam Ave #6369, Portland, OR 97239, United States