Privacy Policy

Effective date: September 1, 2026
Busticated LLC ("Busticated", "we", "us", "our") makes audio software. This policy explains what personal information we collect, why we collect it, who we share it with, how long we keep it, and what you can ask us to do about it.
We are the data controller for the information described here.
Busticated LLC, 5441 S Macadam Ave #6369, Portland, OR 97239, United States

The short version

  • We collect the account details you give us, the order records our store sends us, and the server-side records our own systems create when you use the Service.
  • We never see your payment card details. Checkout happens on Shopify's systems, not ours.
  • Our plugins make no network calls. They contain no license check, no activation, no product registration, and no usage reporting. Once a plugin is installed, it never contacts us, and it works whether or not you are signed in, online, or still a customer.
  • There is no session recording, no advertising tracking, no cross-site tracking, no profiling, and no automated decision-making anywhere in the Service.
  • We do not sell your personal information, and we do not share it for targeted advertising.
  • Every cookie we set is strictly necessary to make the site work. We do not use advertising or analytics cookies, which is why you are not asked to dismiss a cookie banner.
  • You can ask us for a copy of your data, ask us to correct it, or ask us to delete it, by emailing support@busticated.co.
The rest of this document is the detail behind those statements.

1. What this policy covers

Throughout this policy, the Service means all three of the following:
PartWhat it is
The websitebusticated.co, including your account and the customer portal
SoftbossOur desktop application, which installs and updates plugins
The pluginsThe audio plugins themselves (CLAP, VST3, AU) once installed on your computer
Buying from us involves one system we do not operate: checkout is hosted by Shopify. When you click through to buy, you are on Shopify's systems and Shopify's privacy policy governs what happens there. We receive a record of the completed order afterward, described in section 2.3.
This policy does not cover third-party websites we link to. Once you follow a link away from the Service, the privacy policy of wherever you land applies instead.

2. What we collect

2.1 Information you give us

Account information. When you create an account we collect your name and email address. If you sign up with a password, we store a salted one-way hash of it and never the password itself. If you sign in with Google instead, we receive your name, email address, and profile image from Google, along with the tokens that let us verify your session. We never receive your Google password.
Newsletter consent. If you opt in to our newsletter, we record that you did and when. The checkbox on the sign-up form is unticked by default and never affects whether you can create an account.
Support correspondence. If you email us, we keep the message and our reply so we can help you and so we have a record of what was agreed.
Diagnostic reports you choose to send. Softboss may offer to send us a diagnostic report when you are troubleshooting a problem. This is always optional, always initiated by you, and never automatic. See section 2.4.

2.2 Information we collect automatically when you use the website

Session records. When you sign in we create a session record containing a session token, its expiry, your IP address, your browser user-agent string, and a label identifying which client you signed in from (a browser or Softboss). This is what keeps you signed in and what lets you review and revoke your own sessions.
Server logs. Our servers write a log line for the requests they handle. Those lines carry technical detail — the route, the outcome, timing — along with identifiers for the account, session, and where relevant the order involved. Email addresses are masked in log fields before they are written. Logs are written to one destination, our hosting provider's log stream, and are not forwarded anywhere else.
IP address, for rate limiting. We resolve your IP address on authentication requests so that a limit on sign-in attempts applies per visitor rather than to everyone at once. This is a security measure, not analytics.
Error reports. When something in the Service throws an error, we send a report about that error to PostHog so we can fix it. We capture errors and nothing else — page views, clicks, scrolling, session replay, surveys, and user profiles are all switched off, and our test suite fails if anyone turns one on. PostHog is configured to keep no identifier in your browser between page loads.

2.3 Information we receive about your orders

When you complete a purchase, Shopify sends us a record of it. What we store is deliberately narrow:
We storeWe do not store
Your email addressYour payment card details
Shopify's order idYour billing address
The products and quantities orderedYour shipping address
The payment status (paid, refunded, and so on)Any part of the transaction Shopify handles itself
The date the order was placed
Your card details never reach our systems in any form. If you buy physical merchandise, the shipping address you enter stays with Shopify, who fulfill the order; it is not copied into our database.

2.4 Information we collect through Softboss

Requests Softboss makes on your behalf. Softboss signs you in and then asks our API what you own and what is available to download. Those requests identify you the same way a browser would, and they produce the same session records and server logs described in section 2.2. Softboss stores its sign-in token in your operating system's keychain.
Records of what you install. When you install, update, or remove software through Softboss, it records that action with us, so that we can support you, so that your account can show what you have, and so we know which versions are actually in use before we change or retire one.
Optional diagnostic reports. Softboss may offer to send us a diagnostic report — local application logs, your operating system and version, and details of your Softboss installation — when you are reporting a problem. This never happens unless you choose it, it is off by default, and you are told what the report contains before it is sent. We use these reports only to investigate the issue you raised. Because logs can incidentally contain file paths, please review a report before sending it if that concerns you.
What Softboss does not do. It runs no background agent, does not start itself at login unless you ask it to, and collects nothing while you are not using it. Closing it never disables software you have already installed.

2.5 What we never collect, anywhere

To be explicit, because some of these are common in our industry and we have decided against all of them:
  • No copy protection of any kind. No license keys, no activation, no serial numbers, no seat counting, no machine fingerprinting, and no dongle. There is nothing to lose and nothing to transfer.
  • No network activity from a plugin. A plugin never calls home, never checks a license, never reports its usage, and never identifies your computer. It does not know or care whether you have an account.
  • No audio, no projects, no session data. We never receive what you are working on.
  • No advertising or cross-site tracking, no advertising pixels, no data brokers, and no fingerprinting scripts.
  • No session replay and no recording of how you move through the site.
  • No sensitive categories of personal information — we do not collect health, biometric, precise geolocation, racial or ethnic origin, religious belief, sexual orientation, union membership, government identifiers, or financial account numbers.

3. Why we collect it, and our legal basis

If you are in the European Economic Area or the United Kingdom, the GDPR requires us to name a lawful basis for each purpose. Here they are.
PurposeWhat it usesLawful basis
Creating and running your account; keeping you signed inAccount details, session recordsContract — we cannot give you an account without it
Fulfilling your order and giving you access to what you boughtOrder records, account detailsContract
Sending transactional email — verification, password reset, receipts, your download linkEmail address, order recordsContract
Delivering and updating software through SoftbossAccount details, install recordsContract
Customer supportAnything you send us, order recordsContract, and legitimate interests in running a supportable product
Security, abuse prevention, and rate limitingIP address, session records, logsLegitimate interests in keeping the Service available and accounts safe
Fixing bugs and crashesError reports, logsLegitimate interests in a working product
Knowing which software versions are in use before changing or retiring oneInstall recordsLegitimate interests in not breaking working setups
Investigating a problem you reportedOptional diagnostic reportsConsent — you choose to send each one
Sending the newsletterEmail address, name, opt-in recordConsent — you opt in and can withdraw at any time
Meeting tax, accounting, and VAT obligationsOrder recordsLegal obligation
Responding to lawful requests and defending legal claimsWhatever the request concernsLegal obligation, and legitimate interests
Where we rely on legitimate interests, we have considered whether our interest is overridden by your rights, and you can object at any time (section 8).
Withdrawing consent. You can unsubscribe from the newsletter using the link in any newsletter email, or by emailing us. You can decline to send a diagnostic report, and declining costs you nothing beyond making a problem harder for us to diagnose. Withdrawing consent does not affect processing that already happened.

4. Cookies and similar technologies

Every cookie the Service sets is strictly necessary. We use no advertising cookies, no analytics cookies, and no third-party tracking cookies, which is why the site does not ask you to accept cookies before you can read it.
CookiePurposeLifetime
Session cookieKeeps you signed in and identifies your session to our serverUntil it expires or you sign out
Sign-in state cookiesCarry the short-lived state needed to complete a sign-in securely, including Google sign-inMinutes
Our error-reporting tool is configured to keep its state in memory only, so it sets no cookie and writes nothing to your browser's storage that survives a page load.
You can block or delete cookies in your browser settings. Blocking the session cookie will prevent you from signing in, because it is the mechanism by which being signed in works.
Do Not Track and Global Privacy Control. There is no consistent standard for how sites should respond to a Do Not Track header, so we do not act on it. We do honor Global Privacy Control signals — though since we do not sell or share personal information or serve targeted advertising, there is nothing for the signal to switch off.

5. Who we share it with

We do not sell your personal information, and we never have. We share it in three situations: with the service providers who help us run the Service, when the law requires it, and if the business itself changes hands.

5.1 Service providers

Each of these processes personal information on our instructions and is contractually bound to use it only for the purpose we engaged them for.
ProviderWhat it does for usWhat it receives
ShopifyHosts our store and processes checkoutEverything you enter at checkout, including payment details, which are handled by Shopify and its payment processors under PCI-DSS
RenderHosts our application, database, and logsEverything the Service stores, since it is the infrastructure the Service runs on
BrevoSends transactional email and the newsletterYour email address and name, plus the contents of the messages we send you
PostHogReceives error and crash reportsTechnical error detail; where an error occurred inside a signed-in session, the identifiers on that report
CloudflareStores the software archives you downloadThe download request itself; the archives contain no personal information
GoogleProvides "Sign in with Google", if you use itThe sign-in request. Google tells us your name, email, and profile image; we tell Google nothing about you
SlackNotifies us internally when an order or account is createdA short notification. Email addresses in these notifications are masked
We have data processing agreements in place with these providers where the GDPR requires one.

5.2 Legal disclosures

We may disclose personal information where we are legally required to — in response to a subpoena, court order, or other lawful request — or where disclosure is necessary to investigate suspected fraud, enforce our Terms of Service, or protect the rights or safety of a person. We will not volunteer your data to anyone who has not established a legal right to it.

5.3 Business transfers

If Busticated LLC is sold, merged, or reorganized, customer information may transfer with the business, because your account and your purchases would need to keep working. Any acquirer would be bound by this policy in respect of information collected under it until you are notified otherwise and given a chance to object.

6. Where your information is stored

We are based in the United States and your information is stored in the United States. If you use the Service from the European Economic Area, the United Kingdom, or anywhere else outside the US, your personal information is transferred to and processed in the US, where data protection law differs from your own.
For transfers of EEA and UK personal information, we rely on the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, incorporated into our agreements with the service providers listed in section 5.1. You can ask us for more detail on the safeguards that apply.

7. How long we keep it

InformationRetention
Account detailsFor as long as you have an account. Deleted when you ask us to delete your account
Session recordsUntil the session expires or you revoke it, whichever is first
Order records10 years from the date of the order. Required to meet tax, accounting, and EU/UK VAT record-keeping obligations, so these survive account deletion — see section 9
Server logs90 days, after which they are deleted by our hosting provider on a rolling basis
Error reports12 months
Install and update recordsFor as long as you have an account
Optional diagnostic reports12 months, or sooner if you ask us to delete a report you sent
Newsletter subscriptionUntil you unsubscribe
Unsubscribe recordsIndefinitely. We must remember that you unsubscribed in order to honor it
Support correspondence3 years from the last message in the conversation
Where we are required to keep something for longer by law, or need it to establish or defend a legal claim, we keep it for that period instead.

8. Your rights

8.1 If you are in the EEA or the UK

Under the GDPR and the UK GDPR you have the right to:
  • Access — get a copy of the personal information we hold about you
  • Rectification — have inaccurate or incomplete information corrected
  • Erasure — have your information deleted, subject to the legal obligations in section 7
  • Restriction — have us pause processing while a dispute about it is resolved
  • Portability — receive the information you gave us in a structured, commonly used, machine-readable format, and have it sent to another controller where technically feasible
  • Object — object to processing we base on legitimate interests, including at any time and for any reason where the processing is for direct marketing
  • Withdraw consent — at any time, for anything we do on the basis of consent
You also have the right to lodge a complaint with a supervisory authority — your national data protection authority in the EEA, or the Information Commissioner's Office in the UK. We would ask you to raise it with us first, but that is a preference and not a precondition.

8.2 If you are in California or another US state with a privacy law

Depending on your state, you may have the right to know what personal information we collect and why, to access a copy of it, to correct it, to delete it, to obtain it in a portable form, to opt out of its sale, sharing, or use for targeted advertising or profiling, and to be free from discrimination for exercising any of these rights.
We do not sell personal information, we do not share it for cross-context behavioral advertising, we do not use it for targeted advertising, and we do not profile you. We have not done any of these things in the preceding twelve months, including with respect to anyone under 16. There is therefore no opt-out for you to exercise, but the other rights are available to you and we honor them regardless of whether a given state's law strictly applies to a business our size.
The categories of personal information we have collected, the sources, the purposes, and the recipients are set out in sections 2, 3, and 5 of this policy.
Authorized agents. You may use an authorized agent to make a request. We will ask for proof of their authority and may ask you to confirm it directly.
Appeals. If we decline your request, you may appeal by replying to our response or emailing support@busticated.co with "Appeal" in the subject line. We will respond to an appeal within 45 days, in writing, with our reasons. If we deny the appeal, your state attorney general's office can hear a complaint.

8.3 How to exercise any of these rights

Email support@busticated.co. Tell us what you want and, if you have an account, write from the address on it — that is usually all the verification we need. If we cannot match your request to an account, we may need to ask you for more information to confirm who you are, and we will use anything you send for that purpose and no other.
We will respond within 30 days, or within 45 days for requests under a US state law. If a request is genuinely complex we may extend that once and will tell you why before the original deadline passes. Exercising your rights is free unless a request is manifestly unfounded or repetitive.
Some of this you can do yourself without asking us: your account page shows the details we hold and lists every session signed in to your account, and you can revoke any of them there. You can unsubscribe from the newsletter using the link in any newsletter email.

9. Deleting your account

You can ask us to delete your account by emailing support@busticated.co.
What deletion removes: your name, email address, password credentials or linked Google account, profile image, sessions, install records, newsletter subscription, and any diagnostic reports you sent.
What survives, and why: the order records described in section 2.3 remain, detached from your deleted account. Tax and VAT law requires us to keep a record of what was sold, to whom, and when, for the period in section 7, and a deletion request cannot override a statutory retention duty. We also keep an unsubscribe record so we do not email you again by mistake.
Server logs are deleted by expiry, not by purge. Logs written before your request roll off on the 90-day cycle in section 7. We do not selectively rewrite historical logs, because doing so would undermine the security and audit purpose they exist for. They contain no email address, and after 90 days they contain nothing about you at all.
Deleting your account also ends your access to downloads and updates. Because we use no copy protection, plugins you have already installed keep working — deleting your account does not disable, expire, or remove any software on your computer.

10. Security

We protect your information with measures appropriate to its sensitivity:
  • All traffic to and from the Service is encrypted in transit with TLS.
  • Passwords are stored as salted one-way hashes and are never recoverable, by us or by anyone else.
  • We never handle payment card data at all, which removes the single most valuable target from our systems.
  • Access to production systems is restricted to those who need it and protected by two-factor authentication.
  • Secrets, credentials, and email addresses are masked or redacted before anything is written to a log.
  • Sign-in endpoints are rate-limited per visitor to frustrate credential-stuffing attacks.
  • Downloads are served through short-lived, single-purpose links issued only to entitled accounts.
No system is perfectly secure, and we will not claim otherwise. If we become aware of a breach affecting your personal information, we will notify you and the relevant supervisory authority as the law requires, without undue delay.

11. Children

The Service is not directed at anyone under 16, and we do not knowingly collect personal information from children under 16. If you are a parent or guardian and believe a child has given us personal information, email support@busticated.co and we will delete it.

12. Automated decision-making

We do not make decisions about you by automated means that produce legal or similarly significant effects, and we do not profile you.

13. Changes to this policy

We may update this policy to reflect changes in what we do, in the services we use, or in the law. When we do, we will change the effective date at the top and post the new version here.
If a change materially affects how we handle your personal information, we will tell you before it takes effect — by email to account holders, or by a prominent notice on the site. Continuing to use the Service after a change takes effect means the updated policy applies to you.

14. Contact us

For anything in this policy, including any request under section 8, contact:
Busticated LLC, 5441 S Macadam Ave #6369, Portland, OR 97239, United States