Status and scope
This is the English canonical text prepared for final legal review. It is not effective or published while the launch gates shown above remain open.
It covers the public storefront, checkout hand-off, order confirmation, licensing, downloads, updates, support and privacy-rights operations. It does not describe unrelated PsDevs services.
Controller and EU representative
The controller and seller is Ricardo Chiralt García, trading as PsDevs Addons, a sole trader established at 10 Ote 20, 72810 San Andrés Cholula, Puebla, Mexico (RFC CIGR810306IK1). Contact: info@psdevs.com.
An EU representative under Article 27 GDPR is required for launch. The appointment is pending. The representative's final legal name, postal address, contact details and effective appointment date will be inserted only after the written appointment is effective; no provisional details are presented as appointed details.
Data, purposes and legal bases
- Storefront requests: network and security data needed to deliver the site, protect the service and diagnose faults. The bases are legitimate interests in secure, reliable operation and compliance with applicable legal duties.
- Checkout and contract: email, billing or residence country, customer type and, only when needed, name or business fiscal details. These are used to take steps requested before a contract, form and perform the contract, provide access, licensing, updates and support, and comply with legal obligations. Consent is not used as a generic basis for processing necessary to the purchase.
- Payments: order reference, amount, currency, payment status and limited Stripe identifiers. Card details are entered and handled by Stripe, not stored by PsDevs Addons.
- Orders, invoices and fiscal records: identity and transaction snapshots required for the contract, accounting, disputes and legal duties. Final Mexican and cross-border fiscal treatment remains a launch gate; this notice does not claim a specific CFDI, VAT or invoice classification.
- Licensing, installations, updates and downloads: license identity, normalized domain, installation identity, environment, activation history, entitlements, release and download authorization. These are necessary to perform the license contract and protect the service against abuse.
- Support: email, request content and related order or license context supplied by the customer. The bases are contract performance and legitimate interests in resolving requests and improving support quality.
- Security and audit: pseudonymized IP indicators where configured, truncated user agent, event category, timestamps and allowlisted operational context. The bases are legitimate interests in preventing abuse, securing systems and establishing or defending legal claims.
- Privacy requests and incidents: identity-verification evidence, request scope, restriction or objection, response history, breach assessment and legal holds. The bases are compliance with legal obligations and legitimate interests in accountable handling and legal claims.
Required and optional data
Email and billing or residence country are the provisional minimum fields for checkout. A name is requested only when necessary for the license, support or contractual record. Business name and tax identifier are requested only for a business purchase when the fiscal workflow requires them. Phone, full address, VAT/TIN, national ID or passport are not PsDevs Addons default fields.
Stripe may collect a billing address under its own hosted checkout configuration. That does not mean PsDevs Addons stores every address field; the production data mapping must distinguish Stripe collection from the fields returned to and retained by PsDevs.
If required contract or billing information is not provided, we cannot create or fulfil the order. Optional information can be withheld without affecting the purchase unless its necessity is explained at the point of collection.
Accounts and authentication
Version 1 does not require an account. A checkout email identifies the commercial customer and may be associated with an existing PsDevs user only under the backend's documented consolidation rules. A future account feature will require an updated notice before activation.
The order-status credential is stored in a short-lived, HttpOnly, SameSite=Lax cookie scoped to the checkout area. It is not placed in the URL, analytics or local storage.
Recipients and providers
Current processing relevant to the launch design uses PsDevs' server-side Store API and Stripe for hosted payment processing. Infrastructure and backup providers may receive limited data only when their production use, contract, configuration and transfer safeguards are verified in the controller's provider register.
Vercel is prospective and is not described as a current recipient. Prighter is not yet the appointed representative. Guatson does not receive Addons buyer data while its buyer-data and fiscal gates remain open. Telegram is not a current provider or recipient and no Telegram flow is part of this storefront.
International transfers
The controller is established in Mexico. Where personal data is transferred from the EEA to a country without an adequacy decision, PsDevs will use an applicable Chapter V mechanism, commonly approved Standard Contractual Clauses where appropriate, together with documented supplementary measures and transfer assessment. Exact mechanisms must match the active provider register before publication.
You may request information about the safeguards applicable to your data by contacting info@psdevs.com. Information may be limited where necessary to protect security or third-party rights.
Retention
- Checkout retries and order-status credentials: normally up to 24 hours for retry/cleanup, while the browser credential itself has a one-hour default lifetime.
- Unpaid checkout identity: scheduled anonymization after 30 days and deletion of eligible unpaid order shells after 90 days, subject to payment, invoice, license and legal-hold checks.
- Webhook identifiers: 30 days; failed jobs: 168 hours; routine download records: 180 days.
- Pending or rejected activations: 180 days; deactivated activations: 24 months.
- Operational activity: 90 days; telemetry/debug: 30 days; routine security records: 180 days; production application logs: 14 days under the documented configuration.
- Privacy-request exports, if stored, are deleted within seven days.
- Paid or refunded commerce, invoices, active perpetual licenses, material contractual records and records under legal hold are retained or restricted for the applicable contractual, fiscal, limitation or legal period. They are not promised immediate deletion, and no blanket ten-year period is asserted.
Your privacy rights
Depending on the applicable law, you may request access, rectification, erasure, restriction, portability, or object to processing. Where processing relies on consent, you may withdraw it at any time without affecting earlier lawful processing. Where processing relies on legitimate interests, you may object on grounds relating to your situation; direct-marketing objections would be honoured unconditionally, although no marketing programme exists in Version 1.
Send requests to info@psdevs.com. We may ask for proportionate verification and will not treat knowledge of an email address alone as proof of identity. GDPR requests are tracked from receipt and normally answered within one month, subject to a permitted extension for complex or numerous requests.
You may lodge a complaint with the supervisory authority in your habitual residence, place of work, or place of the alleged infringement. This does not limit other administrative or judicial remedies.
Automated decisions and profiling
PsDevs Addons Version 1 does not use personal data for behavioural advertising, marketing profiling or solely automated decisions producing legal or similarly significant effects. Automated fraud, rate-limit and licensing checks may block a request for security reasons; customers can contact support for human review where appropriate.
Security, backups and erasure
PsDevs uses access controls, secret redaction, data minimisation, private download tokens, integrity checks, audit controls and documented incident procedures. No internet system can be guaranteed completely secure.
Backups follow controlled recovery procedures. Erasure is classification-based: eligible data may be erased or anonymized, while paid commerce, invoices, active perpetual licenses and held records may be retained or restricted. Restores require suppression-ledger replay planning so erased identities are not silently reintroduced.
Changes and contact
Material changes will receive a new version and review date. A URL alone is not the contractual snapshot: future orders must record the version identifier and content hash used at purchase.
Privacy, legal and support contact: info@psdevs.com. Postal contact: Ricardo Chiralt García, 10 Ote 20, 72810 San Andrés Cholula, Puebla, Mexico.
Official sources
These sources informed this text. They do not replace advice on the facts and laws applicable at launch.