Skip to content
NarrativePro

NarrativePro Addons

Privacy Policy

What personal data NarrativePro Addons collects, why we collect it, who processes it on our behalf, and how long we keep it.

Last updated

1.1. About this policy

This policy explains what we do with personal data when you visit narrativeaddons.com, hold an account, buy an addon, or sell through us. It is written to satisfy the EU General Data Protection Regulation and the UK GDPR, both of which apply to us.

Our Cookie Policy is the exact inventory of what is stored on your device. Our GDPR notice explains your rights in detail and how to exercise them. This policy is the overview; those two are the specifics.

We do not sell personal data, and we do not share it with advertising networks.

2.2. Who is responsible for your data

The controller of the personal data described here is Narrative, operating NarrativePro Addons ([COUNSEL] insert full registered name, company number and registered office).

Two other entities are part of how the marketplace runs and share in its revenue:

  • D3kryption Studios Ltd, a company registered in the United Kingdom, acting as engineering partner. Personnel of that entity may access production systems for maintenance and support, under contract and on our instructions.
  • Adoptavia Germany UG, a company registered in Germany, acting as infrastructure partner. Some processing therefore takes place on infrastructure located in the European Union.

[COUNSEL] Confirm the correct characterisation of each relationship. The working assumption in this draft is that Narrative is the controller and the other two act as processors under Article 28 contracts. If any of them determines the purposes of processing in its own right, this section must instead describe a joint controller arrangement under Article 26 and publish the essence of that arrangement.

Contact for anything in this policy: [email protected].

3.3. What data we collect

Account data. Your name or display name, email address, hashed password if you set one, the identifier from any social or GitHub sign-in you use, your role on the platform, and the dates your account was created and last changed.

Order and transaction data. Order numbers, the items bought, prices, discounts, currency, tax where applicable, the payment rail used, the billing email you gave at checkout, and the references our payment providers give us for the payment. We never receive your full card number.

Entitlement and delivery data. The licences issued to you, the licence keys, and a record of each download: which version, when, the IP address the request came from and the browser user agent string. That record is what lets us honour a licence, detect key sharing and investigate abuse.

Seller data. If you sell, we hold your public seller profile, your payout preferences, the identifiers our payment providers give us for your connected account, whether your account is enabled for payouts, your linked GitHub login, and your ledger of accrued and paid amounts. Identity and anti-money-laundering verification is carried out by our payment provider, not by us; we receive the outcome, not the underlying documents.

Content you publish. Reviews, ratings, seller responses, listing text and images, and votes on the helpfulness of reviews.

Usage data. Which listings were viewed and when, aggregated daily statistics per addon, and technical logs including IP addresses, request paths, timestamps and error traces.

Communications. Emails you send us, support tickets, refund requests and the reasons given, and delivery and bounce information for the transactional emails we send you.

We do not intentionally collect special category data as defined in Article 9. Please do not put it in a support ticket or a review.

4.4. Where the data comes from

Most of it comes from you directly: when you register, buy, list, download, review or write to us.

Some is generated automatically as you use the site, such as request logs, view counts and download records.

Some comes from third parties: from Stripe or PayPal when a payment succeeds, fails or is disputed, and when a seller's connected account changes status; from GitHub if you sign in with it or link a repository; and from our email provider when a message bounces or is marked as spam.

5.5. Why we process it, and on what lawful basis

Providing the marketplace and your account. Creating and maintaining your account, showing you your orders, issuing entitlements and licence keys, and serving downloads. Lawful basis: performance of a contract with you (Article 6(1)(b)).

Taking payment and preventing payment fraud. Processing your payment, recording the transaction, handling refunds, chargebacks and disputes. Lawful basis: performance of a contract, and our legitimate interests in preventing fraud and recovering money owed (Article 6(1)(f)).

Paying sellers and partners. Maintaining the revenue ledger, running scheduled distributions, and reconciling what has been paid. Lawful basis: performance of a contract with the seller, and legitimate interests in accurate financial administration.

Enforcing licences. Recording downloads and licence key use to detect sharing, credential abuse and licence circumvention. Lawful basis: legitimate interests in protecting sellers' rights and our own, balanced against the fact that this is limited to the minimum needed to spot abuse.

Transactional email. Receipts, licence keys, download links, refund outcomes, payout notifications, security alerts and changes to these policies. Lawful basis: performance of a contract, and legal obligation for some of it. These are not marketing and you cannot unsubscribe from them while you hold an account. Our email provider currently records when a message is opened, including for these messages; section 8 of the Cookie Policy explains that and how to stop it.

Marketing email. We do not currently operate a marketing mailing list, so no marketing email is sent today. If we start one it will be opt-in and separate from account email. Lawful basis, when it exists: your consent, or the soft opt-in for existing customers about similar products where that applies. Every marketing message will carry an unsubscribe link that works.

Analytics and improving the service. Understanding which listings are viewed and how often files are downloaded. This is done entirely on our own servers and stores nothing on your device; we use no third-party measurement product. Lawful basis: legitimate interests, using aggregated and minimised data wherever it will do the job. We would not add anything that stores or reads data on your device without building a consent mechanism and asking you first.

Moderation, security and abuse. Reviewing listings and reviews, investigating reports, blocking attacks and keeping audit logs. Lawful basis: legitimate interests in a safe, lawful marketplace, and legal obligation where a notice requires us to act.

Accounting, tax and compliance. Keeping records of sales, refunds and payouts. Lawful basis: legal obligation (Article 6(1)(c)).

Legal claims. Establishing, exercising or defending legal claims. Lawful basis: legitimate interests, and legal obligation where applicable.

Where we rely on legitimate interests, we have considered whether our interest is outweighed by your rights. You can ask us for the reasoning behind any of those assessments, and you can object at any time: see our GDPR notice.

6.6. Payment data specifically

Card and bank details are handled by Stripe and PayPal, not by us. They are entered on infrastructure controlled by those providers, and we never see or store a full card number.

What we hold is the outcome: an amount, a currency, a status, the last four digits and card brand where the provider supplies them, and the provider's reference for the transaction. That is enough to show you a receipt, issue a refund and reconcile our accounts, and no more.

Stripe and PayPal each act as independent controllers for parts of this processing, including fraud screening and their own regulatory obligations. Their own privacy notices apply to that processing and are published on their websites.

7.7. Who we share data with

We share personal data with the following categories of recipient, and only as much as each of them needs:

  • Payment providers. Stripe and PayPal, to take payments, run fraud checks, handle disputes and make payouts to sellers and partners.
  • Email provider. Mailgun, to send transactional and marketing email and to report delivery outcomes. We use its EU region so that message content and metadata stay in the European Union.
  • Object storage. Cloudflare R2, which stores addon packages and serves them through expiring signed links. Request logs there may include IP addresses.
  • Source hosting. GitHub, where a seller links a repository so releases can be mirrored, and where GitHub sign-in is used. We receive the account identifier and the release metadata, not your GitHub password.
  • Hosting and infrastructure. The providers that run our application servers and database, including infrastructure operated with our German infrastructure partner.
  • Sellers. A seller sees aggregated sales and analytics for their own addons, the reviews left on them, and, where a buyer raises a support request, the information needed to answer it. A seller does not get a list of their buyers' email addresses for marketing.
  • Professional advisers, auditors and insurers, where needed and under a duty of confidence.
  • Authorities and courts, where we are legally required to disclose, and where the request is valid and proportionate.
  • An acquirer, if the business or part of it is sold or reorganised, subject to this policy continuing to apply.

Everyone acting on our behalf is bound by a written contract that meets Article 28: they process only on our instructions, keep the data confidential, apply appropriate security, help us answer your rights requests, and delete or return the data at the end.

The current sub-processor list, with each one's role and region, is published in our GDPR notice and is the version to rely on.

8.8. International transfers

We aim to keep personal data in the European Economic Area and the United Kingdom. Our email provider is configured to its EU region for that reason, and our infrastructure partner is established in Germany.

Some providers are established in, or route support and engineering access through, the United States or other countries outside the EEA and the UK. Where personal data goes to a country without an adequacy decision, we rely on:

  • The European Commission's Standard Contractual Clauses (2021/914), incorporated into our contracts with those providers, together with a transfer impact assessment;
  • for UK transfers, the UK International Data Transfer Addendum to those clauses, or the UK IDTA; and
  • for transfers to certified organisations in the United States, the EU-US Data Privacy Framework and its UK extension, where the provider is certified for the relevant data.

Where the assessment shows the clauses alone are not enough, we apply supplementary measures such as encryption in transit and at rest, key management that keeps keys out of the importer's hands where feasible, and contractual limits on government access requests.

You can ask us for a copy of the transfer mechanism relied on for a specific provider by writing to [email protected].

[COUNSEL] Confirm each provider's current certification status and the correct instrument for each transfer before publication. This section states our intended posture, not a verified inventory.

9.9. How long we keep it

Account data: for as long as you hold an account, and then up to 12 months after closure so that we can deal with anything that arises, unless a longer period is required below.

Orders, invoices, refunds, payouts and ledger records: for the period required by tax and accounting law, which we treat as 7 years from the end of the relevant financial year in the UK, and up to 10 years where German commercial and tax retention rules apply to records held by our infrastructure partner. These records cannot be deleted on request while that obligation runs.

Entitlements and licence keys: for as long as the licence subsists, because the licence is perpetual and you may need to prove it.

Download records: 24 months, then deleted or aggregated. They exist for licence enforcement and abuse detection, which is a short-lived need.

Reviews and public content: until you delete them or your account is closed, after which they may remain in anonymised form so that a product's rating history stays honest.

Security and application logs: 90 days, longer only for a specific incident under investigation.

Marketing consents and suppression records: consents until withdrawn; suppression lists indefinitely, because we need to remember not to email you.

Support correspondence: 24 months after the ticket is closed.

[COUNSEL] Confirm the retention figures against UK and German statutory minimums, particularly the interaction between the 7-year and 10-year positions.

10.10. How we protect it

Encryption in transit for all traffic, and encryption at rest for the database and object storage. Passwords, where used, are hashed with a slow, salted algorithm and never stored in a form we can reverse.

Access to production data is limited to the people who need it, protected by multi-factor authentication, and logged. Download links are individually signed and expire in minutes rather than being permanently public URLs.

Every inbound webhook is signature-verified and processed exactly once, so that a replayed or forged callback cannot create or alter a financial record.

Backups are encrypted and access-controlled, and we test restores. We keep an incident response process and, where a breach is likely to result in a risk to your rights, we notify the relevant supervisory authority within 72 hours and tell you without undue delay where the risk is high. That process is set out in our GDPR notice.

No system is perfectly secure. If you find a vulnerability, please report it to [email protected] rather than exploiting it; we will not pursue good-faith researchers who follow that route.

11.11. Your rights

You have rights of access, rectification, erasure, restriction, portability and objection, the right to withdraw consent, and the right not to be subject to solely automated decisions with legal or similarly significant effects.

Our GDPR notice explains each right, what it means in practice here, how to exercise it, how long we take, and how to complain to a supervisory authority if you are unhappy with how we respond.

The short version: write to [email protected] from the address on your account, tell us what you want, and we will respond within one month.

12.12. Automated decision-making

We do not make decisions about you by purely automated means that produce legal effects or similarly significantly affect you.

Two automated processes come close and are worth naming. Payment fraud screening is performed by our payment providers and can cause a transaction to be declined; you can ask us to look at a declined transaction and a person will review it. Abuse detection on download and licence key activity can flag an account for review; a suspension is never applied without a person looking at the flag first.

13.13. Cookies and similar technologies

We use a small number of strictly necessary cookies to keep you signed in, protect forms against cross-site request forgery, and secure a sign-in with GitHub. We also use your browser's local storage to hold your basket, and - only if you actively pick one - to remember a light or dark appearance. Those do not require consent.

Beyond that we store nothing on your device. There is no analytics storage, no advertising storage and no third-party script on this site, and so there is nothing here to consent to and no consent banner. If we ever add anything optional we will build a real consent mechanism and ask you before setting it, and refusing will be as easy and as prominent as accepting. Our Cookie Policy is the authoritative inventory of what is stored, by whom, and for how long.

14.14. Children

The marketplace is not directed at children. You must be at least 16 to hold an account and at least 18 to buy. We do not knowingly collect data from children below those ages; if we learn that we have, we delete it. If you believe a child has given us data, write to [email protected].

15.15. Changes to this policy

We update this policy when what we do with data changes. The effective date is shown at the top of the page.

If a change materially affects how we use data about you, we will tell registered account holders by email before it takes effect, and where a change requires consent we will ask for it rather than assume it.

16.16. Contact and complaints

Data protection enquiries and rights requests: [email protected].

General support: [email protected]. Legal notices: [email protected].

If you are not satisfied with our response you may complain to a supervisory authority. In the United Kingdom that is the Information Commissioner's Office. In the European Union it is the authority in the member state where you live, work, or where you think the problem happened. Details are in our GDPR notice. We would rather hear from you first, but that route is always open to you.