Marketplace Privacy Notice
Version: marketplace-privacy-v1-2026-08-14
Effective date: 14 August 2026
This Notice supplements the general synclaro.de privacy notice for the Synclaro Marketplace. It covers product views, cart, checkout, customer account, licensing, delivery, and misuse prevention.
1. Controller
Synclaro IT Dienstleistungen
Proprietor Marco Heer
Bahnhofstraße 15
92318 Neumarkt i.d.OPf., Germany
Email: marcoheer@synclaro.de
Telephone: +49 160 99471052
2. Principles
- We process only data necessary to operate a secure Marketplace, perform contracts, meet legal duties, or provide analytics you have chosen.
- Synclaro does not store full card or bank-account numbers or PayPal credentials. Those details are entered on the payment provider’s page.
- Product archives contain no undisclosed usage surveillance. They may contain a transparent customer-specific licence marker as described in the Licence Terms.
- We do not make decisions producing legal or similarly significant effects solely by automated means within the meaning of Article 22 GDPR.
3. Marketplace access and security logs
When you access the Marketplace, the hosting infrastructure processes technically necessary data. This includes IP address, time, requested address, transferred volume, browser and device information, referring address, and security and error data.
Purposes: website delivery, availability, attack prevention, troubleshooting, and evidence of technical operations.
Legal basis: Article 6(1)(f) GDPR. Our legitimate interest is a secure and functional service.
Retention: security and access logs are generally deleted or anonymised within 90 days. Data affected by a specific security incident may be retained longer for investigation and legal enforcement.
4. Strictly necessary cart
The cart is stored under synclaro-marketplace-cart-v1 in your browser’s local storage. It contains the product identifier, licence tier, and quantity. It contains no payment data and adding a product alone does not transmit the cart to Synclaro.
Purpose: retain the requested cart across page navigation.
Legal basis: section 25(2)(2) German Telecommunications Digital Services Data Protection Act for the expressly requested cart; once transmitted, Article 6(1)(b) GDPR for pre-contractual steps.
Retention: until you empty the cart, clear browser data, or we replace the key in a future product version.
5. Checkout and contract
When you start checkout, we process in particular:
- business email address and selected language;
- products, versions, prices, licence tiers, and order amount;
- order, session, and payment status and technical retry identifiers;
- time and evidence of accepting business-customer status, the Terms, Licence Terms, and immediate digital delivery;
- billing name, company, address, country, and VAT identification number where applicable;
- payment method, payment identifier, tax calculation, payment, refund, and dispute status returned by the payment provider; and
- a security-related network identifier pseudonymised with a secret key to limit automated mass requests.
Purposes: prepare checkout, form and perform the contract, process payment and tax, issue invoices, recognise retries safely, prevent fraud and misuse, and establish, exercise, or defend claims.
Legal bases: Article 6(1)(b) GDPR for contracts and pre-contractual steps; Article 6(1)(c) GDPR for tax, commercial, and evidence duties; Article 6(1)(f) GDPR for security, fraud prevention, and legal defence.
We cannot perform a contract without the business email address, order data, and required billing and payment information.
6. Stripe, PayPal, cards, and SEPA Direct Debit
The payment page and tax calculation are provided by Stripe Payments Europe, Limited, Ireland, and affiliated Stripe companies. Stripe receives data required for the selected payment method, fraud screening, tax calculation, and regulatory duties. For PayPal, Stripe may pass data to PayPal group companies. For SEPA Direct Debit, mandate and account details are processed by Stripe and participating banks.
Synclaro receives from Stripe only the status and billing information necessary for the order, accounting, delivery, and issue resolution. We do not receive full card verification codes, PayPal passwords, or full online-banking credentials.
Legal bases: Articles 6(1)(b) and (c) GDPR and, where necessary, Article 6(1)(f) GDPR. Stripe may act as an independent controller for certain processing such as fraud prevention or financial-law duties. See the Stripe Privacy Policy for details.
7. Customer account, licence, and delivery
Following an order, we process account, order, and entitlement data. This includes email address, sign-in activity, Product and version, licence tier, permitted User count, licence code, signed licence record, download entitlements, download times, technical completion and checksum confirmations, and suspension or revocation status.
Purposes: password-light sign-in, personal library, secure delivery, licence evidence, updates, support, misuse limitation, and suspension following a refund or payment dispute.
Legal bases: Article 6(1)(b) GDPR and Article 6(1)(f) GDPR for account security, licence evidence, and misuse prevention.
Product archives are stored privately. A download is released through a short-lived server-side reservation only after sign-in, entitlement, signature, and checksum checks. Small archives are buyer-marked before delivery and then transmitted in full through Synclaro's server. A transfer counts as a successful download only after the signed-in browser has read the complete content and confirmed its byte count and checksum. Aborted or expired transfers consume no successful-download allowance. We do not store content you create with a purchased Product on your own system.
8. Email and support
We send necessary messages about orders, payment status, invoices, account access, security, delivery, and contract-related updates. We use Resend, Inc. as a technical delivery provider. Data transmitted includes the recipient address, subject, message content, and delivery status.
Legal bases: Article 6(1)(b) GDPR for contractual messages; Article 6(1)(c) GDPR for mandatory notices; Article 6(1)(f) GDPR for security and reliable delivery. Marketing email is not covered and requires a separate legal basis.
If you request support, we process contact details, messages, technical information, and files you voluntarily provide to resolve the request. Please do not send secrets, live access keys, or unnecessary personal data.
9. Consent-based Marketplace analytics
We measure behaviour in the Marketplace only if you consent to the “Analytics” category through CookieYes. Without consent, no Marketplace analytics events are stored.
We may collect:
- random pseudonymous visitor and session identifiers;
- Marketplace page and Product viewed;
- timestamps, active viewing time, scroll depth, and visible sections;
- clicks on Product, licence, language, and add-to-cart controls;
- an optional consent-bound association of a valid checkout preparation with the previously active pseudonymous session;
- broad device class, language, and short normalised referral and campaign information. Email addresses, person identifiers, UUIDs, and high-entropy tokens are technically rejected in these campaign fields; and
- a technical event identifier for reliable deduplication.
We do not collect text inputs, form field values, cart or checkout pages, mouse-movement recordings, full IP addresses, payment details, passwords, or the contents of purchased Products. There is no video-like session replay. Payment success, refunds, and disputes come exclusively from necessary contract and payment records and are not recorded as behaviour events. Pseudonymous attention is associated with a checkout preparation only while analytics consent remains active; reporting is presented at Product and funnel level.
Purposes: understand which Products receive attention, where users leave, and how to improve content, usability, and the offer.
Legal bases: your voluntary consent under Article 6(1)(a) GDPR and, where information is stored on or read from a device, section 25(1) German Telecommunications Digital Services Data Protection Act.
Withdrawal: at any time through the CookieYes settings, effective for the future. A purchase is possible without analytics consent.
Retention: raw events for no more than 180 days. Any pseudonymous session and campaign attribution stored on an order while consent remained active is technically and irreversibly removed after no more than 180 days. This does not alter financial, tax, contract, or licence records. Product and funnel aggregates that can no longer be related to a person or device may be retained for up to 24 months. Following withdrawal, no new events are collected; the time-limited deletion of existing attribution and lawfully created anonymous aggregates remain unaffected by the prospective effect of withdrawal.
10. Licence protection using public sources
To protect against unauthorised resale, we may search publicly accessible code repositories, download listings, and marketplaces for characteristic parts of our Products. If a possible copy is found, we process the location, time, publicly visible supplier details, Product characteristics, and the comparison necessary against our licence records.
We do not access private Customer repositories, devices, or accounts for this purpose. Product files send no undisclosed telemetry.
Legal basis: Article 6(1)(f) GDPR. Our legitimate interests are protecting intellectual property, preventing misuse, and enforcing rights. Competing interests are addressed by limiting processing to concrete public findings and necessary data.
11. Recipients and infrastructure
Data is available only to recipients that need it for the purposes described. They may include:
- Netlify, Inc. for website hosting, delivery, and server functions;
- Supabase, Inc. for the separate Marketplace database, authentication, and private storage system in an EU region selected for production;
- Stripe and payment companies or banks involved in the selected payment method;
- Resend, Inc. for transactional email;
- CookieYes Ltd. for consent management; and
- tax advisers, legal advisers, information-security providers, authorities, or courts where necessary or legally required.
Where legally required, providers are bound as processors. Transfers outside the European Economic Area take place only under an authorised mechanism, in particular an adequacy decision, EU Standard Contractual Clauses, and supplementary safeguards. Some recipients may process data as independent controllers.
12. Retention
We delete or anonymise data when the purpose ends unless a prevailing duty or legitimate reason requires continued retention. The following generally apply:
- commercial books and tax-relevant records: up to ten years;
- accounting vouchers and invoices: generally eight years;
- received and sent commercial or business correspondence: generally six years;
- contract, licence, and order data: for contract performance, statutory retention, and ordinary limitation and legal-defence periods;
- consent evidence: for the processing period and generally up to three years afterwards;
- security logs: generally no more than 90 days unless an incident requires longer retention;
- raw Marketplace analytics events: no more than 180 days;
- fully anonymous Product and funnel aggregates: up to 24 months; and
- failed, unaccepted checkout drafts without a legally relevant booking: generally no more than 30 days.
The specific period may change where litigation, a regulatory duty, a chargeback, or a security incident requires continued retention.
13. Your rights
Subject to statutory conditions, you have rights of access, correction, erasure, restriction, portability, and objection. You may withdraw consent at any time with future effect.
Where we rely on legitimate interests, you may object on grounds relating to your particular situation. We will then stop processing unless compelling legitimate grounds or legal claims prevail.
Send requests to marcoheer@synclaro.de. You may also complain to a data-protection supervisory authority. In Bavaria, this includes the Bavarian State Office for Data Protection Supervision, Promenade 18, 91522 Ansbach, Germany.
14. Changes
We update this Notice when the Marketplace, providers, or legal requirements change. The current version remains available in the Marketplace. We will communicate legally significant changes affecting existing accounts by an appropriate channel.