DND

Privacy Policy

Last updated September 24, 2026

This Privacy Policy describes how DND Software ("DND", "we", "us", or "our") collects, uses, stores, and protects personal data in connection with the dndware.dev website, the DND loader, customer accounts, and related services (collectively, the "Services"). If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, this Policy is intended to comply with the General Data Protection Regulation (EU) 2016/679 (GDPR) and other applicable data protection laws.

In short: we collect as little as we can. Your email address is stored encrypted and is only ever read to email you, we never store IP addresses, you have no password with us, and payments are handled entirely by Stripe and Link.

1. Data Controller

DND Software is the data controller responsible for your personal data processed through the Services. For all data protection inquiries, contact us at [email protected].

Data Protection Officer. DND has not designated a Data Protection Officer, as our processing activities do not meet the criteria set out in Article 37 of the GDPR (we are not a public authority, we do not carry out large-scale systematic monitoring of data subjects, and we do not carry out large-scale processing of special categories of data). For any data protection matters, please contact us at [email protected].

2. Categories of Personal Data We Collect

A. Account

  • Username (chosen by you and shown publicly)
  • Email address: stored as a one-way keyed hash (to find your account when you sign in) and encrypted with AES-256-GCM (to send you account and security emails). It is only decrypted at the moment an email is sent, and it is never shown to anyone, including our staff.
  • Account role (user, staff, or owner) and the date your account was created

B. Purchases & Licenses

  • Your licenses: product, expiry date, and each grant that added time (with the Stripe checkout reference or the redeemed key it came from)
  • The time at which you accepted the Terms and requested immediate delivery (waiving the right of withdrawal), stored with your Stripe checkout
  • Your Stripe customer ID, encrypted at rest
  • Redeemed license keys, stored only in hashed form

Your name, billing address, email address for receipts, and payment details are collected by Stripe and Link as merchant of record. Payment card data never reaches our servers.

C. Security & Authentication

  • One-time sign-in codes, stored hashed, valid for 10 minutes
  • Website session tokens, stored hashed (the cookie holds the only readable copy)
  • CSRF protection tokens, derived from your session and never stored
  • Rate-limiting counters, kept in memory only and keyed with a hash of your IP address that changes every day. IP addresses are never written to disk or to our database.
  • The result of a Cloudflare Turnstile check when you sign in or sign up (to stop automated sign-ups)
  • Passkeys you add: the public key, the passkey's ID, whether it is synced between your devices, and when it was added and last used. The private key and your fingerprint or face never leave your device; we never receive them.

D. Loader & Devices

  • Hardware identifier of the device you use the loader on, stored only as a keyed hash
  • Operating system version, and a device name if you set one (encrypted at rest)
  • When the device was approved and last seen, and the dates of device resets
  • Loader session tokens, stored hashed
  • A build ID for each loader download, linked to your account, so leaked copies can be traced

E. Communication

  • Emails you send us
  • Messages you send our staff on Discord

F. Administrative

  • Admin Area audit log: which account opened or tried to open an admin page, when, and whether access was allowed
  • If your account is blacklisted: the reason shown to you, an internal note for staff (encrypted), who made the decision, and when

We do not collect special categories of data (e.g. racial or ethnic origin, political opinions, health data, or biometric data), and we do not use analytics or advertising trackers.

4. How We Use Your Information

  • Send you sign-in and confirmation codes, and authenticate you
  • Provide, operate, and maintain the Services and the loader
  • Deliver licenses after a purchase or key redemption, and remove them after a full refund or lost chargeback
  • Enforce one device per license, the weekly device reset limit, and one website session per account
  • Monitor for abuse, fraud, and unauthorized access, and enforce the Terms of Service
  • Show aggregated, non-identifying statistics to our staff (such as the number of accounts or active licenses)
  • Provide customer support and respond to inquiries

We only email you about your account: sign-in codes, security notices (a passkey added or removed), and blacklist decisions. We do not send marketing emails and we do not use your data for advertising.

5. Data Retention

  • Account data: For as long as your account exists. When you ask us to delete your account, it is deleted together with its sessions, devices, and licenses.
  • Purchase records: Invoices and payment records are kept by Link and Stripe as merchant of record, as long as tax law requires. Where the law requires us to keep an order reference as well (in the Netherlands, generally 7 years), we keep only that reference.
  • Sign-in codes: Deleted within 24 hours.
  • Website sessions: Until you sign out or the session expires (at the latest 30 days with "Remember me"; otherwise 24 hours, or 30 minutes without activity). Sessions ended by a newer sign-in are deleted within 24 hours.
  • Loader sessions: Deleted one day after they expire.
  • Device reset history: Deleted after 30 days.
  • Passkeys: Until you remove them in the dashboard or your account is deleted.
  • Loader download build IDs: Kept for 12 months.
  • Admin Area audit log: Kept for 12 months.
  • Rate-limiting counters: Memory only; they expire within 24 hours and are lost on every restart.
  • Support correspondence: Kept for up to 24 months.

6. Data Sharing & Processors

We share personal data only with the following recipients, and only as strictly necessary to operate the Services:

  • Stripe Payments Europe, Ltd. (Ireland) and Link: Payment processing and checkout. As merchant of record for purchases on dndware.dev, Link processes your checkout, payment, tax, and receipt data as an independent controller. We send Stripe only an opaque account reference and the products in your order. See Stripe's Privacy Policy and Link's Privacy Policy.
  • Cloudflare, Inc.: CDN, DDoS protection, DNS, and the Turnstile security check. Governed by the Cloudflare Customer DPA; see also Cloudflare's Privacy Policy.
  • Tube-Hosting (Germany): Hosting of the servers that run the Services, including our database and our own mail server.
  • Discord Inc.: Only if you choose to join our community server or contact support there. See Discord's Privacy Policy.
  • Legal authorities: When required by law, regulation, or a valid legal process.

Our emails are sent from our own mail server; we do not use a third-party email service. We do not sell, rent, or trade your personal data to any third party.

7. International Data Transfers

Your personal data is stored and processed on servers physically located in the European Union (Germany). We do not routinely transfer your personal data outside the European Economic Area (EEA).

Where a recipient listed in Section 6 may process data outside the EEA (for example Stripe's global payment infrastructure or Cloudflare's edge network), such transfers are governed by the European Commission's Standard Contractual Clauses (SCCs) as incorporated into that recipient's data processing terms, or by an equivalent transfer mechanism recognized under applicable data protection law.

8. Data Security

We implement appropriate technical and organizational measures to protect your personal data, including:

  • Encryption in transit (TLS) on every connection
  • Keyed one-way hashing of sign-in codes, session tokens, hardware identifiers, and license keys, and encryption of your email address, so a copy of our database does not reveal them
  • AES-256-GCM encryption at rest for the few values we must be able to read back
  • No passwords to leak: sign-in works with one-time codes only
  • One active website session per account, and staff access restricted by role, checked on every request, and written to an audit log
  • Servers that only accept traffic through Cloudflare, and rate limits on every sensitive action

9. Your Rights (GDPR)

Under the GDPR, you have the following rights regarding your personal data:

  • Right of Access: Request a copy of the personal data we hold about you.
  • Right to Rectification: Request correction of inaccurate or incomplete data.
  • Right to Erasure: Request deletion of your account and personal data, subject to legal retention obligations.
  • Right to Restriction: Request restriction of processing in certain circumstances.
  • Right to Object: Object to processing based on legitimate interests.
  • Right to Data Portability: Receive your data in a structured, machine-readable format.
  • Right to Withdraw Consent (Art. 7(3)): Where processing is based on your consent, you may withdraw it at any time by emailing [email protected]. Withdrawal does not affect the lawfulness of processing carried out before withdrawal. Withdrawing your consent to immediate delivery of digital content does not reinstate the right of withdrawal under Art. 16(m) of Directive 2011/83/EU once delivery has already begun.
  • Right to Lodge a Complaint: File a complaint with your local data protection authority (in the Netherlands: the Autoriteit Persoonsgegevens).

To exercise any of these rights, email [email protected] from the email address linked to your account and include your username. Because we only store a hash of your email address, we check that the request comes from the account holder, for example by sending a code to that address.

10. Automated Decision-Making and Profiling

DND does not carry out any automated decision-making, including profiling, that produces legal effects or similarly significantly affects you within the meaning of Article 22 of the GDPR. Automatic security rules (rate limits, the one-session and one-device limits, and removing a license whose payment was refunded or charged back) apply the same fixed rules to everyone. Bans and account restrictions are decided by human staff.

11. Cookies and Local Storage

  • dnd_session: Keeps you signed in (httpOnly, Secure). With "Remember me" it lasts up to 30 days; otherwise it is deleted when you close your browser.
  • Cloudflare security cookies: Cloudflare may set short-lived cookies to protect the site against bots and attacks.
  • Local storage in your browser: Your basket, whether dashboard menu categories are folded, and whether you dismissed an announcement. This stays on your device and is not sent to us until you check out.

We do not use tracking cookies, advertising cookies, or third-party analytics. We only use strictly necessary cookies, which are exempt from the prior-consent requirement under Article 5(3) of the ePrivacy Directive 2002/58/EC (as transposed into national law), which is why we do not display a cookie consent banner.

12. Data Breach Notification

In the event of a data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority, and where the risk is high also the affected users, in accordance with Articles 33 and 34 of the GDPR.

13. Children

The Services are not directed to individuals under the age of 16. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child under 16, we will take prompt steps to delete such information.

14. Changes to This Policy

We may update this Privacy Policy from time to time. Changes will be posted on this page with a revised "Last updated" date. Where changes are material, we will also show a notice on the Services. Your continued use of the Services after any changes constitutes acceptance of the updated Policy.

15. Contact

For any questions or concerns regarding this Privacy Policy or our data practices, contact us at [email protected] or via our Discord.