ThirtyAsset

Privacy Policy

GDPR · Last updated: 2026

Data controller

ThirtyOne Lab's [address] - contact@thirtyasset.com.

Data we collect

  • Account: email, name, hashed password (never in clear text).
  • Orders: purchases, invoices, entitlements, download history.
  • Security: IP address and event logs (anti-fraud, anti-sharing).
  • Payment: handled by PayPal & Revolut - we never store your card or bank details.

Why we use it (legal bases)

  • Provide your account and deliver purchases - performance of contract.
  • Prevent fraud and account sharing - legitimate interest.
  • Invoicing and accounting - legal obligation.

Sharing

We share data only with processors needed to run the service: payment (PayPal, Revolut), hosting (Vercel), database/storage (Neon, Cloudflare R2), and transactional email (Resend). No sale of personal data.

Retention

Account data is kept while your account is active; invoices are kept for the legal accounting period (10 years).

Your rights

You have the right to access, rectify, erase, port and object to the processing of your data. Email contact@thirtyasset.com. You may also lodge a complaint with the CNIL (France) or your local authority.

Cookies

We use strictly necessary cookies (session, authentication). Any analytics cookie is only set with your consent via the cookie banner. You can change your choice anytime by clearing site data.

Security

HTTPS everywhere, hashed passwords, single-use signed download links, and download fingerprinting.