1. Data controller
Georgii Khoroshilov, trading as Good Export Studio and operating the GoodSewed website, is the controller of personal data described in this Policy. We are based in Pattaya, Chon Buri 20150, Thailand. Privacy requests can be sent to goodsewed1@gmail.com.
2. Data we collect
- Account data: name, email address, password hash, verification status, profile image, role, and account dates.
- Authentication data: session identifiers, sign-in provider, security events, device or browser information, and network address where needed for security.
- Commerce data: Stripe customer and checkout identifiers, product, amount, currency, payment status, billing details, tax identifiers supplied to Stripe, and the version and time of legal acceptance. We do not store complete card numbers.
- License data: products, entitlements, license keys, capacity, activation status, machine identifiers, versions, and download availability.
- Support data: product, report title and description, attachments, technical context, status, and correspondence.
- Technical data: essential logs required to operate, diagnose, secure, and prevent abuse of the website and API.
3. How and why we use data
We process data to:
- create and secure accounts, authenticate users, and provide Google sign-in;
- take payment, prevent fraud, issue order records, and grant product access;
- create, activate, enforce, and support software licenses;
- deliver downloads, updates, release notes, and account services;
- receive product reports, create linked support issues, and respond to requests;
- comply with tax, accounting, payment, consumer, security, and legal obligations;
- protect the website, products, customers, and our legal rights.
Depending on the context, the legal basis is performance of a contract, steps requested before a contract, compliance with law, legitimate interests in operating and securing the service, or consent where the law specifically requires it. We do not sell personal data.
4. Service providers and disclosures
We disclose only the data reasonably necessary to providers that help deliver the service, including:
- Stripe for checkout, payments, fraud controls, billing, and tax-related collection;
- Google for optional Google sign-in and reCAPTCHA abuse protection;
- GitHub when a product report is synchronised to the product’s issue repository;
- hosting and infrastructure providers for database, storage, security, logging, and delivery.
A support report may become visible in the relevant GitHub repository according to that repository’s visibility. Do not include secrets, private client files, personal data, or confidential production material in a report unless support specifically requests it. We may also disclose information where required by law, to protect rights and safety, or as part of a lawful business transfer.
5. International transfers
We operate from Thailand and use providers that process data in Thailand, the United States, and other countries. This includes Stripe, Google, GitHub, and hosting providers. Where required, we use contractual and organisational safeguards and make disclosures necessary under Thailand’s Personal Data Protection Act and other applicable privacy laws.
6. Cookies and local storage
We use an essential secure session cookie to keep you signed in, short-lived cookies during authentication, and browser local storage to remember the light or dark theme. These are used for account security and requested functionality. We do not currently use advertising cookies or behavioural advertising trackers. Payment pages operated by Stripe apply Stripe’s own necessary technologies and policies.
7. Retention
We retain account and license data while an account or license is active and for a reasonable period afterwards. Transaction, tax, fraud, and accounting records are retained for the periods required by applicable law. Support reports are kept while useful for resolving the report, maintaining product history, or defending legal claims. Security logs are retained only as long as reasonably necessary for diagnosis, abuse prevention, and legal compliance. Data is deleted or anonymised when it is no longer needed.
8. Your choices and rights
Depending on your location, you may have rights to request access, correction, deletion, restriction, objection, portability, withdrawal of consent, or a copy of your data, and to complain to a data protection authority. Some information must be retained to complete a contract, prevent fraud, maintain a license record, or comply with tax and legal duties.
Send a request from the email associated with your account to goodsewed1@gmail.com. We may ask for proportionate verification before disclosing or deleting account information.
9. Security and children
We use access controls, hashed credentials and session tokens, encrypted transport, limited administrative access, and other reasonable safeguards. No internet service is completely secure. GoodSewed products and paid accounts are not directed to children under 18, and we do not knowingly collect their data for independent purchases.
10. Changes
We may update this Policy when services, providers, or legal duties change. The current version and effective date appear at the top of this page. Material changes will be communicated where reasonably necessary.