← Back to the store

Privacy Policy

Last updated: 29 August 2026

Template notice for the operator: replace BUSINESS_NAME, BUSINESS_LOCATION and YOUR_EMAIL throughout. This is a GDPR-shaped starting point for a one-person digital shop selling through a merchant of record — have an accountant or lawyer skim it before you take real payments, and update it if you add analytics or extra services. Delete this box before publishing.

This policy explains how BUSINESS_NAME ("we", "us") handles personal data when you visit this website or buy the product The Money Shorts Machine.

1. Who is responsible

Controller: BUSINESS_NAME, BUSINESS_LOCATION. Contact for any privacy question or request: YOUR_EMAIL.

2. Buying the product — who controls what

Payments and checkout are handled by a third-party merchant of record (for card payments, Lemon Squeezy / Gumroad). When you check out, that provider is the seller of record and the controller of your billing and payment data (name, billing address, card details, tax location). Card details never reach this website or us. Their handling of that data is governed by their own privacy policy, shown to you at checkout.

From a completed order we receive a limited record — your email address and an order reference — so we can deliver the files and provide support. For that limited data we are the controller.

If you instead pay by PayPal or bank transfer, we receive the information you send us directly (email address, and whatever your bank includes with the transfer) in order to identify the payment and send you the files.

3. What we collect, why, and the legal basis

DataPurposeLegal basis (GDPR Art. 6)
Email address + order referenceDeliver the download, send the receipt, provide support, send free updates to the productPerformance of a contract (6(1)(b))
Support emails you send usAnswer your question, keep a record of the exchangeContract (6(1)(b)) / legitimate interest (6(1)(f))
Server & CDN logs (IP address, browser/user-agent, page requested, timestamp)Serve the site, keep it secure, diagnose faults, prevent abuseLegitimate interest in security and operation (6(1)(f))
Refund requestsProcess and record the refundContract (6(1)(b)) / legal obligation for accounting (6(1)(c))
Browser local storage: your cookie choice and interface stateRemember that you dismissed the cookie notice and your layout preferencesStrictly necessary / functional — no consent required

We do not use advertising cookies, ad pixels, or profiling. We do not currently run analytics. If that changes, this policy and the Cookie Policy will be updated and any such script will load only after you accept it.

4. Who we share data with

We never sell personal data. We only share what is needed for the purposes above.

5. International transfers

Some of the providers above are based in, or route data through, countries outside the EEA (for example the United States). Where that happens, transfers are covered by an adequacy decision or by the European Commission's Standard Contractual Clauses, as set out in that provider's own documentation.

6. How long we keep it

7. Your rights

Under the GDPR you have the right to: access your data; have it corrected; have it erased; restrict or object to processing; receive it in a portable format; and, where processing is based on consent, withdraw that consent at any time. To exercise any of these, email YOUR_EMAIL. We will respond within one month.

You also have the right to lodge a complaint with the supervisory authority. In Croatia that is the Agencija za zaštitu osobnih podataka (AZOP), Selska cesta 136, 10000 Zagreb — azop.hr. You may also complain to the authority in your own EU country.

8. Children

This site and product are not directed at children and we do not knowingly collect data from anyone under 16.

9. Changes

If we change this policy we will update the date at the top and, for significant changes, note it on the store page.

10. Contact

BUSINESS_NAMEYOUR_EMAIL