Preview draft, not legal advice: controller identity, lawful-basis analysis, processor agreements, transfer mechanisms and the retention schedule require specialist review before publication.
Controller and contact
[Legal entity and registered address]
Privacy contact: privacy@csauerborn.com
Storage on your device
On the public pages this site sets no cookies. It uses browser storage in three places, and only the checkout and the access area set cookies:
- Campaign context, session storage, no consent required. If you arrive through a campaign link, its parameters (
utm_*,gclid,fbclid) are kept undercampaign_contextfor the browser session so that a purchase can be attributed to the link you clicked. Deleted when the tab closes. - Checkout id, session storage, no consent required. The checkout page keeps one random id per visit so that changing your order does not count as a second visit.
- Visitor id, local storage, consent required. A random identifier
bx_uidrecognises a returning visit for measurement. It is created only after you allow analytics and never on page load. Without that permission no identifier exists. - Session cookie, strictly necessary. Signing in to your access area sets one cookie that identifies your session for thirty days. It contains a random value, nothing about you. Signing out deletes it.
- Offer cookie, strictly necessary. After a purchase, a one-hour cookie ties the one-time offer shown to you to the browser you saw it in.
- Stripe. The checkout is provided by Stripe inside this site. Stripe sets its own cookies for fraud prevention while the payment form is open; see Stripe's privacy notice.
Checkout and purchases
Payments are processed by Stripe (Stripe Payments Europe, Ltd.), including PayPal payments made through Stripe. Stripe collects the payment details, your name, billing address, email address and, if you enter one, your VAT number, and calculates the VAT for your country. This site never sees your card or PayPal details. Stripe issues the receipt and the invoice.
After a payment, this site stores on Cloudflare (EU jurisdiction) what is needed to give you access and to keep the books: your email address, the products bought, the order amounts, the Stripe identifiers of the payment, the campaign context if there was one, and the state of the order. Refunds and disputes update that record.
Your access area
Access is tied to the email address used at checkout. Signing in works with a link sent to that address; no password exists. The link and your session are stored only as cryptographic hashes. Files you download from the access area are served from Cloudflare storage in the EU.
Transactional email (your login link, your access after a purchase) and the post-purchase and newsletter emails are sent through Brevo (Sendinblue GmbH). Purchase and signup events reach Brevo through an automation service (n8n) operated for the seller. The newsletter uses double opt-in: nothing is sent until you confirm the address, and every email carries an unsubscribe link.
Measurement
Measurement is limited to events on this site: a checkout started, a purchase completed, a signup. Marketing signals are sent only where the required consent exists. Files, prompts and keys are never part of an event.
Retention
Purchase records are kept as long as commercial and tax law require. Login links stop working after use or when their validity ends, and are deleted a day after that validity ends; sessions are deleted when they expire. Event records for the automation service are deleted thirty days after they were written.
Your rights
Depending on applicable law, you may have rights of access, correction, erasure, restriction, portability and objection, plus a right to complain to a supervisory authority. Contact privacy@csauerborn.com to make a request.