Preview draft, not legal advice: controller identity, lawful-basis analysis, processor agreements, transfer mechanisms and the retention schedule require specialist review before publication.
Controller and contact
Brixon Group Ltd, Level 4, Centris Business Gateway, Triq Is-Salib Ta' L-Imriehel, Birkirkara CBD 3020, Malta (company registration C 110890). The privacy policy of Brixon Group Ltd applies to its other services; this page describes csauerborn.com.
Privacy contact: privacy@csauerborn.com
Storage on your device
Before analytics or marketing permission is available, the public pages do not set measurement cookies. The site uses the following browser storage and cookies:
- Campaign context. Campaign and advertising click identifiers from an arrival URL are held only in page memory while the marketing choice is unresolved. They move into
campaign_contextsession storage only after marketing permission, are then used to attribute a purchase, and are deleted on denial or withdrawal and when the tab closes. - Checkout id, session storage, no consent required. The checkout page keeps one short-lived random id per visit so that changing your order does not count as a second visit.
- Analytics identifiers. Once the configured analytics consent state allows measurement, the server issues the random, pseudonymous
bx_uidcookie and PostHog may use its own first-party browser storage. Thebx_uidcookie is HttpOnly and has a maximum lifetime of 400 days; it is not created while analytics remains denied. - Consent choice. In CMP mode, Usercentrics stores the choices required to remember and apply your analytics and marketing settings.
- Server consent snapshot. The site also signs the current analytics and marketing choice into an HttpOnly first-party cookie for up to 400 days. For delayed server-side delivery, checkout and newsletter processing use the latest confirmed choice at or before the payment or confirmation occurred; a later change does not rewrite that historical event. The cookie contains the two settings, their policy version and timestamp, plus a random opaque consent-subject id, but no name or email address. Withdrawing analytics permission also deletes the
bx_uidcookie. - Session cookie, strictly necessary. Signing in to your access area sets one cookie that identifies your session for thirty days. It contains a random value, nothing about you. Signing out deletes it.
- Offer cookie, strictly necessary. After a purchase, a one-hour cookie ties the one-time offer shown to you to the browser you saw it in.
- Stripe. The checkout is provided by Stripe inside this site. Stripe sets its own cookies for fraud prevention while the payment form is open; see Stripe's privacy notice.
Checkout and purchases
Payments are processed by Stripe (Stripe Payments Europe, Ltd.), including PayPal payments made through Stripe. Stripe collects the payment details, your name, billing address, email address and, if you enter one, your VAT number, and calculates the VAT for your country. This site never sees your card or PayPal details. Stripe issues the receipt and the invoice.
After a payment, this site stores on Cloudflare (EU jurisdiction) what is needed to give you access and to keep the books: your email address, the products bought, the order amounts, the Stripe identifiers of the payment, the campaign context if there was one, and the state of the order. Refunds and disputes update that record.
Your access area
Access is tied to the email address used at checkout. Signing in works with a link sent to that address; no password exists. The link and your session are stored only as cryptographic hashes. Files you download from the access area are served from Cloudflare storage in the EU.
Transactional email (your login link, your access after a purchase) and the post-purchase and newsletter emails are sent through Brevo (Sendinblue GmbH). Purchase and signup events reach Brevo through an automation service (n8n) operated for the seller. The newsletter uses double opt-in: nothing is sent until you confirm the address, and every email carries an unsubscribe link.
Measurement
PostHog is the primary product analytics service. When analytics is enabled, the public site records page views and a limited event vocabulary such as CTA interactions, form starts, checkout progress and purchases. Public pages may use privacy-masked session replay and exception capture; form fields are explicitly excluded. Login-token and account pages have no analytics, advertising tags or replay, and payment return URLs are stripped of their Stripe session parameter before measurement starts.
Google Analytics follows the analytics-consent state. Google Ads, the Meta Pixel and the LinkedIn Insight Tag follow the separate marketing-consent state. In CMP mode both begin denied and are updated from the configured Usercentrics services. An allowlisted production bootstrap can grant both states on page load; whether that exception may be activated is part of the legal go-live review noted above.
Completed purchases may be sent from both browser and server to Meta with one shared event id so Meta can deduplicate them. Google Ads and LinkedIn conversions use the server route only; the browser tags do not send a second conversion. Server-side advertising delivery also requires the recorded marketing-consent state. Files, prompts, access keys and form-field contents are never event properties.
Retention
Purchase records are kept as long as commercial and tax law require. Login links stop working after use or when their validity ends, and are deleted a day after that validity ends; sessions are deleted when they expire. Finished operational tracking rows and automation events are deleted after thirty days; older checkout and newsletter integrity rows have their analytics identifiers and campaign data removed. Server consent observations are deleted after 400 days.
Your rights
Depending on applicable law, you may have rights of access, correction, erasure, restriction, portability and objection, plus a right to complain to a supervisory authority. Contact privacy@csauerborn.com to make a request.