Last updated: July 5, 2026
This policy explains, honestly and specifically, what personal data the online store aspishop.cc collects, why, who receives it and what rights you have. The data controller is ASPI, the operator of aspishop.cc. You can contact us about anything in this policy — including requests to access or delete your data — through our official Discord server at discord.gg/aspi.
This policy is written for the General Data Protection Regulation (GDPR) and Spanish data-protection law (LOPDGDD).
We only ask for what the store actually needs:
We do not ask for and do not collect postal addresses, phone numbers, national ID documents or dates of birth.
When you use the Website, our servers process certain technical data:
We keep cookies to a minimum and we do not use any advertising or cross-site tracking cookies. What we actually set:
If you arrive through a creator's referral link (?ref=...), we ask for your consent with a banner before storing the referral persistently. If you accept, we set aspi_ref (which creator referred you, 30 days) and aspi_visitor_id (a random ID to count unique visitors per creator, 1 year). If you decline, we only keep the referral for your current browser session so the link you clicked still works, and nothing persists after you close the browser. You can change your choice at any time with the "Cookie settings" link in the footer.
The card-payment form is provided by Stripe, which sets its own fraud-prevention cookies (e.g. __stripe_mid, __stripe_sid) only when the payment step loads. The Cloudflare Turnstile anti-bot check runs on the checkout, login and registration forms. Embedded videos (tutorials and product pages) never load YouTube automatically: the player — in YouTube's reduced-tracking "nocookie" mode — only loads if you press play, and video thumbnails are served through our own server so your IP is not sent to Google while you simply browse.
Consent choices are stored in the aspi_cc cookie for 12 months, and we keep a technical record of the choice as proof of consent.
Every use of your data maps to one of the GDPR legal bases:
We never sell or rent personal data. We share only what each provider needs to do its job:
Some of the providers above are US companies (Stripe, Cloudflare, Discord, Trustpilot's US entities). Transfers to them rely on the EU–US Data Privacy Framework where the provider is certified, and on the European Commission's Standard Contractual Clauses otherwise. Brevo is an EU (French) provider; our own database runs on our own EU-located server.
We keep personal data only as long as its purpose requires:
All traffic is encrypted with TLS. Our origin server has no publicly reachable ports — it is only accessible through an encrypted Cloudflare tunnel. Among the measures we currently apply: delivered product keys are encrypted at rest with strong authenticated encryption (AES-256-GCM), passwords are stored only as bcrypt hashes, sessions use HttpOnly cookies, access to customer data is limited to store staff, and sensitive staff actions are themselves logged. Card numbers never touch our systems. We may update these measures over time to keep protection appropriate.
Under the GDPR you can, at any time and free of charge: access the data we hold about you, correct it, ask for its deletion, restrict or object to specific uses, ask for a portable copy, and withdraw any consent you gave (for cookies, use the "Cookie settings" link in the footer).
To exercise any of these rights, open a ticket on our Discord server stating what you want; we may ask you to prove control of the order email address before acting. We answer within one month at most. Note that we must keep data covered by legal retention duties (for example invoicing records of completed orders) even if you delete your account.
If you believe we are mishandling your data, you have the right to complain to a supervisory authority — in Spain, the Agencia Española de Protección de Datos (www.aepd.es).
We do not send newsletters or advertising emails. The only post-purchase message is the Trustpilot review invitation described above, which you can opt out of directly from the invitation itself. Every transactional email we send (order confirmation, delivery, password reset) is strictly necessary for your purchase or account.
The Website is intended for users aged 18 or over, and we do not knowingly process data of children under 14 (the age of digital consent in Spain). If we learn that a child's data has been submitted, we will delete it.
The Website links to external platforms — mainly our Discord community and the payment providers' own pages. Once you are on a third-party service, its own privacy policy applies. We recommend reading it.
When our data practices change, we update this page and its date. Significant changes will be highlighted on the Website. Earlier versions can be requested through Discord.
If you have questions about this Privacy Policy or want to exercise any of your rights, contact us through our Discord server.
Contact Us