Legal

Privacy Policy

Last updated: July 5, 2026

1

Who is responsible for your data

This policy explains, honestly and specifically, what personal data the online store aspishop.cc collects, why, who receives it and what rights you have. The data controller is ASPI, the operator of aspishop.cc. You can contact us about anything in this policy — including requests to access or delete your data — through our official Discord server at discord.gg/aspi.

This policy is written for the General Data Protection Regulation (GDPR) and Spanish data-protection law (LOPDGDD).

2

Data you give us

We only ask for what the store actually needs:

  • To place an order: first name, last name, email address and, optionally, your Discord ID (used only to deliver Discord-related perks such as the customer role).
  • To create an account: email address and password. The password is stored only as a bcrypt hash — we never see or store it in clear.
  • To top up store credit: the amount; the movement is recorded in your account's balance ledger.
  • To leave a review: your rating and the text you write. Reviews are shown publicly with your first name only.
  • If you contact support on Discord: whatever you choose to tell us there (Discord's own privacy policy also applies on their platform).

We do not ask for and do not collect postal addresses, phone numbers, national ID documents or dates of birth.

3

Data collected automatically

When you use the Website, our servers process certain technical data:

  • IP address, country, browser/device identification (user-agent) and language — recorded with orders, account logins, reviews, balance movements and security events.
  • Pages visited on our own store: we run a small self-hosted live-visitors panel that keeps IP, current page, country and referrer in server memory for a maximum of 24 hours. It is never shared and there is no third-party analytics or advertising tracker on this site.
  • Security screening of your IP address: to prevent payment fraud we check IPs against IP-reputation services that tell us the approximate location, network operator and whether the address is a known VPN, proxy or TOR exit (see section 6). High-risk signals may put an order on hold for manual review.
  • Technical error reports from your browser (error message, page, browser version) so we can fix bugs. They contain no account data.
  • A security log of relevant events (logins, orders, payments, blocked attempts) that includes the technical data above.
4

Cookies and similar technologies

We keep cookies to a minimum and we do not use any advertising or cross-site tracking cookies. What we actually set:

Strictly necessary (no consent required)

  • aspi-customer-token — keeps you logged into your account (7 days, HttpOnly).
  • aspi_review_id — random anonymous ID set when you submit a review, used only to prevent review spam (1 year, HttpOnly).
  • NEXT_LOCALE — remembers the language shown to you (1 year). It is set when you pick a language, or, on your first visit, from the country your network reports; it only stores your language preference and is never used to track you or build a profile.
  • aspi-cart (browser localStorage) — the contents of your cart, stored only in your own browser.
  • Cloudflare security cookies (e.g. __cf_bm) — set by our CDN/security provider to protect the site from bots and attacks.

Referral cookies (only with your consent)

If you arrive through a creator's referral link (?ref=...), we ask for your consent with a banner before storing the referral persistently. If you accept, we set aspi_ref (which creator referred you, 30 days) and aspi_visitor_id (a random ID to count unique visitors per creator, 1 year). If you decline, we only keep the referral for your current browser session so the link you clicked still works, and nothing persists after you close the browser. You can change your choice at any time with the "Cookie settings" link in the footer.

Third parties at checkout and on video pages

The card-payment form is provided by Stripe, which sets its own fraud-prevention cookies (e.g. __stripe_mid, __stripe_sid) only when the payment step loads. The Cloudflare Turnstile anti-bot check runs on the checkout, login and registration forms. Embedded videos (tutorials and product pages) never load YouTube automatically: the player — in YouTube's reduced-tracking "nocookie" mode — only loads if you press play, and video thumbnails are served through our own server so your IP is not sent to Google while you simply browse.

Consent choices are stored in the aspi_cc cookie for 12 months, and we keep a technical record of the choice as proof of consent.

5

What we use your data for, and on what legal basis

Every use of your data maps to one of the GDPR legal bases:

  • Processing and delivering your orders, managing your account and store credit, and answering support requests — performance of a contract (art. 6.1.b GDPR).
  • Keeping accounting and tax records of sales — legal obligation (art. 6.1.c).
  • Preventing payment fraud and abuse: IP screening, rate limiting, security logging, blocking of abusive addresses — legitimate interest (art. 6.1.f) in protecting the store and its customers from fraud; the checks are limited to what a payment actually requires.
  • Operational alerts to our own staff when an order is placed or a security event happens — legitimate interest in running the store (see section 6 about where those alerts go).
  • Inviting you to review your purchase through Trustpilot — legitimate interest in reputation for our existing customers (soft opt-in); every invitation includes an opt-out and we do not send any other marketing email.
  • Referral cookies — your consent (art. 6.1.a), which you can withdraw at any time.
6

Who receives your data

We never sell or rent personal data. We share only what each provider needs to do its job:

  • Stripe (payments): processes your card entirely on its side; we receive and store only the last 4 digits, card brand and the billing name/country Stripe reports back.
  • NOWPayments (crypto payments): receives the order number and amount to generate the payment invoice.
  • PayPal: when you pay by PayPal we receive from PayPal your PayPal name and email to match the payment to your order, and we store that confirmation.
  • Brevo (EU email provider): sends our transactional emails (order confirmation, delivery, password reset) and therefore processes your email address and the email content.
  • Cloudflare (CDN, security, Turnstile anti-bot, media hosting): all traffic to the site passes through Cloudflare's network; it processes IP addresses and requests as our security provider.
  • Trustpilot (review invitations): after a delivered order, Trustpilot receives your email address and order reference so it can send you a single review invitation with an opt-out.
  • Discord: our internal staff notifications (new order, payment, security alert) are delivered into our private staff Discord channels and, depending on the event, may include only the data that event requires — such as your name, email, IP and country; if you buy through our Discord bot or provide your Discord ID, delivery messages and the customer role are also handled through Discord.
  • IP-reputation services (vpnapi.io and ipwho.is): receive customer IP addresses — and nothing else — to detect VPN/proxy/TOR usage and estimate location for fraud prevention.
  • Public authorities: only where the law obliges us.
7

International transfers

Some of the providers above are US companies (Stripe, Cloudflare, Discord, Trustpilot's US entities). Transfers to them rely on the EU–US Data Privacy Framework where the provider is certified, and on the European Commission's Standard Contractual Clauses otherwise. Brevo is an EU (French) provider; our own database runs on our own EU-located server.

8

How long we keep data

We keep personal data only as long as its purpose requires:

  • Orders, invoicing data and the store-credit ledger: at least 6 years, as Spanish commercial and tax law requires for business records.
  • Customer accounts: while the account exists. You can ask us to delete your account at any time (section 10).
  • Security and fraud-prevention logs (including IP-reputation results): only as long as needed to detect and prevent fraud and to handle any related investigation or dispute, and in any case no longer than 24 months, after which they are deleted or anonymized.
  • Live-visitor statistics: maximum 24 hours, in server memory only.
  • Reviews: while the review is published.
  • Delivered product keys: kept encrypted with the order so we can re-show you your purchase and honor the conformity guarantee.
9

How we protect your data

All traffic is encrypted with TLS. Our origin server has no publicly reachable ports — it is only accessible through an encrypted Cloudflare tunnel. Among the measures we currently apply: delivered product keys are encrypted at rest with strong authenticated encryption (AES-256-GCM), passwords are stored only as bcrypt hashes, sessions use HttpOnly cookies, access to customer data is limited to store staff, and sensitive staff actions are themselves logged. Card numbers never touch our systems. We may update these measures over time to keep protection appropriate.

10

Your rights

Under the GDPR you can, at any time and free of charge: access the data we hold about you, correct it, ask for its deletion, restrict or object to specific uses, ask for a portable copy, and withdraw any consent you gave (for cookies, use the "Cookie settings" link in the footer).

To exercise any of these rights, open a ticket on our Discord server stating what you want; we may ask you to prove control of the order email address before acting. We answer within one month at most. Note that we must keep data covered by legal retention duties (for example invoicing records of completed orders) even if you delete your account.

If you believe we are mishandling your data, you have the right to complain to a supervisory authority — in Spain, the Agencia Española de Protección de Datos (www.aepd.es).

11

Marketing

We do not send newsletters or advertising emails. The only post-purchase message is the Trustpilot review invitation described above, which you can opt out of directly from the invitation itself. Every transactional email we send (order confirmation, delivery, password reset) is strictly necessary for your purchase or account.

12

Age of users

The Website is intended for users aged 18 or over, and we do not knowingly process data of children under 14 (the age of digital consent in Spain). If we learn that a child's data has been submitted, we will delete it.

13

Links to other services

The Website links to external platforms — mainly our Discord community and the payment providers' own pages. Once you are on a third-party service, its own privacy policy applies. We recommend reading it.

14

Changes to this policy

When our data practices change, we update this page and its date. Significant changes will be highlighted on the Website. Earlier versions can be requested through Discord.

If you have questions about this Privacy Policy or want to exercise any of your rights, contact us through our Discord server.

Contact Us