Privacy Policy
Last updated: August 2026
1. Controller & Overview
Controller within the meaning of the GDPR: J. Guttchen, email: info@808-vault.com. Full address: see our Impressum.
808Vault ("we", "us", "our") respects your privacy. This policy explains how we collect, use, and protect your personal data when you use our website and services, in accordance with Art. 13 GDPR.
2. Data We Collect
- Contact information (name, email address) when you place an order, use the contact form, the exclusive-license inquiry form, or subscribe to the newsletter
- Order data (ordered beats, license tiers, prices, coupon codes) and consent log (timestamp, IP address, consent wording version) for orders of digital content
- Payment information processed directly by Stripe (including Klarna, SEPA, Sofort and wallet payments such as Apple Pay / Google Pay via Stripe). We never store card details.
- Chat messages you send to our AI beat concierge (processed to answer your request; history is kept only in your browser)
- Technical data (IP address, browser type, visited pages) in server logs for security and abuse prevention. We do not use tracking or advertising cookies, and we do not run analytics tools.
3. Purposes & Legal Bases
- Fulfilment of the purchase contract (Art. 6(1)(b) GDPR): processing your order, payment, delivery of license files, invoices and download links.
- Legal obligations (Art. 6(1)(c) GDPR): retention of order and accounting data for tax purposes (usually 10 years in Germany).
- Legitimate interest (Art. 6(1)(f) GDPR): security, fraud and abuse prevention, server-log analysis, and documentation of the withdrawal-right consent under Sec. 356 (5) BGB.
- Consent (Art. 6(1)(a) GDPR): newsletter and marketing emails (including abandoned-cart reminders and the welcome series) and the express consent to the early provision of digital content in the checkout. You can withdraw consent at any time.
4. Payment Processing
Payments are processed by Stripe, Inc. (including Klarna Bank AB for Klarna payments and SEPA/Sofort via Stripe). Your payment data is handled directly by these providers under their own privacy policies. We never store your credit card information on our servers. Stripe is a US company; data transfers to the USA are covered by the EU Standard Contractual Clauses (SCCs) and, where applicable, the EU-US Data Privacy Framework.
5. Email Services & Marketing
Order confirmations, license files (with PDF license certificate) and download links are sent by email via Resend (US provider; transfers covered by SCCs). If you subscribe to our newsletter you will receive a 10% welcome discount code and occasional beat news. After a purchase or abandoned cart, we may send automated service emails (order confirmation, license delivery, abandoned-cart reminders up to 72 hours, and a welcome series over approx. 14 days). Every marketing email contains an unsubscribe link; you can also object at any time by contacting us.
6. AI Chat Concierge
Our optional chat concierge recommends beats from the catalog. Messages you send are transmitted to Cloudflare Workers AI (Meta Llama model) solely to generate a reply; the chat history is stored only in your browser (localStorage) and is not saved by us on our servers. Cloudflare may log requests for abuse prevention in accordance with its own policies. Please do not send sensitive personal data in the chat.
7. Hosting & Storage
This website is hosted on Cloudflare (Workers, D1 database in the EU region WEUR, R2 object storage for audio previews). Cloudflare processes technical access data (including IP addresses) as our processor for the purpose of operating and securing the website.
8. Cookies & Local Storage
We use only essential cookies and browser storage to keep the site working: your cart, your language preference, the consent status for the digital-content download, and the chat history are stored locally in your browser (localStorage/sessionStorage). We do not use analytics, advertising, or other tracking cookies, and no third-party scripts load before you visit the checkout. You can clear localStorage/sessionStorage at any time in your browser settings.
9. International Data Transfers
Where personal data is transferred to service providers outside the EU/EEA (in particular Stripe and Resend in the USA), the transfer is based on the EU Standard Contractual Clauses (SCCs) and, where applicable, the EU-US Data Privacy Framework. A copy of the relevant safeguards is available on request.
10. Data Retention
We retain order data (including the consent log) for the period required by tax and accounting regulations (typically 10 years in Germany). Contact form messages are deleted after 6 months unless they relate to an active business relationship. Newsletter data is stored until you unsubscribe or request deletion; you can request deletion of your data at any time.
11. Your Rights (GDPR)
Under the GDPR, you have the right to:
- Access your personal data (Art. 15)
- Rectification of inaccurate data (Art. 16)
- Erasure of your data (Art. 17)
- Restriction of processing (Art. 18)
- Data portability (Art. 20)
- Object to processing based on legitimate interest (Art. 21)
- Withdraw consent at any time without affecting the lawfulness of processing based on consent before withdrawal
- Lodge a complaint with a supervisory authority β for us: Die Landesbeauftragte fΓΌr Datenschutz und Informationsfreiheit Bremen (Art. 77 GDPR).
12. Contact
For privacy-related inquiries, access or deletion requests, contact us at info@808-vault.com.