Who is responsible
Peakstone is operated by Peakstone (preview), Czech Republic, which is the controller for the data described here. Contact: [email protected].
Payments are handled by Stripe. When you pay, Stripe and the Author whose plugin you buy process your payment details under their own privacy policies. Peakstone never receives your card number.
What we store and why
- Your email address, to sign you in with a one-time link and to match subscriptions to you. Legal basis: performance of a contract.
- Sign-in sessions: a random token stored as a hash, valid for 30 days or until you sign out.
- Subscription records: the Stripe IDs of your subscription and customer, the plugin and plan, status, renewal date and the email used at checkout. We need them to show your subscriptions, let you cancel and unlock downloads.
- Author applications: your Discord username, email, links to your plugin and GitHub, how you license it and your message. We use them only to review your application.
- Author profiles and listings: everything an Author publishes on their profile and Product pages is public.
- Uploaded releases: jar files Authors upload, with their checksum and who uploaded them.
- Launch notifications: if you press "Notify me at launch" on a plugin that is coming soon, we store your email address next to that plugin, when you signed up and, later, when we sent the launch email. Legal basis: your request, which you can withdraw at any time by pressing "Remove" on the plugin page.
We do not run advertising or third-party analytics, and we do not sell data.
Emails we send
We only send emails that belong to something you did on Peakstone. We do not send newsletters or marketing.
- Sign-in links, when you ask for one.
- Launch notifications: one email when a coming-soon plugin you asked about is published. It is the only email we send about that plugin.
- For Authors: whether your application was approved or declined, that your listing was received, published or sent back, and whether a release you uploaded was approved or rejected. These emails include the reviewer's message when a listing is sent back, a release is rejected, or the reviewer wrote a note on an approved release. The reviewer's private note on an application is never emailed.
These are sent to the address you signed in, applied or signed up with. Peakstone does not send payment receipts or renewal notices; any you get come from Stripe or the Author.
Who else processes data
- Stripe (payments, and the Authors' own Stripe accounts).
- Cloudflare (the network in front of the site and, when enabled, the Turnstile spam check on forms).
- Our email provider, to deliver the emails described above.
- Discord, where new author applications are posted to a private staff channel.
IP addresses are used briefly in memory to limit abuse of the sign-in and apply forms. They are not stored in our database.
How long we keep it
- Sign-in links: 15 minutes of validity.
- Sessions: up to 30 days.
- Applications: up to 12 months after a decision.
- Launch notification sign-ups: until the launch email is sent or you remove yourself, then about 90 days as a record that it was sent. They are deleted with the plugin if it is removed.
- Emails we send: we keep no copy of their content. Our mail server and your mail provider keep delivery logs for their own periods.
- Subscription records: while your account exists, and longer only where the law requires it.
Your rights
You can ask for a copy of your data, its correction or deletion, object to processing, or ask us to restrict it, by writing to [email protected]. You can also complain to the Czech data protection authority (Úřad pro ochranu osobních údajů, uoou.gov.cz) or the authority where you live.