Skip to main content
Star Atlas

Privacy Policy

Version v3 — 2026-08-10 · Last updated 2026-08-10

TODO-OPERATOR: This policy describes the template's defaults, not your deployment. Review every section — especially lawful bases, processors, retention, and international transfers — with qualified counsel before launch, then bump the version in Foundation::Legal.

1. Who is responsible

This policy explains how the operator of Star Atlas ("we") handles personal data when you use the Service at https://example.com. The data controller is TODO-OPERATOR: legal entity name and address. For anything in this policy, contact legal@example.com.

2. Data we collect

Account data. Email address, a salted hash of your password (never the password itself), confirmation and sign-in state, and the versions of the legal documents you accepted together with the time, IP address, and browser identification of that acceptance.

Order data. Where purchases are enabled: what you ordered, amounts and currency, order status, and the email used at checkout; legal versions accepted; and provider session/payment/event identifiers used to prevent duplicate fulfillment. The template sells digital goods only and does not collect shipping addresses. Card numbers and security codes are handled by our payment processor and never reach our servers.

Session data. Cookies that keep you signed in, remember-me tokens if you opt in, device and browser details, IP address, approximate location when available, sign-in method, last activity, failed sign-in attempts, revocations, and account-lock timestamps.

Technical data. Server logs with IP address, browser user agent, requested pages, and timestamps, kept for security and debugging; and the answers of anti-bot challenges (Cloudflare Turnstile) on registration and password-reset forms.

3. Why we use it

  • to provide the Service: authentication, account management, and — where enabled — processing orders;
  • to secure it: preventing abuse, locking brute-forced accounts, filtering bots, and investigating incidents;
  • to communicate: transactional email such as confirmation, password-reset, unlock, and receipt messages;
  • to comply with legal obligations, such as tax and bookkeeping rules for orders;
  • to keep evidence of legal assent (versions accepted, when, from where).

We do not sell personal data and do not use it for third-party advertising.

4. Lawful bases

TODO-OPERATOR: if you are subject to the GDPR/UK GDPR or similar, map each purpose above to a lawful basis. The template's expected mapping is: performing our contract with you (accounts, orders, transactional mail), legitimate interests (security, abuse prevention, service improvement), legal obligation (bookkeeping, assent records), and consent where you opt in to anything optional.

5. Processors and recipients

We share data only with service providers that process it on our instructions, under data processing agreements:

  • Hosting/infrastructure: TODO-OPERATOR: name your host and region.
  • Content delivery and bot protection: Cloudflare (proxying, Turnstile challenges).
  • Email delivery: TODO-OPERATOR: name your SMTP/email provider.
  • Payments (where enabled): Stripe, which acts as its own controller for card data.
  • TODO-OPERATOR: list any analytics, error-tracking, or support tooling you add.

We disclose data to authorities only where a law we are subject to requires it.

6. Cookies and analytics

The template uses only cookies that are necessary to operate the Service: the session cookie, an optional remember-me cookie, CSRF protection, and a signed random device identifier created at sign-in. The device identifier recognizes a browser installation so repeated sign-ins can be managed as one device; it survives logout for up to five years but contains no browser fingerprint or account identifier. These need no consent banner in most jurisdictions. No analytics or marketing cookies are set by default. TODO-OPERATOR: if you add analytics or marketing tags, document them here and add a consent mechanism where required.

7. Retention

  • Account data: kept while the account exists; deleted or anonymized promptly after account deletion, except where law requires longer.
  • Legal-assent records: kept for the life of the account plus the limitation period for contract claims.
  • Order and invoice data: kept for the statutory bookkeeping period.
  • Server logs and security counters: rotated on a short schedule, typically 30-90 days.
  • Device session history: kept for up to 12 months by default, then removed by a daily retention job.

8. Your rights

Depending on where you live, you may have the right to access the personal data we hold about you, correct it, receive a portable copy, have it deleted, restrict or object to certain processing, and withdraw consent you have given. You can exercise most of this directly: account settings let you change your email and password and delete your account. For everything else, email legal@example.com and we will respond within the statutory deadline. You also have the right to complain to your local data protection authority.

9. International transfers

TODO-OPERATOR: state where your servers and processors are located and, if personal data leaves your users' jurisdiction (for example EU data processed in the US), the transfer mechanism you rely on — adequacy decisions, Standard Contractual Clauses, or the EU-US Data Privacy Framework — for each processor in Section 5.

10. Security

Passwords are stored as salted bcrypt hashes; transport is encrypted with TLS; repeated failed sign-ins lock the account; registration and password-reset forms carry an anti-bot challenge. No online service can promise perfect security, but we notify affected users and authorities of breaches where the law requires it.

11. Changes to this policy

When this policy changes materially we will announce it by email or an in-product notice before it takes effect, and the version identifier at the top of this page will change. Earlier versions you accepted remain recorded on your account. Questions are always welcome at legal@example.com.