THE RACCOON LAB
← Back to the lab/PRIVACY_POLICY.TXT
~/lab/legal/privacy_policy.txt

A short
privacy policy._

The Raccoon Lab AB is a one-person operation — one workshop, one email list, one shop, based in Sweden. This page describes in plain words what data is actually kept, why, on what legal basis, how long for, and how to get rid of it. There's no advertising network and no tracking cookies — the only statistics are cookieless page counts, described in section 03.

CONTROLLER · The Raccoon Lab AB, 559443-9670EFFECTIVE · 2026-05-24LAST EDIT · 2026-09-21
// 01what_we_collectFOUR BUCKETS

Only what's needed to run an account, deliver a file, take a payment, and send the list. Nothing is collected for advertising.

// your account
  • email address
  • password (hashed by Clerk — never seen by me)
  • basic Google profile, if you use Google sign-in
  • sign-in activity, IP and device, for security
// your purchases
  • which products you own
  • which you've opened (drives the NEW badges)
  • what's in your cart
  • when purchases were last synced
  • your build guide progress: ticked sections and parts, and your answers to its questions
// the email list
  • email address
  • your consent, and when you gave it
  • IP address and country at signup
  • unsubscribe state
// automatic
  • country, derived from your IP, to pick currency and VAT
  • server logs kept by the host
  • update checks from the desktop app and your devices — see section 07
  • whatever you write to me in an email

Card details are never collected by me at all — see section 04.

// 02why_and_legal_basisGDPR ART. 6

Every piece of data maps to one reason and one lawful basis. If a reason disappears, the data does too.

  • →Running your account and delivering what you bought — email, password, purchase history. Basis: performance of a contract (Art. 6(1)(b)). Without it there's no way to give you your files.
  • →Taking payment and keeping tax records — order and VAT records. Basis: legal obligation (Art. 6(1)(c)) under Swedish bookkeeping and VAT law.
  • →The email list — telling you when a file drops or a batch opens. Basis: your consent (Art. 6(1)(a)), which you can withdraw at any time from any email.
  • →Proving you agreed to be emailed — the IP address, time and rough location of the signup itself. Basis: legal obligation (Art. 6(1)(c)) — the law requires me to be able to demonstrate consent (Art. 7(1)), and a record with no evidence behind it isn't a record. It's used for nothing else, and it goes when you unsubscribe.
  • →Keeping accounts secure and stopping fraud — sign-in activity, IP. Basis: legitimate interests (Art. 6(1)(f)) in not having accounts stolen or files redistributed.
  • →Showing the right price — country from IP, so you see your currency and the correct VAT. Basis: performance of a contract (Art. 6(1)(b)).

There is no profiling and no automated decision-making that produces legal effects for you.

// 03tools_we_use8 VENDORS

A short, named list. If a vendor is on it, your data is on their servers — I'd rather tell you than dress it up. Each acts as a processor on my behalf under a data processing agreement.

  • →Clerk · runs accounts and sign-in. Stores your email, hashed password, Google profile if you use it, and session records including IP and device.
  • →Stripe · takes payments and calculates VAT. Receives your email and the location data needed for tax, and holds the card details directly.
  • →Vercel · hosts this site. Processes your IP address and normal server logs as part of serving pages. Also provides the visitor statistics described below — same company, no extra vendor.
  • →Cloudflare · stores the build files you buy and delivers them to you. Sees your IP address when you download, and nothing else — not your name, not your email, not which account you are. Files are held in the EU and are never public: each download uses a private link that expires within minutes.
  • →MailerLite · manages the email list. Stores your email, unsubscribe state, and — as the record that you agreed to be emailed — the IP address you signed up from, the time you did it, and the country and city that IP resolves to.
  • →Resend · sends the confirmation email after a purchase. Receives your email address and what you bought.
  • →Mailgun · receives mail sent to support@ and contact@ and forwards it to me. Handles whatever you put in that email.
  • →Google · only if you choose "Continue with Google". Google tells me your email and basic profile; I tell Google nothing about you.

That's the whole list of vendors working on my behalf. No advertising network, no data broker, and nothing is ever sold or shared for marketing. When the list changes, this page changes.

Affiliate links. Some shop links in the parts list are marked "Affiliate link". They go through Geniuslink to the right Amazon store for your country. If you click one, those two companies see the click — your IP address and browser, and Amazon whatever you do on its site — under their own privacy policies, as independent controllers, not on my behalf. I receive nothing that identifies you, only a commission report if a purchase follows. Every other shop link is an ordinary link.

Visitor statistics. I count page views to know which pages people actually read and whether the site works — how many opened a page, from which country, and how many got as far as entering an email address. It runs on Vercel, who already host the site, so no new company receives anything.

It is cookieless and has no profile of you in it. Nothing is stored on your device, you are not given an identifier that follows you between visits or between sites, and I cannot see what any individual person did. Your email address is never attached to it — when you sign up to the list, what gets counted is that a signup happened and which form it came from, never who. That is why there is no cookie banner: there is nothing here to consent to.

// 04paymentsNEVER TOUCHES ME

Checkout happens on Stripe's own pages. Your card number, expiry and security code go straight to them and never pass through a Raccoon Lab server. I couldn't see or store them if I wanted to.

You can pay before you have an account. In that case your purchase is filed under the email address you give on Stripe's page, and your files open in the account that later verifies that same address. The link that takes you from the payment to your account carries the order's reference, never the address.

What comes back to me is the minimum needed to give you your files and keep lawful records: that a payment succeeded, the amount, your email, and the location Stripe used to work out VAT.

If you get as far as Stripe's payment page and leave without paying, Stripe tells me that too: the email you typed and what was in the cart. Nothing is done with it. No reminder is sent and the address goes on no list.

Stripe is an independent controller for its own fraud-prevention and regulatory purposes. Their handling of your data is governed by Stripe's privacy policy.

// 05how_long_we_keep_itRETENTION
  • →Account and purchase history · for as long as you have an account. Delete the account and it goes — along with your access to the files, so back them up first.
  • →Order and VAT records · seven years, because Swedish bookkeeping law requires it. This is the one category I can't delete on request — a legal obligation overrides erasure here.
  • →Email list · until you unsubscribe, then removed.
  • →Emails you send me · until the conversation is clearly finished and there's no reason to keep it.
  • →Server logs · short-lived, per the host's own retention.
// 06where_it_goesOUTSIDE THE EU

Some of the vendors above are based in, or process data in, the United States. That means your data may be transferred outside the EU/EEA.

The build files themselves are stored in the EU — the Cloudflare bucket they live in is pinned to a Western European region, so buying and downloading doesn't move your files or your download record out of Europe.

Where that happens, the transfer relies on the safeguards the law requires — the European Commission's Standard Contractual Clauses, or an adequacy decision such as the EU–US Data Privacy Framework where the vendor is certified under it.

I don't transfer your data anywhere else, and I don't sell or share it with anyone for their own purposes.

// 07the_devices_themselvesLOCAL · UPDATES ONLY

A device you build joins your own WiFi and talks to things on your own network — your computer and, if you use it, your Home Assistant. The WiFi password and everything else you set up stay on the device. There is no Lab account on it, no cloud backend and no telemetry: nothing you do with it is sent to me.

The one thing it asks this site for is updates. When it has WiFi, it fetches a small file from theraccoonlab.com saying which firmware version is current, and downloads the new firmware when there is one. Like any request to a website, that reaches the host with the device's public IP address and lands in Vercel's ordinary server logs. It carries no account, no name and nothing about how the device is used, and I don't link it to anyone.

The desktop app works the same way. It checks this site for a newer version, and to download one it sends the update key shown on the software page. That key is tied to your account — it is how the site checks that the app belongs to someone who bought it — so an update download is linked to your account. The check itself is not. Beyond that, the app talks only to the device and to programs on your own computer.

// 08your_rightsGDPR

Standard EU rules. Email me and I'll handle any of these within 30 days — usually the same week, because there's one person reading the inbox. Exercising them is free and I won't treat you differently for it.

SEE

Ask for a copy of everything I hold linked to your email.

FIX

Correct anything inaccurate or incomplete.

FORGET

Ask me to delete your information — except records tax law requires me to keep.

MOVE

Get your data in a portable format, or have it sent to another provider.

PAUSE

Restrict how I use your data while a dispute or correction is sorted out.

OBJECT

Object to anything I do on the basis of legitimate interests.

Where I rely on consent — the email list — you can withdraw it at any time using the unsubscribe link in any email, or by writing to me. Withdrawing doesn't affect anything done before you withdrew.

You also have the right to complain to the Swedish supervisory authority, IMY (Integritetsskyddsmyndigheten), at imy.se — or to the authority where you live.

// 09cookiesESSENTIAL ONLY

Only cookies that are strictly necessary to make the site work — which is why there's no cookie banner asking your permission. Consent is only required for the non-essential kind, and there aren't any.

  • →Sign-in cookies set by Clerk, so you stay logged in between pages. Clearing them logs you out.
  • →Functional cookies set by the host to serve the site correctly.
  • →Stripe may set cookies on its own checkout pages for fraud prevention.

No analytics cookies, no advertising cookies, no third-party tracking pixels. The visitor statistics described in tools_we_use are counted without cookies and without storing anything on your device, which is exactly why they need no banner.

// 10childrenNOT FOR KIDS

This shop isn't aimed at children and accounts aren't knowingly created for them. If you're under 18, ask a parent or guardian to buy for you.

If you're a parent or guardian and think a child has given me their information, email me and I'll delete it.

// 11if_this_page_changesLOG

Any changes are logged below with a date. If a change meaningfully affects your data, you'll get an email.

  • →2026-05-24 · initial version published.
  • →2026-08-07 · rewritten to cover accounts, payments and file delivery, and to add legal bases, retention periods, international transfers and the full list of rights.
  • →2026-08-10 · added Cloudflare, which now stores and delivers the build files (previously Vercel), and noted that those files are held in the EU. Spelled out that the IP, time and rough location of an email signup are kept as proof of consent.
  • →2026-09-21 · section 04 now says what happens when you leave Stripe's payment page without paying: Stripe passes on the email and the cart, and nothing is done with them. For part of this day the cart had a keep me posted box that added the address to the mailing list and allowed one reminder; it was removed the same day, no reminder was ever sent, and anyone who ticked it stays on the list until they unsubscribe. The same section now covers paying before you have an account: the purchase is filed under the email you give at checkout.
  • →2026-09-15 · rewrote section 07 now that devices and the desktop app exist: both check this site for updates, and the app's update download is tied to your account. Added Resend (purchase emails) and Mailgun (the support inbox) as vendors, explained what Geniuslink and Amazon see when you click an affiliate link, listed build guide progress as data kept on your account, and removed a line in the introduction that said there were no analytics when section 03 describes the visitor statistics.
  • →2026-08-11 · added cookieless visitor statistics, run by Vercel, who already host the site. No new company receives anything, nothing is stored on your device, and no email address is attached to it. Also corrected the vendor count in tools_we_use from five to six — six were always listed.
// ask_a_human
Any question on this page, any data request, any concern about what I hold — write to the address on the right. I reply personally, usually within 48 hours.
support@theraccoonlab.com →