
THE RACCOON LABThe Raccoon Lab AB is a one-person operation — one workshop, one email list, one shop, based in Sweden. This page describes in plain words what data is actually kept, why, on what legal basis, how long for, and how to get rid of it. There's no analytics, no advertising network and no tracking beyond what's needed to run an account and take a payment.
Only what's needed to run an account, deliver a file, take a payment, and send the list. Nothing is collected for advertising.
Card details are never collected by me at all — see section 04.
Every piece of data maps to one reason and one lawful basis. If a reason disappears, the data does too.
There is no profiling and no automated decision-making that produces legal effects for you.
A short, named list. If a vendor is on it, your data is on their servers — I'd rather tell you than dress it up. Each acts as a processor on my behalf under a data processing agreement.
That's the whole list. No advertising network, no data broker, and nothing is ever sold or shared for marketing. When the list changes, this page changes.
Visitor statistics. I count page views to know which pages people actually read and whether the site works — how many opened a page, from which country, and how many got as far as entering an email address. It runs on Vercel, who already host the site, so no new company receives anything.
It is cookieless and has no profile of you in it. Nothing is stored on your device, you are not given an identifier that follows you between visits or between sites, and I cannot see what any individual person did. Your email address is never attached to it — when you sign up to the list, what gets counted is that a signup happened and which form it came from, never who. That is why there is no cookie banner: there is nothing here to consent to.
Checkout happens on Stripe's own pages. Your card number, expiry and security code go straight to them and never pass through a Raccoon Lab server. I couldn't see or store them if I wanted to.
What comes back to me is the minimum needed to give you your files and keep lawful records: that a payment succeeded, the amount, your email, and the location Stripe used to work out VAT.
Stripe is an independent controller for its own fraud-prevention and regulatory purposes. Their handling of your data is governed by Stripe's privacy policy.
Some of the vendors above are based in, or process data in, the United States. That means your data may be transferred outside the EU/EEA.
The build files themselves are stored in the EU — the Cloudflare bucket they live in is pinned to a Western European region, so buying and downloading doesn't move your files or your download record out of Europe.
Where that happens, the transfer relies on the safeguards the law requires — the European Commission's Standard Contractual Clauses, or an adequacy decision such as the EU–US Data Privacy Framework where the vendor is certified under it.
I don't transfer your data anywhere else, and I don't sell or share it with anyone for their own purposes.
No devices have dropped yet. This section describes how they are designed to work.
Every device comes with a PDF guide. During setup you enter your WiFi credentials and it connects to your local network — your Home Assistant or MQTT broker. That's the only network it ever talks to. There is no Lab account, no cloud backend, no telemetry endpoint. I have no way to receive anything the devices send, and I'm not building one.
When firmware updates are available, I'll send them by email. You decide whether to apply them. The same principle holds there.
Standard EU rules. Email me and I'll handle any of these within 30 days — usually the same week, because there's one person reading the inbox. Exercising them is free and I won't treat you differently for it.
Ask for a copy of everything I hold linked to your email.
Correct anything inaccurate or incomplete.
Ask me to delete your information — except records tax law requires me to keep.
Get your data in a portable format, or have it sent to another provider.
Restrict how I use your data while a dispute or correction is sorted out.
Object to anything I do on the basis of legitimate interests.
Where I rely on consent — the email list — you can withdraw it at any time using the unsubscribe link in any email, or by writing to me. Withdrawing doesn't affect anything done before you withdrew.
You also have the right to complain to the Swedish supervisory authority, IMY (Integritetsskyddsmyndigheten), at imy.se — or to the authority where you live.
Only cookies that are strictly necessary to make the site work — which is why there's no cookie banner asking your permission. Consent is only required for the non-essential kind, and there aren't any.
No analytics cookies, no advertising cookies, no third-party tracking pixels. The visitor statistics described in tools_we_use are counted without cookies and without storing anything on your device, which is exactly why they need no banner.
This shop isn't aimed at children and accounts aren't knowingly created for them. If you're under 18, ask a parent or guardian to buy for you.
If you're a parent or guardian and think a child has given me their information, email me and I'll delete it.
Any changes are logged below with a date. If a change meaningfully affects your data, you'll get an email.
2026-08-11 · added cookieless visitor statistics, run by Vercel, who already host the site. No new company receives anything, nothing is stored on your device, and no email address is attached to it. Also corrected the vendor count in tools_we_use from five to six — six were always listed.