Privacy policy
Last updated 1 August 2026
Who this covers
This policy explains what BTD Soft collects when you browse the store, buy a licence as a guest, or create an account, and how that information is used.
Guest purchases
Buying as a guest requires only your full name and email address. We use these to process your order, deliver your activation key, and provide support if you contact us about that order. A guest purchase does not create an account.
Optional customer accounts
Creating an account is always your choice. If you create one, we additionally store your password as a one-way cryptographic hash — we cannot read or recover your actual password, and we never store it as plain text. Signing in lets you view your order history and activation keys without needing a new secure link each time.
Order records
Each order we process stores the products purchased, the quantity, the price paid, the payment status, and the activation key(s) assigned to that order. Keys are stored encrypted; a masked version is shown by default, and a key is only decrypted and displayed to you after you explicitly choose to reveal or copy it.
Payment processing
Payment is handled entirely by PayPal. We never see or store your card number, PayPal password, or other funding details. We receive confirmation of payment and a PayPal order/capture reference, which we use to match the payment to your order.
Transactional email
Order confirmations, activation keys, account verification and password-reset messages are sent through Zoho Mail, our transactional email provider. These emails are sent only for actions you take — placing an order, creating an account, or requesting a password reset.
Cookies and sessions
We use one essential session cookie to keep your cart contents while you browse, and to keep you signed in if you have an account. This cookie is required for the store to function and is not used for advertising or cross-site tracking. We do not run analytics or advertising trackers on this site.
Verification and reset tokens
Email verification and password-reset links use a single-use, time-limited token. We store only a cryptographic hash of the token, not the token itself, so a copy of our data cannot be used to reconstruct a working link. Each token expires automatically and stops working once used.
How long we keep data
We keep order and account records for as long as needed to provide support, honour the refund policy, and meet our accounting and tax obligations, after which they are deleted.
Your rights
You can ask us for a copy of the data we hold about you, ask us to correct it, or ask us to delete your account and associated personal data, by writing to our contact form. We may need to keep order records required for tax or accounting purposes even after an account is deleted.
Contact
Questions about this policy can be sent to our contact form.