Privacy Policy

Last updated: 11 August 2026.

This policy explains what data AssetYard collects, why, and what you can do about it.

The data controller is AssetYard Creative LTD (company no. 17373395), 167-169 Great Portland Street, 5th Floor, London W1W 5PF, United Kingdom.

We have not appointed a data protection officer, and none is required for the processing described here. We have not appointed a representative in the EU or the UK.

1. What we collect

When you buy something. Your name, email address, and billing address — country, street, city, and postcode — along with the details of what you ordered. You can check out as a guest; an account is not required.

Payment details. We do not see or store your full card number. Payments are processed by Stripe, who handle card data directly on their own systems. We receive only the result of the transaction and the last digits of the card.

When you create an account. Your email address, and the order history attached to it.

When you contact support. Whatever you put in your message, and your email address.

Automatically. IP address, browser and device information, pages visited, and referring site.

2. Why we use it

  • To deliver your files and give you access to re-download them
  • To handle refunds, licensing questions, and support requests
  • To detect and prevent fraudulent orders
  • To meet our tax and accounting obligations
  • To understand how the site is used, so we can improve it

3. Legal basis

Owner input needed if selling into the EU/UK, state the GDPR basis for each purpose above — contract for delivery, legal obligation for tax records, legitimate interests for fraud prevention, consent for analytics. This should be reviewed by a lawyer.

4. Analytics and third-party services

We run no analytics. There is no Google Analytics, no advertising pixel, no session recording, and no third-party tracking script anywhere on this site. Nothing here builds a profile of you or follows you to other sites.

The services that do handle your data are these, and no others:

  • Stripe — payment processing. Receives your card details, billing address, and the amount, directly from the checkout form. We never see the full card number.
  • WooCommerce — the store software itself: your order, your account, your downloads.
  • WP Mail SMTP — sends your order confirmation and your download links through our hosting provider's own mail server. No separate email company handles your messages, and your address is not passed to a marketing platform.

5. Cookies

The site sets only the cookies the store needs to keep your cart and your login working. They are strictly necessary: without them checkout cannot complete.

We set no analytics or advertising cookies. That is why you see no consent banner — there is nothing optional to consent to, and nothing for you to refuse.

6. Who we share data with

We do not sell your data. We share it only with:

  • Stripe, to take payment
  • Namecheap, our hosting provider, which stores the site and its database and sends our email
  • Tax authorities and professional advisers, where we are required to

Both are United States companies, and the site is hosted on servers in the United States. Your data therefore leaves the United Kingdom when you buy from us.

Owner input needed the safeguard relied on for that transfer — a lawyer's determination.

7. How long we keep it

Order records: six years from the end of the accounting period they fall in. UK tax law requires us to keep them that long, so we cannot delete them sooner on request.

Account data: for as long as your account exists.

Support emails: six years, the same period as the order records they usually relate to.

Analytics data: none. We do not run analytics, so there is nothing to keep.

8. Your rights

Under UK GDPR you can ask us for a copy of the data we hold about you, have it corrected, have it deleted, restrict how we use it, receive it in a portable form, or object to processing we base on legitimate interests.

We answer within one month, which is the deadline the regulation sets. If a request is complex enough to need longer, we will tell you inside that month and explain why.

Deletion has one limit: the order records above, which tax law obliges us to keep.

Requests go to privacy@assetyard.io.

9. Security

Access to customer data is limited to the people who need it to run the store. The site is served over HTTPS. The files you buy are stored outside the web root and served only through a signed link tied to your order, so they cannot be reached by guessing a URL.

Card details never reach our systems: Stripe collects them directly.

Backups are kept for 30 days. If you ask us to delete a record, it goes from the live site straight away and from the backups within 30 days, after which no copy remains.

10. Children

The site is not intended for children and we do not knowingly collect data from them.

11. Changes

We may update this policy. The "last updated" date above shows when it last changed.

12. Contact

privacy@assetyard.io for anything in this policy. For orders, refunds, and files, write to support@assetyard.io — see Support.