Privacy policy
What data of yours we hold, what for, who it's shared with, and for how long. No textbook definitions — just what's there.
1. Who processes your data
SYNTHKEYS, as the store. If you want to talk to us about this, get in touch: the channels are in section 7, and for anything touching your data email comes first.
2. What we process
What we do NOT process: your card details. They never pass through our servers. Whop handles them.
- Your account: email, password (our authentication provider doesn't store it: it stores a hash, a digest the password can't be recovered from; never in the clear and never visible to us), display name if you set one, and the date you signed up.
- Your purchases: what you ordered, when, at what price, with which coupon, the delivery email, the status of each line, the payment identifier the gateway returns, and which version of the terms you accepted at confirmation.
- Your deliveries: delivered keys are stored — encrypted — against your order. If a line needed a link from you, that link.
- Your reveals: every time a key is revealed we store who, when, from which IP address, with which browser, and which version of the notice was accepted.
- Your preferences: language and currency, in a cookie and in your profile if you're signed in.
- The emails we send you: which address they go to, which notice it is, and when it went out. They wait in a send queue (the `email_outbox` table), which is what lets us retry a notice that didn't go out without sending you the same one twice. No key ever travels by email.
- Technical: server logs with IP address, timestamp and what was requested, generated automatically by running the site.
3. What we use it for
We don't sell your data. We don't hand it to anyone to advertise to you.
- To sell and deliver what you buy: without an email and an order there's no delivery.
- To help you when something goes wrong, which is why we keep the history.
- To settle disputes and chargebacks. The reveal log exists for that and nothing else: it's the proof that a key was shown, when, and to whom.
- To prevent fraud and abuse: purchases with someone else's card, resale, attempts to get around limits.
- To meet our accounting and tax obligations, which require us to keep a record of transactions.
- To show you the store in your language and your currency.
4. Who it's shared with
Each of these processes your data to provide us their service and nothing else.
- Supabase: provides our database and authentication. Your account, your orders and the logs described above live there.
- Whop: processes payments. Receives what's needed to charge and to refund. Your card details are theirs, not ours.
- Resend: sends our transactional email. It receives your address and the contents of the notice, never your keys.
- Cloudflare: DNS, site protection, and forwarding for @synthkeys.shop email.
- Code suppliers: when a key is ordered on demand, we send the minimum needed to fulfil the order. We don't send them your email or account details unless the product requires it — and in that case the product page says so before you buy.
- Our infrastructure: the server the site runs on and its technical logs.
- And anyone who requires it under a valid legal obligation.
5. Where it lives
On our providers' servers, which may be in another country. Wherever you buy from, your data is processed where those providers operate.
6. How long we keep it
When a piece of data stops being needed, it's deleted or unlinked from you. The detail is in the Data deletion policy.
- Your account and preferences: as long as the account exists.
- Orders, charges and reveal logs: for as long as accounting obligations require and for as long as we need to defend ourselves in a dispute. They're the proof of what was sold, to whom and when, so they aren't deleted along with an account.
- The IP address and browser held inside each reveal log: 180 days. That comfortably covers the window in which a chargeback can appear; after it they're deleted and the log keeps the fact without the technical trail.
- Emails already sent: 90 days in the send queue, then deleted. What's there is your address and the text of the notice.
- Technical server logs: rotated by the infrastructure itself. We don't cross them with your account except to diagnose a failure or detect abuse.
7. Your rights
You can ask us for access to what we hold about you, to correct what's wrong, to delete what can be deleted, to restrict a specific use, to object to processing, or to give you a copy in a portable format.
Requests go by email to support@synthkeys.shop, or on Telegram. We verify it's you before doing anything: handing an account's data to someone who isn't its owner would be exactly the problem these rights exist to prevent.
There are things we won't be able to delete, and that isn't an excuse: a payment record and a reveal record are evidence in a dispute and an accounting obligation. They're listed in the Data deletion policy.
If there's a data protection authority where you live, you can take it to them.
8. Cookies
We use only what the store needs to work: your session, your language, your currency and your cart. We have no advertising cookies and no third-party cookies following you around other sites.
9. Security
Access to data is restricted at the database level: each customer can only read their own, and that's enforced by the engine, not by a check in the code.
The keys we sell are stored encrypted, and can't be read directly — not even with your own session. They come out only through the reveal operation, which logs them.
No system is infallible. If something happens that affects you, we'll say so.
10. Minors
The store isn't directed at anyone under the minimum age to enter into a contract where they live. If we learn an account belongs to a minor without the appropriate authorisation, we close it.
11. Changes
This policy has a version and a date. If anything substantive changes, it's published here with a new date.
Version 2026-09-13 · Last updated: 13 September 2026