* LEGAL

Privacy policy

Last updated: 31 May 2026

1. Who we are

Retro Commander ("the app", "we", "us") is an independent software product operated by Jarno Beumer, based in the Netherlands. We are the data controller for the personal data described in this policy. For any privacy question or to exercise your rights, contact support@datucker.nl.

2. What data we collect

  • Account data - your email address and a securely hashed (never plaintext) password.
  • Licence & device data - your tier, licence expiry, and a per-device hardware fingerprint plus a device name you choose, used to enforce the per-tier device limit.
  • Usage statistics - aggregate counters such as session count, total usage minutes, and numbers of disk images opened/edited and files transferred. These are operational metrics, not the contents of your files.
  • Security data - a hashed (not raw) form of your IP address and failed-login counts, used to prevent brute-force attacks and licence abuse.
  • Purchase data - the tier purchased, amount paid, and the customer/transaction identifiers returned by our payment processor. We never see or store your full card details.

3. Why we process it & legal basis

  • To provide the service (account, licence, device activation) - performance of our contract with you.
  • To prevent fraud and abuse (device limits, rate-limiting, lockouts) - our legitimate interest in protecting the service.
  • To send essential service email (email confirmation, password reset, purchase receipts) - performance of our contract.
  • To improve the app via aggregate usage statistics - our legitimate interest, kept to the minimum needed.

4. Who we share it with (processors)

We use a small number of carefully chosen sub-processors. We do not sell your data and do not share it for advertising.

  • Creem (Armitage Labs OÜ, Estonia) - our Merchant of Record and payment processor. Creem handles checkout, tax and payment data under its own privacy policy.
  • Brevo - sends our transactional email (confirmations, receipts, resets).
  • Hetzner - hosts our licence server within the EU.

5. Payments

All purchases are processed by Creem acting as Merchant of Record. Creem is the seller of record for your transaction, handles VAT/tax, and processes card and billing data directly. We receive only the confirmation that a payment succeeded together with the tier and a transaction identifier. See our Terms of Service and Refund Policy.

6. Cookies & tracking

This website uses no advertising or cross-site tracking cookies. The app stores its session locally on your device (a signed licence lease and your sign-in tokens) so it can work offline; this never leaves your machine except to talk to our licence server.

7. How long we keep it

Account, licence and purchase records are kept for as long as your account exists and as required by law (e.g. tax records). Security logs and IP hashes are kept only as long as needed for abuse prevention. When you delete your account we erase your personal data except records we are legally required to retain.

8. Your rights (GDPR)

You have the right to access, correct, delete, export, restrict, or object to the processing of your personal data, and to withdraw consent where processing is based on it. To exercise any of these, email support@datucker.nl; we respond within 30 days. You also have the right to lodge a complaint with your local data protection authority (in the Netherlands: the Autoriteit Persoonsgegevens).

9. Changes to this policy

We may update this policy as the service evolves. Material changes will be reflected by the "last updated" date above and, where appropriate, announced in the app or by email.