Privacy Policy

Last updated: September 13, 2026

This Privacy Policy describes how PluginMaker (pluginmaker.ai) collects, uses, and protects your personal information.

1. Information We Collect

Account Information

When you create an account, we collect your email address, name, and profile picture (if you sign in with Google).

Plugin Data

We store the plugins you create, including DSP code, UI blueprints, presets, and generated screenshots. This data is associated with your account.

Payment Information

Payment processing is handled by Stripe. We do not store credit card numbers or bank account details. When you use the marketplace, Stripe processes and stores payment data according to their Privacy Policy.

Marketplace Data

If you sell plugins, we store your seller profile (display name, bio) and transaction history (sales, earnings). If you buy plugins, we store your purchase history.

Shopify Fulfillment Data

For fulfillment and licensing carried out on a merchant’s instructions, we process buyer data on that merchant’s behalf. The merchant determines the purposes and applicable lawful basis for that processing. Authorizing a Shopify connection does not constitute the buyer’s consent to unrelated uses of their information.

For verified reduced-payload connections, we configure Shopify to send us the buyer email, Shopify order reference and update time, and line-item product identifiers from a paid order. We use those fields to match products the merchant mapped, issue the purchased plugin entitlement, prevent duplicate grants, and support fulfillment. We do not request the buyer’s name, phone number, or address.

Until staff activate and verify reduced settings, a connection uses the existing payload with payment status and additional line-item details. We use only the fields needed for fulfillment and do not retain those additional details. Product identifiers from other items in a mixed order may also reach our signed webhook while we perform the mapping. We discard unrelated identifiers in the same processing pass; they are not stored or displayed.

New deliveries are not stored as Shopify order bodies. Order bodies retained by earlier delivery handling require staff review and approved cleanup; there is no automatic expiry for those older bodies.

For an issued entitlement, we retain the normalized buyer email, Shopify order reference, and granted PluginMaker plugin identifiers so the buyer can keep access and we can support fulfillment. We also retain limited delivery audit data, such as a delivery identifier, outcome, and counts, to prevent duplicate grants and diagnose delivery problems.

Shopify also sends privacy-request and uninstall notifications. To handle them, we retain the request identifier, shop and installation reference, relevant customer email or identifier, specified order references, and the request’s status and deadlines. These notifications can contain additional customer or shop details; we do not retain their raw bodies or unnecessary fields such as a phone number. Privacy-request records are separate from paid-order deliveries.

Usage Data

We collect usage data including page views, feature usage, and error reports to improve the platform. When you are logged in, this data is linked to your account. We use PostHog for analytics.

We also use Sentry for website error and performance monitoring. This can include error messages, stack traces, browser and request metadata and sampled performance data. Website Sentry monitoring is configured independently of the analytics-cookie choice and the separate installer diagnostic consent described below.

Our servers also keep a standard request log for security, abuse prevention and troubleshooting: the time, requested path and response status of each request, the network IP address it came from, the browser or plugin user-agent string, and your account identifier when the request was signed in (including white-label plugin activations). This log is retained for 30 days and processed under our legitimate interest in keeping the service secure and working (GDPR Article 6(1)(f)). It is never used for advertising or profiling.

Installer and Native Plugin Diagnostics (Opt-In, Default Off)

A PluginMaker-branded installer, or a white-label installer powered byPluginMaker, and every plugin you install through it can optionally send diagnostic data from your machine to help us identify crashes and installer failures. PluginMaker determines the purposes and fields, receives the data, and is the data controller for this diagnostic service. The customer brand does not receive this diagnostic data. This data is not described as anonymous because a native crash report can contain technical details that may be personal data. This is off by default. The first time you open the installer, you are shown a consent dialog with two buttons (“Share crash + diagnostic data” or “No thanks”). No data is transmitted until you click one. Your choice applies to that branded installer and the plugins installed through it — one decision, one record, no per-plugin re-prompting. This consent is separate from any other consent on the pluginmaker.ai website and from a decision made in another branded installer.

When enabled, we may collect:

  • Installer event name, success or failure, duration, installer version, operating system, CPU architecture, and a plugin identifier where needed to diagnose an installation
  • For a failed Windows install or uninstall: failure category, random diagnostic ID, Windows error codes, retry count, lock-owner count, and the executable and application names (basenames only) of processes holding the affected plugin file
  • For native plugin crashes: event time, plugin ID/type/version and brand, host-process or DAW name, OS/build, CPU architecture and device model, exception information, register values, thread names, stack frames, module basenames, and debug identifiers used for symbolication
  • On Windows, the raw native minidump required for symbolication. A minidump can contain process/module details and module file paths; those paths may contain an operating-system account-folder name.

We do not intentionally collect through this diagnostic feature:

  • Audio buffers, MIDI streams, or any sample content
  • Project content or preset names you have typed
  • License keys, payment data, authentication tokens, command lines, MAC addresses, disk serials, or machine UUIDs
  • Account IDs, operating-system usernames/hostnames, full file paths, or process IDs in installer diagnostic events. The client removes these fields and redacts paths, email addresses, IP literals, and token-like values before sending those events.

Our infrastructure and diagnostic providers necessarily process the network IP address used to deliver and protect a request. We do not add it to the installer diagnostic payload or use it as an installer identifier. As explained above, native Windows crash data can still contain module paths with an account-folder name.

Lawful basis: your explicit consent under GDPR Article 6(1)(a) and the ePrivacy Directive Article 5(3). You can revoke this consent at any time from the installer’s Settings panel (toggle “Share crash + diagnostic data”), or by deleting its telemetry_consent.json file. The flagship installer stores that file in the PluginMaker user-data folder (%APPDATA%\PluginMaker\ on Windows, ~/Library/Application Support/PluginMaker/ on macOS). A white-label installer uses the same locations under its own displayed product name. Revocation takes effect immediately in the installer; plugins already running pick it up on next launch.

Structured installer diagnostic logs are retained for 30 days. Native crash events are stored by Sentry (Functional Software, Inc.) in its EU region for the retention period configured for our project, no longer than 90 days. Aggregated operational counters may be retained longer when they no longer contain event-level diagnostic details.

2. How We Use Your Information

  • To provide and maintain the platform
  • To process marketplace transactions
  • To send important account notifications
  • To improve the platform based on usage patterns
  • To prevent fraud and abuse

3. Data Sharing

We share your data with the following third-party services. Some of these services are based in the US, which means your data may be transferred outside the EU/EEA.

  • Google (US) — authentication via Google Sign-In. Receives your email, name, and profile picture when you log in with Google
  • Stripe (US) — payment processing and seller payouts. Receives your name, email, and payment information
  • Anthropic / OpenAI (US) — your plugin descriptions and prompts are sent to AI providers for generation
  • Cloudflare R2 (US) — stores plugin files and assets linked to your account
  • PostHog (EU) — analytics. Collects usage data linked to your account when you are logged in. Only active if you accept analytics cookies
  • Langfuse (EU) — observability. Logs AI generation requests and responses to monitor and improve the platform
  • Functional Software, Inc. (Sentry) (US provider; installer/native event storage in Germany, EU) — website error and performance monitoring, plus installer and native plugin crash diagnostics. Installer and native reporting requires your diagnostic opt-in. Native Windows minidumps can include module paths and process details; installer events are redacted and bounded before transmission
  • Vercel (US provider, global delivery network) — hosts the production website and forwards web authentication requests to our backend. Processes network/request metadata and authentication data in transit, including the credentials, codes and tokens used by the relevant sign-up or sign-in flow
  • Slack (Salesforce) (international processing, including the US) — internal notifications and support coordination. New Shopify sale alerts use brand/operator labels, plugin names and buyer counts without buyer emails or Shopify order references. Older alerts contained buyer emails and order references and may remain in message history; relevant support messages and historical copies are included in deletion-request handling
  • Hetzner / OVH (Germany/EU) — server infrastructure hosting the backend, database, monitoring services, and structured installer diagnostic logs
  • Neon — managed database hosting for account, plugin and licensing data. Our production database is hosted in Frankfurt, Germany (EU)

We do not sell your personal data to third parties. Marketplace seller display names are publicly visible on plugin listings.

Shopify is selected and operated by the connected merchant. Shopify sends paid-order data to our backend; the infrastructure and database providers listed above process it only as needed to operate the fulfillment service. Connected merchants can also review the current sub-processor information.

4. Data Retention

We retain your account data and plugins as long as your account is active. You can request deletion of your account and associated data at any time by contacting us.

Shopify purchase records are retained while needed to provide the merchant’s ongoing licensing and support service, or for a specific legal retention requirement. Delivery audit records support duplicate prevention and troubleshooting. They do not currently have an automatic age-based expiry; they are included in privacy-request and service-termination review. Approved store redaction removes delivery history.

Disconnecting a Shopify store stops future order processing but does not revoke entitlements already issued. Shopify deletion requests await staff review and explicit administrator confirmation before database erasure. Approved customer redaction removes purchase records for the specific orders listed in that request, preserving other purchases. Approved store redaction removes the uninstalled connection, mappings and delivery history; it cannot delete a newer reconnection. Staff separately review account records, issued licenses and any required retention.

Shopify privacy requests are recorded before acknowledgement and placed in a staff queue. Receiving a request or retrying a background job does not authorize deletion. We retain limited encrypted verification details while related customer records or open requests need them, so later Shopify privacy requests can still be authenticated after disconnection. We track Shopify’s 30-day completion deadline and clear the scoped customer identifiers from the request record after completion. Access requests require secure delivery to the merchant. Completion includes review of queues, logs, Slack, subprocessors and backups under the retention policy.

After Shopify reports an uninstall, fulfillment stops and the disconnected configuration, including the encrypted token revoked by Shopify, remains until approved cleanup. A completed disconnect initiated in our application clears that token immediately.

We keep a keyed, pseudonymous reference for erased Shopify orders while the brand exists to prevent late deliveries from granting access again. Questions about access or deletion can be sent to the contact address below.

Backups and retained database copies may contain earlier versions of records removed from the active database. Some retained copies have no automatic expiry. Our procedure requires review of whether they are still needed. Staff handle these copies manually when addressing a valid deletion request, recording the action and completion deadline for each relevant copy. Some snapshots cannot be edited one record at a time and require controlled replacement or deletion of the whole snapshot. Where immediate erasure is not possible, any temporary retention must have a recorded justification and deletion deadline consistent with applicable law and our agreement with the merchant; the affected data is kept out of use until then. We explain any remaining retention to the authorized requester. Our recovery procedure requires approved deletions to be reapplied before a restored system resumes service.

5. Your Rights (GDPR)

If you are in the EU/EEA, you have the right to:

  • Access your personal data
  • Correct inaccurate data
  • Request deletion of your data
  • Export your data in a portable format
  • Object to processing of your data
  • Withdraw consent at any time

To exercise these rights, contact us at dominik@pluginmaker.ai.

6. Cookies

We use essential cookies for authentication and session management. We use PostHog for analytics which may set tracking cookies. Stripe may set cookies during the checkout process.

7. Security

We use industry-standard security measures including HTTPS, encrypted database connections, and secure authentication. However, no system is 100% secure.

8. Children

PluginMaker is not intended for children under 18. We do not knowingly collect data from minors.

9. Changes

We may update this Privacy Policy from time to time. We will notify you of material changes via email or a notice on the platform.

10. Contact

Email: dominik@pluginmaker.ai / maks@pluginmaker.ai