Ligo Post
Privacy Policy
1. Controller and contact
Ligo Post is an independent software development project created and operated by its founders. For the purposes of the General Data Protection Regulation (GDPR) and applicable data protection legislation, the data controllers are the founders of Ligo Post. For any questions, data requests, or to exercise your statutory rights, contact us directly at info@ligopost.com.
2. Data we process
- Account data: name, email address, unique account identifier (UID), authentication provider (such as email/password or Google Sign-In), and email verification status.
- Trial and entitlement data: software access tiers, license and trial status, and, where a trial requires anti-abuse verification, verified phone number records.
- Device and licensing session data: a randomly generated device identifier (UUID), operating system/platform label, and session heartbeat timestamps to ensure compliance with the maximum allowed active installations per license. We do not inspect, log, or store hardware serial numbers, MAC addresses, or personal system files.
- Download-request data: account identifier, platform, requested software version, file name, timestamp, and signed download link expiration. We do not store IP addresses in this download log.
- Service and project data: sequence, cue sheet, VFX changelist, or project metadata that you voluntarily choose to import or store through enabled cloud workspace features. The software does not transmit your underlying media files or editorial video/audio assets to third parties.
- Billing and transaction data: when paid subscriptions or licenses are active, we process purchase records, subscription identifiers, currency, and referral attribution codes. Payment card information is handled directly and securely by Stripe; Ligo Post does not collect or store credit card numbers or CVC codes.
- Beta application and support communications: details you provide in beta request forms (such as your name, role, email, and workflow notes) or feedback and support messages.
- Marketing preferences: when you explicitly opt in to receive product updates and release announcements, we record your consent choice, its version, source, and timestamp. We manage these communications through Mailchimp.
3. Why we use data and legal basis
We process your data for the following purposes and legal bases:
- Performance of a contract / requested service: creating and maintaining your account, authenticating access, managing trial and paid license entitlements, issuing signed installer downloads, and operating cloud workspace features.
- Legitimate interests: service security, license enforcement (seat limits), preventing trial abuse, investigating technical faults, and improving software stability.
- Consent: sending optional marketing communications and product newsletters, which you can withdraw at any time.
- Legal compliance: retaining transaction and billing records as required by applicable tax, commercial, and accounting regulations.
4. Service providers (Processors)
We work with trusted third-party service providers to deliver our services:
- Google Cloud & Firebase: hosting, user authentication, cloud databases (Firestore), serverless functions, and secure installer storage.
- Google Sign-In & reCAPTCHA: optional federated authentication and automated abuse prevention during SMS verification.
- Stripe: secure payment processing, subscription management, and customer billing portal.
- Resend: transactional email delivery for critical account notifications, verification links, and invitations.
- Mailchimp: delivery of optional marketing emails and management of unsubscribe preferences.
- Cloudflare: content delivery, DNS, and edge security.
These service providers process data on our behalf under contractual data processing terms, or as independent controllers where required by law.
5. Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected:
- Active accounts: account profile and workspace data are retained while your account remains active. Upon verified account deletion, account records are purged from active databases (and cleared from secure system backups within 30 days).
- Billing records: transaction and tax records are retained for the statutory period mandated by applicable fiscal laws.
- Anti-abuse records: trial-verification records (such as verified phone and email identifiers) are retained to protect the service against repeated trial abuse.
- Download logs: installer access logs are retained for up to 90 days for technical auditing and security monitoring.
6. Cookies and local storage
Our public marketing website and account portal do not use third-party tracking or advertising cookies. We use strictly necessary local storage (such as browser localStorage and sessionStorage) exclusively to keep you signed in, preserve your interface preferences, and support authentication flows.
7. Sharing and international transfers
We do not sell, rent, or monetize your personal data. We disclose data only to our service providers as described above, when compelled by valid legal processes, or when necessary to protect our users or service integrity. Where providers process data outside the European Economic Area (EEA), appropriate data transfer safeguards (such as the EU-U.S. Data Privacy Framework or Standard Contractual Clauses) are applied.
8. Your rights
Under the GDPR and applicable privacy legislation, you have the right to:
- Access and request a copy of the personal data we hold about you.
- Rectify inaccurate or incomplete information.
- Request erasure of your account and personal data ("right to be forgotten").
- Restrict or object to specific processing activities.
- Data portability for data provided under contract or consent.
- Withdraw consent at any time (e.g. by using the unsubscribe link in any marketing email).
- Lodge a complaint with a supervisory authority (such as the Italian Garante per la protezione dei dati personali or your local data protection authority).
To exercise any of these rights, contact us at info@ligopost.com.
9. Security
We employ cryptographic authentication, encrypted transport (HTTPS/TLS), secure signed download tokens, and strict access controls to safeguard your data. While no system is invulnerable, we regularly review and update our safeguards to maintain high standards of security.
10. Changes to this policy
We may update this Privacy Policy from time to time to reflect operational or legal changes. Updates will be published on this page with a revised effective date. For significant changes, we will provide noticeable notice or request re-acknowledgement upon account login.