PRIVACY POLICY

Privacy policy

This policy explains in plain language how MacDeer handles personal data related to the site, accounts, orders, support, and security.

Last updated: August 15, 2026https://macdeer.com

1. Controller and contact details

MacDeer / BearNext is the controller of personal data collected directly through the MacDeer website and products. MacDeer is the public brand and BearNext is the operating name. Submit privacy questions, rights requests, and legal notices through the public contact form.

To protect an independent developer’s residential privacy, no private home address is published. If law requires a postal or service address, request an effective service method through the privacy contact above. Transaction records also display applicable Paddle merchant details.

2. Data we collect

  • Account data: name or display name, email, avatar, verification status, and identity-provider identifiers;
  • Authentication and security: irreversible password hashes, session identifiers, IP address, device or browser information, and security audit records;
  • Transactions and fulfillment: Paddle customer and transaction IDs, products, totals, currency, tax snapshots, orders, refunds, subscriptions, and entitlement status;
  • Support communications: questions, attachment descriptions, replies, and resolution history;
  • Technical data: request times, error logs, download records, and limited operational data needed to prevent abuse.

Paddle independently collects and processes full card numbers, security codes, and complete payment credentials; they do not enter the MacDeer database.

3. Purposes and legal bases

Contract
Create accounts, complete digital delivery, display orders, manage downloads, and provide support.
Legitimate interests
Protect accounts and services, prevent fraud, troubleshoot, retain audit records, and improve products while balancing those interests against your rights.
Legal obligations
Keep necessary tax, accounting, refund, sanctions, and compliance records and respond to valid legal requests.
Consent
Only where required for optional marketing, non-essential cookies, or other revocable processing. MacDeer currently sends no marketing email.

4. Sharing and processors

We do not sell personal data. Necessary data may be shared with:

  • Paddle: Merchant of Record and independent controller for sales, payments, tax, invoices, refunds, and subscription management;
  • Cloudflare: Workers, D1, R2, DNS, security, network delivery, and essential transactional email;
  • Google: OAuth authentication only when you choose Google sign-in;
  • Professional advisers, auditors, insurers, or public authorities only where law or protection of rights and safety requires it.

Paddle’s processing is governed by its privacy policy.

5. Cookies and local storage

MacDeer uses cookies necessary for sign-in, security verification, language preference, and checkout. Google sign-in and Paddle Checkout may set cookies required to provide their services. We currently use no advertising cookies and do not sell or share cross-site behavioral profiles. If analytics or marketing cookies are introduced, applicable regions will receive a clear choice and preference controls first.

6. Retention

  • Account and entitlement data: while the account is active and for a reasonable period needed to complete deletion;
  • Order, refund, and tax records: for applicable accounting, tax, and dispute periods, generally no longer than seven years;
  • Security and download audits: generally 12 months, longer when fraud, disputes, or legal duties require it;
  • Email-verification and reset tokens: invalidated on expiry or use and deleted on the system cleanup schedule;
  • Support records: generally no longer than 24 months after resolution.

Data no longer needed is deleted or irreversibly anonymized, though backups may remain for a limited rotation period.

7. International transfers

Cloudflare, Paddle, and Google operate in multiple countries, so data may be processed outside your location. Providers protect transfers under applicable mechanisms such as adequacy decisions, standard contractual clauses, or equivalent safeguards.

8. Your rights

Depending on local law, you may have rights to access, correct, delete, restrict, obtain a portable copy, object to legitimate-interest processing, withdraw consent, and complain to a data-protection authority. Submit requests through the contact form. We may reasonably verify identity and generally reply within one month, subject to lawful extensions with explanation.

You can also view orders and entitlements in your account. Deleting an account does not automatically erase financial, security, or anti-fraud records that law requires us to retain.

9. Security and children

We use transport encryption, access controls, key management, signed webhooks, session protection, least privilege, and security auditing. No system is absolutely secure; we will give legally required notice of a significant incident that may affect you.

The service is not directed to children below the digital age of consent where they live, and we do not knowingly collect their data. A guardian who believes a child supplied data should contact us.

10. Policy changes

Updates are published here with a revised “Last updated” date. Changes with a material effect on processing may also be announced through the site or account email where reasonable.