Privacy Policy
A plain-language overview of what we collect, why we collect it, how long we keep it, and the rights you have — across the WAVFin Audio website and the Dev Portal.
Last updated — July 6, 2026
This Privacy Policy explains how WAVFin Audio (“we,” “our,” “us,” or the “controller”) collects, uses, retains, discloses, and protects personal information when you visit this website, manage your dev portal account settings, sign in to the WAVFin Audio dev portal, submit a support or privacy request, send us email, or purchase or download our software products.
This policy is written to satisfy the EU/UK General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”), the California Consumer Privacy Act as amended by the California Privacy Rights Act (Cal. Civ. Code § 1798.100et seq., “CCPA/CPRA”), the U.S. Children’s Online Privacy Protection Act (15 U.S.C. §§ 6501–6506; 16 C.F.R. Part 312, “COPPA”), and similar U.S. state and international laws. It is also written to be readable. Where this policy and a law conflict, the law controls. This page is not legal advice; consult a privacy attorney for binding guidance on your situation.
1. Who We Are (Controller & Contact)
WAVFin Audio is operated by an independent developer based in Waterville, Maine, United States. We are the data controller for the personal information described in this policy. You can reach us at:
- Email: support@wavfinaudio.com
- Waterville, Maine, USA (full street address on request).
We have not appointed a formal Data Protection Officer because we do not perform large-scale, systematic monitoring of individuals, nor do we process sensitive data on a large scale. For the purposes of GDPR Art. 27, we are not required to appoint an EU representative given the limited nature of our processing; if that changes we will update this section.
Scope: This policy covers the WAVFin Audio website and the dev portal (including signed-in account settings and optional multi-factor authentication). Standalone products such as the DailyDock Chrome extension have their own privacy policy.
2. Information We Collect, Why, and How Long We Keep It
We collect the minimum necessary to operate the site, respond to you, and deliver the products you choose. For each category below, GDPR Art. 6(1) requires us to state our lawful basis; California law requires us to disclose the categories of personal information collected. Both are listed together.
| Data | Purpose | Lawful basis (GDPR) | CCPA category | Retention |
|---|---|---|---|---|
| Cookie / consent preferences | Remember your cookie choices on this device; sync to your account if you sign in. | Consent (Art. 6(1)(a)) | Inferences (preferences) | Until you change them or 12 months of inactivity |
| Dev portal account data | Identify you, authenticate you, apply permissions, and store optional TOTP MFA enrollment. | Contract (Art. 6(1)(b)) | Identifiers (email, UID) | Life of the account, then 30 days for delete-confirmation and audits |
| Session cookie | Keep you signed in to the dev portal. | Contract (Art. 6(1)(b)) | Identifiers | Expires on sign-out or after the configured idle limit |
| Support requests (form or email) | Email address, message, optional screenshot, request category. | Consent (Art. 6(1)(a)) for the message; legitimate interest (Art. 6(1)(f)) to respond | Identifiers; contents of communication; audio/visual (screenshot) | Up to 2 years from submission |
| Admin ticket records (replies, status, deletions) | Track, reply to, and resolve support requests captured by the form. | Legitimate interest (Art. 6(1)(f)) | Identifiers; communication contents | Resolved tickets archived for 1 year after closure |
| Ko-fi transaction & license records | Purchase email, address, transaction ID, message, amount, product codes; used to fulfill WAVFin/JUCE plugin licenses and donations. | Contract (Art. 6(1)(b)) | Identifiers; commercial information | 7 years for tax and consumer recordkeeping |
| Privacy rights requests (form or email) | Email address, request type, description, verification status, and admin replies when you exercise GDPR/CCPA rights. | Consent (Art. 6(1)(a)) for the submission; legitimate interest (Art. 6(1)(f)) to verify identity and fulfill the request | Identifiers; contents of communication | Until fulfilled or closed, then up to 3 years for dispute resolution |
| Privacy audit log (network identifiers, browser info, action, timestamps) | Document privacy rights actions we take (for example, export, erasure, or restriction) and investigate misuse of the privacy request process. | Legal obligation (Art. 6(1)(c)) / legitimate interest (Art. 6(1)(f)) | Identifiers; internet activity | Not auto-purged — retained for regulator audits (GDPR Art. 17(3)(b)) |
| Security incident records (IP, browser info, access metadata, timestamp) | Detect, investigate, document, and respond to unauthorized access or abuse directed at non-public areas of the site. | Legitimate interest (Art. 6(1)(f)) | Identifiers; internet activity | 90 days from the event, then auto-purged |
| Optional coarse geolocation (third-party lookup) | Approximate country, region, or city during security incident review only when this optional feature is enabled. | Legitimate interest (Art. 6(1)(f)) | Geolocation (coarse; never precise GPS) | Same as security incident records: 90 days |
We do not knowingly collect special categories of data under GDPR Art. 9 (race, religion, health, sexual orientation, biometrics, etc.), and we do not collect precise geolocation, government identifiers, financial account numbers, or genetic data. When we investigate possible abuse of non-public areas, we may record connection and access information needed to understand what happened. Those records are typically kept for up to 90 days and then deleted, unless a longer period is required to resolve an active matter or comply with law.
Whether providing the data is required: an email address is contractually required to open a dev portal account, to deliver a license to paid software, or to reply to a support request. Everything else is optional.
3. How We Use Your Information
- Provide, operate, and maintain this website and dev portal.
- Remember your cookie and consent preferences.
- Authenticate authorized users and apply access controls.
- Reply to and resolve support requests.
- Fulfill paid and free software licenses (e.g., JUCE plugin deliveries).
- Send transactional email (license delivery, password reset, privacy-request verification) from
kory@wavfinaudio.comvia Google Workspace. - Send marketing or release-update emails only if you have opted in.
- Detect, investigate, and prevent abuse of non-public areas.
- Comply with applicable legal obligations (tax, consumer protection, security incident reporting).
4. Third-Party Services and International Data Transfers
We use the following trusted processors. Only the minimum data each feature needs is shared with them, and they are bound by their own privacy terms and (where applicable) data-processing agreements with us.
- Google Firebase / Google Cloud (hosting, authentication, database, file storage, and related security services). Google processes data on servers located in the United States. Data may also be processed in other regions depending on service configuration. See Firebase Privacy.
- Upstash — infrastructure used to detect and limit abusive traffic. US region.
- IP-API — optional, off-by-default coarse geolocation used only during security incident review when that feature is enabled. EU/US.
- Ko-fi — donation and shop-order processing. Ko-fi acts as an independent controller for the payment data; we receive only the webhook notification fields needed to fulfill your license or thank-you. See Ko-fi Privacy.
- Google Workspace / Gmail API — outbound transactional email (license delivery, password reset, privacy-request verification) sent from
kory@wavfinaudio.comon our behalf. Google processes recipient addresses and message content in the United States. See Google Privacy. - Google Fonts (Sora, Oxanium) — Next.js’
next/font/googleserves the font files and may transmit your IP address to Google as a technical necessity of self-hosting the bundled font files. We do not load any other Google tracking tags on this site.
Cross-border transfers.If you visit this site from the European Economic Area, the United Kingdom, or another jurisdiction with adequacy requirements, your personal data is processed on servers located in the United States. We rely on the EU–US Data Privacy Framework and the UK Extension for transfers from Google/Firebase, Google Workspace (Gmail), Upstash, and Ko-fi to the extent those providers are self-certified, and on Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) where the framework does not apply. Where IP-API returns data sourced in the EU, no personal identifier is shared beyond what the security incident lookup requires.
5. Cookies, Analytics, and Marketing
Necessary cookies and browser storage are used for core functionality: keeping you signed in to the dev portal and remembering your cookie preferences. These cannot be disabled.
Analytics and Marketingcategories are optional and off by default. We do not load non-essential third-party scripts (analytics, advertising pixels, social trackers) unless you opt in via the cookie consent dialog. If you deny or have not yet chosen, those services are not loaded. You can change your choices at any time by opening the cookie preferences dialog. The “Reject all” / “Decline all” button is presented with the same prominence as “Accept all,” in line with EDPB Guidelines 05/2020 on consent.
6. Data Security
We protect personal information with measures appropriate to the data we hold, including:
- Encrypting information in transit between your browser and our services
- Requiring sign-in for dev portal access and limiting administrative functions to authorized personnel
- Monitoring for activity that targets non-public areas of the site and responding when abuse is detected
- Using established hosting, authentication, and email providers that maintain their own security programs
- Keeping security investigation records only for a limited time (see Section 2)
No method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security. If we become aware of a security incident affecting your personal data, we will notify you and applicable regulators where required by GDPR Art. 33–34, U.S. state breach notification laws, or other applicable rules.
7. Automated Decision-Making (GDPR Art. 22)
We do not make decisions based solely on automated processing that produce legal or similarly significant effects on you (GDPR Art. 22). Automated checks on public submissions may temporarily delay or reject suspicious traffic. These controls do not make legal decisions about you; a human can review and correct mistaken blocks on request via support@wavfinaudio.com.
8. Children’s Privacy (COPPA & GDPR-K)
The WAVFin Audio website and dev portal are not directed to children under the age of 13 (COPPA) or under the age of consent in your jurisdiction (16 in most EU member states; 13 in the UK). We do not knowingly collect personal information from children. If you believe we have collected information from a child in error, contact support@wavfinaudio.com and we will delete the information within a reasonable time. Accounts in the dev portal are provisioned only by an administrator and are not open to public registration.
9. Your Privacy Choices & Rights
Regardless of where you live, you can exercise the rights listed below using our structured intake form or by emailing us. We will respond within 30 days for GDPR/UK requests and within 45 days for CCPA/CPRA requests (extendable once for complexity, with notice). We may need to verify your identity before acting on a request to prevent fraud.
Open the privacy request form — or email support@wavfinaudio.com with the subject “Privacy Request.” Emailed requests are processed the same way as form submissions; the form just lets us confirm your address before the request reaches the queue.
We do not sell or share your personal information for cross-context behavioral advertising, and we do not sell or share it for monetary or other valuable consideration. Because we do not sell or share, no “Do Not Sell or Share My Personal Information” opt-out form is required. We still honour any opt-out request you send, and we do not discriminate against you for exercising your rights.
The rights you can exercise include:
- Access & portability— request a copy of the personal data we hold about you in a portable format (GDPR Art. 15 & 20; CCPA §§ 1798.100, 1798.110, 1798.130).
- Rectification / Correction — correct inaccurate or incomplete data (GDPR Art. 16; CCPA § 1798.106).
- Erasure / Deletion— request deletion of your data (“right to be forgotten”) (GDPR Art. 17; CCPA § 1798.105).
- Restriction — limit how we process your data while a request is being resolved (GDPR Art. 18).
- Objection — object to processing based on legitimate interest or for direct marketing (GDPR Art. 21).
- Withdraw consent — where processing is based on consent, you can withdraw it at any time without affecting prior processing (GDPR Art. 7(3)). Use the cookie consent dialog or email us.
- Opt-out of sale / sharing — even though we do not sell or share, you can request confirmation in writing.
- Limit use of sensitive personal information — California residents (CCPA § 1798.121). We do not collect sensitive PI.
- Lodge a complaint with a supervisory authority — if you are in the EEA, you can complain to your local data-protection authority; in the UK, to the ICO (GDPR Art. 77). EU authorities are listed at edpb.europa.eu.
Please note: when you submit a privacy request, we can only act on information we have actually collected. In many cases, you will receive a response explaining that we do not have or do not collect your information. We still allow you to submit these requests for your convenience.
10. Changes to This Policy
We may update this Privacy Policy from time to time. The “Last updated” date at the top of this page will change. For material changes, we will make a reasonable effort to notify active dev portal users by email and place a banner on the site. Continued use of the site after the new policy takes effect means you accept the revised policy.
11. Contact Us
Questions, requests, or complaints about this Privacy Policy should be sent to support@wavfinaudio.com. If our response does not resolve your concern, you may lodge a complaint with your local supervisory authority as described above.