shmlv.privacy
How data moves
This summary is a navigation aid. The full policy below controls.
- Checkout
- Paddle processes payment, tax, receipt, and buyer details for purchases.
- Account
- Cloudflare-backed services may store account, entitlement, and download records.
- Tracking
- shmlv. does not run advertising trackers or sell personal data.
SHMLV (shmlv.) is the brand of Denis Shumilov, an independent developer based in Ukraine. This policy explains what personal data is handled, why it is used, and which service providers receive it.
What is collected
- Website and hosting providers may process basic technical data such as IP address, browser details, page URL, referrer, and request logs.
- Paddle processes checkout and payment as merchant of record for purchases made through the shmlv. checkout. Paddle and shmlv. may process data such as name, email address, country, transaction and customer identifiers, product purchased, price, payment status, refund status, and tax information.
- Payhip data is retained only where needed to support purchases made through the former Payhip checkout, including legacy order, receipt, billing, refund, and entitlement records.
- If you use a shmlv. account, the account service processes your sign-in email, password credential records where applicable, session records, verification state, product entitlements, download availability, download events, and basic security data needed to protect paid files.
- Passwords are not stored as plain text; the account system stores salted password hashes.
- Download files, account records, and entitlement data may be stored using Cloudflare services.
- Transactional account emails may be sent through Resend.
- If you use Google sign-in, Google returns the account information needed to authenticate you, such as email identity.
- If you contact support, shmlv. may receive your name, email, order details, DAW and OS information, message content, and any screenshots or files you choose to share.
- If you apply for the sndwch beta, shmlv. processes your email address, consent record, application status, receipt, and removal state, together with the DAW or host, Windows version, testing focus, anything you write about yourself, up to three optional links, and the review state of that application. Records from the earlier Select launch list are still held for anyone who joined it before it closed.
- With your separate analytics choice, the site stores first-party pseudonymous measurement data: a random visitor ID, a per-tab session ID, the first landing-page path, the referring host, UTM source, medium, campaign, content, and term values, an allowlisted experiment and variant ID when a test is active, plus allowlisted events such as landing view, product view, demo play, command selection, interest submission, primary action, compatibility, and checkout state. Client analytics events do not contain your email, name, account ID, checkout customer or transaction ID, or message text.
- If you submit a product-interest request after allowing analytics, the request may include that pseudonymous attribution so shmlv. can understand which first-touch source led to the request. If you open a paid checkout after allowing analytics, the persistent visitor ID may also be passed to Paddle with the order as a conversion identifier.
- This site does not run advertising trackers.
How data is used
- To confirm Paddle and legacy Payhip purchases, grant the correct product entitlement, and deliver paid files.
- To let you sign in, recover downloads, access beta builds when provided, and view product entitlements.
- To issue short-lived download tokens and protect paid files from abuse.
- To handle license, refund, and support questions.
- To send service messages about downloads, updates, account verification, password resets, and order issues.
- To send the receipt for a request you made, process a removal request, or record, manually review, and follow up on a sndwch beta application.
- To measure pseudonymous first-party product interactions and, after you allow analytics, relate interest or checkout outcomes to first-touch page, referrer, and campaign attribution so product explanations and checkout paths can be improved.
- To keep accounting, tax, legal, and dispute-resolution records.
shmlv. does not sell personal data and does not use these records for automated decisions about people or for advertising profiles.
How data is shared
Data is shared only when needed to run the business or comply with law. That may include Paddle for checkout, billing, tax, receipts, payment-related buyer support, refunds, order events, and—only after analytics consent—the pseudonymous conversion identifier passed with the order; Payhip for legacy order support and records; Cloudflare for hosting, accounts, private download storage, product-interest and attribution records, pseudonymous product events, security checks, and logs; Google for optional sign-in and YouTube pages or embeds you choose to open; Resend for transactional account emails and the sndwch application receipt; and professional advisers or authorities where required.
Retention
Purchase and billing records are kept as long as reasonably needed for tax, accounting, and legal purposes. Account, entitlement, session, and download records are kept only as long as reasonably needed to provide access, prevent abuse, support refunds, and maintain security. Support emails are kept as long as needed to resolve the request. Select launch subscriptions are kept through the requested launch communication or until the person unsubscribes. sndwch applications are kept only through the relevant review or beta cycle, or until the applicant asks for removal using the link in the receipt. Pseudonymous product-event and attribution records are retained for a limited measurement period and may then be deleted or aggregated. Browser attribution identifiers and their first-touch values expire after 90 days; if analytics remains allowed, a later visit may create a new identifier.
Your rights, cookies, and contact
Depending on your location, you may have rights to access, correct, delete, restrict, or port personal data. Every receipt includes a link that removes your address; you may also email support@shmlv.com to exercise those rights or withdraw an existing request. shmlv. does not use advertising cookies. The analytics choice, pseudonymous visitor ID, and first-touch attribution are stored in local browser storage; the per-tab session ID is stored in session storage. No analytics identifier is created and no analytics event is sent before you allow analytics. Declining analytics or reopening Privacy choices clears the attribution identifiers stored by this site, and clearing site storage also resets them. When the browser sends Global Privacy Control, analytics remains disabled and stored attribution identifiers are cleared. If you sign in, the account system uses secure HTTP-only cookies for your account session and, during Google sign-in, a short-lived OAuth state check. Third-party services such as Paddle, Cloudflare, Google, and YouTube may process request data or use their own cookies under their own policies when their resources are loaded, when checkout is opened, or when you open their pages.