Effective date: February 27, 2026
We collect only the information needed to operate CWYN, process transactions, deliver digital products, provide support, and maintain security/compliance.
| Category | Examples | Primary purposes | Recipient types | Retention baseline |
|---|---|---|---|---|
| Identifiers & contact | Name, email, support identifiers | Account/order communication, support | Hosting, customer support tools, communications vendors | Active customer lifecycle + legal/operational need |
| Commercial/order data | Products purchased, order ID, entitlement status, timestamps | Fulfillment, accounting, dispute handling, fraud review | Payments processors, hosting/database vendors | Accounting/dispute/legal retention periods |
| Payment metadata | Processor IDs, payment status, risk outcomes | Payment processing, chargeback handling, abuse prevention | Payment processors and anti-fraud services | As required for financial controls and legal recordkeeping |
| Security/device telemetry | IP/country signals, request logs, abuse events | Security monitoring, rate limiting, incident response | Hosting/security tooling providers | Limited-duration operational/security windows unless needed for investigation |
| Support communications | Messages, troubleshooting details, attachments | Resolve support issues and improve service quality | Support/communications vendors | Until resolution + reasonable service-quality review period |
CWYN does not intentionally collect highly sensitive personal information categories unless required for legal or fraud-prevention reasons. CWYN does not store full card numbers or CVV. If sensitive data is received unintentionally (e.g., in support messages), access is restricted and the data is deleted or minimized where feasible.
CWYN does not sell personal information for money and does not share personal information for cross-context behavioral advertising. Global Privacy Control (GPC) and similar universal opt-out signals are honored where legally required.
Depending on your state, you may have rights to access, correction, deletion, portability, opt-out (where applicable), and appeal.
Data may be processed in multiple countries. Where required, we apply contractual and technical safeguards for cross-border transfers and enforce least-privilege access controls.
This site is not intended for children under 13, and we do not knowingly collect data from children.
We use administrative and technical safeguards (including access controls and logging). No method of transmission or storage is 100% secure.
We may update this policy from time to time. Changes are effective when posted with a revised effective date.