Legal
Privacy Policy
Last updated: July 24, 2026
Packstub is operated by XLITE. This policy describes what we store when you use the store and the customer portal, and what is handled by our payment provider instead.
What we store
- Account details — your name and email address, used to sign in and to send purchase and license emails.
- Licenses — which plugins and tiers you own, and their update windows.
- Composer tokens — stored as hashes only. The token secret is shown once at creation and cannot be recovered from our records.
- Download logs — which package versions were fetched with your tokens, used for support and abuse prevention.
What Paddle handles
Paddle is the merchant of record for every purchase. Card details, billing address, and VAT information are collected and processed by Paddle and never stored on our servers. Paddle's handling of that data is described in the Paddle privacy policy.
Cookies and tracking
The storefront and customer portal use first-party cookies required for sign-in sessions and security. We do not use third-party advertising trackers.
Data retention and deletion
We keep account and license records while your account exists, and download logs for as long as they are needed for support and abuse prevention. To request a copy of your data or the deletion of your account, email support@packstub.dev. Deletion removes your account, tokens, and personal details; records Paddle must keep for tax and accounting purposes are retained by Paddle under its own policy.
Contact
Privacy questions go to support@packstub.dev.