Legal
Privacy Policy
Last updated: August 6, 2026
Packstub is operated by XLITE TOWER SRL (trading as XLITE). This policy describes what we store when you use the store and the developer portal, and what is handled by our payment provider instead.
What we store
- Account details — your name and email address, used to sign in and to send purchase and license emails.
- Licenses — which plugins and tiers you own, and their update windows.
- Composer tokens — stored as hashes only. The token secret is shown once at creation and cannot be recovered from our records.
- Download logs — which package versions were fetched with your tokens, used for support and abuse prevention.
What our payment providers handle
Every purchase is processed by a merchant of record — Paddle or Lemon Squeezy, shown at checkout and on your receipt. Card details, billing address, and VAT information are collected and processed by the merchant of record and never stored on our servers. Their handling of that data is described in the Paddle privacy policy and the Lemon Squeezy privacy policy.
Cookies and tracking
The storefront and developer portal use first-party cookies required for sign-in sessions and security. If you arrive through a link from a community or article, we remember that referrer for the duration of your session solely so that, if you join a waiting list, we know which channel to thank. We do not use third-party advertising trackers, and nothing on this site profiles you across other websites.
To count visits we use Cloudflare Web Analytics, which is cookieless and does not fingerprint or identify individual visitors. It reports aggregate page views, referrers, countries, and page-speed measurements only. It does not run on the developer portal or the admin panel.
We also count a few storefront actions ourselves — waiting-list signups, checkouts opened, install commands copied, and clicks to other sites. These are stored as counts on our own servers with no cookie, identifier, or IP address attached, so they cannot be traced back to you.
Data retention and deletion
We keep account and license records while your account exists, and download logs for as long as they are needed for support and abuse prevention. To request a copy of your data or the deletion of your account, email support@packstub.dev. Deletion removes your account, tokens, and personal details; records our payment providers must keep for tax and accounting purposes are retained by them under their own policies.
Contact
Privacy questions go to support@packstub.dev.