Summary. To buy from us we only need your email address. We also process technical data (IP address, browser details), order data and support conversations. Payment details are handled by our payment providers — we never receive full card numbers. We do not sell data and do not use advertising trackers; our analytics are self-hosted and cookie-free. You can ask to access or delete your data at legal@xernel.cc.
1. Who We Are
The controller of your personal data is Xernel (“we”, “us”). This policy covers the xernel.cc website and its subdomains, checkout, our support system, the launcher download page and the launcher itself. We process data in accordance with the EU General Data Protection Regulation (GDPR, Regulation (EU) 2016/679), the ePrivacy Directive (2002/58/EC) and other applicable law. Privacy contact: legal@xernel.cc.
2. What We Process
2.1. Order Data
- the email address you enter at checkout;
- order number, product, license term, amount, promo code, chosen payment method, order status and timestamps, and the license key issued;
- a customer device identifier (the
xernel_customercookie) that lets us show all your orders on the “My Orders” page; - your IP address and country (derived from your IP) at the time of the order, a visitor identifier, and a partner’s referral code if you arrived via a partner link.
2.2. Payment Data
Payments are processed by our providers (section 5). From them we receive the payment status, amount, transaction identifier and details needed to reconcile your order. We do not receive or store full card numbers, CVC codes or crypto-wallet keys.
2.3. Support Requests
- ticket subject and text, follow-up messages and attached files;
- a license key and a notification email address, if you provide them;
- your browser push subscription (endpoint and keys), if you enable notifications;
- IP address, browser details (User-Agent) and the ticket’s access token.
If you contact us on Telegram or Discord, we see the profile information those platforms show us and the content of the conversation; their own processing is governed by their policies.
2.4. Launcher Download and Use
When you download the launcher we process your license key, IP address and browser details to validate the key and issue a one-time download link. When running, the launcher sends your license key and technical information about your device needed to validate the license, bind it, and prevent key sharing.
2.5. Technical Data and Logs
When you visit the website, our servers receive your IP address, browser and OS details, referring URL, requested pages and timestamps. Your country is derived from your IP address — from our network infrastructure or, on your first visit if that is unavailable, via the ipapi.co geolocation service — and stored in a cookie to choose the site language.
2.6. Analytics
We use our own instance of the Umami web analytics system, hosted at analytics.xernel.cc and served through our domain. Umami does not use cookies and does not store your IP address in clear form; it records page views, referrer, browser, OS and device type, and country. Analytics data is not shared with advertising networks.
2.7. Partner Referrals
If you arrive via a partner link (the ref parameter), we record the partner code, visitor identifier, landing page, UTM parameters, IP address, country, browser details and referrer, so we can attribute sales to the partner and calculate their commission. Partners do not receive your email address or payment details.
3. Purposes and Legal Bases
- Performance of a contract (GDPR Art. 6(1)(b)): processing orders, issuing and validating licenses, launcher downloads, support, refunds.
- Legal obligations (GDPR Art. 6(1)(c)): accounting, responding to lawful requests from authorities.
- Legitimate interests (GDPR Art. 6(1)(f)): preventing fraud and abuse, security, rate limiting, partner attribution, privacy-friendly analytics, choosing the site language, and defending our rights in disputes.
- Consent (GDPR Arts. 6(1)(a) and 7(3)): push notifications and ticket email notifications. You can withdraw consent at any time.
We do not make decisions with legal or similarly significant effects about you based solely on automated processing. Payment providers may automatically decline payments under their own rules; if that happens, you can contact us to have the situation reviewed by a person.
4. Cookies and Local Storage
We use only first-party cookies and browser storage. We do not use advertising or third-party tracking cookies.
Under Art. 5(3) of the ePrivacy Directive, information may be stored on your device without consent where this is strictly necessary for a service you have requested. We consider xernel_locale, xernel_customer, xernel_promo, the ticket list in local storage and the service worker to fall into this category. The xernel_visitor and xernel_ref cookies are used for partner attribution and are not strictly necessary for your purchase: you can block or delete them in your browser at any time without affecting checkout.
xernel_locale— your site language, 1 year;xernel_customer— a random device identifier giving access to your orders (“My Orders”), 5 years;xernel_visitor— a random visitor identifier linking a partner referral to an order, 1 year;xernel_ref— the code of the partner whose link you followed, 30 days;xernel_promo— a promo code from a link (also copied to local storage), 30 days;- local storage
xernel-support-tickets— a list of up to 20 of your tickets with their access links, so you can return to them; kept until you clear your browser data; - small interface flags (for example, dismissed hints);
- a service worker — used only to display support push notifications if you enabled them.
You can delete cookies and site data in your browser settings. Without the xernel_customer cookie, “My Orders” cannot show your earlier orders, but the order links in your emails will continue to work.
5. Who Receives Your Data
We do not sell personal data. We share it only with:
- payment providers — FreeKassa and Card2Crypto, and the Card2Crypto partner you choose at checkout (for example, Stripe or Revolut) — as needed to process the payment and run their checks;
- infrastructure providers — hosting and network providers, file storage (ticket attachments) and email delivery, acting on our instructions;
- ipapi.co — your IP address on your first visit, if your country cannot be determined otherwise;
- browser push services (for example, Google, Mozilla, Apple, Microsoft) — if you enable push notifications;
- public authorities — only where legally required and after verifying the request.
We do not disclose customer data to rightsholders as part of negotiations (see Pre-Trial Dispute Resolution); disclosure happens only where the law requires it.
6. International Transfers
Our servers and providers may be located outside your country, including outside the EU/EEA. Transfers are limited to what is needed for the purposes above and are made in accordance with Chapter V GDPR — on the basis of a European Commission adequacy decision or Standard Contractual Clauses (Art. 46 GDPR) where required.
7. Retention
- orders and payment records — 5 years from the order (accounting, tax, AML, disputes);
- support tickets and attachments — 2 years after the last activity in the ticket;
- push subscriptions — until you disable notifications or the subscription expires;
- partner referral data — 2 years;
- server logs — up to 30 days; security logs — up to 90 days;
- analytics — no more than 12 months, after which only aggregate statistics are kept;
- cookies — as listed in section 4.
After these periods, data is deleted or anonymised. A period may be extended where needed to resolve a dispute or comply with the law.
8. Your Rights
Under GDPR Articles 15–22, you have the right to: access your data and obtain a copy; have it corrected; have it erased; restrict or object to processing (including processing based on legitimate interests); receive it in a portable format; and withdraw consent at any time. You may also lodge a complaint with the data protection supervisory authority of the EU Member State where you live, work or where you believe the infringement occurred (Art. 77 GDPR).
Send your request to legal@xernel.cc with the email used at checkout or your order number. To avoid disclosing data to the wrong person, we may ask you to confirm that you control that email address. We acknowledge requests within 3 business days and aim to respond substantively within 10 business days, and in any case within one month (Art. 12(3) GDPR); for complex requests this may be extended by two further months, in which case we will tell you why. Erasure of data we must keep by law is postponed until the relevant period ends.
9. Security
We use encrypted connections (TLS), access controls, one-time download tokens and need-to-know staff access. Order pages (“My Orders” and individual order pages) and ticket links work without a password — treat them like a password and do not publish them. If you think a link has been exposed, tell us. Where an incident affects your data, we notify you and the competent authorities as required by law.
10. Age Requirement
Our service is for people aged 18 and over only. We do not knowingly process data of minors; if we learn that we have, we will delete it.
11. Changes
We update this policy when our processing changes. We announce material changes on the website in advance; the date of the current version is shown at the top of this page.
12. Contact
Privacy questions: legal@xernel.cc — Xernel’s sole official email address. Messages sent in Xernel’s name from any other address do not come from us; do not reply to them or send them your data.