Privacy Policy
How coldd Development collects, uses, and protects your information.
This Privacy Policy explains how coldd Development ("coldd", "we", "us"; ABN 34 127 589 633) collects, uses, discloses and protects personal information when you use coldd.dev (the "Site"). This Policy forms part of our Terms of Service.
1. Information We Collect
We collect information in three ways: information you give us directly, information third parties give us when you choose to connect them to your account, and information collected automatically as you use the Site.
Information you provide directly: When you create a coldd account with email and password, we store your email address and a securely hashed version of your password - we never store your password in plain text. We also keep anything you send us directly, such as a support request or ticket message.
OAuth providers: If you sign in with Google, Discord, or Roblox, that provider shares basic profile details with us, typically your name or username, account ID, and email address, so we can create and secure your coldd account.
Payment processors: Card payments are processed by Stripe. We also support PayPal, cryptocurrency (processed by RelayPay, an AUSTRAC-registered Australian processor), and Robux via Roblox. coldd never receives or stores your full card number, PayPal credentials, crypto wallet keys, or Roblox password - those go directly to the relevant processor. Paying with crypto shares your name and email with RelayPay so it can process the transaction and comply with its AML/CTF obligations. We keep a record of the transaction itself (amount, date, product, payment method, and the processor's own reference) for order history, refunds and support.
Roblox: If you pay with Robux, you link a Roblox account via Roblox's own OAuth sign-in, which requests permission to read your inventory. We use your Roblox user ID to confirm which account is yours and match a completed gamepass purchase to your order - we do not use it to browse, store or analyse the rest of your inventory. If you delete your coldd account, this link is deleted with it (see "Data Retention" below).
Discord and support communications: If you contact us by email or through our Discord server, we retain that correspondence to help resolve your request.
Cookies and analytics: We use two kinds of browser storage. Essential storage keeps you signed in, remembers your cart and currency preference, and records the cookie choice you make below - the Site cannot function without it, so it isn't offered as a choice. Analytics storage is optional and stays off until you actively turn it on. It covers two things, which are not equally anonymous:
- Page-view beacon - a page visit logged against a random id generated for that browser session, never your account. This is genuinely anonymous: it isn't linked to your identity and is used only in aggregate, to see which pages get used.
- Abandoned-cart snapshot - if you reach checkout with items still in your cart, we save that cart so we can follow up if you don't complete the order. If you're signed in, this snapshot is linked to your account and email address, and may be used to send you up to a few reminder emails about that cart (the later ones may include a discount code, only if you've separately opted in to marketing emails). If you're signed out, the snapshot has no account or email attached. Either way, it's cleared as soon as you check out or empty your cart.
Both run in-house on our own Supabase infrastructure - we do not use a third-party analytics provider, and neither is shared outside coldd or used for third-party advertising. You can grant or withdraw analytics consent at any time using the button below; withdrawing it stops new page-view and cart-snapshot data being collected going forward.
Automatically collected information: Our infrastructure providers (Cloudflare and Supabase, see "How We Share Information" below) automatically log standard web request data for every visit to the Site, including IP address, browser and device type, the pages requested, timestamps, and error logs generated when something goes wrong. We also use IP addresses ourselves in a narrow, targeted way - for example, to rate-limit repeated abuse of coupon codes - and Supabase's authentication service keeps its own sign-in and account-security logs (such as failed login attempts) to help keep accounts secure. We use this information for security, fraud and abuse prevention, and diagnosing technical problems - not to build a profile of your browsing habits.
2. How We Use Your Information
- Create and maintain your account
- Process orders and deliver purchased assets
- Provide customer support and respond to inquiries
- Detect and prevent fraud, chargebacks, and abuse of our license terms
- Improve the Site and our products
- Send order confirmations and important account or policy updates
3. How We Share Information
We share information only where necessary to operate the Site, and only with the specific providers below:
- Payment processors - Stripe (cards), PayPal, RelayPay (cryptocurrency) and Roblox (Robux), to take payment and confirm it completed
- OAuth providers - Google, Discord and Roblox, when you choose to sign in or link through them
- Infrastructure providers - Supabase, which hosts our database, authentication and file storage; Cloudflare, which fronts the Site's traffic and provides security filtering; and GitHub Pages, which hosts the Site's static pages
- Email delivery - Resend, which sends order confirmations, sign-in codes, and (if you've opted in) marketing emails on our behalf
- Where required by law, or to protect coldd's rights and users' safety
We do not sell your personal information, and we do not share it with third parties for their own advertising.
4. Where Your Information Is Stored
Our database, authentication and file storage are hosted by Supabase in the European Union. If you are in Australia or elsewhere, this means your account and order data is stored overseas.
Beyond that, the specific providers above each process information internationally as part of how they operate:
- Cloudflare operates a global network and may handle your requests at an edge location anywhere in the world, purely to route traffic and filter abuse - it does not store your personal information.
- GitHub Pages (United States) hosts the Site's static pages and logs standard web requests to do so.
- Stripe, PayPal, Resend, Google, Discord and Roblox are all headquartered in the United States and process data there and in other countries as part of their own global operations.
- RelayPay is an Australian, AUSTRAC-registered processor and processes cryptocurrency payments within Australia.
We take reasonable steps to ensure these providers handle your information consistently with this Policy and applicable privacy law, but by using the Site you acknowledge your information may be stored and processed outside your country of residence.
5. Data Retention
How long we keep something depends on what it is:
- Account and profile information is kept while your account is active. If you delete your account, your profile, Roblox account link, any reviews you've posted, your marketing email opt-in, and any active cart snapshot or unredeemed bundle offer are removed immediately.
- Order and payment records are kept for as long as we're legally required to - Australian tax and business records law generally requires transaction records to be kept for around five years. If you delete your account, these records are kept but disassociated from your account where we're able to do that.
- Resell licence records - your email, display name, and where you sell - are kept for as long as necessary to administer and enforce the Resell Licence Terms, including after a licence is suspended or revoked, and to protect customers who bought a product from you while your licence was valid. If you delete your account, this record is kept but disassociated from your account where we're able to, the same as order records above.
- Support and Discord correspondence is kept for as long as reasonably necessary to resolve your request and for a reasonable period afterwards, in case the same issue recurs.
- Page-view analytics (the anonymous beacon described in section 1) is never linked to an account, so it isn't affected by account deletion.
- Abandoned-cart snapshots are deleted automatically once you check out or empty your cart; if left abandoned, the reminder sequence itself completes within about two weeks, after which the snapshot is no longer actively used.
- Security, fraud and administrative logs (rate-limiting records, staff action logs, and infrastructure request logs kept by Supabase/Cloudflare/GitHub) are retained for as long as reasonably necessary for security, fraud prevention and accountability purposes, and are not tied to routine account deletion.
6. Your Rights
You can request access to, or correction of, your personal information at any time by emailing support@coldd.dev or using our Contact Form. You can also request deletion, or delete your account yourself from your dashboard - see "Data Retention" above for what is and isn't retained after account deletion, section 7 if the request relates to a child, and § 3.6 of our Terms of Service for how deletion interacts with your licences and already-published content.
We may need to verify your identity before actioning a request, to make sure we're not disclosing or changing someone else's information. We aim to respond within 30 days as a general target, or sooner where practical - this is our own service standard, not a claim that 30 days is a universal statutory deadline; some jurisdictions' laws may set a different timeframe, which we'll follow where it applies to you.
You can change your cookie choice at any time using the button in section 1 above - including withdrawing analytics consent after granting it.
If you have a concern about how we've handled your information, please contact us first at support@coldd.dev so we have a chance to resolve it directly. If you're not satisfied with our response, you can complain to the Office of the Australian Information Commissioner. If you are in the UK or EU, you may also complain to your local data protection authority.
7. Children's Privacy
coldd is not directed at children. Our account creation flow does not ask for or collect date of birth or other age-verification information, and neither our sign-in providers (Google, Discord, Roblox) nor our own account system are designed to serve children under the minimum age applicable in their country of residence.
Minimising information from children: Because we don't collect age information at signup, we don't knowingly collect more personal information from a child than is necessary to operate the Site, and we don't use information from an account we later learn belongs to a child for marketing or profiling.
If we learn a user is underage: If we become aware that an account belongs to a child below the applicable minimum age for using the Site without parental consent, we will take reasonable steps to deactivate the account and remove the associated personal information we're not otherwise legally required to retain (see "Data Retention" below), and, where practical, notify the account holder that this has happened.
Parent and guardian requests: A parent or guardian who believes their child has created a coldd account or given us personal information can contact support@coldd.dev to ask us to review, restrict, or delete it. We will take reasonable steps to verify the request and respond as set out in "Your Rights" below.
Roblox-linked accounts: Roblox sets its own minimum age for using Roblox and linking a Roblox account to third-party services like ours. Where a Roblox account is linked to pay with Robux, we only use that link to verify and process the specific purchase (see "Roblox" above) - we do not use it to collect any further information about a child's Roblox account or activity.
These practices are intended to be consistent with the Australian Privacy Act, the Children's Online Privacy Code as it comes into effect and applies to services like ours, and comparable international children's privacy laws, to the extent they apply to coldd. This section describes our practices and is not a legal determination of how any specific law applies to coldd; we'll update it as those requirements take effect.
8. Changes to This Policy
We may update this Policy from time to time. Material changes will be reflected by updating the "Last updated" date above.
9. Contact
Questions about this Policy? Email support@coldd.dev or reach us on Discord.