Privacy Policy
Last updated 2 September 2026
This site sells one thing and collects almost nothing. There are no accounts, no cookies of our own, and the analytics we run cannot identify you. What follows is the whole picture, not a summary.
1What we collect, and when
Nothing that identifies you, if you only read. Browsing this site sets no cookies. We do count visits, using Plausible: it records the page, the referrer, the country, and the browser and device type, all of it aggregated, and it stores no cookie, no device identifier and no IP address. There is no profile of you because there is nothing to attach one to, and nothing here follows you to another site. Our host also records standard server logs — IP address, page requested, timestamp, user agent — for security and troubleshooting.
When you buy a licence, Paddle collects your name, email address, billing address, VAT number where applicable, and payment details. Paddle is the seller of record: it takes the payment and handles the tax, and we never see your card details. From Paddle we receive the transaction record and your email address.
Your GitHub username, which you type at checkout. We use it for one purpose: to invite that account to the private webrot9/thefabrica repository. Without it we cannot deliver what you paid for.
2Why we are allowed to hold it
Your email and GitHub username are processed to perform the contract — you bought a licence and we have to deliver it (GDPR Art. 6(1)(b)). Transaction records are kept because tax law requires it (Art. 6(1)(c)). Server logs rest on our legitimate interest in keeping the site up and unabused (Art. 6(1)(f)).
We do not process your data for marketing, and we do not profile you or make automated decisions about you.
3Who else sees it
Four companies, each doing one job:
- Paddle.com Market Ltd (United Kingdom) — merchant of record. Takes the payment, handles VAT, and holds the billing data. Paddle is a controller in its own right for that data; its own privacy notice governs it.
- GitHub, Inc. (United States) — hosts the repository. Receives the username you gave us in order to send the invitation.
- Vercel Inc. (United States) — hosts this site and keeps the server logs described above.
- Plausible Insights OÜ (Estonia) — counts visits. Runs on servers in Germany, sets no cookies, and receives no personal data: what reaches it is an aggregate count, not a record about a person.
Nobody else. We do not sell data, and we do not share it for advertising.
4Data leaving the EU
GitHub and Vercel are United States companies, so hosting this site and delivering your licence involves a transfer outside the EEA. Those transfers rely on the European Commission's Standard Contractual Clauses, and on the EU–US Data Privacy Framework where the recipient is certified under it. You can ask us for a copy of the safeguards in place.
Our analytics are not part of that. Plausible is an Estonian company running on German servers, so counting your visit involves no transfer out of the EEA at all — which is the reason we chose it over the American alternatives.
5How long we keep it
Transaction records: ten years, because Italian tax law requires it. Your GitHub username: for as long as your licence is active, since it is the record of who has access. Server logs: a short rolling window set by our host, typically days rather than months.
6Your rights
You can ask us for a copy of your data, to correct it, to delete it, to receive it in a portable format, or to object to processing based on legitimate interest. Write to the address above and we will answer within one month.
One honest limit: deleting your GitHub username also removes your repository access, because the two are the same fact. Ask and we will say so before acting. Records we are legally required to keep for tax purposes cannot be deleted on request.
If you think we have handled your data badly you can complain to your national supervisory authority — in Italy, the Garante per la protezione dei dati personali.
7Cookies
This site sets none of its own, which is why you have not seen a consent banner. Analytics are the usual reason a site needs one, and ours do not: Plausible stores nothing on your device and keeps no identifier, so there is no consent to ask for. Opening the Paddle checkout loads Paddle's script, which sets cookies necessary to process your payment and prevent fraud; that happens only on the pricing page, and only there. If we ever add anything that does store an identifier on your device, this section and a consent banner arrive together.
8Changes
If this policy changes in a way that affects you, we will email licence holders rather than quietly updating the date at the top.