Privacy Policy

Last updated: October 10, 2026

This Privacy Policy explains what personal data is processed when you use Spidx Uploader (the "App"), buy a licence or a pack, get support or visit spidxuploader.com or spidxshop.com, why, on what legal basis, who receives it and what your rights are.

1. Who is responsible (data controller)

Spidx
Email: contact@spidxshop.com

Most of the App runs on your computer. Settings, tokens, upload history and presets stay there, and your files go from your computer directly to the destination you chose. This policy covers what reaches us or our service providers.

2. What is processed

2.1 Google sign-in

When you sign in, the App receives your Google account email address and a sign-in token that proves it, and keeps the token on your computer to maintain your session. You can revoke the access at any time (see section 9).

2.2 Google Drive

If you choose Google Drive as the destination, the App uses the Google Drive API with the drive.file permission. It can only see files and folders that the App created or that you made available to it. It uses this to create an upload folder (by default "Spidx Uploads"), upload the files you selected and create sharing links. It does not browse your whole Drive.

2.3 Licence and device data

To check your plan, the App sends your Google sign-in token, a random device identifier (created on first run; not a hardware serial number) and the computer's name to our licence service (a Google Apps Script web application). The service verifies the token with Google, looks up your plan, and records the device against your email address so that the device limit of your licence can be applied. The result is kept on your computer for up to about 24 hours so the App keeps working briefly offline.

2.4 Licence administration

Licence codes and related records are kept in a Google Sheet that we manage: email address, plan and add-ons, licence codes, code status, device identifiers and names, dates, and sometimes the order reference. Only people responsible for licence administration have access.

2.5 Orders and payments

Orders are taken in our store at spidxshop.com and payments are handled by Stripe. Stripe receives your payment and order details and acts for its own purposes under its own privacy policy. We receive the data needed to deliver your purchase and keep accounting records: your name, email address, country, the product, the price, the date and the order number. We do not receive your card number. For each order we also keep, in the hosting of our store (Cloudflare), a counter of how many times the order file was downloaded. We also send you one order email with a link to your download page, using your email address from the order; the email is sent through Resend.

2.6 Support

If you write to us by email or open a support ticket on our Discord server, we process your messages, your email address and your Discord user name and ID, and anything you attach, such as a diagnostics file. Do not send passwords, sign-in tokens or card details.

Licence codes may be delivered to you by direct message through a Discord bot.

2.6a Discord access to the Spidx Thumbnail Pack V3

To give you access we process your Discord user name and ID, the role we assign to you, the dates of your purchase and access, and the order reference that links them. To protect the product against abuse we may check, using the information Discord shows to us, whether an account is an alternative account used to get around a ban or to obtain access more than once, and whether the purchase is fraudulent. If we refuse or withdraw access for these reasons, we keep a record of the decision and the reasons so that we can answer a complaint or a legal claim.

2.7 Uploads

The App compresses images on your computer and uploads them to Google Drive or WorkUpload (for WorkUpload, the App uses a web browser on your computer to submit the file to workupload.com). We do not receive or keep copies of your files. After the upload, the destination's own terms and settings decide how long the files are kept and who can open the link.

2.8 Update checks and the leaderboard

2.9 Data stored on your computer

Sign-in tokens, settings, client presets, upload history (file names and links), a cached licence result, the device identifier, a record of the version of our documents you accepted (version, date and email), logs, and the browser profile used for WorkUpload. We do not receive this data. You can remove single history entries or clear the whole history in the Dashboard.

2.10 Diagnostics files

A diagnostics file is created only when you ask for one. It contains a self-test result, recent log lines and your settings, with email addresses, tokens and your Windows user name removed. It stays on your computer until you send it to us. If you do, we use it only to solve your problem. Please look through it before sending.

2.11 Websites

The websites at spidxuploader.com and spidxshop.com are delivered through Cloudflare, which processes visitors' IP addresses and technical request data to deliver and protect the sites. The websites do not use advertising or analytics cookies.

3. Why we process it and on what basis

PurposeDataLegal basis (GDPR)
Provide the App, sign-in and uploadsemail, sign-in token, files (on your computer)performance of a contract (Art. 6(1)(b))
Check licences and apply the device limitemail, plan, device identifier and nameperformance of a contract (Art. 6(1)(b)); our legitimate interest in preventing unauthorised use (Art. 6(1)(f))
Take orders, deliver licence codes, issue invoicesname, email, country, order dataperformance of a contract (Art. 6(1)(b)); legal obligation for accounting and tax (Art. 6(1)(c))
Support and fixing problemsemail, messages, diagnostics fileperformance of a contract (Art. 6(1)(b)); legitimate interest (Art. 6(1)(f))
Delivering and protecting Discord access to the PackDiscord user name and ID, role, order reference, abuse and fraud checksperformance of a contract (Art. 6(1)(b)); legitimate interest in preventing fraud and abuse (Art. 6(1)(f))
Security, fraud and abuse prevention, defending legal claimsIP addresses, device and licence recordslegitimate interest (Art. 6(1)(f))
Update checks and the leaderboardIP address, request dataperformance of a contract (Art. 6(1)(b)); legitimate interest in running these features (Art. 6(1)(f))

Where we rely on legitimate interests, you can object (section 8).

4. Who receives data

Only as needed for the purposes above:

Several of these act as independent controllers of the data you give them directly. We do not sell personal data and we do not use it for advertising.

5. Transfers outside the EEA

Some of these providers are based in, or process data in, the United States or other countries outside the European Economic Area. Where this happens, the transfer relies on an adequacy decision (for example the EU-US Data Privacy Framework for certified companies) or on standard contractual clauses approved by the European Commission. You can ask us for details.

6. How long we keep it

DataKept
Licence and device recordsFor as long as the licence is active and for 6 years afterwards (the limitation period for civil claims), then deleted
Order and accounting records5 years from the end of the calendar year in which the tax obligation arose (accounting and tax rules)
Support emails and tickets, diagnostics filesUp to 2 years after the case is closed. Diagnostics files are deleted when the case is closed
Server logs (IP addresses)Up to 30 days

Data on your computer stays until you delete it or remove the App. Files in your Google Drive stay under your control. After the periods above we delete the data or make it anonymous, unless the law requires us to keep it longer or it is needed to defend a legal claim.

7. Providing data is voluntary, but needed

You do not have to give us any data, but without your email address and the licence check we cannot provide the Pro features, and without order data we cannot deliver a purchase. We do not make decisions about you by automated means that have legal or similarly significant effects. The device limit is applied by a fixed rule, and a person can review it on request.

8. Your rights

Depending on the law that applies to you (in the EU and EEA, the GDPR), you can ask us for access to your data, correction, deletion, restriction of processing and a portable copy, and you can object to processing based on our legitimate interests. Where we process data on the basis of your consent you can withdraw it at any time. Write to contact@spidxshop.com and give us enough to identify your records (the email used for your licence or order). We answer within one month.

You can also complain to a supervisory authority. In Poland this is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warsaw, uodo.gov.pl). You can also complain to the authority in the country where you live or work.

9. Revoking Google access

Use "Reset Google sign-in" in the App's tray menu, and/or revoke the access at myaccount.google.com/permissions. Features that need Google sign-in stop working until you sign in again.

10. Security

Access to licence records is limited to people who administer licences, and licence responses are signed so that edited local data is rejected. No system is completely secure, and you should protect your own computer and Google account.

11. Children

The App is not directed at children. If you believe a child has given us personal data, contact us and we will review and, where appropriate, delete it.

12. Changes

We update this policy when the App, our processing or the law change. The date above shows the latest version. If a change is material, the App asks you to accept the new version.

13. Contact

Spidx. Email: contact@spidxshop.com.