1. Scope
This policy explains the data EditBox processes when you create an account, sign in, purchase or access resources, Membership, courses, and services, contact support, or use a published integration. It applies to the Website and related flows operated by EditBox.
2. Account and identity data
EditBox may store a display name, username, email, account status, language, linked identifiers, and necessary sign-in history to create an account, authenticate, support, and secure the service. Passwords, when used, are handled as hashes; EditBox does not need to know your original password.
When you choose to link Google, Telegram, or Discord, EditBox processes the linking information needed for sign-in, identity verification, and the relevant feature. This policy does not itself expand the permissions of an integration.
3. Google OAuth and Google Drive
To support Drive features, EditBox may process the linked Google email, account identifier, and necessary permission status to check or grant access to Drive resources at your request. EditBox does not use Drive permission to browse or exploit content outside the feature you choose to use.
Google data and user data are not sold. Where needed, data is shared with processors or infrastructure required to operate the feature, secure the service, fulfill your request, or comply with law.
4. Payments and orders
For processing and reconciliation, EditBox may store an order ID, payment request ID, provider, transaction or reference identifier, amount, currency, method, status, creation or payment time, and links to the Product, Membership, or service. A payment provider may process additional data under its own policy.
EditBox does not claim to store full card numbers or card security codes. Card information, where applicable, is entered and processed in the payment provider’s interface or system; EditBox receives only what is needed for status and reconciliation.
5. Delivery, access, and evidence
For access provisioning and post-purchase support, EditBox may store the Product or service, payment time, delivered_at or entitlement timestamp, Membership/course/service status, access or download times when recorded by the system, and delivery or access event history. Download links or tokens are protected; displayed evidence does not contain a raw token.
When needed for security, fraud prevention, delivery checks, or dispute response, the system may store an IP address or IP hash, user agent, account email where available, and related device or request information. This helps distinguish a transaction, granted access, and access activity; it is not used to store passwords or secrets.
6. Versioned legal acceptance
When you consent at checkout, EditBox may store the user ID, order or payment context and reference, Terms, Privacy, and no-refund policy versions, acceptance time, IP, and user agent. Each historical version is stored as a separate record; EditBox does not overwrite an earlier acceptance with a new version.
7. Cookies, sessions, and security
EditBox uses cookies and session data needed to maintain sign-in, protect against CSRF, remember language or interface choices, continue checkout, and detect abuse. The system may record security events, errors, and minimum request information to protect accounts and the Website.
8. Uses and providers
Data is used to operate accounts, verify payments, deliver content, manage access, support customers, prevent fraud, secure the service, audit activity, resolve disputes or chargebacks, improve reliability, and meet legal obligations. EditBox uses infrastructure, email, authentication, storage, and payment providers as needed for these purposes.
9. Data sharing
EditBox shares only data needed with providers processing your request, operating or securing the service, or when law, a competent authority, a payment provider, bank, or card issuer makes a valid request. EditBox does not sell user data or share it for another party’s independent marketing without an appropriate basis.
10. Retention and protection
Data is retained as long as needed to provide the service, maintain access and transaction history, handle support or disputes, prevent fraud, secure the service, and meet legal obligations. The exact period depends on the data type, account status, and evidence-retention need. EditBox applies access controls and safeguards appropriate to the stored data, but cannot guarantee absolute security for every transmission system.
11. Your choices and requests
You may update information available in your account, unlink supported identities, unsubscribe from marketing email, and request help with access, correction, or deletion of data. Some transaction, legal-acceptance, security, or fraud-prevention records may need to remain when required for legal obligations or disputes.
Operational, transaction, and security email may still be sent after you unsubscribe from marketing. EditBox may need to verify your identity and the request scope before processing a request.
12. Privacy contact
For privacy questions or requests, contact admin@editbox.store. Do not send passwords, OAuth tokens, payment secrets, card security codes, or raw download tokens with a request.
Contact: admin@editbox.store