Version 2026-08-30
Privacy policy
This privacy policy explains, in accordance with Articles 13 and 14 GDPR, which personal data is processed when you visit SPFxStore, submit an enquiry or make a purchase.
Business customers only
SPFxStore is intended exclusively for businesses within the meaning of section 14 of the German Civil Code, public-law entities and special funds under public law. We do not enter into contracts with consumers. All store prices are net prices plus any applicable taxes.
1. Controller
The controller within the meaning of the General Data Protection Regulation is Jack Jipp, trading under the business name Lyron, Grünstraße 43, 40667 Meerbusch, Germany.
2. Hosting and server logs
The website runs on server infrastructure provided by IONOS SE, Elgendorfer Straße 57, 56410 Montabaur, Germany. When a page is requested, the server processes technical log data including the IP address, date and time, requested URL, referrer, browser and operating-system information, HTTP status and amount of data transferred.
This processing is necessary to deliver the website, maintain stability, diagnose errors and prevent abusive access. The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is the secure and reliable operation of the service. Logs are retained only for as long as required for operations and security investigations, then deleted or anonymised; where a specific security incident occurs, they may be retained longer to preserve evidence.
3. Product enquiries and contact
When you submit a custom-webpart enquiry, we process your name, email address, optionally your company, budget and timeframe, and your project description. If you contact us directly, we also process the message and metadata you provide.
Processing takes place to answer your enquiry and take steps toward a contract under Article 6(1)(b) GDPR. Where a contact person acts on behalf of an organisation, processing is additionally based on Article 6(1)(f) GDPR; our legitimate interest is handling business communications.
4. Launch notifications
If you subscribe to a launch notification, we store your email address, selected product and registration time solely to notify you when that product becomes available for sale. The legal basis is Article 6(1)(a) GDPR. You may withdraw consent at any time by email. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
5. Checkout, orders and licence delivery
To prepare a B2B purchase, we process the company, contact name, email address, Microsoft 365 tenant ID, selected product, language, price and discount identifiers, acceptance time, and version of the accepted terms. After payment confirmation we additionally process Paddle transaction and customer identifiers, payment status, invoice link, licence and download status, and any refund or chargeback events.
This data is required to process the order and licence agreement, provide the tenant licence key and private download, prevent abuse, provide support, and comply with commercial and tax obligations. The legal bases are Article 6(1)(b), (c) and (f) GDPR. Mandatory fields are required to conclude the contract; the purchase cannot be completed without them.
6. Payment and invoicing by Paddle
Paddle is the authorised reseller and Merchant of Record for purchases. The relevant Paddle group company processes identity, contact, billing, tax, payment, device and transaction data for checkout, fraud prevention, tax calculation, payment, invoices and refunds. The Paddle entity contracting with a buyer depends on the buyer's country and is shown during checkout.
Paddle processes data for its own legal and contractual purposes as an independent controller. We receive the order information required to deliver the product and support the customer. The legal bases for our transfer and subsequent processing are Article 6(1)(b), (c) and (f) GDPR. Paddle may process data internationally as described in its privacy notice.
7. Transactional email through Resend
Purchase and delivery emails are sent through Resend, a service of Plus Five Five, Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA. This involves processing the recipient address, name, order information, message content, licence key, download link and delivery status. We do not use Resend for advertising tracking.
Processing is necessary to perform the contract under Article 6(1)(b) GDPR and for reliable delivery and evidence under Article 6(1)(f) GDPR. Resend stores service data in the United States. According to the provider, transfers are safeguarded by the EU-US Data Privacy Framework and, additionally, the EU Standard Contractual Clauses in its Data Processing Addendum.
8. Cookies, local storage and media
SPFxStore does not use analytics, advertising or profiling cookies. When checkout is started, a random, technically necessary and HttpOnly-protected claim is stored in the browser. It is used solely to securely associate the order status and later delivery with the same browser and expires after 30 minutes. The legal bases are section 25(2)(2) TDDDG and Article 6(1)(b) and (f) GDPR.
When you open Paddle Checkout, Paddle may use technologies required for secure checkout, fraud prevention and payment processing. Product images, PDFs, fonts and videos are delivered from our own server infrastructure; merely playing them does not transmit data to video or analytics networks.
9. Recipients and international transfers
Data is disclosed only to parties that require it for the purposes described: hosting and infrastructure providers, Paddle for resale and payment, Resend for transactional emails, and carefully selected technical providers. Authorities or advisers receive data only where required by law or to establish, exercise or defend legal claims.
For transfers outside the European Economic Area, we rely on an adequacy decision or appropriate safeguards under Articles 44 et seq. GDPR, in particular Standard Contractual Clauses. More detail about Paddle and Resend is available in the linked notices.
10. Retention
We retain personal data only for as long as the relevant purpose continues. Enquiry and contact data is deleted after communication ends if no contract results and no legitimate evidentiary interest remains. Launch data is deleted after the notification or withdrawal of consent. Order, invoice, licence and communication data is retained during the contractual relationship and afterwards in accordance with applicable commercial, tax and liability periods. Security and abuse evidence is retained only as long as required for prevention and legal enforcement.
11. Your rights
Subject to the statutory requirements, you have rights of access, rectification, erasure, restriction of processing and data portability. You may object to processing based on legitimate interests for reasons relating to your particular situation and may withdraw consent at any time for the future.
You may also lodge a complaint with a data-protection supervisory authority, in particular the State Commissioner for Data Protection and Freedom of Information responsible for North Rhine-Westphalia.
12. Security, automated decisions and updates
We apply appropriate technical and organisational safeguards including encrypted transmission, private package storage, signed download claims, access restrictions and data-minimised logging. Lyron does not carry out solely automated decision-making with legal or similarly significant effects or profiling; Paddle may perform its own automated fraud checks as described in its notices.
We update this policy if the services or applicable law change. For a purchase, the contractual-terms version displayed at checkout and stored with the acceptance time applies.
The German version is the governing contractual version. This English version is provided solely as a convenience translation.