Legal
Privacy policy
Last updated September 17, 2026
The controller is Out of Auto, an independent publisher based in Lithuania. Contact: info@21dayreset.me. This policy explains what we collect, why, how long we keep it, and how to exercise your rights under the GDPR and the CCPA/CPRA.
What we collect, and why
- Email address, to deliver the file and handle support.
- Order amount, currency, country, and tax status from Stripe, to fulfil the order and meet tax obligations.
- A salted hash of the IP on download requests, for abuse prevention only. We never store the raw IP.
- Consent to the terms of service at checkout (accepted or not, with a timestamp on the order), so we can show that you saw the refund terms before paying.
What we do not collect
No card numbers ever touch our servers. Stripe handles payment details end to end. We do not collect names unless you put one in an email to us. We do not build a browsing profile. We do not use advertising identifiers. We do not run cross-site tracking. Nothing is ever sold or shared for anyone else's advertising.
Processors we use
- Stripe (payments and tax): https://stripe.com/privacy
- Resend (transactional email): https://resend.com/legal/privacy-policy
- Neon (database): https://neon.tech/privacy-policy
- Cloudflare (file storage and DNS): https://www.cloudflare.com/privacypolicy/
- Vercel (hosting): https://vercel.com/legal/privacy-policy
- Upstash (rate limiting): https://upstash.com/trust/privacy
- Plausible (cookieless, aggregate analytics): https://plausible.io/privacy
How long we keep it
- Order and delivery records: seven years, because tax law requires it.
- Download tokens: deleted sixty days after purchase.
- IP hashes: deleted after thirty days.
- Support emails: kept as long as needed to resolve the request, then a reasonable period afterward.
GDPR
Legal bases: contract performance for delivery, legal obligation for tax records, legitimate interest for abuse prevention (rate limits and IP hashes), and consent where you accept the terms at checkout. You have the right to access, rectification, erasure, restriction, portability, and objection. Email info@21dayreset.me to exercise any of these. We respond within thirty days. You also have the right to complain to a supervisory authority. In Lithuania that is the State Data Protection Inspectorate (VDAI).
CCPA / CPRA
Categories collected: identifiers (email), commercial information (order amount, currency, country), and internet activity limited to a salted IP hash on download. We do not sell personal information and we do not share it for cross-context behavioral advertising, as those terms are defined. There is nothing to opt out of under Do Not Sell or Share because nothing is sold or shared that way. To request access or deletion, use https://21dayreset.me/privacy/request or email info@21dayreset.me. We will not discriminate against you for exercising these rights.
International transfers
Data moves between the EU and the US through the named processors, under their standard contractual clauses and related transfer tools.
How to make a request
Use the form at https://21dayreset.me/privacy/request, or email info@21dayreset.me from the address involved. A human handles every request. We do not run an automated deletion pipeline.
Ready to make a request? Use the privacy request form.