Privacy Policy
Last updated on April 10, 2026
This Privacy Policy describes how DND Software ("DND Menu", "Company", "we", "us", or "our") collects, uses, stores, and protects personal data in connection with the DND Menu website, digital products, customer accounts, and related services (collectively, the "Services"). If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, this Policy is intended to comply with the General Data Protection Regulation (EU) 2016/679 (GDPR) and other applicable data protection laws.
1. Data Controller
DND Software is the data controller responsible for your personal data processed through the Services. For all data protection inquiries, contact us at [email protected].
Data Protection Officer. DND Menu has not designated a Data Protection Officer, as our processing activities do not meet the criteria set out in Article 37 of the GDPR (we are not a public authority, we do not carry out large-scale systematic monitoring of data subjects, and we do not carry out large-scale processing of special categories of data). For any data protection matters, please contact us at [email protected].
2. Categories of Personal Data We Collect
A. Account & Registration
- Name
- Email address
- Username
- Encrypted password
- Discord account ID (if linked via OAuth)
- Discord server (guild) names and identifiers (when linked via OAuth)
B. Billing & Transaction
- Billing address
- VAT number (if applicable)
- Subscription details
- Transaction identifiers
- Purchase history
- License key assignment records
Note: Payment card data is processed exclusively by Stripe and is never stored on our servers.
C. Security & Authentication
- Session tokens
- Hashed IP addresses (we do not store raw IPs)
- Two-factor authentication (TOTP) secrets (encrypted at rest)
- Trusted device identifiers
- Password reset tokens (hashed, time-limited)
- CSRF tokens
- Rate limiting data
D. Technical & Usage
- Device identifiers
- Browser type and version
- Operating system
- Usage analytics
- Error reports
E. User Content
Custom configurations, scripts, UI themes, banners, and layout settings uploaded to the platform.
F. Communication
- Support tickets
- Email correspondence
- Feedback submissions
G. Reseller Data (if applicable)
- Reseller order history
- Bulk license key assignments
- Transaction records
H. Administrative
- Admin audit logs
- Account restriction records
We do not intentionally collect special categories of data (e.g., racial or ethnic origin, political opinions, health data, biometric data).
3. Legal Basis for Processing
- Contract Performance (Art. 6(1)(b)): Processing necessary to fulfil our obligations under the agreement with you: account creation, license key delivery, subscription management, and fulfilment of the purchase contract.
- Legal Obligation (Art. 6(1)(c)): Processing required to comply with applicable laws, including tax, accounting, and regulatory record-keeping requirements.
- Legitimate Interests (Art. 6(1)(f)): We rely on legitimate interests for fraud prevention, service security, abuse detection, and protection of our license keys from unauthorized distribution. We have assessed these interests against your rights and freedoms and concluded they are necessary, proportionate, and would be reasonably expected by users of a paid digital product. You may object to this processing at any time (see Section 9).
- Consent (Art. 6(1)(a)): Where required by law, we rely on your explicit consent for specific processing activities. In particular, at the moment of purchase you give express consent to the immediate delivery of digital content and acknowledge the resulting waiver of your right of withdrawal under Art. 16(m) of Directive 2011/83/EU. This consent is recorded server-side at the time of checkout and is auditable on request. You may withdraw consent at any time (see Section 9), though withdrawal does not affect the lawfulness of processing carried out beforehand.
4. How We Use Your Information
- Authenticate your identity and manage account access
- Provide, operate, and maintain the Services
- Process purchases, subscriptions, and deliver license keys
- Send security notifications (two-factor authentication, password resets, suspicious activity alerts)
- Monitor for abuse, fraud, and unauthorized access
- Enforce account restrictions and Terms of Service
- Generate aggregated, anonymized statistics to improve the Services
- Provide customer support and respond to inquiries
5. Data Retention
- Account data: Retained for the duration of your account plus 12 months after deletion.
- Billing & transaction data: Retained as required by applicable tax and accounting laws.
- Security logs: Automatically purged after 90 days.
- Support correspondence: Retained for up to 24 months.
- Marketing consent: Retained until withdrawn.
6. Data Sharing & Processors
We share personal data only with the following categories of recipients, and only as strictly necessary to operate the Services. Each processor listed below is bound by a written Data Processing Agreement under Article 28 of the GDPR.
- Stripe Payments Europe, Ltd. (Ireland): Payment processing and checkout. Governed by Stripe's DPA; see also Stripe's Privacy Policy.
- Cloudflare, Inc.: CDN, DDoS protection, and DNS. Governed by the Cloudflare Customer DPA; see also Cloudflare's Privacy Policy.
- Discord Inc.: Optional OAuth sign-in and voluntary community support channel (only if you choose to link your account or join our server). See Discord's Privacy Policy.
- Legal authorities: When required by law, regulation, or a valid legal process.
We do not sell, rent, or trade your personal data to any third party.
7. International Data Transfers
Your personal data is stored and processed on servers physically located within the European Union (Netherlands / Germany). We do not routinely transfer your personal data outside the European Economic Area (EEA).
Where a processor listed in Section 6 may incidentally process data outside the EEA (e.g. Stripe's global payment infrastructure or Cloudflare's edge network), such transfers are governed by the European Commission's Standard Contractual Clauses (SCCs) as incorporated into each processor's Data Processing Agreement, or by an equivalent transfer mechanism recognized under applicable data protection law.
8. Data Security
We implement appropriate technical and organizational measures to protect your personal data, including:
- Encryption of data in transit (TLS) and at rest
- Strict access controls and role-based permissions
- Comprehensive logging and monitoring
- Regular security reviews and vulnerability assessments
9. Your Rights (GDPR)
Under the GDPR, you have the following rights regarding your personal data:
- Right of Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Request correction of inaccurate or incomplete data.
- Right to Erasure: Request deletion of your personal data, subject to legal retention obligations.
- Right to Restriction: Request restriction of processing in certain circumstances.
- Right to Object: Object to processing based on legitimate interests.
- Right to Data Portability: Receive your data in a structured, machine-readable format.
- Right to Withdraw Consent (Art. 7(3)): Where processing is based on your consent, you may withdraw it at any time by emailing [email protected]. Withdrawal does not affect the lawfulness of processing carried out before withdrawal. Note that withdrawing your express consent to immediate delivery of digital content does not reinstate the right of withdrawal under Art. 16(m) of Directive 2011/83/EU once delivery has already begun.
- Right to Lodge a Complaint: File a complaint with your local Data Protection Authority (DPA).
To exercise any of these rights, contact us at [email protected].
10. Automated Decision-Making and Profiling
DND Menu does not carry out any automated decision-making, including profiling, that produces legal effects or similarly significantly affects you within the meaning of Article 22 of the GDPR. License key assignments, reseller eligibility, account moderation, and ban decisions are reviewed by human staff.
11. Cookies
- Essential session cookies required for authentication and CSRF protection.
- Trusted device cookie (30-day expiry, httpOnly) for two-factor authentication persistence.
We do not use tracking cookies, advertising cookies, or third-party analytics cookies.
We only use strictly necessary cookies. Strictly necessary cookies are exempt from the prior-consent requirement under Article 5(3) of the ePrivacy Directive 2002/58/EC (as transposed into national law), which is why we do not display a cookie consent banner.
12. Data Breach Notification
In the event of a data breach that poses a high risk to your rights and freedoms, we will notify affected users and the relevant supervisory authority in accordance with GDPR Articles 33 and 34.
13. Children
The Services are not directed to individuals under the age of 16. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child under 16, we will take prompt steps to delete such information.
14. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with a revised "Last updated" date. Your continued use of the Services after any changes constitutes acceptance of the updated Policy.
15. Contact
For any questions or concerns regarding this Privacy Policy or our data practices, contact us at [email protected] or via our Discord.