1. What we collect
Account details: display name, username, email address, what you make and a password (stored only as a salted hash). Orders: the items, the contact and delivery details you enter at checkout, the payment reference and status returned by the payment provider. We never see or store full card numbers; card details go straight from your browser to the payment provider.
Content you create: forum topics and replies, room and direct messages. Technical data: IP address, browser and device type, pages visited and the time of each request.
2. Why we use it
We rely on the contract with you for accounts and orders, on our legitimate interest in running a safe and useful service for security and analytics, and on your consent where the law requires it. We do not sell personal data and we do not use it for third-party advertising.
- To run your account and keep you signed in.
- To process orders, deliver downloads and course access, send receipts and let sellers fulfil what you bought.
- To show your public profile, shop, posts and messages to the people you chose to share them with.
- To keep the site safe: rate limits, fraud checks and the investigation of abuse reports.
- To improve the site using aggregated usage statistics.
4. How long we keep it
Account data for as long as your account exists, then 30 days. Order and receipt records for the period required by tax and accounting law (typically 7 years). Messages and community posts until you delete them or your account is closed; public posts may remain visible with the author shown as “Former member”. Security logs for 90 days.
5. Your choices and rights
Depending on where you live you can ask for a copy of your data, have it corrected or deleted, restrict or object to its use, and take it elsewhere in a machine-readable format. Write to privacy@norla.io; we answer within 30 days.
You can edit your profile and shop, delete your own listings and close your account from the account page at any time.
7. International transfers and security
Data is stored in the hosting provider's data centres, which may be outside your country, under standard contractual clauses or equivalent safeguards. Connections are encrypted (TLS), passwords are hashed and access to stored data is limited to staff who need it.
8. Changes and contact
We update this policy when our practices change and show the effective date at the top. Controller: [operating company name and address to be confirmed]. Contact: privacy@norla.io.