Privacy policy

Document status: a draft grounded in what the service actually does with data, with the controller's details filled in on 16 August 2026. Before the store launches, have the document reviewed by a lawyer.

1. Who controls your data

The data controller is Daniel Sornek, a private individual not running a registered business, operating the ScriptLab store at https://script-lab.shop.

Data protection contact: [email protected].

2. What we collect and why

PurposeDataLegal basis
Running your accounte-mail address, username, password hash, IP addressArt. 6(1)(b) GDPR (performance of a contract)
Completing a purchase and delivering the scripte-mail address, transaction id, amount and currencyArt. 6(1)(b) GDPR
Issuing and validating licensespurchase e-mail, license key, identifier of the server requesting validation, date and number of validationsArt. 6(1)(b) and (f) GDPR (preventing unauthorised use)
Product reviewsdisplay name, review text and ratingArt. 6(1)(b) and (f) GDPR (content moderation)
Support ticketse-mail address, ticket contentArt. 6(1)(b) GDPR
Newslettere-mail address, date and IP of the sign-up and of the confirmationArt. 6(1)(a) GDPR (consent)
Security and audit logsuser id, IP address, event type and timeArt. 6(1)(f) GDPR (legitimate interest)

We keep the IP address and timestamp of a newsletter sign-up because GDPR requires us to be able to demonstrate that consent was given (Art. 7(1)).

3. Who we share data with

  • Tebex Limited — handles payments, billing and refunds. Payment happens on Tebex's side; we never store card numbers.
  • Cfx.re (FiveM) — a cfx.re account is required to buy, and the purchased script is delivered to "Granted Assets" on the cfx.re portal. Signing in with cfx.re gives us only your forum id and username.
  • Google — only if you choose to sign in with a Google account.
  • E-mail provider (SMTP) — delivers transactional messages and the newsletter.
  • Discord — used for our own operational notifications; we do not send your e-mail address or ticket contents there.
  • Hosting provider — runs the application and the database.

Tutorial videos are embedded from YouTube in no-cookie mode and only after you press play — simply opening a product page does not contact Google's servers.

4. How long we keep data

  • Account — until you delete it.
  • Purchase and billing records — 6 years, as required by tax law.
  • License validation data — 12 months.
  • Security and audit logs — 12 months.
  • Newsletter — until consent is withdrawn; after unsubscribing we keep the record of the consent and its withdrawal, because that record is what proves we acted lawfully.

After account deletion the record is pseudonymised and individual categories are erased on a schedule: marketing data after 30 days, data needed to defend against claims after 3 years, accounting records after 6 years, and final erasure after 10 years. The exact dates are shown in the panel when you confirm the deletion.

5. Your rights

You have the right to access, rectify, erase, restrict and port your data, and to object to processing based on our legitimate interest. Marketing consent can be withdrawn at any time; this does not affect the lawfulness of processing before the withdrawal.

Two of these you can do yourself, without writing to us:

  • Download a copy of your data — in the account panel ("My data").
  • Delete your account — in the account panel, together with the erasure schedule.
  • Unsubscribe from the newsletter — with the link in the footer of every message.

You also have the right to lodge a complaint with the Polish supervisory authority (Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warsaw).

6. Cookies

We use no analytics or advertising cookies and we do not profile visitors. Only cookies strictly necessary for the service to work are set:

CookiePurpose
authjs.session-token, authjs.csrf-tokenkeeping you signed in and CSRF protection
NEXT_LOCALEremembering the chosen language
preferred_currencyremembering the display currency
scriptlab_cart, tebex_basket_statecart contents
cfx_auth_state, cfx_auth_locale, cfx_auth_intentshort-lived cfx.re sign-in data

7. Changes to this policy

We announce material changes on the site, and by e-mail to newsletter subscribers. The date of the last update is shown below this document.