iZdigi.
AUTONOMOUS WEB INFRASTRUCTURE
DATA PROTECTION // GDPR & CCPA READY

Privacy Policy

Effective Date: October 1, 2026•Last Updated: October 1, 2026•Version 1.0

Privacy Pledge: iZdigi operates on strict Privacy-by-Design principles. We do not sell, rent, or monetize your personal data. We collect only the minimum technical parameters required to deliver digital code licenses, operate customer webhooks, and provide engineering support.

1. Core Data Protection Principles

At iZdigi, we consider data privacy a fundamental architectural requirement. Our infrastructure follows three non-negotiable rules:

  • Zero Data Monetization: We will never sell, lease, exchange, or trade your personal identifiable information (PII) to data brokers, advertising networks, or third-party marketing entities.
  • Data Minimization: We only store information strictly necessary for transaction fulfillment, license activation, and server health monitoring.
  • Zero Invasive Tracking: We do not inject invasive cross-site tracking scripts or behavioral ad cookies.

2. Data We Collect and How We Process It

Depending on your interaction with iZdigi, we process the following categories of data:

2.1 Transaction & Licensing Telemetry (Lemon Squeezy MoR)

When you purchase a Landing Kit, Commercial Code License, or technical service, transaction billing is handled directly by Lemon Squeezy, LLC. We receive an automated, cryptographically signed webhook notification (HMAC-SHA256) containing:

  • Customer email address and full name for license generation.
  • Lemon Squeezy Order ID, purchase timestamp, and product SKU.
  • Tax country/region identifier to facilitate VAT/GST compliance auditing.

Note: We never access, capture, or store your credit card numbers, CVC codes, or banking credentials.

2.2 Cookieless Web Performance Telemetry

We utilize Cloudflare Web Analytics to measure site performance, Core Web Vitals, and aggregate traffic patterns. This system is entirely cookieless: it does not use client-side storage, does not profile individuals, and respects "Do Not Track" (DNT) headers.

2.3 Inbound Inquiries & n8n Automation Webhooks

When you submit a contact or service inquiry form on izdigi.com, information (name, work email, project requirements) is routed directly through secure HTTPS webhooks to an isolated self-hosted n8n container. This data is strictly used to evaluate and reply to your engineering request.

3. Authorized Third-Party Sub-Processors

To deliver global digital distribution and high-availability hosting, we partner with industry-leading technical infrastructure providers:

Sub-ProcessorRole / Processing ActivityJurisdiction & Compliance
Lemon Squeezy, LLCMerchant of Record, payment processing, tax remittance, fraud preventionUSA • PCI-DSS Level 1
Cloudflare, Inc.Global CDN edge routing, DDoS shielding, cookieless telemetryUSA / Global Edge • SOC 2 Type II
Hetzner Online GmbHIsolated cloud server hosting for n8n workflows and WaaS stagingGermany (EU) • GDPR Compliant / ISO 27001

4. Your Rights Under GDPR & CCPA

Regardless of your geographic location, iZdigi affords all customers the core privacy safeguards defined by the European General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA):

  • Right of Access: You may request a machine-readable export of all personal information and order records linked to your email address.
  • Right to Rectification: You may request corrections to inaccurate contact or licensing metadata.
  • Right to Erasure ("Right to Be Forgotten"): You may request the permanent deletion of your customer records, inquiry histories, and webhook logs from our internal systems within thirty (30) calendar days.
  • Non-Discrimination: We do not offer degraded service or pricing differences if you choose to exercise your legal privacy rights.

5. Data Security Standards & Contact Information

All data in transit across izdigi.com is encrypted using modern Transport Layer Security (TLS 1.3). Application secrets, database credentials, and webhook keys are managed through isolated environment variables and never committed to version-controlled repositories.

To submit a data access request, execute your right to erasure, or raise privacy questions, please contact our Data Protection Officer:

Privacy Desk[email protected]