VAMfor MacBack to website

Privacy Policy

Version 2026-10-10 · Last updated 10 October 2026

1. Who is responsible

The controller is Grupa Portalowa Bartosz Kaczmarek, at ul. Św. Wawrzyńca 7, 62-045 Pniewy, Poland, registration/tax number Polish tax ID (NIP) 7871974559. Contact for privacy and data requests: support@macsnapshotbackup.com. Website: vam4mac.com. This policy covers the website, purchase process and our launcher services. Third-party software and services have their own privacy notices.

2. Website and checkout data

The landing page does not install advertising trackers, analytics or newsletter forms. Our website code does not set first-party tracking cookies or store marketing identifiers in your browser. Technical checkout retry identifiers are held in page memory and are not advertising identifiers.

Our hosting and security providers may process your IP address, requested URL, browser information, request time and error information to deliver the website and protect it. Our website and licensing service are hosted by dhosting.pl, which may process these technical records on our behalf. The period depends on the security purpose and any incident being investigated.

Stripe hosts checkout and processes payment information, including payment method and billing details you enter. We do not receive or store your full card number or card security code. We may receive your checkout email, Stripe customer/subscription and order identifiers, payment status, amount, currency, invoice information and any billing details required for tax or support.

The order database stores verified event and checkout identifiers, payment/subscription references, checkout email, the selected plan, accepted terms and delivery consent. License codes and queued email contents are encrypted at rest. Purchase and recovery messages are sent through our hosting provider to the purchase email address. A test-mode checkout, when explicitly labelled as such, must not contain real card details and does not issue paid access.

3. Activation and launcher data

When account and license activation are enabled, we process the email used for the purchase or account, authentication and activation records, entitlement type, trial start, payment status, license expiry and last verification time. A device identifier and public device key bind access to one Mac and prevent ordinary license sharing or repeated trials. Device private keys are kept on the Mac; they are not sent to our server.

A hashed or pseudonymous device identifier is still personal data when linked to an account. We do not describe it as anonymous. We request only the device and platform information needed for activation, compatibility and fraud prevention.

We do not require upload of your scenes, add-ons, gameplay recordings or headset camera footage for licensing. VR images, head/controller movement and audio used for play are processed between the Mac and headset. Local diagnostic logs may contain paths, device information or error messages. Send diagnostics to support only after reviewing them; do not include private scene files or secrets.

Messages you send to support may include your contact details, order reference, problem description and voluntarily supplied diagnostics. No marketing subscription is implied by a purchase or support request.

4. Purposes and legal bases

Providing payment and activation data is necessary for a paid license. Without it, we cannot verify payment or issue access. Optional support attachments are not required to buy. The acknowledgement about immediate digital delivery is a consumer-contract choice, not blanket consent to personal-data processing.

5. Recipients and international transfers

Data may be shared with Stripe for payments; contracted hosting/database, email-delivery and support providers when those services are used; authorized personnel who need it; and public authorities when legally required. We do not sell personal data or share gameplay for advertising.

Stripe may process information outside your country, including outside the EEA. See Stripe’s Privacy Policy for its roles, safeguards and privacy contacts. For transfers we control that require GDPR safeguards, we use a valid adequacy decision or appropriate contractual safeguards and any necessary supplementary measures. You can request information about those safeguards from us. We confirm any new provider and required transfer safeguards before disclosing data to it.

6. Retention

We keep personal data only for a necessary purpose. Account and entitlement records are kept while the account or license remains relevant to providing access; financial records for the statutory accounting/tax period; security logs for the proportionate period needed to detect or investigate abuse; and complaint or dispute records for the applicable limitation period.

A minimal device/trial record may be retained after reinstall or account closure where necessary and justified to prevent repeated trials. It is not a reason to keep all account data indefinitely. We review necessity, restrict retained records to that purpose and honor applicable objection or erasure rights. Test records are reviewed and deleted when no longer required for integration verification or a documented legal need. You may ask for the retention period or criteria applicable to your particular records.

7. Your rights

Where GDPR applies, you may request access, correction, erasure, restriction and portability of eligible data; object to processing based on legitimate interests; and withdraw consent for processing based on consent without affecting prior lawful processing. Some rights have legal exceptions, for example required accounting retention. We may proportionately verify your identity before releasing account information.

Contact the email in section 1. We respond within the applicable deadline, normally one month under GDPR, and explain any lawful extension. You may complain to the data-protection authority in your place of residence, work or the alleged infringement. For Poland, this is the President of the Personal Data Protection Office, UODO. Consumers elsewhere retain any applicable local privacy rights.

8. Security and automated checks

We use appropriate technical and organizational measures for the services we operate, such as access controls, encrypted connections and verified payment notifications. No system is completely secure. An activation check can automatically refuse a launch when it cannot confirm a valid entitlement. You may contact support to challenge an incorrect refusal and request review. We do not use this data for advertising profiling.

9. Changes and contact

We update this policy when processing changes and publish the new date. Where required, we give advance notice or obtain consent for a new purpose. Contact the controller in section 1 for questions, privacy requests or copies of relevant safeguards.