LabelPilot
LabelPilot
INDUSTRIAL LABELING SYSTEM
FeaturesHardwareBarcodesFAQ
RUENDEUA
Demo
Sign inSign up
LEGAL

Privacy Policy

Last updated: 2026-07-20

This policy describes what data Hryhorii Fedorovskyi (sole proprietorship, Germany) (the “Operator”) processes when you use the LabelPilot site and service, and how it is protected. The Operator is the controller (Verantwortlicher) under the GDPR.

1. Data we process

Account data: email address, name or company name (on registration and in the account area).

Licensing data: server machine_id, order history, payment statuses and issued licenses (including license identifiers).

Installer download logs: IP address, approximate country (from CDN headers), browser User-Agent, referer (if sent), request time, installer type (client/server), and—if signed in—user id and email. The client (demo) installer may be downloaded before payment; the server installer is provided after payment / from the account area. Records are written server-side (Edge Function / database) and are not cookies.

Telemetry from an installed LabelPilot server component (the server is supplied after payment; when Internet is available): machine_id (one-way hash, not a full PC hardware fingerprint); whether a license is present/valid; license_id; software version; boot/heartbeat, .lpl activation, export/encrypt denials and commercial-use attempts without a license; IP and country at event time. The client demo does not send these events. Catalog, labels and production data are not sent. Disable with LICENSE_TELEMETRY=0 or by running offline.

Infrastructure technical data: hosting and CDN operational logs (e.g. Supabase, Vercel) needed to run and secure the service.

Payment data is processed by Stripe; the Operator does not store bank card details.

The Operator does not use advertising browser fingerprinting (Canvas/WebGL, etc.) and does not sell personal data.

2. Purposes

Issuing and supporting licenses, performing the contract (public offer), communicating with the User, accounting, and meeting legal requirements.

Service security: preventing and investigating abuse, unauthorized access, DDoS and other attacks.

Protecting exclusive rights in the LabelPilot software: accounting for installer downloads (including the server installer after payment); supporting paid server installs; detecting and documenting use of the server component without a license, license-protection circumvention, redistribution of installers, and other breaches of the offer; preparing evidence where necessary.

Technical support and keeping the site operational (no marketing profiling while third-party analytics is not enabled).

3. Legal bases (GDPR)

Art. 6 (1) lit. b GDPR — performance of a contract and steps prior to entering into a contract (registration, payment, license issuance, access to installers after payment).

Art. 6 (1) lit. c GDPR — compliance with legal obligations (e.g. tax/accounting retention where applicable).

Art. 6 (1) lit. f GDPR — legitimate interests of the Operator: service security, fraud prevention, protection of intellectual property, and investigation of license-term breaches / unauthorized software use. These interests are balanced: download logs use only necessary fields, access is limited to authorized staff, and data is not used for advertising.

Art. 6 (1) lit. a GDPR — consent, where consent is expressly requested (e.g. future marketing analytics). Withdrawal does not affect lawfulness before withdrawal.

4. Third parties

To run the service, data is processed by infrastructure providers: Supabase (hosting, database, Edge Functions), Stripe (payments), GitHub and/or CDN (installer delivery), static site hosting (e.g. Vercel).

These services may process data outside the User's country (including in the EU/EEA or with GDPR-appropriate safeguards). The Operator does not sell personal data or share it with third parties for their own advertising.

Where legally required (court or competent authority), the Operator may disclose data to the extent required by applicable law.

5. Retention and security

Account and licensing data are kept while the account/contract exists and as long as needed for accounting and enforcement of rights (claims), generally not longer than applicable limitation and tax periods unless law requires otherwise.

Download logs (IP, User-Agent, country, email/user_id if any, file type, timestamp) are kept as a rule for up to 24 months, unless a longer period is required for a specific dispute, security incident or legal obligation. After that, records may be anonymized or deleted.

Technical and organizational measures apply: TLS, access control (including RLS / staff role), and data minimization.

6. Your rights

Under the GDPR you may request access, rectification, erasure, restriction, portability (where applicable), object to processing based on legitimate interests, and lodge a complaint with a supervisory authority (in Germany, the competent Landesdatenschutzbehörde; or your local EU authority).

Send requests to h.fedorovskyi@outlook.com. The Operator will respond within GDPR timelines.

An objection to security / rights-enforcement logs may be refused where processing remains necessary to protect the Operator's rights or service security, within the law.

7. Cookies and local storage

The site uses necessary technical storage: login session and UI language preference (localStorage). Optional visit analytics storage is used only after separate consent; see the details below.

Logging of IP and User-Agent on installer downloads is performed server-side and is not the setting of cookies in the browser.

Third-party marketing/statistics analytics (e.g. Google Analytics) is not currently enabled. If added, this policy will be updated and consent will be requested where required.

8. Relationship to the offer and software protection

Terms of use of the Software, the ban on commercial use without a license, and the ban on circumventing protection are set out in the public offer (/offer). Processing of download and account data supports performance of those terms and protection of the Operator's rights in the Software.

9. Contact

Operator (controller): Hryhorii Fedorovskyi (sole proprietorship, Germany), Loewestr. 7, 40724 Hilden, Deutschland. Wirtschafts-IdNr: DE462300658-00001. Data questions: h.fedorovskyi@outlook.com. See also the Impressum.

Website visit analytics

When analytics is enabled, visitors in the 27 EU countries and territories that are part of the EU, Iceland, Liechtenstein, Norway, the United Kingdom and Switzerland, or with an unknown country, are tracked only after separate consent. The operator can add other countries or require consent everywhere. The server estimates country from trusted Vercel data, not the page language. In other countries, collection starts without a prior question unless a refusal is stored. Do Not Track and Global Privacy Control disable collection in every country.

Supabase stores an event identifier, timestamp, public-page path without query or fragment, language, server-determined country, referrer hostname, coarse device category, browser and OS family, the full server-validated IP address, a random session UUID and collection mode: accepted (consent) or regional_default (regional default). These statistics are not anonymous: IP addresses and session identifiers are personal data. Names, emails, form contents, raw User-Agent and precise coordinates are not stored; fingerprinting and advertising profiling are not used. Only staff/admin users can view the statistics.

When tracking is permitted, sessionStorage holds a random UUID per tab, renewed after 30 minutes of inactivity. The consent or refusal choice is stored in localStorage for up to 180 days. Persistent “Analytics settings” and a privacy-policy link at the bottom of public pages let you opt out, change your choice or withdraw consent. Refusal does not restrict use of the site and stops future collection. Old version 1 acceptance does not cover the new IP collection: fresh version 2 consent is required in consent-required regions. A previously stored refusal remains effective within its choice-retention period.

A daily job nulls IP addresses on events older than 30 days and deletes events older than 90 days. Physical cleanup can occur up to 24 hours after each threshold: an IP may remain for up to 31 days and an event for up to 91 days. Opting out does not itself delete previously stored events; these retention periods still apply. Vercel also processes the incoming IP for request delivery and country estimation; infrastructure logs are handled separately.

This regional setting describes site behavior, not a certification that automatic collection is lawful in every other country. Before enabling analytics, the operator must review applicable requirements, the legal basis for processing and whether additional countries require consent.

Public Offer (Terms)Privacy PolicyRefund Policy
LabelPilot
LabelPilot
Industrial Labeling System
ImpressumTermsPrivacyRefunds
© 2026 LabelPilot · Hryhorii Fedorovskyi