Last updated: 2026-09-15

Privacy Policy

This policy explains what personal data the DayZ PBO Protector site processes, why, and what your choices are. The data controller is Zhao Jinyuan (individual operator). We keep collection minimal and sell no personal data.

1. What we process and where it lives

Identity: your email, name and profile from Logto (our sign-in provider). We receive an identity token at login; the password itself is never visible to us.

Orders and subscriptions: your customer record, orders, subscription state and payment status live with our commerce backend (Medusa). Amounts and timestamps are stored for accounting and entitlement grants.

Payments: card and wallet details are handled entirely by PayPal (USD) or the Epay channel (CNY). We store only the payment's status, amount, currency and provider reference — never PANs or secrets.

Entitlement mirror: a small database (Cloudflare D1) keyed by your customer id records your plan and expiry so the desktop tool can verify access. This is a cache of the order data, not a new purpose.

Site usage: optional, cookie-free aggregate statistics (Cloudflare Web Analytics). No advertising or cross-site tracking pixels are used.

Security logs: request metadata (IP address, timestamp, outcome) in runtime logs, kept by Cloudflare for a limited retention window and used only for abuse control and debugging.

2. Legal bases (where applicable)

Contract (to deliver the service you buy), legitimate interest (security, abuse prevention, aggregate statistics without cookies), and consent where required (e.g. optional analytics features in some jurisdictions).

3. Cookies

We use strictly necessary cookies only: a signed session cookie, a short-lived login-intent cookie, and a language preference cookie. See the cookies page for the list. No advertising or tracking cookies.

4. Retention

Identity and entitlement data are kept while your account is active. Order and tax-relevant records are kept as long as applicable law requires. Security logs roll automatically.

5. Sharing

We share data only with the processors named above (Logto, Medusa host, PayPal, Epay, Cloudflare) and, in a legal dispute, with authorities on valid request. We do not sell or rent personal data.

6. Your choices

Email 13680421384a@gmail.com from your account address to request a copy, correction, export or deletion of your data, or an objection to a processing activity. Deletion may be limited by records we must keep for taxes or fraud prevention; we will tell you what remains and why.

7. Security

Transport is HTTPS-only (HSTS). Session cookies are signed and encrypted (JWE) and marked HttpOnly. Secrets are stored in platform-protected secret stores, never in source code. No system is perfectly secure; report concerns to the address above.

8. Changes

If this policy changes materially we will note it on the changelog page; the "last updated" date at the top always reflects the current version.