Privacy Policy last revised: July 14, 2018

Table of Contents

  1. Scope
  2. Types of Data We Collect
  3. Cookies and Similar Technologies
  4. Use of Your Personal Data
  5. Our Disclosure of Your Personal Data
  6. Account Protection
  7. Your Choices
  8. Security
  9. International Transfers
  10. Third Parties
  11. Changes to this Privacy Policy
  12. Contact Us
  13. Additional Information for European Union Users

1. Scope

This Privacy Policy describes how we handle your personal information for our Service on the Gumroad websites, tools, and mobile applications. It applies generally to information collected on the Gumroad.com website, mobile application and content (collectively, the "Site" or “Sites”) or though the use of our Service. Capitalized terms used in this Privacy Policy shall have the meaning set forth herein or in the User Agreement posted on the Site.

If you established a Gumroad account before the “last revised” date above, this Privacy Policy is effective as of August 15th, 2018. For all other individuals, the Privacy Notice is effective immediately.

2. Types of Data We Collect

We may collect and store the following Personal Data:

3. Cookies and Similar Technologies

What are cookies?

Cookies are small data files stored on your computer or mobile device by a website. Our Sites may use both session cookies (which expire once you close your web browser) and persistent cookies (which stay on your computer or mobile device until you delete them) to provide you with a more personal and interactive experience on our Site.

We use two broad categories of cookies: (1) first party cookies, served directly by us to your computer or mobile device, which we use to recognize your computer or mobile device when it revisits our Sites; and (2) third party cookies, which are served by service providers or business partners on our Sites, and can be used by such service providers or business partners to recognise your computer or mobile device when it visits other websites.

Cookies we use

Our Site uses the following types of cookies for the purposes set out below:

Disabling cookies

You can typically remove or reject cookies via your browser settings. In order to do this, follow the instructions provided by your browser (usually located within the “settings,” “help” “tools” or “edit” menus). Many browsers are set to accept cookies until you change your settings.

For further information about cookies, including how to see what cookies have been set on your computer or mobile device and how to manage and delete them, visit www.allaboutcookies.org.

If you do not accept our cookies, you may experience some inconvenience in your use of our Site. For example, we may not be able to recognize your computer or mobile device and you may need to log in every time you visit our Site.

Other technologies

In addition to cookies, our Sites may use other technologies, such as Flash technology, pixel tags, and software development kits (or SDKs) to collect information automatically.

Flash Technology

We may use Flash cookies (which are also known as Flash Local Shared Object (“LSOs”)) on our Site to collect and store information about your use of our Site. Unlike other cookies, Flash cookies cannot be removed or rejected via your browser settings. If you do not want Flash cookies stored on your computer or mobile device, you can adjust the settings of your Flash player to block Flash LSO storage using the tools contained in the Website Storage Settings Panel at this website. You can also control Flash LSOs by going to the Global Storage Settings Panel at this website and following the instructions. Please note that setting the Flash Player to restrict or limit acceptance of Flash LSOs may reduce or impede the functionality of some Flash applications, including, potentially, Flash applications used in connection with our Site.

Pixel tags

We may also use pixel tags (which are also known as web beacons and clear GIFs) on our Site and in our HTML formatted emails to track the actions of users on our Site and interactions with our emails. Unlike cookies, which are stored on the hard drive of your computer or mobile device by a website, pixel tags are embedded invisibly on webpages or within HTML formatted emails. Pixel tags are used to demonstrate that a webpage was accessed or that certain content was viewed, typically to measure the success of our marketing campaigns or engagement with our emails and to compile statistics about usage of the Site, so that we can manage our content more effectively.


Software Development Kits

Our mobile applications may use software development kits (“SDKs”) provided by third parties. SDKs enable us to provide features and functionality developed by third-party developers, including to provide us with analytics, social media integration, and advertising. The SDKs we use may enable third parties to collect information about the users of our mobile applications. The types of SDKs we use include:

We maintain a list of SDKs used in our App here: http://help.gumroad.com/326594-what-sdks-are-used-in-your-mobile-applications.

4. Use of Your Personal Data
Use of Personal Data About Buyers on Behalf of Our Sellers.

We use personal information we collect about buyers from or on behalf of our sellers to provide services only as directed or authorized by the seller. We do not use this information for our own purposes. Typically, our clients direct or authorize us to use personal information collected on their behalf to enable ecommerce and payments functionality on our clients’ websites, to manage the delivery of electronic goods, and to deliver communications from the sellers to their buyers.

5. Our Disclosure of Your Personal Data

We may disclose Personal Data to respond to legal requirements, enforce our policies, respond to claims that a listing or other content violates the rights of others, or protect anyone's rights, property, or safety. Such information will be disclosed in accordance with applicable laws and regulations.

We may also share your Personal Data with:

6. Account Protection

Your password is the key to your account. Use unique numbers, letters and special characters, and do not disclose your Gumroad password to anyone. If you do share your password or your Personal Data with others, remember that you are responsible for all actions taken in the name of your account. If you lose control of your password, you may lose substantial control over your Personal Data and may be subject to legally binding actions taken on your behalf. Therefore, if your password has been compromised for any reason, you should immediately notify Gumroad and change your password.

7. Your Choices

Accessing, Reviewing and Changing Your Personal Data

You may change any of your Personal Data in your account by editing your profile within your account or by sending an e-mail to us at the e-mail address set forth below. You may request deletion of your Personal Data by us, but please note that we may be required to keep this information and not delete it (or to keep this information for a certain time, in which case we will comply with your deletion request only after we have fulfilled such requirements). Upon your request, we will close your account and remove your Personal Data from view as soon as reasonably possible, based on your account activity and in accordance with applicable law. We do retain Personal Data from closed accounts to comply with law, prevent fraud, collect any fees owed, resolve disputes, troubleshoot problems, assist with any investigations, enforce our User Agreement, and take other actions otherwise permitted by law.

Marketing communications

You may opt out of marketing-related emails by clicking on a link at the bottom of our marketing emails, or by contacting us at support@gumroad.com. You may continue to receive service-related and other non-marketing emails.

Targeted online advertising

Some of the business partners that collect information about users’ activities on our Sites may be members of organizations or programs that provide choices to individuals regarding the use of their browsing behavior or mobile application usage for purposes of targeted advertising.

Users may opt out of receiving targeted advertising on websites through members of the Network Advertising Initiative by clicking here: www.networkadvertising.org/choices, or the Digital Advertising Alliance by clicking here: www.aboutads.info/choices. European users may opt out of receiving targeted advertising on websites through members of the European Interactive Digital Advertising Alliance by clicking here: https://www.youronlinechoices.eu/, selecting the user’s country, and then clicking “Choices” (or similarly-titled link). Mobile app users may opt out of receiving targeted advertising in mobile apps through participating members of the Digital Advertising Alliance by installing the AppChoices mobile app, available here: https://www.youradchoices.com/appchoices, and selecting the user’s choices. Please note that we also may work with companies that offer their own opt-out mechanisms and may not participate in the opt-out mechanisms that we linked above.

If you choose to opt-out of targeted advertisements, you will still see advertisements online but they may not be relevant to you. Even if you do choose to opt out, not all companies that serve online behavioural advertising are included in this list, and so you may still receive some cookies and tailored advertisements from companies that are not listed.

In addition, your mobile device settings may provide to limit our, or our partners’, ability to engage in ad tracking or targeted advertising using the Google Advertising ID or Apple ID for Advertising associated with your mobile device.

Do Not Track Signals

Some Internet browsers may be configured to send "Do Not Track" signals to the online services that you visit. We currently do not currently respond to do not track signals. To find out more about "Do Not Track," please visit http://www.allaboutdnt.com.

Choosing not to share your personal information

Where we are required by law to collect your personal information, or where we need your personal information in order to provide our services to you, if you do not provide this information when requested (or you later ask to delete it), we may not be able to provide you with our services. We will tell you what information you must provide to receive the services by designating it as required in or on the Sites or through other appropriate means.

8. Security

Your information is stored on our servers located in the United States. We use a variety of security technologies and procedures to help protect your Personal Data from unauthorized access, use or disclosure. However, as you probably know, third parties may unlawfully intercept or access transmissions or private communications, and other Users may abuse or misuse your Personal Data that they collect from the Site. Therefore, we do not promise, and you should not expect, that your Personal Data or private communications will always remain private.

9. International Transfers

Gumroad is headquartered in the United States and has service providers in other countries, and your personal information may be transferred to the United States or other locations outside of your state, province, country or other governmental jurisdiction where privacy laws may not be as protective as those in your jurisdiction.

European Union users should read the important information provided here about transfer of personal information outside of the European Economic Area: https://www.dataprivacymonitor.com/cybersecurity/cross-border-data-transfers-cutting-through-the-complexity/.

10. Third Parties

Except as otherwise expressly included in this Privacy Policy, this document addresses only the use and disclosure of information we collect from you. If you disclose your information to others, whether they are bidders, buyers or sellers on our Site or other sites throughout the Internet, different rules may apply to their use or disclosure of the information you disclose to them. Gumroad does not control the privacy policies of third parties, and you are subject to the privacy policies of those third parties where applicable. We encourage you to ask questions before you disclose your Personal Data to others.

11. Changes to this Privacy Policy

We reserve the right to modify this Privacy Policy at any time. We encourage you to periodically review this page for the latest information on our privacy practices. If we make material changes to this Privacy Policy, we will notify you by updating the date of this Privacy Policy and posting it on the Sites and in the app stores where our mobile applications are available for download. We may (and, where required by law, will) also provide notification of changes in another way that we believe is reasonably likely to reach you, such as via e-mail (if you have an account where we have your contact information) or another manner through the Sites.

Any modifications to this Privacy Policy will be effective upon our posting of the new terms and/or upon implementation of the new changes on the Sites (or as otherwise indicated at the time of posting). In all cases, your continued use of the Sites after the posting of any modified Privacy Policy indicates your acceptance of the terms of the modified Privacy Policy.

12. Contact Us

If you have any questions or concerns at all about our Privacy Policy, please feel free to email us at support@gumroad.com.

13. Additional Information for European Union Users

Personal information

References to “personal information” in this Privacy Policy are equivalent to “personal data” governed by European data protection legislation.

Controller

For purposes of European data protection legislation, Gumroad, Inc. is the controller of personal information that we collect for our own business purposes. See the Contact Us section above for contact details.

Gumroad acts as a processor to sellers through the Services, as described throughout this Privacy Policy. When we act as a processor to a seller, the relevant seller is the data controller of your personal information processed in connection with the sale or delivery of goods to you.

Legal bases for processing

We use your personal information only as permitted by law. We are required to inform you of the legal bases of our processing of your personal information, which are described in the table below. If you have questions about the legal basis of how we process your personal information, contact us at support@gumroad.com.

Use for new purposes

When we act as a data controller, we may use your personal information for reasons not described in this Privacy Policy where permitted by law and the reason is compatible with the purpose for which we collected it. If we need to use your personal information for an unrelated purpose, we will notify you and explain the applicable legal basis.

Retention

We will only retain your personal information for as long as necessary to fulfil the purposes for which we collected it, including for the purposes of satisfying any legal, accounting, or reporting requirements.

To determine the appropriate retention period for personal information, we consider the amount, nature, and sensitivity of the personal information, the potential risk of harm from unauthorized use or disclosure of your personal information, the purposes for which we process your personal information and whether we can achieve those purposes through other means, and the applicable legal requirements.

When we no longer require the personal information we have otherwise collected about you, we will dissociate such information from the information attached to your content. In some circumstances we may anonymize your personal information (so that it can no longer be associated with you), in which case we may use this information indefinitely without further notice to you.

Your rights

European data protection laws give European Union users certain rights regarding their personal information. If you are located within the European Union, you may ask us to take the following actions in relation to your personal information that we hold in the capacity of a data controller:

You can submit these requests by email to support@gumroad.com or our postal address provided above. We may request specific information from you to help us confirm your identity and process your request. Applicable law may require or permit us to decline your request. If we decline your request, we will tell you why, subject to legal restrictions. If you would like to submit a complaint about our use of your personal information or response to your requests regarding your personal information, you may contact us as described above or submit a complaint to the data protection regulator in your jurisdiction. You can find your data protection regulator here.

To the extent we act as a processor on behalf of a seller, individuals should contact the relevant seller to exercise the rights and choices described in this section.

Cross-Border Data Transfer

Whenever we transfer your personal information out of the EEA to countries not deemed by the European Commission to provide an adequate level of personal information protection, the transfer will be based:

Please contact us if you want further information on the specific mechanism used by us when transferring your personal information out of the EEA.