Legal
Privacy
Policy
Last updated: July 2026 · Ignacio Rauscher, Vienna, Austria
01
Who We Are
Ignacio Rauscher (trading as "New Sound Studio", "NSS", "we", "us") operates the website newsound-studio.com. We are the data controller responsible for your personal data. You can reach us at nachorauscher@gmail.com.
This policy explains what data we collect, how we use it, and your rights under the General Data Protection Regulation (GDPR) and Austrian data protection law.
02
What Data We Collect
We collect the following categories of personal data:
- Account data: email address, username, password hash, account role, and security settings when you register or manage an account.
- Purchase and seller data: order history, licenses, download activity, payout status, and the identifiers needed to connect purchases and payouts to Stripe.
- Payment data: Stripe processes card and payment details. We do not store full card numbers, bank details, or CVV codes on our servers.
- Usage data: page and product interactions, beat plays and listening duration, session or account identifiers, approximate country supplied by the hosting edge, and browser/device information. This data may be pseudonymous rather than anonymous.
- Community data: public forum posts, beat requests and service offers, plus private conversation messages and deal status, together with usernames and timestamps.
- Communication data: emails, support and bug reports, seller applications, and information you voluntarily enter into the optional AI chatbot.
- Security data: login metadata and short-lived, single-use two-factor authentication records. A 2FA code cannot be used after its ten-minute validity window.
- Newsletter data: email address, signup source, consent status, and consent timestamp when you subscribe. Marketing mail requires confirmation through double opt-in.
03
How We Use Your Data
We use personal data to operate accounts; process orders, licenses, downloads, and seller payouts; send transactional messages; provide community and support features; prevent abuse and fraud; analyse and improve the service; and meet legal obligations.
The legal basis depends on the activity: contract performance for orders and requested services, legitimate interests for security, fraud prevention, service analytics, and platform operation, consent for optional marketing, and legal obligations where records must be retained or disclosed by law.
The AI chatbot is optional. Please do not enter passwords, payment-card data, or other sensitive information into it.
04
Service Providers
We disclose only the data needed to operate the relevant feature to these service providers:
- Stripe for payment processing, subscriptions, refunds, and seller payouts.
- Supabase for database, account, authentication, order, and community data.
- Resend for transactional email, including account and order messages.
- Brevo for newsletters or administrative email campaigns when those features are used.
- Cloudflare R2 for public preview assets and protected delivery of purchased digital files.
- Cloudflare Turnstile for automated-abuse protection during registration.
- Netlify for website hosting, edge delivery, and serverless request processing.
- Groq for the optional AI chatbot. The chatbot sends the text and recent chat context you provide, together with public catalogue context; it is designed not to include your account email or purchase history.
Some providers may process data outside the European Economic Area. Where GDPR requires it, international transfers must use an applicable adequacy decision, Standard Contractual Clauses, or another lawful transfer mechanism.
We do not sell personal data or share it with third-party advertisers.
05
Cookies & Local Storage
NSS uses browser local storage for functions such as the cart, language and currency preferences, recommendations, chatbot history, and—when you are logged in—your authentication token. The authentication token is sent only to our own authenticated API endpoints. You can remove local data through your browser settings, but doing so may sign you out and reset preferences.
We use a small cookie to remember that the newsletter popup was dismissed. NSS does not use advertising cookies. Cloudflare Turnstile may process technical device and network signals that are necessary to distinguish people from automated abuse.
06
Data Retention
- Account profile data is kept while the account exists and removed following verified account deletion, except where specific records must be retained by law or for the establishment, exercise, or defence of legal claims.
- Purchase, payment, and payout records are retained for the period required by applicable Austrian tax and accounting law.
- Community content and conversations are kept while needed to provide and moderate the service, subject to valid deletion requests and the rights of other conversation participants.
- Usage and security records are kept only as long as reasonably necessary for analytics, abuse prevention, and operational security, and are subject to periodic retention review.
- 2FA codes expire after ten minutes, are single-use, and are removed from the database during retention cleanup.
- Newsletter records are retained until consent is withdrawn or they are no longer needed to document consent and compliance.
07
Your Rights (GDPR)
Depending on the circumstances, you may have rights of access, rectification, erasure, restriction, portability, and objection, and the right to withdraw consent at any time without affecting prior lawful processing.
To exercise a right, contact nachorauscher@gmail.com. We may need to verify your identity. You also have the right to lodge a complaint with the Austrian Data Protection Authority (DSB).
08
Changes to This Policy
We may update this Privacy Policy when the service or legal requirements change. We will update the date above and provide additional notice where required.
09
Contact
Ignacio Rauscher
Josef-Schuster-Gasse 1/3/4, 1130 Vienna, Austria
nachorauscher@gmail.com