← Red Rooster Labs

Privacy Policy

Last updated: 20 July 2026

In short: we collect what we need to sell you a product and deliver it — your email, your order, and your payment confirmation. We do not use advertising or analytics cookies, we do not track you across sites, and we do not sell your personal data.

1. Who is responsible for your data

Red Rooster Labs LLC, a Delaware limited liability company ("Red Rooster Labs", "we", "us"), registered at 8 The Green, Suite B, Dover, DE 19901, United States, is the controller of the personal data described in this policy.

We operate certain products under trade names or "doing business as" (DBA) designations. Unless a product publishes its own privacy policy, this policy applies to it.

Privacy contact: hello@redroosterlabs.com

2. What we collect

When you buy a product

Checkout collects:

  • your email address, which is where the download link is sent;
  • your name and billing country, for the invoice and tax purposes;
  • your company name and VAT or tax ID, if you provide them; and
  • the order itself — which products, the amount, and the date.

We never see your full card details. Payment data is captured and processed by our payment processor; we receive only a confirmation that payment succeeded, plus the last four digits and card brand for reconciliation.

When you ask to be notified about a product in development

The roadmap section of our site has an optional field where you can leave an email address to be told when a product we are building becomes available. If you use it we store only that address and the date you submitted it. We use it for that single purpose, we do not add you to any other mailing, and we do not share it. Ask us at admin@redroosterlabs.com and we will delete it.

When you email us

We keep the message and your address so we can answer and, where relevant, keep a record of the support request against your order.

Information collected automatically

Our hosting provider processes standard server request data, including IP address, to deliver the site and protect it from attack. We do not build profiles from it.

Cookies

This site does not use cookies for analytics, advertising, or tracking. Our payment processor may set cookies strictly necessary to complete your checkout; those are governed by its own privacy policy, linked from the checkout page.

3. Why we use it, and our legal basis

For individuals in the European Economic Area and the United Kingdom, the General Data Protection Regulation (GDPR) requires us to state a legal basis:

  • Selling and delivering a product — legal basis: performance of a contract (Art. 6(1)(b) GDPR).
  • Answering support requests — legal basis: performance of a contract, or our legitimate interest in supporting our customers (Art. 6(1)(b) and 6(1)(f) GDPR).
  • Preventing abuse and securing the site — legal basis: our legitimate interest in protecting our infrastructure (Art. 6(1)(f) GDPR).
  • Meeting tax and accounting obligations — legal basis: compliance with a legal obligation (Art. 6(1)(c) GDPR).

We do not send marketing email unless you separately ask us to. Transactional email about an order you placed — the download link, a receipt, a security or version notice — is not marketing and is sent as part of the sale.

4. Who we share it with

We do not sell or rent personal data. We share it only with service providers who process it on our behalf under contract:

  • Google Cloud Platform — website hosting and storage of order records.
  • Google Workspace — delivery of the notification email generated by your submission, and our business email, where your message is received and read.
  • Our payment processor / merchant of record — to take payment, issue invoices, and handle refunds and chargebacks. Where a merchant of record is used, it is the seller of record for the transaction and an independent controller of your payment data. We do not receive or store your full card details.

We may also disclose personal data where required by law, to enforce our agreements, or in connection with a merger, acquisition, or sale of assets, in which case we will notify affected individuals where required.

5. International transfers

We are established in the United States and our service providers are primarily located there. If you are in the European Economic Area, the United Kingdom, Switzerland, or Latin America, your personal data will be transferred outside your country.

Where required, these transfers rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or an applicable adequacy decision or certification held by the receiving provider. You may request information about the safeguards applied by writing to us.

6. How long we keep it

  • Order records: retained for the period required by tax and accounting rules, typically seven (7) years.
  • Support email: up to 24 months from the last message, then deleted.
  • Abuse-prevention data (IP, user agent): up to 12 months.

7. Your rights

Depending on where you live, you may have some or all of the following rights: access to your data, correction, deletion, restriction of processing, objection to processing, portability, and the right to withdraw consent where processing is based on consent.

European Economic Area and United Kingdom (GDPR / UK GDPR)

You may exercise the rights above and lodge a complaint with your national supervisory authority, or with the UK Information Commissioner's Office, if you believe we have handled your data unlawfully.

California (CCPA / CPRA)

You have the right to know what personal information we collect, to request its deletion or correction, and to be free from discrimination for exercising these rights. We do not sell or share personal information as those terms are defined by the CCPA, and we do not process sensitive personal information for the purpose of inferring characteristics.

Colombia (Ley 1581 de 2012)

You may exercise your rights of access, update, rectification, and deletion ("derechos de acceso, actualización, rectificación y supresión"), revoke your authorisation, and file a complaint with the Superintendencia de Industria y Comercio.

Mexico (LFPDPPP)

You may exercise your ARCO rights (access, rectification, cancellation, and opposition), limit the use or disclosure of your data, and revoke your consent, by writing to the privacy contact below.

How to exercise your rights

Write to hello@redroosterlabs.com. We will respond within the period required by applicable law — within one month under the GDPR, and within 45 days under the CCPA — and we may need to verify your identity before acting. Exercising these rights is free of charge.

8. Security

We apply technical and organisational measures appropriate to the risk, including encryption in transit (HTTPS), access controls with least-privilege permissions, secrets held in a managed secret store rather than in code, and infrastructure hosted on Google Cloud Platform. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

9. Children

The Services are intended for businesses and professionals. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact us and we will delete it.

10. Automated decision-making

We do not carry out automated decision-making that produces legal or similarly significant effects concerning you, as described in Art. 22 GDPR.

11. Changes to this policy

We may update this policy. We will update the "Last updated" date above and, for material changes affecting how we use your data, provide notice where we have your contact details.

12. Contact

Red Rooster Labs LLC
8 The Green, Suite B, Dover, DE 19901, United States
hello@redroosterlabs.com