Consumer Privacy, GDPR & International Compliance Statement

Last Updated: September 7, 2026

This statement outlines the comprehensive data protection framework, privacy principles, and regulatory compliance standards maintained by FastrSoft (https://fastrsoft.com) in compliance with the General Data Protection Regulation (GDPR – EU & UK), the California Consumer Privacy Act as amended by CPRA (CCPA/CPRA), and international e-commerce and merchant standards (IBC Policy).


1. Regulatory Roles: Controller vs. Processor

Understanding our data protection posture requires distinguishing between how fastrsoft.com operates and how our self-hosted software plugin (Pixel Ultimate Pro) functions.

A. FastrSoft as a Data Controller (Our Website & Licensing)

FastrSoft acts as a Data Controller with respect to personal information you submit directly to us (e.g., your account username, email address, support tickets, and license activation tokens).

B. Pixel Ultimate Pro as Self-Hosted On-Premise Software

  • Zero Centralized Telemetry on Customer Orders: Pixel Ultimate Pro is an on-premise, self-hosted WordPress plugin installed directly on your web server.
  • Direct Server-to-Server: When the plugin dispatches Server-Side Conversions API (CAPI) events to Meta, Google, TikTok, or Pinterest, the data travels directly from your WordPress server to the ad platform API endpoints.
  • FastrSoft Never Intercepts Store Data: FastrSoft does NOT route, proxy, inspect, store, or sell your end customers’ checkout details, names, or order values on any FastrSoft central server. Your store’s end-customer data remains 100% under your sovereign control as the store’s Data Controller.

C. Paddle as Merchant of Record & Independent Data Controller

Our online reseller, Paddle.com (Paddle Payments Limited / Paddle.com Inc.), acts as an authorized Merchant of Record and an independent Data Controller for the purpose of processing customer payments, conducting anti-fraud screening, issuing invoices, and remitting statutory sales taxes.


2. Lawful Bases for Processing Under GDPR

FastrSoft processes personal data strictly under valid lawful bases established in Article 6 of the GDPR:

  1. Performance of a Contract (Art. 6(1)(b)): Processing necessary to execute transactions, deliver license keys, provide software downloads, verify domain activations, and deliver customer support.
  2. Legitimate Interests (Art. 6(1)(f)): Processing necessary to ensure website security, protect against malicious license fraud, debug software errors, and improve product performance.
  3. Compliance with Legal Obligations (Art. 6(1)(c)): Retaining financial transaction tokens and tax records to comply with statutory accounting requirements.
  4. Consent (Art. 6(1)(a)): Processing non-essential analytics or promotional newsletters only when affirmative, explicit consent has been granted.

3. Data Subject Rights & How to Exercise Them

Under European (GDPR), United Kingdom (UK GDPR), and California (CCPA/CPRA) regulations, consumers possess statutory privacy rights:

Statutory RightDescriptionHow FastrSoft Honors This Right
Right of AccessRequest confirmation of data processing and a complete copy of stored personal data.Provided within 30 days upon email request.
Right to RectificationCorrect inaccurate or incomplete personal information.Editable directly via your FastrSoft Account or by contacting support.
Right to Erasure (“Forgotten”)Request deletion of your account and personal records.Account and activation telemetry permanently purged, excluding statutory tax records.
Right to Restrict ProcessingRestrict how your personal data is utilized during disputes.Implemented immediately upon formal verified request.
Right to Data PortabilityReceive your data in a structured, commonly used JSON or CSV format.Dispatched to your verified email within 30 days.
Right to ObjectObject to processing based on legitimate interests or direct marketing.One-click unsubscribe links in all marketing emails; instant objection handling.
Right to Non-DiscriminationExercise privacy rights without denial of service or unfair pricing.Guaranteed: equal pricing, service, and support regardless of rights exercised.

To submit a data subject privacy request, email our compliance desk at support@fastrsoft.com with the subject line Data Privacy Request.


4. International Data Transfers & Standard Contractual Clauses (SCCs)

Because FastrSoft serves software users globally, personal data may be processed in countries outside the European Economic Area (EEA).

Where cross-border data transfers occur:

  • Transfers to Paddle and our cloud infrastructure providers are governed by Standard Contractual Clauses (SCCs) approved by the European Commission.
  • Encryption in transit (TLS 1.3) and encryption at rest (AES-256) are strictly enforced.

5. Third-Party Sub-Processors

Sub-ProcessorRole / FunctionLocation / Safeguard
Paddle.comMerchant of Record, Payment Gateway, Invoicing, Tax RemittanceUK / USA (PCI-DSS Level 1, SCCs)
Cloud Hosting InfrastructureWeb Server Hosting, Automated License Validation APIGlobal Edge (SOC 2, ISO 27001)
Transactional Email ServicesOrder confirmation and license delivery notificationsUSA / EU (GDPR Compliant, SCCs)

6. Contact Data Protection & Compliance

If you have questions regarding our GDPR posture, international compliance, or consumer data rights, please contact our compliance officer: