Legal
Privacy Policy
MasterPack is a marketplace where one subscription unlocks many independent apps, and the makers of those apps are paid according to how much you actually use them. Measuring usage means handling some data about you, so this page explains exactly what we hold, why, where it lives, and how to get rid of it.
Who we are
The controller of your personal data is SIA InVanilla, registration number 40203218282, Pūces iela 53–32, Rīga, LV-1082, Latvia, European Union. We operate MasterPack at masterpack.app.
For anything in this policy — including access, export, correction, or deletion requests — write to support@xternal.ai.
We never see your payment details
MasterPack does not process, transmit, or store card numbers, bank details, or any other payment credentials. All payments are handled by Stripe (Stripe Payments Europe, Limited for customers in the EEA, and Stripe, Inc. elsewhere), acting as an independent controller for payment data. When you subscribe, you enter your card details on Stripe's own systems. When a maker gets paid, payouts run through Stripe Connect, and Stripe collects any identity and bank information required by financial regulation.
We receive back only what we need to run the service: a Stripe customer and subscription identifier, the plan, its status, the renewal date, and — for makers — whether payouts are enabled. Stripe's own privacy policy governs the data it collects directly: stripe.com/privacy.
What we collect, and why
| Data | Why we have it | Legal basis (GDPR Art. 6) |
|---|---|---|
| Account identity: email address, display name, sign-in method | To create your account and let you sign in to MasterPack and to catalog apps | Performance of a contract |
| Subscription record: plan, status, renewal date, Stripe identifiers | To give you access, bill you, and calculate what each maker is owed | Performance of a contract |
| Usage signals: which catalog app, which minutes you were active, session identifiers | To split your subscription fee fairly between the apps you used — this is the core of the service | Performance of a contract |
| Security signals: salted, irreversible hashes of your IP address and browser user-agent, taken when a sign-in token is issued | To detect fraud — for example, fake accounts inflating an app's usage to steal from the payout pool | Legitimate interests (protecting makers and subscribers from fraud) |
| Maker data: your apps, their listings, images you upload, API key hashes | To publish your listing and let your app authenticate users | Performance of a contract |
| Financial records: payments, platform fees, payout allocations | Accounting and tax obligations | Legal obligation |
We do not store raw IP addresses, run advertising trackers, sell data, or use it to train machine-learning models. We use no analytics or advertising cookies — only the strictly necessary cookies that keep you signed in, which is why you have never seen a cookie banner here.
What apps in the catalog can see about you
When you sign in to a catalog app through MasterPack, that app receives a pairwise identifier — an ID unique to you and that one app, so two apps cannot compare notes to work out you are the same person — plus your display name and your subscription tier. Apps never receive your email address. Anything you subsequently do inside an app is governed by that app's own privacy policy; the maker is the controller for that data.
Where your data lives
Our database and application servers run in Frankfurt, Germany (EU), and images uploaded by makers are stored in the EU as well. Some of our processors are based in the United States; where personal data reaches them, transfers rely on the EU–U.S. Data Privacy Framework and/or Standard Contractual Clauses.
| Processor | Purpose | Location |
|---|---|---|
| Neon | Primary database | Frankfurt, EU (AWS eu-central-1) |
| Vercel | Application hosting, image storage, global content delivery | Functions and image storage in Frankfurt, EU; CDN worldwide; company in the U.S. |
| Clerk | Account sign-in and identity | U.S. |
| Stripe | Payments and maker payouts (independent controller) | Ireland (EEA) and U.S. |
How long we keep it
- Account and usage data — while your account exists. Delete your account and it goes.
- Raw heartbeat records — kept only as long as needed to compute and verify a payout period, then reduced to daily totals.
- Archived apps — listing content and credentials are deleted 30 days after a maker archives an app.
- Financial records — retained for as long as accounting and tax law requires (in Latvia, generally five years). After you delete your account these records remain, but stripped of personal identifiers, so they can no longer be traced back to you.
Your rights
Under the GDPR you may access, correct, export, delete, or restrict your personal data, object to processing based on legitimate interests, and withdraw consent where processing relies on it. Two of these are buttons rather than emails:
- Export everything we hold about you as a JSON file — your account page.
- Delete your account and data — also on your account page. If you are a maker with an unpaid balance, contact us first so we can pay you out.
For anything else, email support@xternal.ai. We answer within 30 days. You also have the right to complain to a supervisory authority — ours is the Latvian Data State Inspectorate, and you may instead complain to the authority where you live.
If you are in the United States
We apply the same protections everywhere; we do not maintain a second-class standard for non-EU users. We do not sell or share personal information as those terms are used in U.S. state privacy laws, and we do not use it for cross-context behavioural advertising. California, Colorado, Connecticut, Virginia and other state-law residents can exercise their access, deletion, correction, and portability rights using the same buttons and the same email address above, and we will not discriminate against you for doing so.
Children
MasterPack is not intended for children under 16. We do not knowingly collect their data; if you believe a child has created an account, email us and we will delete it.
Security
Sign-in tokens are short-lived and rotate; API keys are stored only as hashes and can be rotated by makers at any time; IP and user-agent values are stored only as salted hashes; access to production data is limited to people who need it. No system is perfect — if you find a vulnerability, please tell us at support@xternal.ai.
Changes
If we change this policy in a way that materially affects you, we will say so by email or in the product before it takes effect. The date at the top always reflects the current version.