Privacy Policy
Last Updated: June 5, 2026
ChromSword (“we,” “our,” or “us”) operates hplcmd.com (the “Site”). This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you visit our website, purchase software licenses, or interact with us, ensuring compliance with the European Union General Data Protection Regulation (GDPR) and United States privacy laws (including the CCPA/CPRA).
1. Information We Collect
We collect information that identifies, relates to, or could reasonably be linked with you.
-
Account & Billing Data: Name, company name, billing address, email address, and phone number collected via WooCommerce during checkout.
-
Payment Data: Payment card processing is handled securely by our third-party processor, Stripe. We do not store or directly see your raw credit card numbers or security codes.
-
Technical & Usage Data: IP address, browser type, operating system, and interaction with our website (collected via cookies and, in the future, Google Analytics and Facebook Pixel).
-
License Data: Information related to the software licenses purchased, issued, and activated.
2. Legal Basis for Processing (EU Clients)
If you are located in the European Economic Area (EEA), our legal bases for processing your data under the GDPR are:
-
Performance of a Contract: To process your payment, fulfill your WooCommerce order, and deliver your HPLC Method Development software license keys.
-
Consent: For marketing communications and non-essential tracking (Google Analytics/Facebook Pixel) managed via our cookie banner.
-
Legitimate Interests: To prevent fraud, secure our checkout system, and improve our software solutions.
3. How We Share Your Data
We do not sell your personal data. We only share your data with trusted service providers critical to our operations:
-
Stripe: To process your secure payments.
-
Hosting & Platform Providers: WordPress and WooCommerce to run the platform.
-
Analytics/Advertising Providers: Google and Meta (Facebook) subject to your cookie consent choices.
-
Legal Obligations: If required by law, subpoena, or to protect our legal rights.
4. International Data Transfers
Data collected from EU/EEA citizens may be transferred to and processed in countries outside the EEA (such as the United States where Stripe or hosting servers may operate). We ensure standard contractual clauses (SCCs) or equivalent legal mechanisms are in place to safeguard this data.
5. Your Rights (EU & US Clients)
Depending on your residency (e.g., EU GDPR or California CCPA), you have the following rights:
-
Right to Access/Know: Request a copy of the personal data we hold about you.
-
Right to Deletion/Erasure: Request that we delete your personal data (except where we must retain it for tax, legal, or active license fulfillment obligations).
-
Right to Rectification: Update incorrect or incomplete account information.
-
Right to Opt-Out / Withdraw Consent: Decline marketing cookies or analytics tracking at any time via the cookie banner.
To exercise your rights, contact us at: ak@chromsword.com.