Privacy Policy

Last updated: June 9, 2026

This Privacy Policy explains what personal data we collect when you use Baud Runner (the "Site") at https://baudrunner.com, why we collect it, how we use and share it, and the choices and rights you have. Baud Runner is a storefront operated by Defensible Logic, Inc. ("we", "us", "our"). We sell digital goods (3D-printable model files and similar downloads) and physical hardware that we ship. This policy covers the Site only; it does not cover the separate consulting business that Defensible Logic, Inc. runs at defensiblelogic.com. By using the Site you agree to the practices described here and in our Terms of Service.

1. Who we are

The business responsible for your personal data is Defensible Logic, Inc., a corporation. You can reach us about privacy matters at privacy@defensiblelogic.com.

2. Data we collect

We collect only the data we need to run the Site, fulfil orders, and deliver your downloads. Specifically:

  • Account data. Your email address and a password. We never store your password in plaintext; we store only a salted cryptographic hash of it.
  • Order and payment metadata. Records of your orders, amounts, payment status, and reference identifiers from our payment processor. We do not collect, receive, or store your full card number or other raw card data; payment card details are entered on, and processed by, Stripe (see Section 4).
  • Shipping address. The name and postal address you provide for physical orders so we can ship them.
  • Technical request data. The IP address and browser user-agent string sent with your requests, captured in our logs.
  • Digital-download activity. For licensed downloads, the number of downloads taken against a grant and the timestamps of those downloads, so we can enforce download limits, link expiry, and revocation.

We do not use advertising trackers, ad networks, or third-party behavioural advertising, and we do not build advertising profiles about you.

3. How we use your data

We use the data above to:

  • Create and maintain your account and keep your order history tied to it.
  • Process orders, take payment through Stripe (or settle off-Stripe by arrangement, e.g. invoice, wire, cash, or consignment, at our discretion), and ship physical goods.
  • Deliver digital goods as secure, tokenized download links, and enforce per-grant download counts, expiry, and revocation (for example, on refund or chargeback). See our License and Refunds & Returns pages.
  • Provide customer support and respond to your requests.
  • Detect, prevent, and handle fraud, chargebacks, and disputes (which are processed through Stripe).
  • Maintain the security and integrity of the Site, including logging requests.
  • Comply with our legal obligations, including tax and accounting record-keeping, and enforce our agreements.

4. Third parties and subprocessors

We share personal data with the following service providers only as needed to operate the Site. We do not sell your personal data and we do not share it for third-party advertising.

  • Stripe (payments). Stripe processes card payments on Stripe-hosted checkout pages. You enter your card details directly with Stripe, not with Baud Runner, so card data and the associated PCI scope sit with Stripe. We receive and store order records, amounts, payment status, and Stripe reference identifiers, but never raw card numbers. Stripe acts as an independent processor of your payment data under its own terms; see Stripe's privacy notice at https://stripe.com/privacy.
  • Transactional email provider. We use Zoho to send account and order-related emails (such as confirmations, download links, and support replies).
  • File and object storage. We host digital files and related assets on our own object/file storage to deliver your downloads.

We may also disclose data where required by law, to respond to lawful requests, or to protect our rights, users, or the security of the Site.

5. Cookies and sessions

We use cookies only for the Site to function, primarily authentication and session cookies that keep you logged in and protect your session. We do not use advertising or cross-site tracking cookies. If you block essential cookies, parts of the Site (such as logging in or checking out) may not work. Beyond the session cookie that keeps you logged in, the only other client-side storage we use is a locally stored theme (light/dark) preference; we set no third-party or advertising cookies.

6. Data retention

We keep account data for as long as your account is active. We retain order, payment metadata, and download-activity records for as long as needed to fulfil the order, support you, and meet legal, tax, and accounting obligations, after which we delete or anonymize them. Request logs containing IP addresses and user-agent strings are retained for a limited period for security and troubleshooting. Specific retention periods are: request logs containing IP addresses and user-agent strings, about 90 days; order and payment records, about 7 years to meet tax and accounting obligations; and account data, until you delete your account.

7. How we protect your data

  • Passwords are stored only as salted hashes, never in plaintext.
  • Traffic to and from the Site is encrypted in transit using TLS.
  • Digital downloads are delivered through secure, tokenized links with finite download counts and expiry, and can be revoked.
  • Card data never touches our systems; it is handled by Stripe.

No system can be guaranteed perfectly secure, but we take reasonable measures appropriate to the data we hold.

8. Your rights and choices

You can access and update your account email and review your order history by logging in. You may also ask us to access, correct, or delete your personal data by emailing privacy@defensiblelogic.com. We will respond as required by applicable law, and we may need to verify your identity first. Note that we may retain certain records (for example, completed order and payment records) where the law requires or permits us to do so, even after an account is closed.

Depending on where you live, you may have additional rights (such as data portability, objection, restriction, or the right to lodge a complaint with a supervisory authority). Residents of the EU, the UK, California, and other U.S. states with privacy laws have additional rights — such as access, correction, deletion, and portability — under laws like the GDPR and the CCPA. To exercise any of these rights, contact us at privacy@defensiblelogic.com.

9. Children

The Site is not directed to children, and we do not knowingly collect personal data from anyone under 13. If you believe a child has provided us personal data, contact us at privacy@defensiblelogic.com and we will delete it.

10. International data transfers

We and our service providers (including Stripe) may process and store data in countries other than the one in which you reside. Where we transfer personal data across borders, we rely on appropriate safeguards, such as the EU/UK Standard Contractual Clauses where they apply. By using the Site, you understand your data may be processed in the United States.

11. Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date shown above. Material changes will be reflected on this page, and your continued use of the Site after an update means you accept the revised policy.

12. Contact

Questions about this policy or your personal data? Email us at privacy@defensiblelogic.com. This policy is governed by the laws of the State of Wyoming, United States. For related terms, see our Terms of Service and About page.