Privacy

Last Updated: July 31st 2026

AP Mastering, accessible from apmastering.com, is committed to protecting your personal data and ensuring transparency about how your information is handled. This Privacy Policy explains how your data is collected, used, stored and protected when you use the website, purchase products including online courses and plugin licenses.

Data Controller

AP Mastering is the data controller for personal data collected directly through the website and account system (e.g. email address, account activity, plugin licensing). Full company registration details and registered address are available in the footer of this website.

For payment and transaction data, Paddle acts as an independent data controller, as described in the Purchases and Payment Processing section.

Account Creation and Data Security

When an account is created at AP Mastering, the following personal data is collected and processed:

  • Email Address: Collected to establish account identity, deliver transactional communications, and associate product licenses.
  • Password: Stored securely as an irreversible hash. Plain-text passwords are never viewable by anyone.

Infrastructure & Storage

AP Mastering utilizes cloud-based infrastructure provided by Amazon Web Services (AWS). Account authentication and password management are handled securely via AWS Cognito. When purchases are linked to an account in the database, no personal payment details are stored directly on the server, and all databases are hosted in AWS secure cloud environments.

Purchases and Payment Processing

All purchases on the AP Mastering website are processed by Paddle, acting as the Merchant of Record.

  • For payment and transaction data, Paddle acts as an independent data controller. This means Paddle determines the purposes and means of processing that data in its role as Merchant of Record (e.g. for tax, compliance, and fraud prevention). Paddle's own privacy policy governs how this data is handled.
  • Paddle handles all transaction details, tax calculations, invoicing, credit card processing, and PayPal payments.
  • AP Mastering accesses transaction details solely through Paddle's platform for support, order fulfillment, and license management. No financial or payment details are stored directly by AP Mastering.

Plugin Licensing and Validation

AP Mastering plugins run locally without maintaining an ongoing server connection. During the activation process, clicking the link generated by the plugin includes a hashed representation of the computer's unique hardware identifier within the activation URL. This hash functions strictly as an anonymized technical identifier, allowing AP Mastering to record which devices have activated a license. It contains no personal information and cannot be used to access the underlying hardware.

Legal Basis for Processing Data (GDPR Compliance)

For users located in the European Economic Area (EEA) or UK, the legal grounds for processing personal data include:

  • Performance of a Contract: Necessary to create an account, deliver purchased courses, and validate plugin licenses.
  • Consent: Required for sending optional marketing newsletters.
  • Legitimate Interests: Necessary to secure the website, prevent fraud, and deliver customer support.

No decisions are made about you based solely on automated processing, including profiling, that would produce legal or similarly significant effects.

Email Communications & Marketing

  • Transactional Emails: Essential system emails are sent regarding account verification, password resets, and purchase receipts.
  • Marketing Emails:Marketing emails are strictly opt-in. Unsubscribing or subscribing can be managed at any time via account settings, or by clicking the "Unsubscribe" link included at the bottom of any marketing email.

Cookies and Local Storage

The website uses only strictly necessary cookies and local browser storage — for example, to maintain login sessions, manage session state, and save shopping preferences. No non-essential, analytics, or advertising cookies are used, so no cookie consent banner is required. Browsing data is never sold to third parties.

Data Rights

Subject to applicable regulations (such as GDPR or CCPA/CPRA), users have the following rights regarding personal data:

  • Right to Access & Portability: A copy of personal data held on record can be requested at any time.
  • Right to Rectification: Updates or corrections to inaccurate personal data can be requested.
  • Right to Erasure (Right to be Forgotten): The deletion of an account and associated personal data can be requested.
  • Right to Object: Objection can be raised at any time to processing based on legitimate interests.
  • Right to Restrict Processing: A request can be made to limit how personal data is used under certain circumstances (e.g. while a dispute over accuracy is resolved).

Important Note on Account Erasure: Requesting full account deletion will permanently remove the associated email address from the authentication system. As a result, access to any previously purchased courses and the ability to manage or re-license purchased plugins will be permanently lost.

If you are not satisfied with how a data request has been handled, you have the right to lodge a complaint with the Office of the Commissioner for Personal Data Protection in Cyprus, or with the supervisory authority in your own EEA member state.

Data Sharing and International Transfers

Personal data is never sold, rented, or shared with third parties for marketing purposes. Data is only processed through specialized third-party infrastructure providers (such as AWS and Paddle) necessary to deliver services. Information may be processed on secure servers outside a user's home country, subject to standard contractual security safeguards.

Data Retention

Personal data is retained for as long as an account remains active, in order to provide access to purchased courses and manage plugin licenses. If account deletion is requested, associated personal data is removed from the authentication system as described in the Data Rights section. Transaction records may be retained by Paddle in accordance with their own legal and tax obligations, independent of account status.

Server Logs

Requests to this website and its API are recorded in server logs, which are used only to investigate faults and to keep accounts secure. The legal basis is legitimate interests.

A record covers the time of the request, the route requested, the response status, how long it took, the IP address the request came from and the browser user-agent string. Where an operation fails, a record may additionally contain the account identifier involved, and occasionally other details submitted with the request, so that the fault can be traced. Passwords, session cookies and the contents of requests are not recorded, and these records are never used to build a profile of you or to analyse behaviour.

Server logs are automatically deleted after 30 days. They are stored encrypted within the European Union and are readable only by the site operator. Because entries cannot reliably be located or removed for an individual person, log data is excluded from erasure requests and is instead limited by retention period.

Children's Privacy

Services and software offered by AP Mastering are not directed to individuals under the age of 16. Personal data from children is not knowingly collected.

Contact Information

To exercise data rights, request account deletion, or ask questions regarding how data is handled, please reach out via email - see contact page for current email address.