Privacy and data
Privacy Policy
This policy explains how the current Form Audioworks store uses personal information, including accounts, orders, support, consented analytics and Meta measurement.
Effective and last updated: 31 August 2026
1. Scope
This policy applies to the current Form Audioworks website, store, customer accounts, downloads and support service. It does not describe the separately operated legacy WooCommerce site or any independent website you may reach from an external link.
2. Who we are and how to contact us
Form Audioworks LTD is the controller for the personal information described here. We are registered in England and Wales under company number 14785152 and with the Information Commissioner's Office under registration ZB714038.
Our registered office is 71-75 Shelton Street, Covent Garden, London, England, WC2H 9JQ. For privacy questions, rights requests or complaints, use our support form and choose Privacy/data-protection complaint where appropriate.
3. Information we use
Depending on what you do, this can include:
- your name, email address, account identifier and account settings;
- order contents, prices, currency, discounts, payment and refund references and outcomes;
- product entitlements, download and access evidence;
- an email address submitted to receive requested free sample-pack files, the pack requested, bounded link-use evidence and any separate optional promotional-email choice;
- support messages, an optional order number and information needed to answer you;
- reviews, display names and moderation information;
- your cookie choices, changes to those choices and the choice recorded when checkout starts;
- consented page, product, cart and checkout events, referral and campaign information; and
- limited security and technical information such as session data, IP address, browser information and abuse-prevention evidence where needed for the relevant service.
Please do not send passwords, sign-in links, password-reset links, full card details or other information we have not asked for.
4. Why we use information and legal grounds
We use information to create and secure accounts; provide checkout, receipts, downloads and support; administer refunds and disputes; prevent fraud and abuse; keep business and financial records; remember choices; understand consented use of the store; and measure consented advertising results.
Optional browser storage and access for Support chat, Analytics or Marketing is used only after the relevant consent choice. Depending on the activity, we rely on taking steps at your request or performing a contract, complying with legal duties, our legitimate interests in service security, support and business administration, or consent where required for optional Support chat, Analytics and Marketing. Cookie consent is not used as the legal basis for every record we hold.
5. Accounts, payments, orders and downloads
Supabase provides account confirmation, sign-in, sessions and password recovery. Resend helps deliver account, order and other transactional email. Purchased files and media are held in private object storage, and eligible customers receive short-lived download links rather than permanent public links.
Payments are handled by Stripe on its hosted checkout. Form Audioworks does not store your full payment-card details. We keep the order, payment, refund, dispute, finance and access evidence needed to fulfil purchases, provide receipts, restore access and maintain business records. Stripe receives information directly on its checkout and may use it for its own payment, fraud-prevention and legal purposes.
A free sample-pack demo does not require or create an account. We use the submitted email address to provide the requested samples and send one transactional backup download link. The private link expires after seven days and permits at most five successful uses. This does not grant purchased access or unlock the full pack.
6. First-party analytics and Google Analytics
Analytics is optional. Before you grant Analytics, the application does not store behavioural events or load Google Analytics 4, so no GA4 script, configuration, cookie or event is sent and no denied-mode measurement ping is made. Withdrawing Analytics stops future first-party and Google Analytics events from that browser.
Our first-party system can record allowed page views, product views, cart additions, checkout starts and purchases, together with a random browser identifier, session information, page path, product/order references and bounded campaign information. It does not retain raw IP addresses or complete User-Agent strings as analytics event data. Analytics events and sessions are retained for up to 180 days from their original creation; short-lived presence rows expire after 24 hours.
Google Analytics 4 receives the same bounded event families: page_view, view_item, add_to_cart, begin_checkout and purchase. Google also receives ordinary request and device information used by Analytics, such as browser/device details, IP address and approximate location derived from it. Google Signals, advertising personalisation, Google Ads linking features, Enhanced Conversions, User-ID and user-provided data are not enabled by this integration. Learn more in Google's Analytics data information and privacy and security information.
7. Meta Pixel and server-side Purchase measurement
Marketing is a separate optional choice. When it is off, the native Meta Pixel does not load, initialise, set or read its cookies, or send a browser event. When it is on, the Pixel can send PageView, ViewContent, AddToCart, InitiateCheckout and Purchase. Automatic configuration and browser advanced matching are disabled.
For an eligible completed order, Form Audioworks may also send one server-to-server Purchase event to Meta using the Marketing choice saved when checkout starts. It can contain the products, quantities, currency and value; a SHA-256 hash of the checkout email; the trusted checkout User-Agent and validated IP address; and available Meta _fbp or _fbc values. Hashing makes the email pseudonymous, not anonymous. We do not include your name, phone number, postal address, raw email address or a Form Audioworks user ID in that event.
The browser and server Purchase use the same event ID so Meta can avoid counting the same purchase twice. The server event can be sent or retried even if the thank-you page is not opened. If Marketing was denied when checkout started, no Meta Purchase is created and a later grant does not replay it. A later withdrawal stops affected future browser events, but does not rewrite the order-time record or recall information already sent to Meta. Refunds and upper-funnel events are not sent through this server integration.
Google Tag Manager is not used by this application. See Meta's Business Tools Terms and Meta's Privacy Policy.
8. Email, support and reviews
Transactional messages cover accounts, orders, downloads, service notices and support replies. The optional promotional-email setting is separate from Analytics and Marketing measurement and is not inferred from cookie choices. A free-sample backup link is transactional. Promotional email is optional, uses a separate unchecked checkbox, and is not required to receive the samples. A signed-out request does not create an account or add the address to promotional-email automation. A signed-in customer who chooses the option uses the existing account preference and provider-synchronisation process.
Support submissions are private and are used to respond to and manage your request. Approved reviews may be displayed publicly with the chosen display name; reviewer email addresses are not displayed.
The optional support chat is provided by Brevo. When you accept all under the current notice, or enable the separate Support chat choice under Manage preferences, Brevo Conversations loads in the background so support is ready and can see the current page as you move around the site, even while the chat window is closed. This makes you available to support but does not report the chat window as opened until you select Support. The former combined Analytics and Marketing choice is not reused for this purpose. If the Support chat choice is off, simply seeing the Form Audioworks launcher does not load Brevo or allow it to use browser storage; Brevo loads only if you selectOpen support chat after the disclosure. That action enables the Support chat preference for later visits without changing Analytics, Marketing or promotional email. You can switch it off again through Cookie settings. Brevo processes chat messages and can receive the current page and referrer plus ordinary browser, device and network information. Its cookies and browser storage keep the conversation available when you return. Closing the chat does not remove provider storage or a conversation already held by Brevo. You can instead use the support form without loading the chat.
9. Who receives information
We use the following providers for the stated parts of the service:
- Supabase for the database and authentication;
- Stripe for hosted checkout and payments;
- Vercel for application hosting and delivery;
- DigitalOcean for private product and media storage;
- Resend for transactional email delivery;
- Brevo for support chat enabled through Cookie settings or the chat disclosure, and separately managed promotional-email delivery;
- Cloudflare for Turnstile bot and abuse prevention on the support form and public account access forms;
- Google for consented Analytics; and
- Meta for consented Pixel and Purchase measurement.
Some providers process information on our instructions, while others may process information for their own purposes and legal obligations, particularly payment, analytics and advertising providers. We may also disclose information where required by law or where necessary to protect customers, the service or legal rights.
10. International processing
Some providers may process information outside the UK. Their privacy notices explain their processing locations and transfer arrangements. Where UK law requires safeguards for an international transfer, we use the safeguards applicable to that provider and transfer.
11. How long we keep information
- first-party analytics events and sessions: up to 180 days from original creation;
- aggregate presence rows: 24 hours;
- encrypted Meta checkout matching context: no more than 21 days and normally removed when the delivery record is prepared;
- encrypted Meta delivery payload: removed on success or terminal failure and cannot remain eligible beyond seven days from the original purchase completion;
- short-lived account confirmation, recovery, access and security state: according to the expiry described in the Cookie Policy;
- free-sample download links: seven days and at most five successful uses; the associated claim and token-digest evidence is retained while needed for service, consent, security or legal evidence; and
- order, finance, access, consent, support, review, transactional-email, security and provider records: retained while needed for their purpose, legal duties, disputes, access or evidence.
We retain other records only for as long as needed for the purposes described above, including legal, accounting, security, dispute-resolution and customer-access needs. Deletion from active systems may not appear immediately in encrypted recovery copies. Recovery copies are kept according to the applicable backup rotation and are used only for disaster recovery or authorised incident response.
12. Security
We use access controls, private storage, short-lived download links, encryption for temporary Meta delivery context, bounded logs and data-minimisation controls. No internet service can promise absolute security.
13. Your choices and rights
Use Cookie settings in the footer to change Support chat, Analytics and Marketing separately. Promotional email is managed separately in account settings. Depending on the circumstances, UK data-protection law may give you rights to ask for access, correction, deletion, restriction or portability, or to object to certain uses. You can withdraw consent for future optional processing at any time.
Some requests may be limited where records must be retained for transactions, access, security, disputes, accounting or another lawful reason. To make a request, use Support and we will verify and assess it.
14. Children
This store is not directed at children. We do not knowingly seek personal information from children. If you are responsible for a child and believe they have provided personal information, contact us so we can assess it and take appropriate action.
15. Complaints
Submit a privacy complaint through Support. We will acknowledge it within 30 days, investigate it, keep you informed where appropriate, and explain the outcome without undue delay. Thirty days is the acknowledgement period, not a promised resolution deadline.
You can also complain to the UK Information Commissioner's Office through its complaints service.
16. Changes to this policy
We will update the date at the top when this policy changes. If a change introduces a new optional purpose or provider that needs consent, we will ask for a new choice rather than treating an earlier choice as permission.