Privacy Policy — STBOOKS.PRO
Privacy Policy

What we know
about you.

Selling a download needs very little information — an email address to send it to, and a payment that clears. This page sets out exactly what we hold, why we hold it, and how to make us delete it.

Last updated 8 September 2026

We never see your card Card numbers go straight to our payment provider. They never reach our server.
Nothing is sold We do not sell, rent or trade your details to anybody.
Ask and it goes Email us and we delete what we are not legally required to keep.

Who we are

STBOOKS.PRO is a digital ebook shop operated by SofiTech LLC, 30 N Gould St, STE R, Sheridan, WY 82801, United States. We are the data controller for the information described on this page — meaning we decide what is collected and why, and we are the ones answerable for it.

For anything about your personal data, write to help@stbooks.pro.

What we collect

Only what a download shop actually needs. There is no profiling, no scoring, and nothing collected "just in case".

WhatWhenWhy it exists
Email address At checkout, or when you write to us To send your file and your receipt
Name At checkout or account signup To address you, and for the invoice
Billing address and country At checkout Required by our payment processor and for tax records
Order details When you buy What you bought, so you can download it again
Account password If you create an account Stored encrypted — we cannot read it, and neither can anyone else
Message content When you use the contact form or email us To answer you
A review you write When you review a book you bought Published on that product page, with the name you choose to show
IP address, browser, timestamps Automatically, in server logs Security, fraud prevention, and diagnosing faults
What we never collect: your card number, CVC or expiry date. Those are typed into our payment provider's own secure form and never touch our website or our database. We also do not ask for a date of birth, a phone number, or a government ID.

Why we collect it

Under UK and EU data protection law every use of your data needs a lawful basis. Ours are:

  • To perform our contract with you. We cannot deliver a file we have no address for, or let you re-download a purchase we have no record of.
  • To meet a legal obligation. Sales and tax records have to be kept for a set number of years, whether or not you still want an account with us.
  • Our legitimate interests. Keeping the site up, blocking fraudulent orders, and fixing things that break.
  • Your consent. Only where we ask for it plainly — and you can withdraw it at any time without affecting anything you have already bought.

Payments

Payments are handled by a third-party payment provider. When you pay, your card details go directly from your browser to that provider. They are never sent to our server, never written to our database, and never visible to us.

What comes back to us is confirmation that the payment succeeded, the amount, and the last few digits of the card so you and we can recognise the transaction. Our provider handles your payment data under its own privacy policy, which is linked at checkout.

Refunds work the same way. A refund is issued back through the same provider, to the card you paid with. We never need, and never ask for, your card number in order to refund you.

Cookies

A cookie is a small file the site stores in your browser. We use the ones the shop cannot run without:

  • Cart and session cookies — so the shop remembers what you put in your basket while you move between pages.
  • Login cookies — so you stay signed in to your account instead of logging in on every page.
  • Security cookies — used by the checkout and contact form to block automated abuse.

These are strictly necessary, which is why they do not sit behind a consent prompt. You can delete or block cookies in your browser settings, but the cart and checkout will stop working if you do.

Analytics and tracking

We look at aggregate visitor statistics to understand which books people are actually looking for and where the site is slow or broken. This is measurement of the shop, not surveillance of you: we are interested in totals, not in following an individual around.

Where these tools set non-essential cookies, they are used only with your consent, and you can withdraw that consent at any time through your browser settings or the cookie controls on this site.

Do Not Track and Global Privacy Control. If your browser sends a Do Not Track or GPC signal, we treat it as an opt-out of any non-essential tracking.

Who we share it with

We do not sell, rent or trade your personal information. Full stop. There is no advertising business here to sell it to.

We do rely on a small number of service providers to run the shop, and they only ever receive what they need to do their job:

  • Our payment provider — to take payment and issue refunds.
  • Our hosting provider — the servers the site and its database run on.
  • Our email provider — to deliver your receipt, your download link, and our replies to you.

Beyond that, we would only disclose data if we were legally compelled to — a court order, a lawful request from an authority, or to establish or defend a legal claim.

If the business changes hands. If SofiTech LLC is sold or restructured, customer records would transfer to the new owner along with the rest of the business. The new owner would be bound by this policy, and we would tell you before anything about how your data is handled changed.

Where your data is stored

SofiTech LLC is a United States company, and the site and its database are hosted on servers operated by our hosting provider. If you are reading this from the UK, the EU or anywhere outside the US, your information will be transferred to and stored in the United States.

Where such a transfer involves UK or EU personal data, we rely on the appropriate safeguards permitted under that law, including the European Commission's Standard Contractual Clauses in our agreements with our processors.

How long we keep it

Not indefinitely, and not longer than we have a reason to.

  • Order and invoice records — kept for seven years, because tax and accounting law requires it. This is the one category we cannot delete on request.
  • Your account — kept while the account is open. Ask us to close it and we remove it.
  • Contact form and email messages — kept while the conversation is useful, then deleted.
  • Server logs — kept for a short period for security, then rotated out automatically.

Your rights

Depending on where you live you have some or all of the following rights. We honour them for every customer regardless of country, because running two standards would be worse for everyone.

  • Access — ask for a copy of what we hold about you.
  • Correction — have anything wrong put right.
  • Deletion — have your data erased, except records we are legally required to keep.
  • Portability — receive your data in a machine-readable file.
  • Objection and restriction — object to a particular use, or ask us to pause it.
  • Withdraw consent — at any time, for anything based on consent.
  • Opt out of sale or sharing — if you are in California. Since we do not sell or share personal information, there is nothing to opt out of, but the right stands.
  • No retaliation — exercising any of these will never affect the price you pay or the service you get.

To use any of them, email help@stbooks.pro. We will reply within 1 days. We may need to confirm your identity first — usually just by writing from the address on the order.

If you are not happy with our answer, you can complain to your national data protection authority. In the UK that is the Information Commissioner's Office; in the EU it is the supervisory authority for your country. We would rather you told us first so we can fix it.

Security

The site runs over an encrypted HTTPS connection, passwords are stored hashed rather than in readable form, and card data never enters our systems at all — which removes the most valuable thing an attacker could want.

No system is perfectly secure and we are not going to claim otherwise. If a breach ever affected your personal data, we would notify you and the relevant authority within the timeframes the law sets.

Children

This shop is not intended for children. Our Terms & Conditions require buyers to be 18 or older, and we do not knowingly collect personal information from anyone under that age. If you believe a child has given us their details, write to us and we will delete the record.

Changes to this policy

When we change how we handle data, we update this page and change the date at the top. If a change is significant — a new category of data, or a new third party — we will say so clearly rather than quietly editing a line.

Continuing to use the site after a change means you accept the updated policy.

Contact us

Questions about your data, or want a copy or a deletion? Write to us and say what you need. Plain language is fine — you do not have to quote a regulation at us.

SofiTech LLC
30 N Gould St, STE R
Sheridan, WY 82801
United States