Privacy Policy
Last updated 23 July 2026
This policy explains how The Software Laboratory (“we”, “us”) handles your personal data when you use the OAuth Verification Pack. We are the data controller.
Who we are
The Software Laboratory, Gewerbeweg 2, 9486 Schaanwald, Liechtenstein. Privacy contact: hello@oauthpack.dev. Liechtenstein is in the EEA, so the EU GDPR (as incorporated into the EEA Agreement) and the Liechtenstein Data Protection Act (DSG) apply.
What we collect
- Order & billing: your email and the transaction record (amount, date, and payment references). Card details are handled by Stripe — we never see or store them.
- Intake you provide: your app URL, the Google scopes you request, your tech stack, the rejection message you paste, your app names, your legal entity name/address, and your OAuth client ID — used to build your pack.
- Free scanner: the URL and scopes you submit, kept as a usage record.
Why we use it — and our legal basis
- To deliver the product (take your order, generate and deliver the pack, provide support and re-runs) — performance of a contract (GDPR Art. 6(1)(b)); providing billing data is a requirement of purchase.
- To keep the records the law requires (invoices/transactions) — legal obligation (Art. 6(1)(c); Liechtenstein PGR Art. 1059 and VAT law).
- To secure the service, prevent fraud, and defend legal claims — legitimate interests (Art. 6(1)(f)).
We do not send marketing email and do not use your data to train AI models. We contact you only about your order.
How long we keep it
- Transaction & invoice records: 10 years, as Liechtenstein accounting and VAT law require (PGR Art. 1059; MWSTG Art. 70), counted from the end of the business year.
- Your submitted intake and generated pack: up to 12 months after delivery, to provide support and re-runs — then deleted, and deleted sooner whenever you ask.
Who processes it for us
We use a small set of service providers, each under a data-processing agreement:
- Stripe — payments (merchant of record for tax and invoicing).
- Supabase — database and file storage.
- Vercel — application hosting.
- Resend — transactional email.
- Anthropic — generating the written portions of your pack.
Some providers process data in the United States; those transfers rely on the EU Standard Contractual Clauses and/or the EU–US Data Privacy Framework.
Your rights
You can request: access to your data, correction, erasure, restriction of processing, a portable copy, and to object to processing based on legitimate interests (and to withdraw consent where we rely on it). For your order you can do most of this yourself from your order page — download your data, correct your intake, or delete your data. Erasure does not cover records we must keep by law (the transaction/invoice record), which we restrict to accounting use until the 10-year period ends. To exercise any right, use your order page or email hello@oauthpack.dev; we respond within 30 days.
Complaints
You have the right to complain to the Liechtenstein supervisory authority: Datenschutzstelle (DSS), Städtle 38, P.O. Box 684, 9490 Vaduz, Liechtenstein · info.dss@llv.li · datenschutzstelle.li.
Contact
The Software Laboratory, Gewerbeweg 2, 9486 Schaanwald, Liechtenstein · hello@oauthpack.dev.