Privacy Statement
Last updated: September 24, 2026
This statement describes how NearNative LLC collects, uses, and protects personal data when you use the Cr8te Media Manager website and desktop application. It is intended to be transparent and factual; it is not legal advice or a certification of compliance with any specific regulation.
1. What we collect
- Account and purchase information: your email address, Stripe customer ID, payment-intent ID, checkout session ID, licence key, licence status, major version, update window, and which DAW connectors you have bought.
- Desktop activation data: a one-way hash of your machine identifier (the raw identifier is never sent or stored), an optional machine label you provide, operating system, Cr8te app version, and first/last-seen timestamps. This is used only to enforce the per-licence machine limit and to issue signed licence files.
- Security logs: IP address, requested action, licence key involved, and timestamp. These are kept in an audit log to support rate limiting, abuse detection, and troubleshooting.
- Essential session data: when you sign in with a magic link, an authentication session is stored in your browser so you can access your account page. No marketing or tracking cookies are used.
2. What we do not collect
- We do not collect or store payment card numbers. All card processing is handled by Stripe under their privacy and security practices.
- We do not access, upload, or store your sample library, audio files, project files, or any content processed by the Cr8te desktop application.
- We do not use advertising trackers, analytics beacons, or third-party marketing cookies.
- The site loads fonts from Google Fonts, so Google may see your IP address when your browser requests them.
3. How we use your data
- To deliver your licence key and connector entitlements by email.
- To authenticate you on the account page so you can view and manage your machines.
- To enforce the per-licence machine limit and detect misuse of the activation API.
- To process refunds, disputes, and chargebacks in accordance with Stripe events.
- To provide software updates and download links.
- To keep security audit logs for troubleshooting and abuse prevention.
4. Legal basis for processing (GDPR visitors)
We process personal data on the basis of:
- Performance of a contract: issuing your licence, maintaining activations, and delivering updates.
- Legitimate interests: fraud prevention, rate limiting, abuse detection, and keeping audit logs.
- Consent: where required, for example if you opt in to marketing communications. We currently do not send marketing emails.
5. Who we share data with
We share only what is necessary with the following service providers:
- Stripe — payment processing and checkout sessions.
- Resend — transactional email delivery (licence keys, account links).
- Lovable Cloud / Supabase — database, authentication, and storage hosting for releases and installers.
- GitHub — release metadata and installer assets are mirrored from a private repository; no user personal data is sent to GitHub.
We do not sell, rent, or trade personal data.
6. International data transfers
Our service providers may process data in the United States and other jurisdictions. When data is transferred, we rely on the safeguards provided by our processors, such as standard contractual clauses where applicable.
7. Data retention
We keep your data for as long as your licence remains active or as needed to provide the service, resolve disputes, enforce agreements, and comply with legal obligations. There is no automatic expiry or deletion job; deactivated machines are retained as a historical record tied to your licence. You can request deletion of personal data by contacting us.
8. Your rights
Depending on where you live, you may have the right to:
- Access the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Request deletion of your personal data.
- Restrict or object to certain processing.
- Receive your data in a portable format.
- Withdraw consent where processing is based on consent.
To exercise any of these rights, contact us at info@near-native.com. We will respond within a reasonable timeframe.
9. Security
We use row-level access controls, encryption in transit, signed licence files, and rate limiting to protect your data. No online system is completely secure, however, and we cannot guarantee absolute protection.
10. Children's privacy
Cr8te is not intended for users under 16 years of age. We do not knowingly collect personal data from children. If you believe we have received such data, please contact us so we can delete it.
11. Changes to this statement
We may update this statement as the service evolves. The latest version will always be available at this page, with the effective date at the top.
12. Contact
Questions about this statement or your data? Email info@near-native.com.