Legal
Privacy Policy
Effective date: May 31, 2026.
Controller contact: Scripley is operated from Malaga, Spain. Privacy contact: info@airistoteles.com.
Scripley applies privacy by design and data minimization. We collect the account, GitHub, checkout, download, report, moderation, billing, tax, security, and support data needed to operate the marketplace and protect buyers, creators, and the platform.
Account data may include name, email, authentication identifiers, GitHub handle, country, role, profile details, preferences, support messages, and security logs. Creator data may include connected repository metadata, product listings, declarations, media, pricing, payout status, Stripe Connect status, analytics, and moderation history. Buyer data may include cart, checkout, purchase, entitlement, download, refund, invoice, tax, and support records.
Private repository contents are processed for security scanning, listing generation where the creator consents, and sanitized ZIP packaging. Scripley does not expose the source repository to buyers before purchase unless the creator separately makes it available outside Scripley.
Buyer lead data shared with creators is limited to the data needed to understand marketplace demand and provide product support, such as GitHub handle, country, product/version, lead type, and date. Paid buyer country may come from Stripe billing data when available. Free download country comes from the buyer profile. We avoid IP-derived country for seller leads.
We process personal data to provide accounts, authentication, GitHub integrations, product ingestion, security review, checkout, tax handling, delivery, downloads, seller leads, payouts, support, legal notices, fraud prevention, abuse prevention, analytics, reliability monitoring, and compliance. Depending on the context, the legal bases may include contract performance, legal obligation, legitimate interests, consent, and the establishment, exercise, or defense of legal claims.
We use service providers for hosting, authentication, storage, GitHub integration, payment processing, tax calculation, payout onboarding, security scanning, analytics, reliability monitoring, email, and support. Providers receive only the data needed to perform those services. Some providers may process data outside the European Economic Area using appropriate transfer safeguards where required.
We keep personal data only for as long as needed for the purposes described above. Some records may be retained where required for legal, tax, accounting, fraud-prevention, marketplace safety, payment, dispute, security, or audit reasons.
You may request access, correction, deletion, export, objection, restriction of processing, or withdrawal of consent where applicable. You can exercise these rights by contacting info@airistoteles.com. You also have the right to lodge a complaint with the Spanish Data Protection Agency or another competent supervisory authority.
