Privacy Policy
Last updated: 8 August 2026
Who is responsible
[Your company name - TO BE COMPLETED]
[Street and number]
[Postcode and city]
[Country]
Email: [email protected]
The short version
StorePackager Cloud resolves Microsoft Store apps into a signed manifest. The actual package files are downloaded by an agent running inside your own network, straight from Microsoft. That is a privacy property, not just an architectural one: we never receive, store or proxy your package content, and we have no access to the machines you deploy to.
What we store
| Data | Why | Legal basis (GDPR) |
|---|---|---|
| Name, email, hashed password | Your account and sign in | Art. 6(1)(b) - performance of a contract |
| Organisation name, members, roles | Shared access for your team | Art. 6(1)(b) |
| Which Store apps you resolve, versions, file hashes, job history | Running the service and showing your history | Art. 6(1)(b) |
| Agent registrations and hashed tokens | Letting your agents authenticate | Art. 6(1)(b) |
| Audit log of security relevant actions | Traceability of changes in your organisation | Art. 6(1)(f) - legitimate interest in a secure service |
| Messages you send through the contact form | Answering your enquiry | Art. 6(1)(b) and (f) |
| Billing details, if you take a paid plan | Invoicing and payment | Art. 6(1)(b) and (c) - legal retention duties |
We do not use tracking cookies, advertising pixels or third party analytics. The only cookie we set is the session cookie that keeps you signed in.
What we deliberately do not store
- The package files themselves - those go from Microsoft to your agent.
- Your Intune or Entra ID credentials. If you upload packages to Intune, those credentials stay in the agent's local configuration on your own machine and are never sent to us.
- Anything about the devices you deploy to.
- Your password in readable form - only a salted hash.
Processors and where data sits
The service runs on infrastructure operated by [Hosting provider]. Traffic passes through Cloudflare, which acts as a reverse proxy and terminates TLS. If you take a paid plan, payments are handled by Stripe, and we never see your full card details. Each of these acts as a processor on our instructions under Art. 28 GDPR.
How long we keep it
- Account and organisation data: until you delete the account.
- Job history and audit entries: while the account exists, so you can trace what happened.
- Contact form messages: up to 24 months after the enquiry is closed.
- Invoices and accounting records: as long as tax law requires, typically ten years.
Your rights
You can ask for access to your data, correction, deletion, restriction of processing, a portable copy, and you can object to processing based on legitimate interest (Art. 15 to 21 GDPR). Write to [email protected] and we will deal with it. You also have the right to complain to a supervisory authority.
Changes
If this policy changes in a way that matters, we will say so at https://storepackager.download and, for anything substantial, by email. Questions are welcome at [email protected].