Privacy Policy
Last updated: September 27, 2025
Introduction
pkgstore ("we," "our," or "us") operates a marketplace for private NuGet feeds. Our platform connects two types of users: sellers who publish and monetize their NuGet packages, and buyers who purchase access to these private feeds. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service at pkgstore.io.
Information We Collect
Account Information (All Users)
- • Email address (used for login and notifications)
- • User profile information and preferences
For Sellers (Package Publishers)
- • Publisher profile information (company name, contact details)
- • NuGet packages you upload (metadata, files, version history)
- • Package download statistics and analytics
- • Feed configuration and access settings
- • API key usage and access logs
- • Stripe seller account information for receiving payments
- • Tax information and payout details
For Buyers (Package Consumers)
- • Purchase history and subscription status
- • Package access credentials and usage
- • Billing details processed through Stripe
- • Download activity and usage patterns
Technical Information (All Users)
- • IP addresses and browser information
- • Session data and authentication tokens
- • Service usage patterns and error logs
How We Use Your Information
General Platform Operations
- • Service Operation: Provide marketplace infrastructure and NuGet package hosting
- • Authentication: Secure access to your account and packages
- • Communication: Send important service updates and transaction notifications
- • Security: Protect against fraud and unauthorized access
- • Analytics: Improve service performance and user experience
For Sellers
- • Package Management: Host, organize, and distribute your NuGet packages
- • Revenue Processing: Handle payments from buyers and process payouts to you
- • Analytics: Provide download statistics and revenue reporting
- • Tax Compliance: Generate tax documents and maintain records
For Buyers
- • Purchase Processing: Handle subscription payments and package access
- • Access Management: Provide secure credentials for package downloads
- • Usage Tracking: Monitor your package usage for billing and support
- • Customer Support: Provide assistance with purchases and technical issues
Third-Party Services
Stripe
Payment processing for marketplace transactions - handles buyer payments and seller payouts. Subscription management for package access. View Stripe's Privacy Policy.
Cloudflare
CDN, DDoS protection, and R2 object storage for package files. CAPTCHA verification via Turnstile. View Cloudflare's Privacy Policy.
Email Service
Transactional emails for authentication, purchase confirmations, seller notifications, and service updates.
Data Storage and Security
- • Encryption: All data is encrypted in transit using TLS/SSL
- • Database Security: Secure database with encrypted connections and access controls
- • File Storage: Package files stored securely in Cloudflare R2 with access controls
- • Authentication: ASP.NET Identity with secure password hashing
- • Access Control: Role-based permissions and API key management
Data Retention
- • Account Data: Retained while your account is active (buyers and sellers)
- • Package Files (Sellers): Retained as long as you maintain your seller account
- • Purchase Records (Buyers): Retained as long as you have active subscriptions
- • Financial Records: Retained for tax and legal compliance (typically 7 years)
- • Usage Logs: Retained for 90 days for security and debugging purposes
Your Rights
You have the right to:
- • Access and download your data
- • Correct inaccurate information
- • Delete your account and associated data
- • Export your package data
- • Opt out of non-essential communications
To exercise these rights, please use the feedback button at the bottom right of the page to contact us. Note that some data retention may be required for legal compliance, particularly for financial records related to marketplace transactions.
Cookies and Tracking
We use essential cookies for:
- • Session management and authentication
- • Security and anti-forgery protection
- • User preferences and settings
We use Plausible Analytics, a privacy-friendly analytics service that does not use cookies or track personal data. We do not use advertising cookies or invasive tracking scripts.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by email or through a prominent notice on our service. Your continued use of the service after such changes constitutes acceptance of the updated policy.
Contact Information
If you have questions about this Privacy Policy or our data practices, please use the feedback button at the bottom right of the page to contact us.