Living Stack checkout privacy

The checkout service processes an order identifier, the public half of an installation key, immutable package and request hashes, Stripe payment identifiers and status, entitlement state, installation registrations, webhook event identifiers, and buyer-submitted support messages. It does not need or receive the private installation key. Stripe handles payment-card data on Stripe-hosted pages.

These records are used to bind payment to fulfillment, prevent replay, verify licenses, deliver the exact private package, process support, and apply refund or dispute status. Do not put credentials, private keys, card data, or unrelated personal data in a support message.

Checkout policies