Privacy Policy
This policy explains how Visioun collects, uses, shares, and protects information that results from your use of our website and services. It is issued by Inoryum Ltd, which operates Visioun.
Effective date: 16 August 2026. Please read this policy together with our Terms of Use and Refund Policy.
Who we are
Visioun is a product of Inoryum Ltd, a company registered in England and Wales with company number 12392337. For UK and UK GDPR purposes, Inoryum Ltd is the data controller of personal data processed through visioun.com.
Privacy requests: [email protected].
Information Collection and Use
We collect information to provide and improve the Visioun service: accounts, theme purchases, downloads, partner applications, support, and related communications. By using the service, you agree to the collection and use of information under this policy where consent is the lawful basis. Other processing is based on contract (to fulfil an order or account), legitimate interests (security, fraud prevention, service improvement), or legal obligation (tax and accounting records).
Payments: we do not store card or billing information
Visioun does not collect, see, or store your payment card number, CVC/CVV, PIN, bank account number, or the billing address you enter at checkout. That information is handled entirely by Stripe on Stripe-hosted Checkout pages.
In particular:
- We never receive or store the full Primary Account Number (PAN) of a card.
- We never receive or store CVC, CVV, or PIN codes.
- We never store bank account or sort-code details for customer purchases.
- Billing name, billing address, and card details entered at payment are collected by Stripe, not by Visioun’s servers.
- Checkout, card validation, 3-D Secure / SCA, receipts, and refunds in the payment network are performed by Stripe.
- We do not store card data in cookies, logs, email, or our database.
After a successful (or failed) payment, Stripe may send us limited transaction metadata so we can create your order, grant a download, send a receipt, and process a refund. That metadata can include: payment status, amount, currency, Stripe customer ID, Checkout Session ID, Payment Intent ID, and, where Stripe provides it, card brand, last four digits, expiry month/year, and billing country. That is not full card or billing-form storage. Stripe’s own processing is described in the Stripe Privacy Policy.
Types of Data Collected
Account and contact data
When you create an account, check out as a guest, subscribe to updates, or contact us, we may collect your name, email address, password (stored as a one-way hash, never in plain text), and messages you send to support.
Order and licence data
We store the theme purchased, licence type, price paid, currency, order reference, download tokens, refund status, and the Stripe identifiers listed above. We do not store card numbers or checkout billing forms.
Partner data
If you apply as a creative partner or receive payouts, we may collect portfolio URL, specialty, tools, application notes, partner agreement records, payout email, and commission amounts. Partner payouts are arranged separately from customer card checkout; we still do not store customer card data.
Usage and technical data
Usage data may include browser type, device and operating-system information, pages visited, time spent on pages, referring URL, approximate location derived from IP address at sign-up, IP address, and diagnostic or error information. Session records may include IP address and user agent for security.
Communications
We keep records of transactional email (sign-in links, order receipts, refund notices, partner payout updates) and support correspondence.
Cookies
We use cookies and similar technologies to operate the service, keep you signed in, protect forms (CSRF), remember a pending checkout so we can show your purchase confirmation, improve security, and understand site usage.
| Type | Purpose | Legal basis |
|---|---|---|
| Strictly necessary | Signed session cookie, account authentication, CSRF protection, checkout completion, maintenance-preview access for staff. | Required to provide the site you requested (UK PECR essential cookies). These do not require consent. |
| Stripe Checkout | Stripe may set cookies on checkout.stripe.com when you pay. Those cookies are Stripe’s, not Visioun’s. | Stripe’s terms and privacy policy. |
| Analytics or marketing (only if enabled) | If we later inject analytics or advertising scripts in the site head, those would be non-essential. | Consent under UK PECR / ePrivacy, where required. |
You can block cookies in your browser. Essential cookies are needed to sign in, complete a purchase, and stay logged in. Stripe cookies are governed by Stripe when you are on their checkout page.
Use of Data
Visioun uses collected data to:
- Create and manage your account and sign-in (password or emailed magic link).
- Process theme purchases, licences, downloads, and refunds.
- Notify you about orders, account changes, and security-related events.
- Provide customer support and investigate defects.
- Monitor usage, prevent abuse, fraud, and technical issues.
- Meet tax, accounting, and legal record-keeping duties.
- Communicate relevant product updates where we have a lawful basis (including where you have not opted out of similar-product mail where permitted).
- Operate the creative partner programme, agreements, and payouts.
We do not use your card details because we never hold them. We do not sell personal data.
Sharing and processors
We share personal data only as needed to run the service:
- Stripe, Inc. and Stripe Payments Europe / UK entities — payment processing. Card and billing details stay with Stripe.
- Email delivery — our configured SMTP provider sends sign-in, order, refund, and support mail.
- Hosting and infrastructure — servers, databases, backups, and file storage used to operate visioun.com.
- Professional advisers and authorities — where required by law, to establish or defend legal claims, or to prevent fraud.
We do not sell, rent, or share personal data with third parties for their own independent marketing.
International transfers
Inoryum Ltd is established in the United Kingdom. Some processors (including Stripe) may process data in the United Kingdom, European Economic Area, United States, or other countries. Where a transfer is restricted under UK GDPR, we rely on an adequacy regulation and/or appropriate safeguards such as the UK International Data Transfer Agreement or Standard Contractual Clauses.
Retention
We keep account and order records for as long as you have an account and for a further period required for tax, accounting, refunds, licence proof, and dispute handling (typically up to six years in the UK for financial records). Session and download tokens expire. Support mail is kept as long as needed to resolve your request and for a reasonable follow-up period. Partner records are kept for the life of the partnership and applicable legal periods. When data is no longer needed, we delete or irreversibly anonymise it.
Security
We take reasonable technical and organisational steps to protect your data, including hashed passwords, HTTPS, signed HttpOnly session cookies, access controls, and keeping card data off our systems by using Stripe Checkout. No method of transmission over the internet or electronic storage is completely secure. You are responsible for keeping your email account and any password confidential.
Your rights (UK and EEA)
Subject to UK GDPR / EU GDPR, you may request access to your personal data, correction, erasure, restriction of processing, objection to processing based on legitimate interests, and data portability. You may withdraw consent where processing is based on consent. You may also lodge a complaint with the UK Information Commissioner’s Office at ico.org.uk, or with your local EEA supervisory authority.
To exercise these rights, email [email protected]. We may need to verify your identity. Email is your sign-in channel, so we treat email-change requests with extra care.
California residents (CCPA / CPRA)
We do not sell or share personal information for cross-context behavioural advertising as those terms are defined under California law. California residents may request that we disclose the categories of personal information collected, the purposes of use, the categories of third parties to whom it is disclosed, and deletion or correction, subject to legal exceptions. We will not discriminate against you for exercising these rights. Submit requests to [email protected].
Children
Visioun is not directed at children. We do not knowingly collect personal data from anyone under 16. Theme purchases are intended for adults or organisations. If you believe a child has provided us data, contact [email protected] and we will delete it.
Automated decisions
We do not make solely automated decisions that produce legal or similarly significant effects about you. Stripe may apply its own fraud and authentication checks on the payment.
Changes to this policy
We may update this policy from time to time. The effective date at the top of this page will change when we do. Continued use of the service after an update constitutes notice of the revised policy, except where a law requires a different form of notice or consent.
Contact
Inoryum Ltd (Visioun), company number 12392337, England and Wales.
Privacy and data protection: [email protected].