01What we collect
When you create an account, we ask for the absolute minimum needed to deliver a license key and let you sign in later. We never request, intercept, or store anything happening inside the games you play.
Account information
- Email address — for login, key delivery, and security notifications.
- Username — chosen by you, shown on support tickets and in our Discord.
- Password hash — Argon2id; the plaintext password is never written to disk.
Hardware & session
- Hashed HWID — a one-way fingerprint that ties your license to your machine.
- IP address — at signup and login, for fraud detection. Discarded after 30 days.
- Loader version — to serve the right injection payload and bypass.
Payment
Payments are processed by Stripe and Coinbase Commerce. Solstice Client never sees your card number, crypto wallet, or billing address — only a transaction ID and the plan you bought.
02How we use it
Your data is used exclusively to operate the service, secure your account, and improve detection of license-key abuse. We do not use it for advertising, profiling, or any kind of analytics resale.
- Authenticate you and bind your license to your HWID.
- Detect shared accounts, key resellers, and credential stuffing.
- Send transactional email — receipts, HWID reset confirmations, security alerts.
03HWID & licensing
The loader generates a SHA-256 of your motherboard serial, primary disk serial, and BIOS UUID, salted with a per-account secret. We store the resulting hwid_hash — never the underlying values.
This means we cannot identify your hardware from our database, and a stolen copy of our database cannot be used to identify any user's machine.
Each license includes 3 self-service HWID resets. Resets are logged with a timestamp and the new hash. The old hash is overwritten — we don't keep history.
05Retention
- Account data — kept as long as your account is active.
- Login IPs — 30 days, then permanently deleted.
- Support tickets — 12 months from last reply.
- Payment records — 7 years (legal requirement).
- Deleted accounts — purged from active systems within 24 hours, from backups within 30 days.
06Your rights
Under GDPR (EU/UK) and CCPA (California), and regardless of where you live, you can request any of the following from your dashboard or by emailing privacy@solsticeclient.shop:
- Access — a copy of everything we hold about you, in JSON.
- Correction — fix anything that's wrong.
- Erasure — close your account and wipe the data.
- Portability — export your data and take it elsewhere.
- Objection — tell us to stop processing for any specific purpose.
We answer requests within 14 days, usually much faster.
07Security
The website and dashboard run over TLS 1.3 only. Application databases are AES-256 encrypted at rest. Production access requires hardware security keys and is logged.
We support 2FA via TOTP and security keys. If we ever detect a breach affecting your account, we will email you within 72 hours.
08Contact
Questions, requests, complaints — we read every email.