// legal

Privacy Policy

This describes what the MultiPerson licence service actually stores, field by field. It is written from the system itself rather than from a template, so it is specific enough to be checked.

Last updated 13 August 2026 · TsGoTouch, operator of tsgotouch.com

1. Who we are

"TsGoTouch", "we" and "us" mean the operator of tsgotouch.com, account.tsgotouch.com and the MultiPerson licence service. You can reach us at support@tsgotouch.com about anything in this policy, including a request to delete your data.

2. What we collect

Everything we hold falls into four groups. There is nothing else.

GroupFieldsWhy
Your account Email address · password hash · whether the email is verified · a verification or password-reset token while one is outstanding · the date you signed up To let you sign in, recover your password, and see the keys you own
Your orders Order id · your email · licence term · quantity · amount in USD · payment status · the payment processor's invoice id · which keys the order produced To issue keys against a payment and show you your order history
Your licences Key id · term · status · the device identifier the key is bound to · that device's public key · activation date · expiry date To bind a key to one device and answer whether it is still valid
Activation log Device identifier · key id · timestamp · the IP address the request came from Written on activation and on each daily re-check, to detect a device image copied onto other hardware

Your password is never stored. What is stored is a salted PBKDF2-SHA256 hash at 210,000 iterations, from which the password cannot be recovered — not by us either.

The device identifier is not your hardware

The identifier a key binds to is a random value generated on your device the first time it is needed. It is not your serial number, IMEI, UDID, MAC address or Apple ID, and it carries no information about the hardware. Two devices of the same model produce entirely unrelated identifiers, and it tells us nothing about you beyond distinguishing one installation from another.

3. What we do not collect

MultiPerson runs on your device and keeps its business there. None of the following is transmitted to us, at any point:

The licence re-check sends the key id, the device identifier and a signed counter. That is the whole payload.

4. Cookies and tracking

This website sets no cookies and runs no advertising or analytics trackers. There is no tracking pixel, no session recording and no third-party script on any page of tsgotouch.com.

When you sign in at account.tsgotouch.com, your browser stores a session token in local storage so you stay signed in. It is not a cookie, it is not sent to third parties, and signing out removes it.

5. Who else receives data

We use two service providers. We do not sell personal data, and we do not share it for advertising.

No third-party CDN, on any of our sites

Every asset we serve — stylesheets, typefaces, images — comes from our own domains. There is no Google Fonts, no font CDN, no script CDN and no embedded widget on tsgotouch.com, account.tsgotouch.com or manage.tsgotouch.com. Nobody but us and the two providers above learns that you visited, and no third party receives your IP address as a side effect of a page loading.

6. Legal basis and purpose

We process the account and order data because it is necessary to provide what you bought — an account, a key, and a working licence. We process the activation log because we have a legitimate interest in enforcing a per-device licence and detecting cloned devices. We do not use any of it to profile you or to make automated decisions about you beyond answering "is this licence valid on this device".

7. How long we keep it

Account and order records are kept while your account exists, and afterwards only as long as needed to meet accounting and anti-fraud obligations. Licence records are kept for the life of the key, so that a key cannot be silently rebound after expiry. Activation-log entries age out on the same basis. Verification and password-reset tokens are deleted as soon as they are used, and reset tokens expire an hour after they are issued whether used or not.

8. Your rights

Write to support@tsgotouch.com and we will:

Depending on where you live, you may have further rights under local law. Those rights are not affected by anything in this policy or by the governing-law clause below.

9. Security

Data is held in Amazon Web Services. Passwords are salted and hashed as described above. Licence keys are stored encrypted, and leases are signed with a key held in a managed hardware security module so a lease cannot be forged. Traffic to this site and to the licence service is HTTPS only.

No system is perfect. If you find a weakness in ours, please tell us at support@tsgotouch.com with SECURITY in the subject.

10. Children

This is a technical product sold to adults. It is not directed at children, and we do not knowingly collect data from anyone under 16.

11. Changes

If this policy changes materially we will update the date at the top and, where the change affects data we already hold about you, tell account holders by email.

12. Governing law

This policy is governed by the laws of Cyprus. This does not remove any mandatory data-protection or consumer right you have where you live.


See also the Terms of Service and the Refund Policy.