Privacy Policy
What ValTerra processes and why: license email, hashed machine ID, update-feed logs. Map tiles go straight from your machine to the provider.
Last updated
This policy explains what data is processed when you visit getvalterra.com, purchase a ValTerra license, and use ValTerra for Autodesk 3ds Max (“the Software”).
Data controller: Valerii Nikulin, sole proprietor (FOP) registered in Ukraine, trading as Shall We Art. Contact: [email protected].
The short version
- We never see your map data. Map tiles, imagery, and elevation data are requested by the Software on your machine directly from the providers you use (Google Maps Platform under your own API key, OpenStreetMap, open elevation tile services). This traffic does not pass through our servers, and we have no access to it.
- Your API keys stay on your machine. They are stored locally and sent only to the respective provider, never to us.
- Telemetry is off by default. Nothing about your usage is collected unless you explicitly turn it on.
- The website sets no cookies and runs no analytics. No tracking scripts, no third-party embeds, nothing to consent to.
- We process the minimum needed to sell licenses, deliver keys, and serve updates.
1. What we process and why
1.1. Purchases (via Paddle)
Purchases are processed by Paddle, our merchant of record. Paddle is the seller of record and an independent data controller for the checkout: it collects your name, email, billing country, VAT/tax data, and payment details under its own privacy policy (https://www.paddle.com/legal/privacy (opens in a new tab)). We never receive your payment card details. From Paddle we receive: your name, email, billing country, order identifier, and the product/tier purchased.
- Purpose: delivering your license key, maintaining your license record, support, legally required accounting.
- Legal basis: performance of a contract; legal obligation (accounting/tax records).
- Retention: for as long as your license exists, plus the period required by Ukrainian accounting and tax law.
1.2. License keys
Your license does not call home. A key is a signed file. When you paste it into the panel, the Software checks the signature on your own machine and stores the key there. There is no activation server and no license API: nothing about your computer is sent to us when you enter a key, or at any time afterwards.
The key format can be locked to one machine, in which case the Software compares an identifier it derives locally against the one written inside the key. That comparison happens entirely on your device and the identifier is never transmitted. Keys issued today are not machine-locked.
- Purpose: making the license you bought work.
- Legal basis: performance of a contract.
- Retention: we keep the license record created at purchase (see 1.1); the key on your machine is yours and we hold no copy of your installation.
1.3. Update checks
When the Software looks for a new version it requests one small file from a public feed hosted on GitHub. GitHub records its own standard server logs for that request, including your IP address; GitHub’s privacy statement applies to them (https://docs.github.com/en/site-policy/privacy-policies/github-privacy-statement (opens in a new tab)).
We run no server of our own in this path, we receive no copy of those logs, and no license check of any kind takes place.
- Purpose: telling you that a newer version exists.
- Legal basis: legitimate interest.
- Retention: none by us. GitHub keeps its logs under its own policy.
1.4. Optional telemetry (opt-in)
If — and only if — you enable telemetry in the Software settings, we collect anonymous usage events (which features are used, timings, non-personal error/crash reports: stack traces, Software and Autodesk 3ds Max versions, GPU model). Telemetry never includes scene contents, file names, geographic coordinates you work with, API keys, or captured images.
- Purpose: prioritizing development, fixing crashes.
- Legal basis: consent (withdraw any time by turning telemetry off).
- Retention: up to 24 months, then deleted.
1.5. Support and email
If you write to support, we process your email and the contents of your messages for as long as needed to help you and keep support history. If you opt in to product news, we send occasional emails; every email has an unsubscribe link. We do not buy or sell mailing lists.
- Legal basis: legitimate interest (support); consent (news).
2. The website (getvalterra.com)
getvalterra.com is a set of pre-built static HTML pages. There are no accounts, no login, no user profiles, and no application server: the site cannot recognise you between visits.
2.1. Hosting and server logs
The site is served from Cloudflare Pages (Cloudflare, Inc., acting as our hosting processor, https://www.cloudflare.com/privacypolicy/ (opens in a new tab)). Like any web host, Cloudflare records standard connection data — IP address, timestamp, requested URL, user agent, and connection metadata — in order to deliver the pages and to protect the site from attacks and abuse. We do not export those logs, do not enrich them, do not build profiles from them, and do not use them for advertising.
- Purpose: serving the site, security, abuse prevention.
- Legal basis: legitimate interest.
- Retention: as set by Cloudflare for its own edge logs; we keep no separate copy.
2.2. Cookies, analytics, and browser storage
The site sets no cookies of its own. There is no analytics, no tag manager, no advertising or tracking pixel, no A/B testing, no session recording, and no fingerprinting. Because nothing non-essential is placed on your device, there is no cookie banner to click.
One thing is written to your device, and we would rather name it than let you find it:
if you use the light/dark switch in the header, the site saves your choice in your
browser’s local storage under the key vt-theme, with the value light or dark. That
is the whole contents. It is read once when a page opens so the site does not flash the
wrong theme at you, it never leaves your browser, and it identifies nothing about you. If
your browser blocks local storage, the switch still works — the choice just will not
survive a reload. You can clear it with the rest of your site data at any time.
Your browser also caches static files (HTML, CSS, fonts, images) using ordinary HTTP cache headers so that pages load faster on the next visit. That cache lives on your device, contains no personal data, and can be cleared in your browser at any time.
2.3. The Founders list form
The pricing page carries one form: the Founders list. It is the only place on this site that collects anything about you. Checkout is not open yet, so the form does not take orders or payment details.
What it asks for. Your email address, which licence you are interested in, and a tick confirming you agree to be written to. The email and the tick are required; the licence choice is not.
The decoy field. The form contains a text field labelled “Company” that is hidden from view and skipped by keyboard and screen readers. It exists to catch automated submissions, which fill in every field they find. If it arrives filled in, we discard the submission. We would rather do that than make every human solve a puzzle to prove they are human. Nothing typed into it is stored.
What we store. Your email address, the licence you picked, the two-letter country code Cloudflare derives from your connection, and the date and time. We do not store your IP address — the database has no column for it. Entries live in our own database on Cloudflare; no third-party form or newsletter service is involved, so your address is not handed to anyone by the act of submitting.
What we use it for. To email you once when checkout opens, to honour the Founders price you signed up at, and — if you told us you are asking for a team — to answer that. Nothing else. We do not send unrelated marketing and we do not pass your address on.
- Legal basis: consent.
- Retention: until licensing goes live and for up to 12 months after that, or until you ask to be removed — whichever comes first.
- How to be removed: write to [email protected] asking to be removed from the waitlist, or use the unsubscribe link at the bottom of any email we send. We action it within 30 days and keep no shadow copy of the entry.
There is no contact form anywhere on this site. The contact page shows an email address and nothing more, so writing to us is an ordinary email — covered by “Support and email” below.
2.4. No third-party embeds
No fonts, scripts, videos, maps, chat widgets, or social buttons are loaded from other domains. The site’s Content-Security-Policy permits resources only from getvalterra.com, so a third-party tracker cannot be introduced by accident.
3. What we never process
- Map tiles, imagery, elevation data, or anything you import or render. This traffic goes directly from your machine to the provider (Google, OpenStreetMap, elevation tile hosts). We are not in that path and have no access to it.
- Your third-party API keys (kept locally on your machine only).
- Your Autodesk 3ds Max scenes, renders, captures, or camera data.
- Payment card details (handled by Paddle).
4. Sharing
We share personal data only with the processors and independent controllers named above (Paddle, Cloudflare, and GitHub for the update feed) and if required by law. There is no form provider and no newsletter provider on this list because we use neither: the Founders list is stored on Cloudflare with the rest of the site. If that ever changes, the provider will be named here before it can receive anything. We do not sell personal data and do not use it for advertising. We do not sell or share personal information as those terms are defined by the California Consumer Privacy Act.
5. International transfers
We are located in Ukraine. Our processors are located in the United Kingdom, the European Union, and the United States (Paddle: United Kingdom and United States; GitHub: United States; Cloudflare: United States). Ukraine is not covered by an EU adequacy decision. Where GDPR or UK GDPR applies, transfers rely on the Standard Contractual Clauses contained in our processors’ data processing agreements; where you send us data directly so that we can enter into or perform a contract with you, Article 49(1)(b) GDPR applies.
6. Your rights
Depending on your jurisdiction (including GDPR and UK GDPR), you may have the right to access, correct, delete, or receive a copy of your personal data, restrict or object to processing, and withdraw consent. Write to [email protected]; we respond within one month. You may also lodge a complaint with your local supervisory authority.
Note: deleting your license record deletes your ability to re-activate the license — we will warn you and confirm before deleting anything tied to an active license.
7. Security
License infrastructure access is restricted and authenticated; machine identifiers are stored only as one-way hashes; transport is HTTPS everywhere, and the website is served over HTTPS only. No method is 100% secure, but the data we hold is deliberately minimal.
8. Children
The Software and site are not directed at children under 16, and we do not knowingly process their data.
9. Changes
We will post changes here with a new “Last updated” date; material changes affecting the Software’s data behavior will also be noted in release notes.
Contact: [email protected] — Valerii Nikulin, sole proprietor (FOP) registered in Ukraine, trading as Shall We Art.