Version 2.0 · Effective 4 September 2026 · Previous versions
This policy explains what information we collect when you use sonniss.com or gdc.sonniss.com (our GDC Game Audio Bundle site), what we do with it, and the rights you have over it. It replaces the policy that had been in place since 20 October 2020. What changed: a complete rewrite for the UK GDPR, with new sections on product recommendations, how long we keep things, and where your data goes.
Who we are
Sonniss is a sound effects marketplace. The libraries are made and owned by independent publishers; we sell the licences.
The company behind it is Sonniss Limited, registered in England and Wales, company number 09377364. Registered office: Colony, 5 Piccadilly Place, Manchester, M1 3BR, United Kingdom. VAT number GB 205 1073 61. We are the data controller for both sites under the UK GDPR. You can reach us about anything in this policy at [email protected]. We are not required to appoint a statutory Data Protection Officer and have not done so; privacy questions go to that address and are dealt with directly.
Some plain promises, each one true:
- We do not sell your personal data. Ever.
- We do not pass your details to the publishers whose libraries you buy.
- Card numbers never touch our systems. You enter them directly with Stripe or PayPal.
- We do not send marketing email unless you asked for it, either by ticking the box at checkout or by signing up on one of our email forms, such as on the GDC Game Audio Bundle pages.
- No advertising company’s code runs in your browser on either site, and no advertising cookies are set on your device.
- We do measure our own ads: when one leads to a sale, we count that sale with the platform the ad ran on, server-side. We do not build advertising audiences from your data, and we never retarget you with ads.
What we collect
We collect what the store needs to work, and not much else.
When you browse: our servers and the networks that deliver our sites record your IP address, the pages you request, and your browser type. These logs exist for security and to keep the sites up.
When you make an account: your name, email address and password. The password is stored hashed; we cannot read it.
When you buy: your name, email, billing address and country, what you ordered, and your VAT number if you buy as a business. Your card or PayPal details go directly to the payment provider and are never seen or stored by us. We cannot take an order without an email address.
When you download from the store: which files, when, and from which IP address. We keep this because your order and download history are the proof your licence exists.
When you contact us: whatever you write to us by email or live chat, and the address you write from.
When you sign up for our emails: your first name and email address. Our sign-up forms, including the ones on the GDC Game Audio Bundle pages, collect nothing unless you fill them in and press the button yourself.
If you publish libraries with us: see the publisher section below.
And what we do not collect: we do not ask for or want any sensitive personal data (health, beliefs and so on), we do not buy data about you from anyone, and we do not knowingly collect anything from children.
Why we use it
Every use of your information has a legal basis under the UK GDPR. This is the full list.
| What we do | What we use | Legal basis |
|---|---|---|
| Run the store, deliver your downloads, and keep your order history as proof of your licence | Account, order and download data | Contract (Article 6(1)(b)) |
| Take payment and prevent fraud | Checkout data, order IP address | Contract, and our legitimate interests in protecting the store and other customers from fraud |
| Answer your questions | Whatever you send us | Contract, and our legitimate interests in helping you |
| Pay our publishers | Publisher payout data | Contract |
| Send marketing email you asked for | Email, name, and the record of your opt-in | Consent: the ticked box at checkout or your sign-up on one of our email forms, withdrawable at any time |
| Show product recommendations on this website | See the dedicated section below | Legitimate interests (Article 6(1)(f)) |
| Understand how the site is used, where visitors come from, and which of our marketing led to a sale | Pseudonymous analytics data, and a first-party record of how you arrived | Legitimate interests |
| Measure whether our own ads work | Order events and the ad-click reference that led to the sale, relayed server-side | Legitimate interests (knowing which ads pay for themselves) |
| Keep the sites running and find pages that are slow or failing | Page performance data, IP address, browser and device information | Legitimate interests (a store that works) |
| Show on-screen tips, mainly to guide publishers through the submission form | IP address, and an identifier recording which tips you have been shown | Legitimate interests (helping people find their way around without having to ask us) |
| Keep the records tax and company law require | Order and invoice records | Legal obligation (Article 6(1)(c)) |
Marketing emails
We only send marketing email to people who asked for it, either by ticking the box at checkout or by signing up on one of our email forms, such as the ones on the GDC Game Audio Bundle pages. Every email has an unsubscribe link.
One honest detail: when you unsubscribe or object, we keep a minimal record of that permanently. It is the only way to make sure we never email you again. That record is personal data we hold specifically to honour your objection.
Product recommendations on our website
In a few places on this website we show a row of related sound libraries, put together automatically by comparing products (their tags, price and publisher), or sometimes chosen by us. On product pages and search results the row is the same for everyone and uses no information about you at all. On the page shown after you complete an order the row uses only the items in that order, and on your downloads page only the item you are downloading. We do not add these recommendations to the order confirmation or download emails we send you.
Where a row does use information about you, our legal basis is legitimate interests (Article 6(1)(f) UK GDPR): helping you find relevant libraries among several thousand, and selling more of them. We consider this fair because it happens in the moment and nothing is kept. We do not:
- track you from one visit to the next,
- use your browsing history,
- combine your separate orders to work out what kind of customer you are,
- keep a record of what was shown to you, or
- share anything with advertising networks or any other third party for this purpose.
Your right to object to product recommendations. It is absolute: you do not need to give a reason, and we will stop. Email [email protected] with “Recommendations opt-out” in the subject line, from the email address you use for orders, and we will turn the rows off for your account and any future orders from that address. This right is separate from the rights listed below and will not affect your orders, downloads, or anything else about your account.
Who we share it with
No one buys your data from us, and no one gets it to market to you. The services below process it to run the store, each under a contract that limits what they can do with it.
Payments: Stripe and PayPal take your payment. For the payment itself they act as independent controllers under their own privacy policies; your card details exist at their end, not ours. If you enter a VAT number as a business buyer, we check it against the European Commission’s VAT-number validation service.
Hosting, backups and performance monitoring: the store and its database, including your account and order data, run on a managed server in London, United Kingdom. Backup copies of the database are made through the day and held encrypted with an off-site storage provider. Performance monitoring comes built into our hosting stack: New Relic (US) receives page performance data, your IP address, and browser and device information, so slow and failing pages can be spotted.
Site delivery and security: Cloudflare (US) sits in front of both sites: it delivers pages, blocks attacks, runs the bot check on our forms, and measures how fast pages load. Bunny CDN (Slovenia, EU) serves media such as images and audio previews. Your download files are stored on and delivered from Cloudflare’s storage network.
Email: our support inbox is hosted with Google. Everything we send you, order emails, password resets, and the marketing email you asked for, is delivered by SMTP2GO, a New Zealand company.
Live chat: the chat window is provided by Charla, a US company. If you use it, your messages are processed by that provider, along with your name and email address if you type them in, or your account name and email if you are signed in. Chat conversations are held on servers in the European Union, and Charla works for us under a data processing agreement with standard contractual clauses covering transfers. If you would rather not use chat, email works just as well: [email protected].
On-screen guidance: short pop-up tips, mainly to guide publishers through the library submission form, are provided by Usetiful. Its script loads on our pages, receives your IP address, and sets an identifier so a tip you have already seen is not shown again.
Analytics and ad measurement: we use Google Analytics to understand how the site is used and where visitors come from. The measurement happens at our own network edge and is passed to Google server-side: Google’s code does not run in your browser, and no Google cookies are set on your device. What Google receives is pseudonymous: pages viewed, where visitors arrive from, rough location, device type, and purchase events with no payment details. We do not set a User-ID. In the same server-side way, when a sale follows one of our own ads on Google or LinkedIn, we count that sale with the platform the ad ran on, so we know which ads pay for themselves. None of it is used to build advertising audiences, and we never retarget you.
Embedded videos: some product pages embed the publisher’s demo video from YouTube. When one loads, Google receives your IP address and treats your viewing under its own privacy policy.
Professional and legal: our accountant sees the financial records, and HMRC and the Irish Revenue (for EU VAT One Stop Shop returns) receive the tax filings the law requires. If the police or a court lawfully demand data, we comply.
Back office: like any business, we also use a small number of service providers for business administration, IT, productivity and operational tooling. Some are located in the United States. Each works under a contract that limits what they may do with any data to providing their service to us, and transfers are covered by the safeguards in the next section.
If the business is ever sold or restructured, customer records would transfer with it, under this policy or one at least as protective, and we would tell you.
Where your data lives
Your account and order data live on a server in London. When data does leave the UK, we use the safeguards UK law provides:
- The UK adequacy regulations, for countries the UK has approved. This covers our EU providers, such as Bunny CDN in Slovenia, and New Zealand, where SMTP2GO is based.
- The UK Extension to the EU-US Data Privacy Framework (the “UK-US Data Bridge”) for certified US providers, including Stripe, Google, LinkedIn and Cloudflare.
- PayPal’s approved Binding Corporate Rules.
- The UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses, for anything the above does not cover.
Our live chat provider holds chat data in the European Union and works under standard contractual clauses, as described in the section above. We never treat “you gave us the data” as permission to send it abroad; transfers rest on the safeguards listed here, and you can ask us for a copy of the ones that apply to your data.
How long we keep it
Different records have different clocks. This is the schedule we actually work to.
| What | How long | Why |
|---|---|---|
| Orders, invoices and download logs | Kept indefinitely | Your order is the proof your licence exists. Licences are perpetual, so the evidence is too |
| EU VAT One Stop Shop transaction records | 10 years from the end of the year of the sale | EU OSS scheme rules require it |
| UK VAT and tax records | 6 years | UK tax law |
| Support email | For as long as it may matter to your orders or licences | Support threads often record what your licence covers |
| Live chat transcripts | While the conversation stays relevant to your account or orders | If a transcript records something about your licence, that part is kept with your order |
| Contact form entries | While your query stays live | They have no long-term value once answered |
| Email sending logs | 14 days, then deleted automatically | Kept briefly to troubleshoot delivery |
| Marketing list | Until you unsubscribe or object | A minimal suppression record is then kept permanently so the objection sticks |
| Fraud records | As long as needed to protect the store | The name, email and IP of fraudulent transactions only |
| Server and network logs | A short rolling window | Security |
| Backups | Age out automatically on a rolling cycle | If you ask us to erase your data, it is put beyond use and drops out of the backups as the cycle turns |
Anything not listed is kept only as long as the purpose it was collected for requires. If you close your account, we delete the account data and keep only what the table above requires.
Your rights
The UK GDPR gives you rights over your information: to see a copy of it, to have it corrected, to have it deleted, to restrict or object to our use of it, to take it away in a portable format, and to withdraw any consent you gave. The objection to direct marketing is absolute: object, and it stops.
The practical part: rights requests are free. We answer within one month, as the law requires. We check identity in proportion to the request: writing from the email address on your account is normally enough, and we do not ask for ID documents. If we say no to a request, we will explain why, and if you think we got it wrong, reply and a human will look at it again.
We do not make decisions about you by computer alone that produce legal or similarly significant effects.
If you are unhappy with how we have handled your data, you can complain to the Information Commissioner’s Office, the UK regulator: ico.org.uk. We would appreciate the chance to sort it out first: [email protected].
Cookies
The site sets a small number of cookies it needs to work: keeping you logged in, remembering your cart, and remembering whether you have already seen one of our popups so we do not show it twice. Our store also keeps a first-party record of how you arrived, for example which site referred you, so we know which of our marketing works; it is attached at most to your order and is never shared with advertising platforms. A few of the services described above set an identifier of their own so they can tell one visit from another: the live chat widget, so a conversation survives a page reload; the performance monitoring built into our hosting; and the on-screen guidance tool, so a tip you have already seen is not shown again. No Google cookies and no third-party advertising cookies are set by either site. You can limit or clear cookies in your browser settings, though blocking the essential ones will break login and checkout.
One modern note: if you reach this site through an AI assistant or a similar tool, what that tool does with your questions and browsing is governed by its own privacy policy, not this one.
Security
Data moves over encrypted connections, both sites sit behind Cloudflare’s protections, the store’s server is in London, and card data never touches us. Access to personal data is on a need-to-know basis. We have procedures for suspected personal data breaches, and we will notify you and the ICO where the law requires it.
Children
This store is for adults. Accounts and purchases are for people aged 18 and over. We do not knowingly collect children’s data, and if we learn we hold any, we delete it.
If you publish libraries on Sonniss
From our publishers we collect what we need to run the partnership: your name and contact details, your storefront information, and payout details. Payout details means your PayPal address, or your bank account details if we pay you by bank transfer. Bank details are never stored in our website’s database. We use this to pay you, to keep commission records, and to meet tax obligations, and we keep it as long as the financial records above. Two promises, both ways: your buyers’ personal details are not shared with you, and your personal details are not shared with buyers beyond what you choose to put on your public storefront.
Changes to this policy
When we change what we do with your information, we will update this policy, move the version number, and post a dated notice on the site. When we only clarify wording, the edit date changes. Every previous version stays available at sonniss.com/our-privacy-policy/previous-versions/, so you can always see what this policy said on any given day. This is a notice of what we do, not a contract you sign, and we will never treat your continued use of the site as agreement to anything.
Contact
Email: [email protected]
Post: Sonniss Limited, Colony, 5 Piccadilly Place, Manchester, M1 3BR, United Kingdom.
