Our Privacy Policy​

Version 2.0 · Effective 4 September 2026 · Previous versions

This policy explains what information we collect when you use sonniss.com or gdc.sonniss.com (our GDC Game Audio Bundle site), what we do with it, and the rights you have over it. It replaces the policy that had been in place since 20 October 2020. What changed: a complete rewrite for the UK GDPR, with new sections on product recommendations, how long we keep things, and where your data goes.

Who we are

Sonniss is a sound effects marketplace. The libraries are made and owned by independent publishers; we sell the licences.

The company behind it is Sonniss Limited, registered in England and Wales, company number 09377364. Registered office: Colony, 5 Piccadilly Place, Manchester, M1 3BR, United Kingdom. VAT number GB 205 1073 61. We are the data controller for both sites under the UK GDPR. You can reach us about anything in this policy at [email protected]. We are not required to appoint a statutory Data Protection Officer and have not done so; privacy questions go to that address and are dealt with directly.

Some plain promises, each one true:

  • We do not sell your personal data. Ever.
  • We do not pass your details to the publishers whose libraries you buy.
  • Card numbers never touch our systems. You enter them directly with Stripe or PayPal.
  • We do not send marketing email unless you asked for it, either by ticking the box at checkout or by signing up on one of our email forms, such as on the GDC Game Audio Bundle pages.
  • No advertising company’s code runs in your browser on either site, and no advertising cookies are set on your device.
  • We do measure our own ads: when one leads to a sale, we count that sale with the platform the ad ran on, server-side. We do not build advertising audiences from your data, and we never retarget you with ads.

What we collect

We collect what the store needs to work, and not much else.

When you browse: our servers and the networks that deliver our sites record your IP address, the pages you request, and your browser type. These logs exist for security and to keep the sites up.

When you make an account: your name, email address and password. The password is stored hashed; we cannot read it.

When you buy: your name, email, billing address and country, what you ordered, and your VAT number if you buy as a business. Your card or PayPal details go directly to the payment provider and are never seen or stored by us. We cannot take an order without an email address.

When you download from the store: which files, when, and from which IP address. We keep this because your order and download history are the proof your licence exists.

When you contact us: whatever you write to us by email or live chat, and the address you write from.

When you sign up for our emails: your first name and email address. Our sign-up forms, including the ones on the GDC Game Audio Bundle pages, collect nothing unless you fill them in and press the button yourself.

If you publish libraries with us: see the publisher section below.

And what we do not collect: we do not ask for or want any sensitive personal data (health, beliefs and so on), we do not buy data about you from anyone, and we do not knowingly collect anything from children.

Why we use it

Every use of your information has a legal basis under the UK GDPR. This is the full list.

What we doWhat we useLegal basis
Run the store, deliver your downloads, and keep your order history as proof of your licenceAccount, order and download dataContract (Article 6(1)(b))
Take payment and prevent fraudCheckout data, order IP addressContract, and our legitimate interests in protecting the store and other customers from fraud
Answer your questionsWhatever you send usContract, and our legitimate interests in helping you
Pay our publishersPublisher payout dataContract
Send marketing email you asked forEmail, name, and the record of your opt-inConsent: the ticked box at checkout or your sign-up on one of our email forms, withdrawable at any time
Show product recommendations on this websiteSee the dedicated section belowLegitimate interests (Article 6(1)(f))
Understand how the site is used, where visitors come from, and which of our marketing led to a salePseudonymous analytics data, and a first-party record of how you arrivedLegitimate interests
Measure whether our own ads workOrder events and the ad-click reference that led to the sale, relayed server-sideLegitimate interests (knowing which ads pay for themselves)
Keep the sites running and find pages that are slow or failingPage performance data, IP address, browser and device informationLegitimate interests (a store that works)
Show on-screen tips, mainly to guide publishers through the submission formIP address, and an identifier recording which tips you have been shownLegitimate interests (helping people find their way around without having to ask us)
Keep the records tax and company law requireOrder and invoice recordsLegal obligation (Article 6(1)(c))

Marketing emails

We only send marketing email to people who asked for it, either by ticking the box at checkout or by signing up on one of our email forms, such as the ones on the GDC Game Audio Bundle pages. Every email has an unsubscribe link.

One honest detail: when you unsubscribe or object, we keep a minimal record of that permanently. It is the only way to make sure we never email you again. That record is personal data we hold specifically to honour your objection.

Product recommendations on our website

In a few places on this website we show a row of related sound libraries, put together automatically by comparing products (their tags, price and publisher), or sometimes chosen by us. On product pages and search results the row is the same for everyone and uses no information about you at all. On the page shown after you complete an order the row uses only the items in that order, and on your downloads page only the item you are downloading. We do not add these recommendations to the order confirmation or download emails we send you.

Where a row does use information about you, our legal basis is legitimate interests (Article 6(1)(f) UK GDPR): helping you find relevant libraries among several thousand, and selling more of them. We consider this fair because it happens in the moment and nothing is kept. We do not:

  • track you from one visit to the next,
  • use your browsing history,
  • combine your separate orders to work out what kind of customer you are,
  • keep a record of what was shown to you, or
  • share anything with advertising networks or any other third party for this purpose.

Your right to object to product recommendations. It is absolute: you do not need to give a reason, and we will stop. Email [email protected] with “Recommendations opt-out” in the subject line, from the email address you use for orders, and we will turn the rows off for your account and any future orders from that address. This right is separate from the rights listed below and will not affect your orders, downloads, or anything else about your account.

Who we share it with

No one buys your data from us, and no one gets it to market to you. The services below process it to run the store, each under a contract that limits what they can do with it.

Payments: Stripe and PayPal take your payment. For the payment itself they act as independent controllers under their own privacy policies; your card details exist at their end, not ours. If you enter a VAT number as a business buyer, we check it against the European Commission’s VAT-number validation service.

Hosting, backups and performance monitoring: the store and its database, including your account and order data, run on a managed server in London, United Kingdom. Backup copies of the database are made through the day and held encrypted with an off-site storage provider. Performance monitoring comes built into our hosting stack: New Relic (US) receives page performance data, your IP address, and browser and device information, so slow and failing pages can be spotted.

Site delivery and security: Cloudflare (US) sits in front of both sites: it delivers pages, blocks attacks, runs the bot check on our forms, and measures how fast pages load. Bunny CDN (Slovenia, EU) serves media such as images and audio previews. Your download files are stored on and delivered from Cloudflare’s storage network.

Email: our support inbox is hosted with Google. Everything we send you, order emails, password resets, and the marketing email you asked for, is delivered by SMTP2GO, a New Zealand company.

Live chat: the chat window is provided by Charla, a US company. If you use it, your messages are processed by that provider, along with your name and email address if you type them in, or your account name and email if you are signed in. Chat conversations are held on servers in the European Union, and Charla works for us under a data processing agreement with standard contractual clauses covering transfers. If you would rather not use chat, email works just as well: [email protected].

On-screen guidance: short pop-up tips, mainly to guide publishers through the library submission form, are provided by Usetiful. Its script loads on our pages, receives your IP address, and sets an identifier so a tip you have already seen is not shown again.

Analytics and ad measurement: we use Google Analytics to understand how the site is used and where visitors come from. The measurement happens at our own network edge and is passed to Google server-side: Google’s code does not run in your browser, and no Google cookies are set on your device. What Google receives is pseudonymous: pages viewed, where visitors arrive from, rough location, device type, and purchase events with no payment details. We do not set a User-ID. In the same server-side way, when a sale follows one of our own ads on Google or LinkedIn, we count that sale with the platform the ad ran on, so we know which ads pay for themselves. None of it is used to build advertising audiences, and we never retarget you.

Embedded videos: some product pages embed the publisher’s demo video from YouTube. When one loads, Google receives your IP address and treats your viewing under its own privacy policy.

Professional and legal: our accountant sees the financial records, and HMRC and the Irish Revenue (for EU VAT One Stop Shop returns) receive the tax filings the law requires. If the police or a court lawfully demand data, we comply.

Back office: like any business, we also use a small number of service providers for business administration, IT, productivity and operational tooling. Some are located in the United States. Each works under a contract that limits what they may do with any data to providing their service to us, and transfers are covered by the safeguards in the next section.

If the business is ever sold or restructured, customer records would transfer with it, under this policy or one at least as protective, and we would tell you.

Where your data lives

Your account and order data live on a server in London. When data does leave the UK, we use the safeguards UK law provides:

  • The UK adequacy regulations, for countries the UK has approved. This covers our EU providers, such as Bunny CDN in Slovenia, and New Zealand, where SMTP2GO is based.
  • The UK Extension to the EU-US Data Privacy Framework (the “UK-US Data Bridge”) for certified US providers, including Stripe, Google, LinkedIn and Cloudflare.
  • PayPal’s approved Binding Corporate Rules.
  • The UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses, for anything the above does not cover.

Our live chat provider holds chat data in the European Union and works under standard contractual clauses, as described in the section above. We never treat “you gave us the data” as permission to send it abroad; transfers rest on the safeguards listed here, and you can ask us for a copy of the ones that apply to your data.

How long we keep it

Different records have different clocks. This is the schedule we actually work to.

WhatHow longWhy
Orders, invoices and download logsKept indefinitelyYour order is the proof your licence exists. Licences are perpetual, so the evidence is too
EU VAT One Stop Shop transaction records10 years from the end of the year of the saleEU OSS scheme rules require it
UK VAT and tax records6 yearsUK tax law
Support emailFor as long as it may matter to your orders or licencesSupport threads often record what your licence covers
Live chat transcriptsWhile the conversation stays relevant to your account or ordersIf a transcript records something about your licence, that part is kept with your order
Contact form entriesWhile your query stays liveThey have no long-term value once answered
Email sending logs14 days, then deleted automaticallyKept briefly to troubleshoot delivery
Marketing listUntil you unsubscribe or objectA minimal suppression record is then kept permanently so the objection sticks
Fraud recordsAs long as needed to protect the storeThe name, email and IP of fraudulent transactions only
Server and network logsA short rolling windowSecurity
BackupsAge out automatically on a rolling cycleIf you ask us to erase your data, it is put beyond use and drops out of the backups as the cycle turns

Anything not listed is kept only as long as the purpose it was collected for requires. If you close your account, we delete the account data and keep only what the table above requires.

Your rights

The UK GDPR gives you rights over your information: to see a copy of it, to have it corrected, to have it deleted, to restrict or object to our use of it, to take it away in a portable format, and to withdraw any consent you gave. The objection to direct marketing is absolute: object, and it stops.

The practical part: rights requests are free. We answer within one month, as the law requires. We check identity in proportion to the request: writing from the email address on your account is normally enough, and we do not ask for ID documents. If we say no to a request, we will explain why, and if you think we got it wrong, reply and a human will look at it again.

We do not make decisions about you by computer alone that produce legal or similarly significant effects.

If you are unhappy with how we have handled your data, you can complain to the Information Commissioner’s Office, the UK regulator: ico.org.uk. We would appreciate the chance to sort it out first: [email protected].

Cookies

The site sets a small number of cookies it needs to work: keeping you logged in, remembering your cart, and remembering whether you have already seen one of our popups so we do not show it twice. Our store also keeps a first-party record of how you arrived, for example which site referred you, so we know which of our marketing works; it is attached at most to your order and is never shared with advertising platforms. A few of the services described above set an identifier of their own so they can tell one visit from another: the live chat widget, so a conversation survives a page reload; the performance monitoring built into our hosting; and the on-screen guidance tool, so a tip you have already seen is not shown again. No Google cookies and no third-party advertising cookies are set by either site. You can limit or clear cookies in your browser settings, though blocking the essential ones will break login and checkout.

One modern note: if you reach this site through an AI assistant or a similar tool, what that tool does with your questions and browsing is governed by its own privacy policy, not this one.

Security

Data moves over encrypted connections, both sites sit behind Cloudflare’s protections, the store’s server is in London, and card data never touches us. Access to personal data is on a need-to-know basis. We have procedures for suspected personal data breaches, and we will notify you and the ICO where the law requires it.

Children

This store is for adults. Accounts and purchases are for people aged 18 and over. We do not knowingly collect children’s data, and if we learn we hold any, we delete it.

If you publish libraries on Sonniss

From our publishers we collect what we need to run the partnership: your name and contact details, your storefront information, and payout details. Payout details means your PayPal address, or your bank account details if we pay you by bank transfer. Bank details are never stored in our website’s database. We use this to pay you, to keep commission records, and to meet tax obligations, and we keep it as long as the financial records above. Two promises, both ways: your buyers’ personal details are not shared with you, and your personal details are not shared with buyers beyond what you choose to put on your public storefront.

Changes to this policy

When we change what we do with your information, we will update this policy, move the version number, and post a dated notice on the site. When we only clarify wording, the edit date changes. Every previous version stays available at sonniss.com/our-privacy-policy/previous-versions/, so you can always see what this policy said on any given day. This is a notice of what we do, not a contract you sign, and we will never treat your continued use of the site as agreement to anything.

Contact

Email: [email protected]

Post: Sonniss Limited, Colony, 5 Piccadilly Place, Manchester, M1 3BR, United Kingdom.

Shopping Cart

Your cart is empty.

Return to shop
Proceed to Checkout