Privacy
What we keep, and for how long.
Written from the code rather than from a template, so the durations below are the ones the system actually uses.
In one line
We hold what is needed to run your shop and nothing speculative. We do not sell it, and we do not hand it to anyone for advertising. You can export all of it whenever you want, and ask for it to be erased.
What we hold about you
- · Your Second Life avatar name and UUID, and your shop names.
- · Your sales, products, vendors and delivery history — the reason the service exists.
- · Your team members and their roles, if you invited any.
- · A password hash if you set one. The password itself is never stored.
- · Your subscription and billing ledger.
What we hold about your customers
You are the merchant they bought from, so you decide how this data is used in your shop. We store and protect it on your behalf.
- · The avatar name and UUID of anyone who buys from you, and what they bought.
- · Their store credit balance and its movement history.
- · Their support tickets with you, and the messages in them.
- · Whether they asked not to receive your product updates.
Why we are allowed to hold it
- To run your shop. Sales, products, deliveries and payouts are processed because they are necessary to provide the service you signed up for.
- To keep it safe. Sign-in records, request signatures and abuse checks are processed for our legitimate interest in keeping the service secure for everyone using it.
- To know who came in. A visitor counter records the avatars that walk into a shop for the merchant’s legitimate interest in knowing their own traffic, the footing every counter on the grid has stood on for twenty years.
- Where consent applies, you can withdraw it at any time, and doing so does not affect what came before.
Visitor counters, said plainly
If you rez a visitor counter, it records who walks into your shop — the avatar’s name and UUID, the region, and the time — and it keeps that record for as long as the shop runs. No consent is asked of the visitor. That has been the norm in Second Life for twenty years and it is what merchants expect, but we would rather write it here than let anyone discover it.
It is a log of visits, not a profile: nothing is inferred from it, and it is never shared or sold. A visitor who would rather not appear in it can write to contact@plurion.io, and we will take them out of the record.
How long we keep it
- Sales and deliveries
- Kept for as long as your shop exists, and exportable the whole time. Nothing expires on a timer.
- Store credit ledger
- Kept as long as the balance exists. It is append-only: a balance is the sum of its history.
- Support messages
- Kept with the ticket, and the content of a message can be erased on request.
- Visitor passages
- Kept for as long as the shop runs. A visitor counter is the shop’s own record of who came in, and nothing in it expires on a timer. See the section above.
- Sign-in and security records
- A dashboard session lasts seven days; a customer hub session, thirty. A sign-in link expires after fifteen minutes, a sign-in code after ten. IP addresses throttle abuse as it happens: they are never stored in the database, only in short-lived server logs.
- Proof of purchase
- One record ties an avatar to a product and a date, and it outlives the shop on purpose. It is what lets a buyer get back, years later, something they paid for. It is a reference rather than a profile, but it does still point at an avatar, and we would rather say so than call it anonymous.
- Billing records
- What you paid us is kept for as long as your Plurion account exists, with the account rather than with any one shop.
Taking it back, or having it erased
You can access, correct, export or erase what we hold, and where it applies, restrict or object to how it is used.
- Export. One click in your settings gives you a JSON file of your shop — summary or full. No request form, no waiting on us.
- Deletion. Ask, and your shop closes immediately. Thirty days later — time enough to change your mind — every identifying detail is stripped from it: names, avatar UUIDs, private notes, and the support messages themselves — apart from the one exception below. The sale rows stay behind with nothing left to attach them to you or to your buyers. The payout rows still name the people you paid: that line is their record of what they earned, frozen at the sale, and erasing it would erase their history rather than yours.
- Closing the account itself. Deleting a shop leaves your Plurion account and your other shops untouched. Closing the account covers every shop it owns and the login behind them, on the same thirty-day timer — and your billing record goes with it, apart from what accounting rules require us to keep.
- The one exception. Closing a shop does not erase its buyers’ proof of purchase — that one is not the merchant’s to erase. A buyer who wants theirs gone only has to ask us, and we will, after telling them the cost: redelivery through Plurion then ends permanently for those purchases.
- Backups. Erasure applies to the live database. A rolling backup lets us rewind the last six hours after an incident, so a copy can survive that long — then the window moves past it.
- Your customers. A buyer can ask you, or us, for any of this — what we hold, a copy of it, or its erasure. Write to contact@plurion.io.
Where your data lives
Everything the product itself stores sits in EU regions — the database, the cache, the dashboard, the archives and the error monitoring, each one checked rather than assumed. Requests are a different matter: they are handled by an edge network that runs the code close to whoever made the call, so a vendor sold from a North American region is served from there. Data at rest stays in the EU; the processing of a request happens where the request does.
Two things sit outside that inventory, and pretending otherwise would be the easy version: the short-lived request logs are kept by the edge provider that produces them, and any email you send us lives with our mail provider. Neither of those locations is one we pin ourselves.
Who else is involved
Running Plurion involves a small number of infrastructure providers — hosting, database, monitoring — who hold data on our behalf and process it under their data-processing terms, on our instructions. None of them receives it as a customer file. Each of them also runs its own service on top of that — keeping it secure, billing us, meeting its own legal duties — and we describe that rather than promise it away. We do not sell data, and we do not share it for advertising.
Second Life is not us
Plurion is an independent product, not affiliated with or endorsed by Linden Lab. What happens inside Second Life itself — your account there, your L$ balance, the platform’s own records — is governed by their terms, not ours.
Who runs Plurion
Plurion is independently operated by Vox Bachman, a Second Life resident. Privacy questions, data requests and deletion requests all go to the same place: contact@plurion.io.
Status
This is how Plurion handles your data, described in plain words. If anything here changes, this page changes with it.
Questions: contact@plurion.io. Security issues: the disclosure page.