Back

Privacy

What we keep, and for how long.

Written from the code rather than from a template, so the durations below are the ones the system actually uses.

In one line

We hold what is needed to run your shop and nothing speculative. We do not sell it, and we do not hand it to anyone for advertising. You can export all of it whenever you want, and ask for it to be erased.

What we hold about you

What we hold about your customers

You are the merchant they bought from, so you decide how this data is used in your shop. We store and protect it on your behalf.

Why we are allowed to hold it

Visitor counters, said plainly

If you rez a visitor counter, it records who walks into your shop — the avatar’s name and UUID, the region, and the time — and it keeps that record for as long as the shop runs. No consent is asked of the visitor. That has been the norm in Second Life for twenty years and it is what merchants expect, but we would rather write it here than let anyone discover it.

It is a log of visits, not a profile: nothing is inferred from it, and it is never shared or sold. A visitor who would rather not appear in it can write to contact@plurion.io, and we will take them out of the record.

How long we keep it

Sales and deliveries
Kept for as long as your shop exists, and exportable the whole time. Nothing expires on a timer.
Store credit ledger
Kept as long as the balance exists. It is append-only: a balance is the sum of its history.
Support messages
Kept with the ticket, and the content of a message can be erased on request.
Visitor passages
Kept for as long as the shop runs. A visitor counter is the shop’s own record of who came in, and nothing in it expires on a timer. See the section above.
Sign-in and security records
A dashboard session lasts seven days; a customer hub session, thirty. A sign-in link expires after fifteen minutes, a sign-in code after ten. IP addresses throttle abuse as it happens: they are never stored in the database, only in short-lived server logs.
Proof of purchase
One record ties an avatar to a product and a date, and it outlives the shop on purpose. It is what lets a buyer get back, years later, something they paid for. It is a reference rather than a profile, but it does still point at an avatar, and we would rather say so than call it anonymous.
Billing records
What you paid us is kept for as long as your Plurion account exists, with the account rather than with any one shop.

Taking it back, or having it erased

You can access, correct, export or erase what we hold, and where it applies, restrict or object to how it is used.

Where your data lives

Everything the product itself stores sits in EU regions — the database, the cache, the dashboard, the archives and the error monitoring, each one checked rather than assumed. Requests are a different matter: they are handled by an edge network that runs the code close to whoever made the call, so a vendor sold from a North American region is served from there. Data at rest stays in the EU; the processing of a request happens where the request does.

Two things sit outside that inventory, and pretending otherwise would be the easy version: the short-lived request logs are kept by the edge provider that produces them, and any email you send us lives with our mail provider. Neither of those locations is one we pin ourselves.

Who else is involved

Running Plurion involves a small number of infrastructure providers — hosting, database, monitoring — who hold data on our behalf and process it under their data-processing terms, on our instructions. None of them receives it as a customer file. Each of them also runs its own service on top of that — keeping it secure, billing us, meeting its own legal duties — and we describe that rather than promise it away. We do not sell data, and we do not share it for advertising.

Second Life is not us

Plurion is an independent product, not affiliated with or endorsed by Linden Lab. What happens inside Second Life itself — your account there, your L$ balance, the platform’s own records — is governed by their terms, not ours.

Who runs Plurion

Plurion is independently operated by Vox Bachman, a Second Life resident. Privacy questions, data requests and deletion requests all go to the same place: contact@plurion.io.

Status

This is how Plurion handles your data, described in plain words. If anything here changes, this page changes with it.

Questions: contact@plurion.io. Security issues: the disclosure page.