Privacy Policy

Privacy Policy

Last updated: September 5, 2026

CacheRat sells digital files. I don’t need your life story to do that.

The general rule here is simple: collect what the site needs to take an order, deliver the file, keep the servers working, and deal with actual problems. No advertising profile. No mailing-list ambush. No selling customer data.

Who we are

This site is CacheRat.

Clear-web address: https://cacherat.com

CacheRat also operates an onion service. Both routes lead to the same store.

What the server sees

Like basically every web server since people started putting web servers on the internet, the systems behind CacheRat may create technical logs.

Those logs can include things such as your IP address, browser user-agent string, requested pages, timestamps, errors, and other information needed to operate or secure the site.

I don’t use that information to build an advertising profile about you.

Orders

CacheRat uses WooCommerce to handle products, orders, and downloads.

When you place an order, the store may retain information connected with that transaction, including the product purchased, order number, payment amount, payment status, timestamps, download activity, and technical information needed to process or troubleshoot the order.

Guest checkout is the normal way to use the store. You don’t need an account just because you wanted a ZIP file.

If the checkout process asks for an email address or other information, it is being collected for order processing, delivery, recovery, fraud prevention, support, or another operational reason. It isn’t an invitation to a newsletter unless you explicitly sign up for one.

Bitcoin and Lightning payments

Payments are handled through BTCPay Server.

Payment records can include invoice identifiers, amounts, timestamps, payment status, and transaction information needed to determine whether an order was paid.

Bitcoin is not a private database. On-chain transactions are recorded on the public Bitcoin network. CacheRat doesn’t control what information exists on the Bitcoin blockchain or what somebody else may infer from it.

Using Bitcoin also doesn’t magically erase the rest of an ecommerce transaction. The store still has to know that invoice 123 got paid so it can hand over the file. Computers remain annoyingly literal about this stuff.

Tor

CacheRat can also be accessed through its Tor onion service.

Using Tor can reduce the network information exposed during your connection. It does not make information you deliberately submit to the store disappear, and it does not change the public nature of an on-chain Bitcoin transaction.

Cookies

WordPress and WooCommerce use cookies for things that actually need cookies: keeping track of sessions, carts, logins, preferences, and similar site functions.

If you log into an account, WordPress may store login and preference cookies. If you use the cart or checkout, WooCommerce may use cookies or similar browser storage to remember what you’re doing between pages.

CacheRat does not intentionally use cookies to build a cross-site advertising profile about you.

Comments

If comments are enabled and you leave one, WordPress may collect the information entered in the comment form along with technical information such as your IP address and browser user-agent string. This can be used for moderation and spam detection.

If Gravatar support is active, an anonymized hash derived from your email address may be sent to the Gravatar service to determine whether you have a profile image there. Gravatar is operated by Automattic and has its own privacy policy.

Media uploads

Normal store customers aren’t expected to upload media.

If some part of the site later allows image uploads, remember that image files can contain metadata, including GPS coordinates. Don’t upload location metadata you don’t want somebody else to have.

Embedded stuff from other sites

Some pages may contain embedded material from another website: images, videos, documents, posts, or similar things.

An embed can behave much like visiting that outside site directly. The outside service may receive technical information about your visit, set cookies, or track interaction according to its own policies.

If I can link to something without loading half somebody else’s surveillance machinery into the page, I generally prefer the link.

Who gets your data

I don’t sell customer information.

Information may still pass through or be stored by systems required to operate the site: web hosting, WordPress, WooCommerce, BTCPay Server, network infrastructure, spam or security tools, backups, and other services actually being used to keep the thing running.

Information may also be disclosed when reasonably necessary to comply with law, respond to a valid legal demand, investigate abuse, protect the site, or deal with fraud or a security incident.

How long information is kept

Order and payment records may be retained as long as reasonably necessary for accounting, transaction history, refunds, disputes, security, backups, legal obligations, and proving what happened when something breaks six months later.

Server logs and security data may also be retained for a limited period when needed to operate and protect the systems.

If comments exist, approved comments and their metadata may remain on the site indefinitely unless they are removed.

The goal isn’t to accumulate customer information because storage is cheap. The goal is to keep what there’s an actual reason to keep.

Accounts

If you create an account, WordPress stores the information associated with that account until it is changed or removed, subject to records that may need to remain for legal, accounting, security, or transaction-history reasons.

You don’t need an account for ordinary guest purchases unless a particular function says otherwise.

Your data

If CacheRat has personal information associated with you, you can contact me and ask what is being retained, request a copy, correct inaccurate information, or ask for deletion where applicable.

Some records can’t simply be erased because somebody asks. Transaction, accounting, security, fraud-prevention, backup, or legally required records may need to remain.

Use the Contact page for privacy requests. Include enough information to identify the relevant account or order. Please don’t send additional personal information that isn’t needed to solve the problem.

Where information may go

Depending on what features are active, site traffic or submitted information may be processed by hosting infrastructure, payment infrastructure, spam-detection systems, security tools, embedded third-party services, or other systems necessary to provide the site.

I’m deliberately trying to keep that list short.

The short version

I need enough information to sell you the file, prove you paid for it, deliver it, and keep the server from catching fire.

I don’t need a demographic profile, your shopping habits across the rest of the internet, or a reason to email you every Thursday until one of us dies.

That’s the policy.