Privacy Policy
Last updated: 17 May 2026
1. Introduction
At Pilot XLS, we respect your privacy and are committed to protecting your personal data.
This Privacy Policy explains how we collect, use, store, share and protect personal data when you visit our website, create an account, place an order, download a digital product, contact us, request support or interact with our services.
This Privacy Policy applies to the website operated under the Pilot XLS brand, including pilot-xls.com, and to digital products sold through our website.
2. Data Controller
The data controller is Pilot XLS, a brand operated by a registered self-employed worker in Portugal.
For privacy-related questions or requests, you can contact us at:
If legally required or necessary to handle a formal request, additional business identification details may be provided through the contact email above.
3. Personal Data We Collect
We may collect different categories of personal data depending on how you use our website and services.
Account and Identification Data
We may collect:
- Full name.
- Email address.
- Username and account details, if you create an account.
- Billing details, such as country, address and tax identification number, where applicable.
Order and Transaction Data
When you place an order, we may collect:
- Products purchased.
- Order number.
- Order date and status.
- Amount paid.
- Currency.
- Discounts, coupons or promotional codes used.
- Invoice, tax and accounting information, where applicable.
Payment Data
Payments are processed securely by third-party payment providers.
Pilot XLS does not store full credit card numbers or full payment authentication details on its own systems.
We may receive limited payment-related information, such as payment status, payment method, transaction reference, billing details and fraud-prevention results, where necessary to process the order, provide support and maintain business records.
Digital Download Data
Because we sell digital products delivered by download, we may collect and store information related to digital delivery, including:
- Download permissions.
- Download link activity.
- Date and time of downloads.
- Number of downloads.
- Product file access records.
- IP address or technical data associated with download activity.
This information is used to confirm digital delivery, provide customer support, prevent misuse of download links, investigate technical issues and review refund or replacement requests.
Technical and Usage Data
When you visit our website, we may collect technical and usage data, including:
- IP address.
- Browser type and version.
- Device type.
- Operating system.
- Pages visited.
- Time spent on the website.
- Referring URLs.
- Cookie identifiers.
- Approximate location derived from technical data.
Communication and Support Data
When you contact us, we may collect:
- Messages sent to us by email or contact forms.
- Support requests.
- Refund or complaint requests.
- Screenshots, error messages or files you choose to send to us for support purposes.
Marketing and Preference Data
Where applicable, we may collect:
- Newsletter subscription status.
- Marketing consent preferences.
- Email engagement information.
- Cookie consent preferences.
Reviews, Comments and User Content
If you leave a review, comment or feedback on our website, we may collect the information you provide, together with technical data necessary to prevent spam, abuse or fraud.
4. How We Collect Personal Data
We collect personal data directly from you when you place an order, create an account, subscribe to communications, contact us, request support, submit a review or use our website.
We may also collect data automatically through cookies, analytics tools, security tools, WooCommerce order and download systems, and similar technologies.
Some personal data may be provided to us by third-party service providers, such as payment processors, only where necessary to process your order, prevent fraud or provide customer support.
5. Purposes and Legal Bases for Processing
We process personal data only when we have a legal basis to do so.
Depending on the situation, we may rely on contract performance, legal obligations, legitimate interests or consent.
Performance of a Contract
We process personal data to:
- Create and manage customer accounts.
- Process orders and payments.
- Deliver digital download access.
- Send order confirmations and product download emails.
- Provide customer support.
- Handle technical issues related to purchased products.
Legal Obligations
We process personal data to comply with legal, tax, accounting, consumer protection and regulatory obligations.
Legitimate Interests
We may process personal data for legitimate business interests, including:
- Maintaining website security.
- Preventing fraud, abuse or misuse of download links.
- Keeping business records.
- Improving our website and digital products.
- Responding to support, refund and complaint requests.
- Protecting our legal rights.
- Understanding how customers use our website and products.
Consent
We rely on consent where required by law, including for certain cookies, analytics, advertising technologies and marketing communications.
Where processing is based on consent, you may withdraw your consent at any time.
Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.
6. How We Use Personal Data
We use personal data to:
- Operate and maintain our website.
- Sell and deliver digital products.
- Process payments and orders.
- Send order confirmations and download links.
- Provide technical and customer support.
- Manage accounts and customer records.
- Analyse and improve website performance.
- Prevent fraud and protect website security.
- Comply with legal, tax and accounting obligations.
- Respond to legal requests, disputes, complaints or regulatory obligations.
- Send marketing communications where you have consented or where legally permitted.
7. Website Platform and Store Technology
Our website is operated using WordPress and WooCommerce.
WooCommerce is used to manage products, orders, customer accounts, checkout, digital downloads and related ecommerce functions.
Depending on your interaction with the website, WordPress and WooCommerce may process information such as account details, order details, billing information, download permissions, download logs, cookies and technical data.
8. Sharing Personal Data
We do not sell personal data.
We may share personal data with trusted third parties where necessary to operate our website, process orders, provide digital products, comply with the law or protect our rights.
These third parties may include:
- Website hosting providers.
- WordPress and WooCommerce-related service providers.
- Payment processors.
- Email and transactional email providers.
- Analytics providers, such as Google Analytics, where enabled.
- Cookie consent and privacy management tools.
- Security, anti-spam and fraud-prevention tools.
- Accounting, tax, legal or professional advisers.
- Authorities, regulators or courts, where legally required.
Third-party service providers are expected to process personal data only as necessary to provide their services and in accordance with applicable data protection requirements.
9. Payments
When you make a purchase, your payment is processed by third-party payment providers.
These providers may collect and process payment details, billing information, fraud-prevention data and transaction information.
Pilot XLS does not store full credit card details.
We receive only the information needed to confirm payment, complete the order, provide support, keep records and comply with legal obligations.
10. Email Communications and Marketing
We may send you transactional emails related to your order, account, download access, support requests or legal notices.
These emails are necessary to provide our services and are not marketing emails.
If you subscribe to our newsletter or marketing communications, we may send you product updates, offers, discounts or news.
You can unsubscribe at any time by using the unsubscribe link in our emails or by contacting us at:
11. Cookies and Similar Technologies
We use cookies and similar technologies to operate the website, manage accounts and checkout, remember preferences, measure website performance, improve user experience, prevent fraud and, where enabled, support analytics or advertising.
Cookies used on our website may include:
- Essential cookies, required for the website, checkout, account login and security.
- Preference cookies, used to remember settings such as cookie consent preferences.
- Analytics cookies, used to understand website traffic and performance.
- Marketing or advertising cookies, where enabled and where permitted by law.
- WooCommerce cookies, used for cart, checkout, order attribution and store functionality.
- WordPress cookies, used for login, account management and site functionality.
You can manage your cookie preferences through our cookie banner or through your browser settings.
Disabling some cookies may affect website functionality, including checkout, account access or digital product delivery.
Cookie List
The table below lists the cookies detected and managed through our cookie consent tool.
12. Analytics
We may use Google Analytics or similar analytics tools to understand how visitors use our website, measure traffic, improve content and evaluate website performance.
Analytics tools may collect information such as IP address, device data, browser data, pages visited, session duration, approximate location and interaction data.
Where required by law, analytics cookies will only be used with your consent.
13. Security
We use reasonable technical and organisational measures to protect personal data against unauthorised access, loss, misuse, alteration or destruction.
These measures may include secure website connections, access controls, account protection, backups, security monitoring, software updates and anti-spam or anti-fraud tools.
However, no method of transmission over the Internet or electronic storage is completely secure.
We cannot guarantee absolute security.
14. Data Retention
We retain personal data only for as long as necessary for the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law.
In general:
- Order, invoice, payment and tax-related data are kept for the period required by applicable tax, accounting and legal obligations.
- Customer account data is kept while the account remains active, unless deletion is requested and we are legally able to delete it.
- Download permissions and download logs may be kept as long as necessary to provide access, confirm digital delivery, provide support, prevent abuse and handle refund or legal requests.
- Support and complaint communications may be kept as long as necessary to resolve the issue and protect our legal rights.
- Marketing data is kept until you unsubscribe or withdraw consent, unless another legal basis applies.
- Cookie consent records may be kept as necessary to demonstrate your choices and comply with legal obligations.
- Technical logs may be kept for security, fraud prevention and website maintenance purposes for a limited period, unless longer retention is needed to investigate abuse, security incidents or legal claims.
Where possible and appropriate, data may be deleted, anonymised or minimised when it is no longer needed.
15. International Data Transfers
Because Pilot XLS sells digital products worldwide and uses online service providers, personal data may be processed in countries outside your country of residence, including outside the European Economic Area.
Where required by applicable law, we take steps to ensure that international transfers are protected by appropriate safeguards, such as adequacy decisions, contractual protections or other lawful transfer mechanisms.
16. Your Data Protection Rights
Depending on your location and applicable law, you may have the following rights:
- Right to access your personal data.
- Right to request correction of inaccurate or incomplete data.
- Right to request deletion of your personal data.
- Right to request restriction of processing.
- Right to object to processing based on legitimate interests.
- Right to data portability.
- Right to withdraw consent where processing is based on consent.
- Right to lodge a complaint with a data protection authority.
To exercise your rights, contact us at:
We may need to verify your identity before responding to a request.
Some requests may be limited by legal, tax, accounting, fraud-prevention or security obligations.
17. Supervisory Authority
If you are located in Portugal or the European Union and believe that your data protection rights have been violated, you have the right to lodge a complaint with a competent supervisory authority.
18. Children and Minors
Our website and products are not intended for children.
We do not knowingly collect personal data from children.
If you are under 18, you should use our website or purchase products only with permission from a parent, guardian or legally authorised representative.
If you believe that a child has provided us with personal data, please contact us so that we can review and, where appropriate, delete the information.
19. Automated Decision-Making
Pilot XLS does not intentionally make decisions based solely on automated processing that produce legal or similarly significant effects for customers.
However, payment processors, fraud-prevention tools, security tools or analytics providers may use automated systems to detect fraud, abuse, suspicious transactions or security risks.
20. Third-Party Links
Our website may contain links to third-party websites, platforms or services.
We are not responsible for the privacy practices, security or content of those third parties.
We recommend that you read the privacy policies of any third-party websites or services you use.
21. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our business, website, services, technologies or legal obligations.
Any changes will be published on this page.
If changes are significant, we may provide a more prominent notice on the website.
The “Last updated” date at the top of this page indicates when this Privacy Policy was last revised.
22. Contact
If you have any questions about this Privacy Policy or how we handle personal data, please contact us at:

