Privacy Policy

Last updated September 30, 2026

Template — review with your legal adviser before relying on it.

This Privacy Policy explains how Your App processes personal data in connection with Your App (the "Service"), in accordance with the General Data Protection Regulation ("GDPR") and other applicable data-protection law.

1. Controller

The data controller for the personal data described in this policy is:

Your App
[Company address]

Contact: [Legal contact email]

2. What we collect and why

Data Purpose Legal basis
Account details (name, email, password) Creating and administering your account Performance of a contract
Store and billing information Operating your subscription and store Performance of a contract
Invoices and payment records Accounting and tax compliance Legal obligation
Server and security logs Detecting abuse, fraud and outages Legitimate interest
Analytics cookies Understanding site usage Consent
Marketing cookies and marketing emails Sending you product news and offers Consent
Cookie-consent record (consent ID, categories chosen, policy version, browser language, anonymised IP address, browser user agent, and time) Demonstrating and auditing consent as required by law Legal obligation

You can withdraw consent for analytics and marketing at any time — see our Cookie Policy and the unsubscribe link in any marketing email.

3. Recipients and sub-processors

We share personal data only with service providers who need it to help us run the Service, under a written agreement that protects it. Our payment processor, Stripe, processes billing and payment data as an independent controller for fraud-prevention and regulatory purposes and as our processor for the rest of the payment flow. Our current sub-processors are:

[Sub-processors]

4. International transfers

Where a recipient is located outside the European Economic Area, the transfer is protected by an adequacy decision, the EU Standard Contractual Clauses, or (for US-based recipients) the EU-U.S. Data Privacy Framework, as applicable.

5. Retention

We keep personal data only for as long as necessary for the purposes above: account and billing data for the life of the account plus the period required by tax and accounting law; security logs for a limited operational window; cookie-consent records for 12 months.

6. Your rights

Subject to the conditions in the GDPR, you may request access to, rectification of, erasure of, or restriction on the processing of your personal data, may object to processing based on legitimate interest, may request portability of data you provided to us, and may withdraw consent at any time without affecting processing carried out before the withdrawal. To exercise a right, contact [Legal contact email]. You may also lodge a complaint with [Supervisory authority].

7. Cookies

The Service uses cookies as described in our Cookie Policy. Strictly necessary cookies are set without consent; analytics and marketing cookies are set only after you consent through the cookie banner.

8. Bot protection

If CAPTCHA protection from a third-party provider (for example Google reCAPTCHA) is enabled on our signup form, that provider processes limited technical data (such as your IP address and browser characteristics) to distinguish humans from bots, under its own privacy policy.

9. If you run a store on the Service

If you operate a store on the Service, this policy covers the data we process about you as our customer. Data you collect from your own customers through your storefront is processed by Your App on your behalf, as your processor, under the terms of our Data Processing Agreement — you remain the controller of that data and are responsible for your own store's privacy notice to your customers.