Privacy Policy
Last updated September 30, 2026
Template — review with your legal adviser before relying on it.
This Privacy Policy explains how Your App processes personal data in connection with Your App (the "Service"), in accordance with the General Data Protection Regulation ("GDPR") and other applicable data-protection law.
1. Controller
The data controller for the personal data described in this policy is:
Your App
[Company address]
Contact: [Legal contact email]
2. What we collect and why
| Data | Purpose | Legal basis |
|---|---|---|
| Account details (name, email, password) | Creating and administering your account | Performance of a contract |
| Store and billing information | Operating your subscription and store | Performance of a contract |
| Invoices and payment records | Accounting and tax compliance | Legal obligation |
| Server and security logs | Detecting abuse, fraud and outages | Legitimate interest |
| Analytics cookies | Understanding site usage | Consent |
| Marketing cookies and marketing emails | Sending you product news and offers | Consent |
| Cookie-consent record (consent ID, categories chosen, policy version, browser language, anonymised IP address, browser user agent, and time) | Demonstrating and auditing consent as required by law | Legal obligation |
You can withdraw consent for analytics and marketing at any time — see our Cookie Policy and the unsubscribe link in any marketing email.
3. Recipients and sub-processors
We share personal data only with service providers who need it to help us run the Service, under a written agreement that protects it. Our payment processor, Stripe, processes billing and payment data as an independent controller for fraud-prevention and regulatory purposes and as our processor for the rest of the payment flow. Our current sub-processors are:
[Sub-processors]
4. International transfers
Where a recipient is located outside the European Economic Area, the transfer is protected by an adequacy decision, the EU Standard Contractual Clauses, or (for US-based recipients) the EU-U.S. Data Privacy Framework, as applicable.
5. Retention
We keep personal data only for as long as necessary for the purposes above: account and billing data for the life of the account plus the period required by tax and accounting law; security logs for a limited operational window; cookie-consent records for 12 months.
6. Your rights
Subject to the conditions in the GDPR, you may request access to, rectification of, erasure of, or restriction on the processing of your personal data, may object to processing based on legitimate interest, may request portability of data you provided to us, and may withdraw consent at any time without affecting processing carried out before the withdrawal. To exercise a right, contact [Legal contact email]. You may also lodge a complaint with [Supervisory authority].
7. Cookies
The Service uses cookies as described in our Cookie Policy. Strictly necessary cookies are set without consent; analytics and marketing cookies are set only after you consent through the cookie banner.
8. Bot protection
If CAPTCHA protection from a third-party provider (for example Google reCAPTCHA) is enabled on our signup form, that provider processes limited technical data (such as your IP address and browser characteristics) to distinguish humans from bots, under its own privacy policy.
9. If you run a store on the Service
If you operate a store on the Service, this policy covers the data we process about you as our customer. Data you collect from your own customers through your storefront is processed by Your App on your behalf, as your processor, under the terms of our Data Processing Agreement — you remain the controller of that data and are responsible for your own store's privacy notice to your customers.