Privacy Policy
1. Scope and our two roles
1.1 This Privacy Policy explains how we handle personal data where we are the controller, that is, data about Shopiza account holders (merchants), prospective merchants, and visitors to shopiza.io.
1.2 Data about your customers. When you run a store on Shopiza, we process your customers' personal data (orders, addresses, emails, and so on) on your behalf and on your instructions. For that data, you are the controller and we are the processor under our Data Processing Agreement. This Privacy Policy does not cover how you use your customers' data, you must provide your own privacy notice to your customers. Your customers should read the store owner's privacy policy, not this one.
2. What we collect (as controller)
- Account data: name, email, password (hashed), shop name and URL, and, if you sign in with Google, your Google account email, name, and identifier.
- Billing data: plan, and limited payment metadata (full card data is handled by our payment provider, not stored by us).
- Usage and device data: log data, IP address (truncated for analytics), device and browser type, pages visited, and actions in the dashboard.
- Communications: messages, support requests, and bug reports you send us.
- Cookies and similar technologies: see Section 5.
3. Why we use it and our legal bases (GDPR Art. 6)
- To provide the Service and your account, performance of a contract.
- Security, fraud prevention, debugging, and product improvement, legitimate interests.
- Service and transactional emails (for example verification, security, billing), contract and legitimate interests.
- Marketing emails, consent, which you can withdraw at any time.
- Legal and tax compliance, legal obligation.
4. Sharing and sub-processors
4.1 We share personal data only with service providers that help us run Shopiza, under contract and only as needed, including (current list): Google (sign-in, United States), Stripe (payments, United States), Paddle (subscription billing, United Kingdom), Cloudflare (security and CDN, United States), Hetzner (hosting, Germany, EU), and Resend (email, United States). Providers outside the EEA process data under the safeguards described in Section 6. A current sub-processor list is available on request at [email protected].
4.2 We may disclose data if required by law, to protect our rights or users' safety, or in a merger or acquisition (with notice). We do not sell your personal data, and we do not "share" it for cross-context behavioural advertising as defined under US state laws.
5. Cookies, analytics and opt-out signals
5.1 We use strictly necessary cookies to run the site and secure sessions. We use first-party, privacy-preserving analytics (see our analytics notice); we do not load third-party advertising trackers by default.
5.2 Non-essential cookies and trackers are used only with your consent where required (EU and UK ePrivacy). We honour browser Global Privacy Control (GPC) and universal opt-out signals as an opt-out of any "sale", "sharing", or targeted advertising under applicable US state laws.
6. International data transfers
6.1 We are based in the EU. Some providers are in the US or elsewhere. Where we transfer personal data outside the EEA, we rely on an adequacy decision (including the EU-US Data Privacy Framework for certified US recipients) and/or the European Commission's Standard Contractual Clauses with appropriate safeguards. Given ongoing legal developments around transatlantic transfers, we keep Standard Contractual Clauses in place as a fallback. You can request details at [email protected].
7. Retention
7.1 We keep account data for as long as your account is active and as needed to provide the Service, then delete or anonymise it within a reasonable period, unless a longer period is required by law (for example tax and accounting) or to resolve disputes. Truncated analytics and aggregate data may be kept longer as described in our analytics notice.
8. Security and breaches
8.1 We use reasonable technical and organisational measures (for example encryption of sensitive fields, hashed passwords, and access controls). However, given the Service's development status, no system is perfectly secure and we cannot guarantee absolute security. You are responsible for your credentials and your own backups.
8.2 If a personal-data breach occurs, we will notify affected users and authorities where and as required by applicable law.
9. Your rights
9.1 EU, EEA, and UK (GDPR / UK GDPR): you may request access, rectification, erasure, restriction, and portability, and object to processing based on legitimate interests; withdraw consent at any time; and lodge a complaint with your supervisory authority (in Hungary, the NAIH). We do not use solely automated decision-making that produces legal or similarly significant effects on you; if that changes, we will tell you and honour your Art. 22 rights.
9.2 United States (California / CPRA and other state laws): you may request to know, access, correct, and delete your personal information; opt out of "sale", "sharing", or targeted advertising (we honour GPC); and you will not be discriminated against for exercising rights. You may appeal a decision by contacting [email protected].
9.3 Canada (PIPEDA / Quebec Law 25): you may access and correct your personal information and withdraw consent; Quebec residents have additional rights (portability, information about automated processing, and to complain to the Commission d'accès à l'information).
9.4 To exercise any right, email [email protected]. We will verify your identity and respond within the timeframe required by applicable law. These rights are free except where the law allows a fee for excessive requests.
9.5 9.5 Shop owners can delete their own account and shop directly from Settings, under Profile. Your storefront goes offline immediately and everything is permanently erased after 30 days, during which you can cancel. You can download a full copy of your shop data from the same page before you do. We keep the records of what you paid us, and our payment provider keeps its invoices, for as long as accounting and tax law requires; those records are no longer linked to your shop.
10. Marketing and anti-spam
10.1 We send marketing emails only with the consent required by law and always include an unsubscribe link. We comply with the EU ePrivacy rules, the US CAN-SPAM Act, and Canada's CASL. You can opt out at any time; you will still receive essential service messages.
11. Children
11.1 The Service is for business users and is not directed to children. We do not knowingly collect personal data from anyone under 16. If you believe a child provided us data, contact [email protected] and we will delete it.
12. Your obligations as a merchant
12.1 When you process your customers' personal data using Shopiza, you are the controller. You are responsible for having a lawful basis, providing your customers a privacy notice, handling their rights requests, and entering our Data Processing Agreement. Shopiza acts only on your documented instructions as your processor.
13. Changes to this Policy
13.1 We may update this Policy; the "Effective date" shows the latest version and we will notify you of material changes by email or in-app. Continued use after changes take effect means you accept the updated Policy.
14. Contact
14.1 Privacy questions or requests: [email protected]. General: [email protected].
15. Language
15.1 This Policy is drafted in English, which is the authoritative version. Any translation is provided for convenience only; in case of any discrepancy or conflict, the English version prevails.
This policy covers Shopiza as a controller. For data we process on a merchant's behalf, see the Data Processing Agreement.