Skip to content

Privacy policy

Last updated · Operator: StoreCompliant

This policy explains what personal data StoreCompliant processes, why, for how long, who else is involved and what rights you have. It covers three groups of people, because our role is different for each:

You are… What it concerns Our role Read
A visitor of storecompliant.com, or someone who emails us The website and our mailboxes Controller Section 2
A merchant who installs the StoreCompliant app Your installation, plan, settings and support requests Controller Section 3
A shopper in a shop that uses the app A withdrawal request you send through the shop’s withdrawal form Processor for the shop; the shop is the controller Section 4

In short: the website has no accounts, no forms and no advertising or tracking cookies. The app works mostly with catalogue data (products and prices), which is not personal data. The only shopper data it handles is what a shopper types into the withdrawal form. We do not sell personal data and we do not share it with advertisers.

1. Who we are

StoreCompliant is operated by StoreCompliant, Yeni Mah. Mezitli, Mersin, 33200, Turkey. Our details are in the legal notice.

Because we offer the app to shops in the European Union and the European Economic Area, we apply the General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”) to the personal data described in this policy.

In this policy “the app” means the StoreCompliant app a merchant installs on an online shop through a shop platform such as Wix. “The website” means storecompliant.com.

2. Visitors of our website

2.1 What we process and why

The website consists of static pages. You cannot create an account on it, there are no contact forms and no newsletter sign-up, and we show no advertising.

Data Where it comes from Purpose Legal basis (Art. 6 GDPR) How long
Connection data: IP address, date and time, the page requested, the referring page, browser and device information Sent by your browser with every request Delivering the pages to you, keeping the site available and protecting it against attacks and abuse Legitimate interest in running a secure website, Art. 6(1)(f) Processed by our hosting provider, Cloudflare, at the moment of the request and kept by it only for a limited time for security and operational purposes. We keep no visitor logs of our own.
Usage statistics: page visited, referring page, type of browser, operating system and device, country, page-loading times Cloudflare Web Analytics Knowing which pages are read and whether the site loads properly Legitimate interest in improving the website, Art. 6(1)(f) Aggregated figures only. We cannot single out or recognise an individual visitor in them.
Emails you send us: your name, email address, the content of your message and anything you attach You Answering you; dealing with your request or complaint Legitimate interest in answering enquiries, Art. 6(1)(f); steps taken at your request before a contract, or performing a contract, Art. 6(1)(b), where the message is about using the app Up to 24 months after the last message in the conversation, longer only where we need it to establish or defend a legal claim
“Tell me when it is ready” requests: your email address and the platform you asked about You, by emailing us Sending you the notice you asked for when the app becomes available on that platform Steps taken at your request, Art. 6(1)(b) Until we have sent you that notice, or until you tell us you no longer want it, whichever comes first

Cloudflare Web Analytics works without cookies and without storing anything on your device. It does not follow you across other websites and it does not build a profile of you for advertising. Details of what is and is not stored in your browser are in the cookie policy.

You do not have to give us any data to read the website. Your browser has to send connection data for a page to load; without it the website cannot be delivered.

The website links to other sites, for example the official texts of EU law and the app stores of shop platforms. Those sites are run by others and have their own privacy policies.

3. Merchants who install the app

This section applies to you if you install the app on your shop, or act for a business that does. For the data described here we are the controller.

3.1 What we process and why

Data Where it comes from Purpose Legal basis (Art. 6 GDPR)
Installation data: the app instance ID and site ID given by the platform, your shop’s address (URL), its languages and currency, the catalogue version, the date of installation, and the access tokens the platform issues so the app can work on your shop The shop platform, when you install the app Identifying your installation, connecting to your shop and running the app for it Performance of the contract with you, Art. 6(1)(b)
Plan data: the plan your installation is on, plan changes and cancellations, the number of products covered and, where relevant, the date your catalogue went over the plan limit The shop platform Applying the features and limits of your plan Performance of the contract, Art. 6(1)(b)
Settings: which features are switched on, where they appear, the display language, your own wording for the price line, who sees each feature, progress through the set-up checklist You, in the app’s dashboard Showing the features on your storefront the way you chose Performance of the contract, Art. 6(1)(b)
Catalogue data: product and variant IDs, product names, prices, “compare-at” prices, the times prices changed, and earlier prices you import from a file Your shop, through the platform; you, by import Working out and showing the lowest price of the 30 days before a discount, flagging discounts the records do not support, and producing price evidence exports Performance of the contract, Art. 6(1)(b)
Support and contact data: your name, email address, shop address, the content of your messages and anything you attach You, when you write to us Helping you, fixing problems, answering questions about the service or an invoice Performance of the contract, Art. 6(1)(b); legitimate interest in answering enquiries, Art. 6(1)(f)
Connection data when your browser loads the app’s dashboard: IP address, date and time, browser information Your browser Delivering the dashboard, security and prevention of abuse Legitimate interest in a secure service, Art. 6(1)(f)
Usage milestones: that the dashboard was opened, that set-up was finished, that the price line went live, that a plan was upgraded (with the plan name) The app Reporting these milestones to the shop platform, which asks app providers for them, and understanding how the app is used Legitimate interest in operating and improving the app within the platform’s rules, Art. 6(1)(f)
Business records: what the platform reports to us about subscriptions and payouts The shop platform Bookkeeping and tax Legal obligation, Art. 6(1)(c)

Catalogue data describes products, not people, and is normally not personal data. We list it because it can relate to an identifiable person where a shop is run by a sole trader.

Where you are a company, we process the contact details of the people who act for you on the basis of our legitimate interest in dealing with our business customers, Art. 6(1)(f).

What we do not receive. Billing is handled by the shop platform. We do not receive or store your card or bank details. The app does not ask for or store your password for the platform. The app itself stores no email address for you; we have one only if you write to us.

Is the data required? Installation, plan, settings and catalogue data are needed to provide the app: without them it cannot work. Writing to us is voluntary.

In the dashboard. The dashboard remembers your choice of dashboard language in your browser’s local storage. See the cookie policy.

3.2 How long we keep it

Data Retention
Installation data, plan data, settings For as long as the app is installed
Price history The 30 days needed for the calculation, plus an audit period of up to 24 months so you can evidence past price reductions
Everything the app stores for your installation, after you uninstall Withdrawal requests are deleted when the app is removed. The rest is deleted within 90 days of the uninstall. You can ask for earlier deletion at any time.
Support and contact emails Up to 24 months after the last message in the conversation
Business records For the periods that the commercial and tax law that applies to us requires

Where we need data to establish, exercise or defend a legal claim, we keep the relevant data until that matter is closed.

4. Shoppers in a shop that uses the app

4.1 Who is responsible for your data

If you buy from a shop that uses StoreCompliant, the shop is the controller of your personal data. It decides to offer the withdrawal form, receives your request and deals with it. We are the shop’s processor: we store and handle your request on the shop’s behalf and on its instructions, under a data processing agreement. We do not use your data for our own purposes.

Please contact the shop first if you have a question about your withdrawal, your order or your data, or if you want to exercise your rights. The shop’s own privacy notice tells you how it handles your data. You can also write to us at privacy@storecompliant.com. If you do, tell us which shop it concerns: we will pass your request to that shop without delay and help it to answer you.

4.2 What the app processes

The app processes shopper data in one situation only: when you send a withdrawal request through the shop’s withdrawal form.

Data Where it comes from Purpose
Your name, email address, the order number you typed, and the items concerned if you listed them You, in the form Letting the shop receive your withdrawal, identify the contract and act on it
The language of the page, the time zone set in your browser, and the date and time you sent the request Your browser and our server Sending your confirmation in your language, showing the time in your local time, and recording when the request was made
A reference number, the status of the request (new or handled, and when it was handled) and whether and when the confirmation email was sent Created by the app; the status is set by the shop Giving you and the shop a record of the request
A contact record with your name and email address in the shop’s own contact list on its shop platform Created by the app in the shop’s account Sending you the dated confirmation email from the shop’s own site. The email is sent by the shop platform’s email automation, not from our systems.
Where the shop is on a paid plan: whether the order number you typed matches an order in the shop, and that order’s number, date and total The shop’s order records on its platform Showing the shop whether the request matches an order. The app reads only the one order you name. It compares the email address on that order with the one you typed and stores the result of the comparison, not the address from the order.

The app sends the shop a notification in its dashboard when a new request arrives.

The legal basis is the shop’s to determine. Typically the shop relies on its legal obligation to offer an online withdrawal function and to acknowledge your withdrawal (Art. 6(1)(c) GDPR) and on the sales contract with you (Art. 6(1)(b) GDPR).

4.3 What the app does not process

Apart from withdrawal requests, the app does not access or store shoppers’ names, email addresses, postal addresses, orders or payment data, and it keeps no analytics about shop visitors. It sets no cookies in your browser. It makes no automated decisions about you: the order check only shows the shop whether a match was found, and a person at the shop decides what happens next.

When you simply browse a shop that uses the app:

  • Your browser loads the app’s components and the public price line from our servers at Cloudflare. As with any web request, this involves your IP address and browser information, which are used to deliver the response and to protect the service, and are not stored by the app.
  • If the shop has chosen to show a feature to visitors in the EU and EEA only, the app uses the country Cloudflare derives from your IP address to decide whether to show it. The country is used for that decision and is not stored by the app.
  • The app saves the last price line it showed for a product in your browser’s local storage, so the line still appears if our server is briefly unreachable. It contains the public price figure and its wording only: no personal data and no identifier, and it is not sent back to us. See the cookie policy.

4.4 How long withdrawal requests are kept

Withdrawal requests are deleted automatically three years after they were sent. They are deleted earlier when the shop removes the app, or when the shop asks us to delete them. The contact record in the shop’s own contact list and the confirmation email are held by the shop on its platform and follow the shop’s own retention rules.

5. Who receives personal data

We use a small number of providers. They process data on our behalf and under contract, and for shopper data they act as our sub-processors.

Recipient What for Which data
Cloudflare, Inc. Hosting of the website and the app (Cloudflare Workers), the app’s database (Cloudflare D1), network delivery and protection against attacks, cookieless website analytics, routing of incoming email All data described in this policy passes through or is stored on Cloudflare’s infrastructure
The shop platform the merchant uses (for Wix shops: Wix) The app is installed, billed and displayed through the platform; the platform sends the app catalogue events and hosts the dashboard; for withdrawal requests it holds the shop’s contact list and sends the confirmation email Installation and plan data; usage milestones; for shoppers, the contact record and the content of the confirmation email
Our mailbox provider Receiving, storing and sending our email Emails you exchange with us
Professional advisers and authorities Legal, tax and accounting advice; requests we are legally obliged to answer Only what the matter requires

The shop platform is the merchant’s own provider. It processes merchants’ and shoppers’ data under its own terms and privacy policy, which the merchant accepted when opening the shop. For shopper data, it acts for the shop and not as our sub-processor.

If our business were sold or reorganised, the data needed to continue the service could pass to the successor, under this policy.

We do not sell personal data, and we do not pass it to advertisers or data brokers.

6. Transfers outside the European Economic Area

We are established in Turkey, a country outside the European Economic Area (EEA) for which the European Commission has not adopted an adequacy decision. Our providers operate internationally. Cloudflare runs a global network and is headquartered in the United States. Personal data is therefore processed outside the EEA: in Cloudflare’s data centres, and when we access it to run and support the service. We do not promise that data stays in the EU.

Where personal data is transferred to a country outside the EEA that the European Commission has not recognised as providing adequate protection, the transfer relies on a safeguard provided for in Chapter V of the GDPR. In practice these are the European Commission’s standard contractual clauses, which form part of our providers’ data processing terms, and, for recipients in the United States that take part in it, the EU–US Data Privacy Framework. Between a merchant to whom the GDPR applies and us, the standard contractual clauses in section 12 of the data processing agreement apply. You can ask us for more information about the safeguards for a particular provider at privacy@storecompliant.com.

7. Security

We protect data with measures suited to a small, focused service:

  • data is encrypted in transit (TLS) and at rest in the database;
  • every request from the app’s dashboard must carry a token signed by the shop platform, so a merchant can reach only their own shop’s data;
  • messages from the shop platform are accepted only if their signature is valid;
  • the app collects as little as it can, and deletes withdrawal requests on a fixed schedule;
  • the public withdrawal form has protections against automated abuse;
  • access to the production systems is limited to the people who need it to run the service.

More detail is on the security and data page and in Annex 2 of the data processing agreement. No system is perfectly secure. If a personal data breach occurs we will act as the law requires, including notifying the supervisory authority, the people affected and, for shopper data, the shop concerned, where the law calls for it.

8. Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you and receive a copy;
  • have inaccurate data corrected;
  • have data erased where there is no longer a reason for us to keep it;
  • restrict the processing in certain cases;
  • object, on grounds relating to your situation, to processing based on legitimate interest;
  • receive data you gave us in a portable format (data portability), where the processing is based on contract or consent and carried out by automated means;
  • withdraw consent at any time where processing is based on consent. We do not currently rely on consent for any processing described here.

We do not take decisions about you based solely on automated processing, and we do not profile you.

How to exercise your rights. Write to privacy@storecompliant.com and tell us which right you want to exercise. We may ask for information to confirm who you are. It is free of charge. We answer within one month; for complex or numerous requests the law allows an extension of up to two further months, and we will tell you if we need it.

If you are a shopper, your rights are exercised against the shop, which is the controller. Contact the shop first. If you write to us, we will forward your request to the shop and assist it.

9. Complaints

If you believe your data has been handled unlawfully, please tell us first so we can try to put it right. You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the EU country where you live or work or where the matter occurred.

10. Children

The website and the app are intended for businesses. They are not directed at children and we do not knowingly collect children’s personal data for our own purposes. Whether a shop sells to minors, and how it handles their data, is the shop’s responsibility.

11. Changes to this policy

We may update this policy when the service, our providers or the law change. The date at the top shows the latest version. If a change significantly affects how we handle merchants’ data, we will tell merchants in the app’s dashboard or by email before it takes effect.

12. Contact

Email: privacy@storecompliant.com. Our postal address is in section 1.

See also: terms of use, cookie policy, data processing agreement, legal notice.