Privacy Policy
1. Introduction
This Privacy Policy explains how [COMPANY NAME], registered at [Address], Company ID [ID], VAT [VAT ID, if applicable], ("Seller", "we") processes personal data in connection with the sale of digital products worldwide.
We comply with the EU General Data Protection Regulation (GDPR) and applicable data protection laws.
2. What Data We Collect
We may collect:
Full name
Email address
Billing details
Country of residence
VAT ID (if applicable)
Payment information (processed by payment providers)
IP address
Order history
We do not store card details.
3. Purpose of Processing
We process personal data to:
Deliver digital products
Process payments
Issue invoices
Provide customer support
Fulfill legal obligations (accounting, tax)
Improve website and services
Prevent fraud
Sending marketing and informational emails (only with user consent)
4. Legal Basis
Processing is based on:
Performance of a contract
Legal obligations
Legitimate interests
Consent (for marketing, where applicable)
5. Data Retention
Data is stored only as long as necessary:
Invoices and accounting data: according to legal requirements
Customer accounts: until deletion request
Marketing data: until withdrawal of consent
6. Data Sharing
We may share data with:
Payment providers
Accounting services
Hosting and IT providers
Legal authorities when required
We do not sell personal data.
7. International Transfers
As we operate globally, data may be processed outside the EU. In such cases, appropriate safeguards (e.g., standard contractual clauses) are applied.
8. Data Subject Rights
Users have the right to:
Access their data
Correct inaccurate data
Request deletion
Restrict processing
Data portability
Object to processing
Withdraw consent
Requests may be sent to: [Email]
9. Security
We apply appropriate technical and organizational measures to protect personal da
10. Cookies
Our website may use cookies. Details are provided in the Cookie Policy.
11. Complaints
Users may file a complaint with their local data protection authority.
12. Changes to This Policy
We may update this Privacy Policy. The latest version is always available on our website.
Use of Third-Party Service Providers
To operate our services, we use trusted third-party providers. These entities process personal data either as data processors or independent data controllers, depending on the service provided.
1. SimpleShop – Order & Billing Platform
Role: Data Processor
Purpose: order management, invoicing, product delivery
Data processed: name, email, billing details, IP address
2. Stripe – Payment Processor
Role: Independent Data Controller
Purpose: payment processing
Data processed: email, transaction data, payment details, IP address
Data may be transferred outside the EU under appropriate safeguards (e.g., SCC).
3. PayPal – Payment Provider
Role: Independent Data Controller
Purpose: payment processing
Data processed: email, transaction details, payment data
4. Webnode – Website Hosting
Role: Data Processor
Purpose: website hosting and operation
Data processed: IP address, log files, technical data
5. Google Analytics / Google Tag Manager
Role: Independent Data Controller
Purpose: traffic analysis
Data processed: anonymized IP, device data, usage behaviour
Processing is based on user consent (cookies).
6. Meta (Facebook/Instagram)
Role: Independent Data Controller
Purpose: advertising, conversion tracking
Data processed: cookies, IP address, interactions
Processing is based on user consent.
7. Google Workspace / Gmail
Role: Data Processor
Purpose: communication with customers
Data processed: email address, message content
8. TikTok (Advertising & Analytics)
Role: Independent Data Controller
Purpose: advertising performance measurement, conversion tracking, remarketing
Data processed: IP address, cookies, device information, browsing behaviour, interactions on the website
Legal basis: User consent (marketing cookies)
TikTok may process data outside the EU. Appropriate safeguards, such as Standard Contractual Clauses (SCC), are applied where required.
9. Email Marketing Provider
Role: Data Processor
Purpose: sending newsletters, marketing communication
Data processed: email address, name (if provided), interaction data (email opens, clicks)
Processing is based on user consent.
The specific provider may vary. Data is processed under GDPR-compliant agreements.
Legal Basis for Processing by Third Parties
Processing may be based on:
performance of a contract (orders, payments)
legitimate interests (security, analytics)
user consent (cookies, marketing tools)
