Trust
Data handling and retention
What we store, for how long, where it lives and who can reach it.
This page is the operational answer to “what do you actually have about me”. The legal statement of the same thing — with the lawful basis for each category — is clause 2 of the privacy policy. Where the data belongs to your buyers rather than to you, we are your processor and the data processing addendum governs it.
Where it lives
On infrastructure we operate in the European Union. Records are held in per-purpose databases rather than one undifferentiated store, which is what makes the table below possible to write honestly: money records are kept apart from usage counters, which are kept apart from the work itself. Copies leave that infrastructure only for the five purposes listed on sub-processors.
What is stored, and for how long
| Store | What it holds | How long we keep it |
|---|---|---|
| Account and session records | Your email address, when the account was created and verified, the plan it is on, and the sessions signed in to it. Sign-in links are single-use and expire minutes after they are sent. | While the account is open; deleted 30 days after closure. |
| Product, claim and offer records | Products claimed, held or passed, the evidence recorded with a find, offer and pricing figures, and the reasons the engine recorded for its choices. | While the account is open; deleted 30 days after closure. |
| Store records | Generated pages and copy, section order and the rationale for it, domain settings, and whether payments on the store are live or in sandbox. | While the account is open; deleted 30 days after closure. |
| Usage counters | How many actions each tool has performed in the current rolling window, and the entitlement checks behind them. Counters are counts, not copies of the work. | 13 months, then deleted. |
| Payment and ledger records | Amount, currency, status, time, plan, the provider's transaction reference, and each movement of an advertising balance with the reason for it. No card numbers. | 8 years, as Hungarian accounting law requires. This is the one category account closure does not delete. |
| Referral records | Your referral code, the visitor sessions that opened it, and the milestone each reached. Not the identity of the person invited. | 24 months from the last recorded milestone. |
| Store orders and support mail | Orders recorded against your store, satisfaction samples, and email your buyers send to the support address issued to your store, with the rules you configured for it. | While the account is open, or until you delete it; deleted 30 days after closure. |
| Supplier and payout settings | Supplier connection settings and the payout destination for store revenue. | While the account is open; then retained only as long as accounting law requires. |
| Technical logs | IP address, user agent, request path, timestamps, errors and rate-limit events. | 90 days, extended only for a specific incident under investigation. |
What we do not do with it
- We do not train models on your work. Storefront content, product research, buyer orders and support email are used to run your account and for nothing else.
- We do not sell data, and we run no advertising trackers. The only cookie we set is listed in the cookie policy.
- We do not read your data casually. Staff access is limited to the people who operate the service, is exercised to resolve a fault or a support request, and is logged.
- We do not keep what we do not need. A category missing from the table above is missing because it is not collected.
Deletion, and what deletion actually means
When you delete an object in the product, it stops being reachable immediately and is removed from the live databases. When you close an account, the same happens to everything in it except the payment and ledger records, which Hungarian accounting law requires us to retain for eight years — we cannot delete those on request, and we would be wrong to say we could.
Backups are the honest complication. Encrypted snapshots are taken so that a failure does not destroy your work, and a deleted record persists in a snapshot until that snapshot rotates out, within 30 days. We do not restore an individual record from a backup to bring deleted data back, and data in a backup remains subject to the same protections until it is gone.
Export
You can export your work from the product at any time while the account is open. Do it before you close the account, because closure starts the deletion schedule above. A machine-readable copy of the personal data we hold about you is available on request under clause 9 of the privacy policy — write to [email protected] and we answer within a month.
If something goes wrong
Where a breach is likely to create a risk to people, the supervisory authority is notified within 72 hours and affected individuals without undue delay where the risk is high; business customers are told within 48 hours. What we do while an incident is live is on availability commitment, and the measures meant to prevent one are on security.