Legal

Privacy Policy

Effective 24 July 2026

Note. This is the English translation of our German privacy policy. In case of discrepancies, the German version at /de/legal/datenschutz prevails.

1. Controller

The controller responsible for data processing on Storewy websites and shops is:

Marcelo Carvalho Silva Junior (trading name: Mietzu)
Wichertstr. 73

10439 Berlin

Germany

Phone: +49 176 44249190

Email (shop support): support@storewy.com
Email (privacy / data-subject requests): privacy@storewy.com

Storewy operates the platform storewy.com and brand-specific shops on subdomains (e.g. your-brand.storewy.com).

2. Overview

We process personal data only where necessary to operate our websites, fulfil orders, provide support, connect sales channels (e.g. TikTok Shop), or — with your consent — run conversion analytics.

ProcessingLegal basis (Art. 6 GDPR)
Orders, shipping, supportArt. 6(1)(b) contract / (c) legal obligation
TikTok Shop / marketplace channel sync (catalog, orders, fulfillment)Art. 6(1)(b) contract fulfillment for marketplace sales; Art. 6(1)(f) where needed for shop operations
Server logs, abuse preventionArt. 6(1)(f) legitimate interest
Strictly necessary storage (cart, language, consent state)§ 25(2) TDDDG; Art. 6(1)(f)
Conversion analytics (PostHog) after opt-inArt. 6(1)(a) consent / § 25(1) TDDDG
Anonymous, server-side reach measurement without cookiesArt. 6(1)(f); objection Art. 21
Aggregated device-free landing count (currently off)Art. 6(1)(f); objection Art. 21

See our Cookie Policy for cookies and local storage.

3. Hosting and server logs

Our application runs on Google Cloud Run (Google Cloud Platform, typically EU regions). Each request generates technical log data (e.g. truncated IP, timestamp, URL, user agent, status code).

Purpose: operation, stability, error analysis, abuse prevention.
Legal basis: Art. 6(1)(f) GDPR.
Retention: per GCP log rotation, usually a few weeks.

4. Orders and payment

When you place an order we process name, delivery/billing address, email, order contents, payment status, and order reference.

ServiceProviderPurposeLocation
SupabaseSupabase, Inc.Order, product, support databaseEU project region
StripeStripe Payments Europe Ltd., DublinPayment processing (Stripe Checkout)EU / possible third country per Stripe routing
ResendResend, Inc.Transactional email (order confirmation)USA (SCCs)
AliExpress Open PlatformAlibaba / AliExpressOrder forwarding to suppliers (dropshipping)Third country (China) — see section 10

Legal basis: Art. 6(1)(b) GDPR; tax/commercial retention Art. 6(1)(c).

Stripe cookies: Stripe Checkout may set its own cookies — see the Cookie Policy.

5. TikTok Shop / marketplace connection

For brand shops connected via Storewy to TikTok Shop (Partner / Open API), we sync catalog, order, and fulfillment data with the seller’s marketplace (Germany / EU where offered).

Purpose: list products, sync stock and prices, import orders, and push tracking information to TikTok Shop.

Data categories: product/listing data; order IDs, line items, and amounts; buyer name, email, and shipping address when provided by TikTok; shop auth tokens (access_token / cipher) stored encrypted server-side.

Recipient: TikTok Shop / ByteDance as marketplace operator (TikTok Shop Partner / Open API) — not a classic processor under a standard Art. 28 DPA for the marketplace itself; transfers under applicable marketplace terms and, where required, appropriate safeguards (e.g. Standard Contractual Clauses) for international transfers.

Storage: credentials encrypted in our database (AES-256-GCM); order and listing records in Supabase / Cloud SQL as for other sales channels.

Retention: tokens until disconnect or rotation; orders per commercial/tax retention (see section 11). On disconnect we clear stored Shop credentials.

Minimisation: only product, order, and logistics scopes/fields needed for the service. The TikTok Shop Open API does not set storefront cookies.

Legal basis: Art. 6(1)(b) GDPR (contract fulfillment for marketplace sales); where needed Art. 6(1)(f) GDPR (legitimate interest in shop operations and channel integration).

6. Support chat (AI)

Brand shops offer a support chat. Messages are processed using Google Gemini / Google Generative AI API.

Data: chat content, optional email you provide, thread id, page URL.
Legal basis: Art. 6(1)(b) and/or (f).
Storage: support threads in Supabase.
You are chatting with an AI assistant (see in-chat notice).

7. Conversion analytics (PostHog) — consent only

If you choose “Accept analytics” in the cookie banner, we use PostHog (PostHog Cloud EU, eu.i.posthog.com).

Data (summary): pseudonymous id (storewy.ph_anon_id), page views, masked click/interaction signals (autocapture), checkout events, email after purchase (person merge).

Legal basis: Art. 6(1)(a) GDPR and § 25(1) TDDDG.
Session recording: active after consent — session replays with text masking (inputs and text content are masked).
DPA: PostHog as processor (Art. 28) via posthog.com/dpa.
Withdraw consent: Cookie settings link in the footer at any time.
Retention: per PostHog project settings (EU).

After purchase, the analytics chain may be linked to your email for conversion reporting. Pre-consent ephemeral ids are not back-joined.

8. Anonymous, server-side reach measurement without cookies

For visitors who do not accept analytics or ignore the banner, we count anonymous visits entirely server-side on our own infrastructure (Google Cloud Run, EU). Nothing is stored on or read from your device — we only use data your browser already transmits with every request (IP address, user agent).

How it works: Our server derives a cryptographic hash from the IP address and user agent using a daily-rotating key and discards the raw IP immediately; it is never stored or shared. The hash only supports counting unique visits within a single day — recognition across days, or identifying a person, is not possible. The user agent is additionally reduced to a non-personal bot flag (yes/no) and likewise discarded. Only the hash, the page type and the shop are sent to our analytics provider PostHog (EU) — no person profile, no IP, no user agent.

Your cookie-banner decision (accept or reject) is additionally counted server-side as an aggregated event (with no further personal data) and logged as a record of your choice.

Legal basis: Art. 6(1)(f) GDPR (aggregated reach measurement). § 25 TDDDG is not triggered, as no information is stored on or read from your device.
Objection: Art. 21 GDPR by email to privacy@storewy.com.

9. Aggregated landing measurement (currently disabled)

A server-side, device-free landing view count is implemented but currently disabled. No person profile; visitor IP is not sent to PostHog for this event.

If enabled: Art. 6(1)(f) GDPR; objection under Art. 21 via privacy@storewy.com.

10. Third-country transfers

Where providers outside the EEA are used (e.g. Resend, Google, AliExpress, TikTok Shop / ByteDance), transfers rely on appropriate safeguards (especially EU Standard Contractual Clauses, Art. 46 GDPR) or applicable marketplace terms, and supplementary measures where required.

11. Retention

  • Order/invoice data: commercial/tax retention (often up to 10 years) — including orders imported via TikTok Shop where tax- or commercially relevant.
  • TikTok Shop credentials (tokens): until disconnect or rotation; on disconnect we clear stored Shop credentials.
  • Support threads: until resolved, then deletion/anonymisation unless legally required to keep.
  • PostHog analytics: per PostHog retention; deletion on request (form below).
  • Consent records: timestamp, banner version, choice — kept for accountability (~3 years).

12. Your rights

Access, rectification, erasure, restriction, portability, objection (Art. 21) to legitimate-interest processing, and withdrawal of consent (Art. 7(3)) — via cookie settings or email.

To exercise your rights, contact privacy@storewy.com. For shop support (orders, shipping), use support@storewy.com.

You may lodge a complaint with a supervisory authority (e.g. Berlin Commissioner for Data Protection).

13. Analytics erasure and consent management

  • Change / withdraw consent: Cookie settings in the site footer.
  • Delete PostHog data: form at the bottom of this page or email privacy@storewy.com (alternatively support@storewy.com) with your checkout email.

Order records kept for tax law are not deleted by analytics erasure.

Delete analytics data (Art. 17 GDPR)

If you previously chose “Accept analytics”, you can request deletion of your PostHog analytics profile and related events. Order records kept for tax law are not affected.