1. Who is responsible
The company named in the provider details on this page is the controller of the personal data described in this policy. The one exception is the data of our merchants’ customers, which we process on the merchant’s behalf (section 4).
You can reach us about your data at the email address in the provider details.
2. Visitors to this website
No cookies, no tracking. This website does not use cookies and does not track you. Fonts and images are served from our own servers, and the site contains no advertising or social media embeds. Our cookie policy lists the one thing the site stores in your browser.
Server logs. Our hosting provider records technical data such as your IP address, browser and the pages requested, to deliver the website and keep it secure. Our legal basis is our legitimate interest in running a secure website (Article 6(1)(f) GDPR). Logs are kept for a limited period and then deleted.
Statistics. If we add visitor statistics, they will be cookieless and anonymous, and we will name the tool in this policy.
Messages. When you write to us by email or through the contact form, we use your name, email address, company and message to reply. Our legal basis is taking steps at your request before a contract (Article 6(1)(b) GDPR) or our legitimate interest in answering you (Article 6(1)(f)). We keep the correspondence as long as needed to deal with your request and any follow-up.
3. Merchants and their teams
When your business uses Gravilo, we process:
- account details: name, email address, password (stored only as a hash) and role;
- company details: legal name, address, registration and VAT numbers;
- billing details: top-ups, orders, invoices and your balance history. Card payments are handled by Stripe; we never see full card numbers;
- usage data: actions in your account, API requests and an audit log of changes, to run and secure the service;
- your messages to us.
We use this data to provide the service under our contract with you (Article 6(1)(b) GDPR), to meet our accounting and tax obligations (Article 6(1)(c)), and to keep the service secure and prevent fraud (Article 6(1)(f)). We send you emails about your account and orders. We do not send marketing without your consent.
We keep this data while your account is open. After you close it, we delete it, except what accounting and tax law requires us to keep, for the period the law sets.
4. Your customers’ data
When your customer orders a Gravilo product from your store, we receive their name, delivery address, phone number and email, and the photos and text of their personalisation.
We process this data on your behalf, only to produce, ship and support the order. You are the controller and we are the processor, under the data processing terms in our terms of service. We never use it to contact your customers or for marketing. Ninety days after delivery, or after cancellation for a cancelled order, we remove their personal details and the photos and text of their personalisation from the order. That period covers complaints and returns.
Your customers should contact your store to exercise their rights, and we will help you answer them.
5. Who we share data with
We share personal data only with providers that help us run the service, under contracts that protect it:
- hosting and storage: DigitalOcean, in its Frankfurt data centre;
- payments: Stripe;
- invoicing: SmartBill;
- email delivery: Postmark;
- shipping: the courier platform Woot (Romania) books each parcel with a carrier, and both receive its delivery details;
- Shopify, when you use the Gravilo app for Shopify.
We also share data with authorities when the law requires it.
6. Transfers outside the EU
We store data in the European Union. Some of our providers belong to groups based outside the European Economic Area. Where data may be accessed from outside the EEA, the transfer is covered by the EU–US Data Privacy Framework or by the European Commission’s standard contractual clauses.
7. Security
Data is encrypted in transit. Access is limited to the people who need it, and staff accounts require two-factor authentication. Secrets such as access tokens are encrypted at rest, and API keys are stored only as hashes.
8. Your rights
You have the right to access your personal data, to have it corrected or erased, to restrict or object to its processing, and to receive it in a portable format. Where we rely on your consent, you can withdraw it at any time.
To exercise your rights, write to us at the email address in the provider details. You can also complain to the Romanian data protection authority (Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal, www.dataprotection.ro) or to the authority in your country.
9. Changes
We update this policy when our practices change and show the date of the last change at the top. We tell merchants about material changes before they take effect.