Privacy Policy

1. Controller (Data Controller)

The data controller responsible for processing personal data in connection with the Dovail App by SlideNbite (hereinafter "App") is:

slideNbite UG (haftungsbeschränkt)
Frahmredder 37
22393 Hamburg, Germany
Commercial Register: Amtsgericht Hamburg (Hamburg Local Court), HRB 195340
Managing Director: Marten Henke
Email: support.dovail@slidenbite.com
Website: www.dovail.slidenbite.com

(hereinafter "we", "us", or "SlideNbite")

2. Scope of this Privacy Policy

This Privacy Policy explains how we collect, use, store, and protect personal data when merchants ("Merchants") install and use our App on the Shopify platform, and when end-customers of those Merchants ("End Customers") interact with the App's waitlist functionality (e.g. signing up for back-in-stock notifications).

This policy applies to:

3. Data We Collect

3.1 Merchant Data

When a Merchant installs and uses the App, we process the following data:

Legal basis: Art. 6(1)(b) GDPR — performance of contract.

3.2 End Customer Data

When an End Customer signs up for a back-in-stock notification through the App embedded in a Merchant's store, we process the following data:

The delivery address, requested quantity, selected product variant and, for business deliveries, the optional company name are sent to Shopify to determine whether delivery is available for the requested destination and quantity. The optional company name is not required for consumer deliveries.

Technical access tokens are used exclusively to provide secure confirmation, management and deletion links. They are not used for advertising or tracking.

We process End Customer data exclusively on behalf of the Merchant as a data processor under Art. 28 GDPR. The Merchant is the data controller and is responsible for ensuring a valid legal basis for collecting and processing the data.

We do not determine a legal basis for this processing ourselves. The Merchant, as controller, determines the purposes and means and is responsible for establishing a valid legal basis under Art. 6(1) GDPR. We process End Customer data solely on the Merchant's documented instructions in accordance with Art. 28(3)(a) GDPR and the data processing agreement concluded with the Merchant.

4. Purpose of Processing

We process the data described above for the following purposes:

We do not use End Customer data for our own marketing purposes, and we do not sell personal data to third parties.

5. Third-Party Service Providers (Sub-Processors)

To deliver the App's functionality, we engage the following sub-processors. All sub-processors are contractually bound to appropriate data protection standards:

Supabase, Inc. (database hosting)

Purpose: Secure storage of waitlist data and app configuration.

Location: EU-based server region (Frankfurt). Standard Contractual Clauses (SCCs) in place for any cross-border transfers.

Privacy Policy: www.supabase.com/privacy

Postmark (AC PM LLC, an ActiveCampaign company)

Purpose: Transactional email delivery (back-in-stock notifications to End Customers).

Location: United States. Standard Contractual Clauses (SCCs) in place.

Privacy Policy: www.postmarkapp.com/privacy-policy

Shopify International Ltd.

Purpose: Platform infrastructure, billing, and OAuth authentication. For these purposes, Shopify acts as an independent data controller for its own platform data.

In addition, the App submits the End Customer's delivery address, requested quantity and selected product variant to a Shopify API to determine whether delivery is available for the requested destination. For this specific processing, Shopify acts as a sub-processor on the Provider's instructions.

Location: Ireland (EU).

Privacy Policy: www.shopify.com/legal/privacy

STRATO GmbH

Purpose: Hosting of the public website, application server and domain infrastructure.

Location: Germany / European Union.

Depending on the configured hosting service, STRATO may process technical connection data such as IP addresses, timestamps, requested resources, browser information and error information in server log files.

Privacy Policy: www.strato.de/datenschutz

We have concluded a data processing agreement with STRATO pursuant to Art. 28 GDPR.

6. Data Retention

We retain personal data only for as long as necessary for the purposes described in this Privacy Policy:

7. Rights of Data Subjects

Under the GDPR and applicable privacy laws, individuals have the following rights regarding their personal data:

Note for End Customers: Since we process End Customer data on behalf of the Merchant, data subject requests relating to End Customer data should be directed to the relevant Merchant (the data controller). We will support Merchants in fulfilling such requests as required.

To exercise your rights as a Merchant, or for general privacy inquiries, please contact us at: support.dovail@slidenbite.com

You also have the right to lodge a complaint with a supervisory authority. The competent authority for SlideNbite is:

Hamburgischer Beauftragter für Datenschutz und Informationsfreiheit
Ludwig-Erhard-Str. 22, 20459 Hamburg, Germany
www.datenschutz.hamburg.de

8. International Data Transfers

Some of our sub-processors are located outside the European Economic Area (EEA), in particular in the United States (Postmark). For such transfers, we rely on the Standard Contractual Clauses (SCCs) adopted by the European Commission pursuant to Art. 46(2)(c) GDPR as the legal transfer mechanism, ensuring an adequate level of data protection.

9. Data Security

We implement appropriate technical and organisational measures (TOMs) to protect personal data against unauthorised access, loss, or destruction. These measures include:

While we strive to protect personal data, no method of transmission over the internet is 100% secure. Where we act as controller (Section 3.1), we will notify the competent supervisory authority of a personal data breach without undue delay and, where feasible, within 72 hours in accordance with Art. 33(1) GDPR, and will inform affected individuals where Art. 34 GDPR requires it.

Where we act as processor on behalf of a Merchant (Section 3.2), we will notify the Merchant without undue delay and in any event no later than 24 hours after becoming aware of a personal data breach, in accordance with Art. 33(2) GDPR and the data processing agreement. It is then for the Merchant, as controller, to notify the supervisory authority and affected individuals where required.

10. Shopify Mandatory Privacy Webhooks

In accordance with Shopify's app requirements, our App implements the mandatory Shopify privacy webhooks:

11. Cookies and Tracking Technologies

The App itself (as embedded in the Shopify Admin) does not use cookies or third-party tracking technologies for marketing or analytics purposes. Shopify may set its own cookies as part of its platform infrastructure; please refer to Shopify's own privacy policy for details.

Our public website does not currently use analytics or marketing cookies. It stores only the selected interface language in the browser's local storage.

If optional analytics or marketing technologies are introduced, they will not be loaded before any consent required by applicable law has been obtained.

12. Children's Privacy

The App is a B2B service directed at business operators (Merchants). It is not intended for individuals under the age of 18. We do not knowingly collect personal data from minors.

13. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our data processing practices or applicable law. We will notify Merchants of material changes via email or an in-app notification. The date of the latest update is indicated at the top of this document.

Continued use of the App after the effective date of an updated Privacy Policy constitutes acceptance of the revised terms.

14. Contact

For any questions, concerns, or requests relating to this Privacy Policy or our data processing practices, please contact us at: support.dovail@slidenbite.com

Full contact details are available in our Legal Notice (Impressum).