Privacy Policy
1. Controller (Data Controller)
The data controller responsible for processing personal data in connection with the Dovail App by SlideNbite (hereinafter "App") is:
slideNbite UG (haftungsbeschränkt)
Frahmredder 37
22393 Hamburg, Germany
Commercial Register: Amtsgericht Hamburg (Hamburg Local Court), HRB 195340
Managing Director: Marten Henke
Email: support.dovail@slidenbite.com
Website: www.dovail.slidenbite.com
(hereinafter "we", "us", or "SlideNbite")
2. Scope of this Privacy Policy
This Privacy Policy explains how we collect, use, store, and protect personal data when merchants ("Merchants") install and use our App on the Shopify platform, and when end-customers of those Merchants ("End Customers") interact with the App's waitlist functionality (e.g. signing up for back-in-stock notifications).
This policy applies to:
- Merchant data: data we collect when Merchants install and use the App via Shopify.
- End Customer data: personal data of the Merchant's customers that we process on behalf of the Merchant as a data processor under Art. 28 GDPR.
3. Data We Collect
3.1 Merchant Data
When a Merchant installs and uses the App, we process the following data:
- Shopify store domain and shop ID
- Merchant email address (from Shopify account)
- App configuration settings and preferences
- Usage data and technical logs (e.g. API request timestamps, error logs)
Legal basis: Art. 6(1)(b) GDPR — performance of contract.
3.2 End Customer Data
When an End Customer signs up for a back-in-stock notification through the App embedded in a Merchant's store, we process the following data:
- First and last name, where provided
- Email address
- Delivery address, including street, postal code, city, country and, where applicable, province
- Company name, where voluntarily provided for a business delivery
- Requested quantity and product or product variant of interest
- Preferred language
- Consent text, consent source and consent timestamp
- Confirmation, withdrawal and unsubscription status and timestamps
- Technical identifiers and access tokens used for secure self-service links
- Notification and transactional email delivery status
- Single-use discount codes issued in connection with the waitlist entry, including their issue date and redemption status
- Limited order data used to calculate whether a notified request resulted in an order
The delivery address, requested quantity, selected product variant and, for business deliveries, the optional company name are sent to Shopify to determine whether delivery is available for the requested destination and quantity. The optional company name is not required for consumer deliveries.
Technical access tokens are used exclusively to provide secure confirmation, management and deletion links. They are not used for advertising or tracking.
We process End Customer data exclusively on behalf of the Merchant as a data processor under Art. 28 GDPR. The Merchant is the data controller and is responsible for ensuring a valid legal basis for collecting and processing the data.
We do not determine a legal basis for this processing ourselves. The Merchant, as controller, determines the purposes and means and is responsible for establishing a valid legal basis under Art. 6(1) GDPR. We process End Customer data solely on the Merchant's documented instructions in accordance with Art. 28(3)(a) GDPR and the data processing agreement concluded with the Merchant.
4. Purpose of Processing
We process the data described above for the following purposes:
- Providing the App's core functionality: managing back-in-stock waitlists and triggering notification emails when products become available again.
- Sending transactional notification emails to End Customers via our email service provider (Postmark).
- Maintaining and improving the App's technical performance and reliability.
- Responding to Merchant support requests.
- Complying with legal obligations.
We do not use End Customer data for our own marketing purposes, and we do not sell personal data to third parties.
5. Third-Party Service Providers (Sub-Processors)
To deliver the App's functionality, we engage the following sub-processors. All sub-processors are contractually bound to appropriate data protection standards:
Supabase, Inc. (database hosting)
Purpose: Secure storage of waitlist data and app configuration.
Location: EU-based server region (Frankfurt). Standard Contractual Clauses (SCCs) in place for any cross-border transfers.
Privacy Policy: www.supabase.com/privacy
Postmark (AC PM LLC, an ActiveCampaign company)
Purpose: Transactional email delivery (back-in-stock notifications to End Customers).
Location: United States. Standard Contractual Clauses (SCCs) in place.
Privacy Policy: www.postmarkapp.com/privacy-policy
Shopify International Ltd.
Purpose: Platform infrastructure, billing, and OAuth authentication. For these purposes, Shopify acts as an independent data controller for its own platform data.
In addition, the App submits the End Customer's delivery address, requested quantity and selected product variant to a Shopify API to determine whether delivery is available for the requested destination. For this specific processing, Shopify acts as a sub-processor on the Provider's instructions.
Location: Ireland (EU).
Privacy Policy: www.shopify.com/legal/privacy
STRATO GmbH
Purpose: Hosting of the public website, application server and domain infrastructure.
Location: Germany / European Union.
Depending on the configured hosting service, STRATO may process technical connection data such as IP addresses, timestamps, requested resources, browser information and error information in server log files.
Privacy Policy: www.strato.de/datenschutz
We have concluded a data processing agreement with STRATO pursuant to Art. 28 GDPR.
6. Data Retention
We retain personal data only for as long as necessary for the purposes described in this Privacy Policy:
- Unconfirmed waitlist requests are deleted automatically after 7 days.
- Active waitlist data is retained while required to provide the requested notification.
- Processed or withdrawn waitlist entries and personal data no longer connected to an active entry are deleted automatically after 90 days.
- When the App is uninstalled, deletion of App data is initiated immediately upon receipt of Shopify's app/uninstalled webhook.
- Valid shop/redact and customers/redact requests are processed without undue delay and within the period required by Shopify and applicable law.
- Merchant account data is retained for the duration of the contract, subject to mandatory legal retention obligations for specific business and tax records.
- Limited application and hosting logs used for security, error diagnosis and reliable operation are retained for no longer than 90 days, unless temporary preservation is required to investigate a specific security incident.
7. Rights of Data Subjects
Under the GDPR and applicable privacy laws, individuals have the following rights regarding their personal data:
- Right of access (Art. 15 GDPR): You may request information about the personal data we hold about you.
- Right to rectification (Art. 16 GDPR): You may request correction of inaccurate data.
- Right to erasure (Art. 17 GDPR): You may request deletion of your data, subject to legal retention obligations.
- Right to restriction of processing (Art. 18 GDPR): You may request that we limit how we use your data.
- Right to data portability (Art. 20 GDPR): You may request your data in a machine-readable format.
- Right to object (Art. 21 GDPR): You may object to processing based on legitimate interests.
Note for End Customers: Since we process End Customer data on behalf of the Merchant, data subject requests relating to End Customer data should be directed to the relevant Merchant (the data controller). We will support Merchants in fulfilling such requests as required.
To exercise your rights as a Merchant, or for general privacy inquiries, please contact us at: support.dovail@slidenbite.com
You also have the right to lodge a complaint with a supervisory authority. The competent authority for SlideNbite is:
Hamburgischer Beauftragter für Datenschutz und Informationsfreiheit
Ludwig-Erhard-Str. 22, 20459 Hamburg, Germany
www.datenschutz.hamburg.de
8. International Data Transfers
Some of our sub-processors are located outside the European Economic Area (EEA), in particular in the United States (Postmark). For such transfers, we rely on the Standard Contractual Clauses (SCCs) adopted by the European Commission pursuant to Art. 46(2)(c) GDPR as the legal transfer mechanism, ensuring an adequate level of data protection.
9. Data Security
We implement appropriate technical and organisational measures (TOMs) to protect personal data against unauthorised access, loss, or destruction. These measures include:
- Encrypted data transmission via TLS/HTTPS
- Access to production systems and personal data is restricted to authorised personnel and limited to necessary business operations
- Logical separation of each Merchant's data at the database level
- Contractual data protection obligations with all sub-processors
While we strive to protect personal data, no method of transmission over the internet is 100% secure. Where we act as controller (Section 3.1), we will notify the competent supervisory authority of a personal data breach without undue delay and, where feasible, within 72 hours in accordance with Art. 33(1) GDPR, and will inform affected individuals where Art. 34 GDPR requires it.
Where we act as processor on behalf of a Merchant (Section 3.2), we will notify the Merchant without undue delay and in any event no later than 24 hours after becoming aware of a personal data breach, in accordance with Art. 33(2) GDPR and the data processing agreement. It is then for the Merchant, as controller, to notify the supervisory authority and affected individuals where required.
10. Shopify Mandatory Privacy Webhooks
In accordance with Shopify's app requirements, our App implements the mandatory Shopify privacy webhooks:
- shop/redact: Initiates deletion of all shop-level App data.
- customers/redact: Deletes App data that can be associated with the requesting End Customer.
- customers/data_request: Collects the App data associated with the requesting End Customer and provides it to the Merchant.
11. Cookies and Tracking Technologies
The App itself (as embedded in the Shopify Admin) does not use cookies or third-party tracking technologies for marketing or analytics purposes. Shopify may set its own cookies as part of its platform infrastructure; please refer to Shopify's own privacy policy for details.
Our public website does not currently use analytics or marketing cookies. It stores only the selected interface language in the browser's local storage.
If optional analytics or marketing technologies are introduced, they will not be loaded before any consent required by applicable law has been obtained.
12. Children's Privacy
The App is a B2B service directed at business operators (Merchants). It is not intended for individuals under the age of 18. We do not knowingly collect personal data from minors.
13. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our data processing practices or applicable law. We will notify Merchants of material changes via email or an in-app notification. The date of the latest update is indicated at the top of this document.
Continued use of the App after the effective date of an updated Privacy Policy constitutes acceptance of the revised terms.
14. Contact
For any questions, concerns, or requests relating to this Privacy Policy or our data processing practices, please contact us at: support.dovail@slidenbite.com
Full contact details are available in our Legal Notice (Impressum).