1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
Roman Allenstein
Schnepfenweg 1C
27607 Geestland
Germany
Email: info@shopwatch.io
2. General Information on Data Processing
As a matter of principle, we process the personal data of our users only to the extent necessary
to provide a functioning website together with our content and services. Processing regularly
takes place only with the consent of the data subject (Art. 6(1)(a) GDPR), for the performance of
a contract or pre-contractual measures (Art. 6(1)(b) GDPR), or on the basis of our legitimate
interest in the secure and efficient operation of the service (Art. 6(1)(f) GDPR).
3. Hosting and Provision of the Website
Our service is operated on our own infrastructure in Germany. When the website is accessed, the
server automatically collects information and stores it in so-called server log files. In
particular, the following is recorded: the anonymised or truncated IP address, the date and time
of access, the URL requested, the HTTP status code, the volume of data transferred, and the
browser and operating system used. This data is technically necessary in order to deliver the
website, ensure its stability and security, and prevent misuse (e.g. attacks). The legal basis is
Art. 6(1)(f) GDPR.
4. Cookies and Session Storage
We use technically necessary cookies that are required for the operation of the signed-in area:
- a session cookie that maintains your sign-in during a visit;
- an optional “keep me signed in” cookie with a lifetime of one week, if you
use this feature.
These cookies are strictly necessary to provide the feature you have expressly requested
(signing in); the legal basis is Section 25(2) TDDDG as well as Art. 6(1)(b) and (f) GDPR. To
store your display preference (light/dark mode) we use your browser's local storage
(localStorage); no personal data is transmitted to us in this process.
5. Registration and Passwordless Sign-In
Using the signed-in area requires registration with your email address. Signing in is
passwordless: we send a one-time code (one-time password) to your email address. For this purpose
we process your email address and the timestamp of the sign-in. The legal basis is Art. 6(1)(b)
GDPR (performance of the usage relationship). Your data is deleted as soon as your account is
deleted and no statutory retention obligations apply.
6. Waitlist
If you join our waitlist, we process your email address and, optionally, the shop domain you
provide and the plan you are interested in. We use this data solely to inform you about the
launch or availability of the service. The legal basis is your consent pursuant to Art. 6(1)(a)
GDPR, which you may withdraw at any time with effect for the future (e.g. by email to the address
stated above).
7. Shop Monitoring and Analysis
The core of our service is the analysis of online shops. For this purpose we process the shop
domains you provide as well as the publicly accessible content of these shops in order to
determine metrics on performance, trust, and SEO and to calculate the “ShopWatch Score”. The
legal basis is Art. 6(1)(b) GDPR.
8. Services Used and Recipients
To provide our service we use the following service providers and interfaces:
- Email delivery (Brevo): To send sign-in codes and notifications we use the
service provider Brevo (Brevo GmbH, Germany) as a processor. Your email address together
with the content of the respective message is transmitted.
- Google PageSpeed Insights: To measure loading speed we transmit the shop URL
to be checked to Google's PageSpeed Insights interface (Google Ireland Limited). This may
involve a transfer to a third country (USA).
- HTML validation: The validation of HTML markup takes place on our own
infrastructure; no disclosure to third parties occurs in this process.
The legal basis for the use of these services is Art. 6(1)(b) and (f) GDPR. Corresponding
contracts pursuant to Art. 28 GDPR are in place with processors.
9. Data Security
All data is transmitted in encrypted form via HTTPS (TLS). We take appropriate technical and
organisational measures to protect your data against loss, manipulation, and unauthorised access.
10. Storage Period
We store personal data only for as long as is necessary for the respective purposes or as
required by statutory retention periods. The data is deleted thereafter.
11. Your Rights
Under the GDPR you have the following rights: access (Art. 15), rectification (Art. 16), erasure
(Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and objection to
processing (Art. 21). You may withdraw consent you have given at any time with effect for the
future (Art. 7(3)). To exercise your rights, a message to
info@shopwatch.io is sufficient.
12. Right to Lodge a Complaint with a Supervisory Authority
Without prejudice to any other administrative or judicial remedy, you have the right to lodge a
complaint with a data protection supervisory authority, in particular in the Member State of your
residence, your place of work, or the place of the alleged infringement.
13. Currency of this Privacy Policy
This privacy policy will be updated as soon as changes to our data processing or to the legal
framework arise. The version published on this page applies in each case.