Trust

Data handling and retention

What we store, for how long, where it lives and who can reach it.

This page is the operational answer to “what do you actually have about me”. The legal statement of the same thing — with the lawful basis for each category — is clause 2 of the privacy policy. Where the data belongs to your buyers rather than to you, we are your processor and the data processing addendum governs it.

Where it lives

On infrastructure we operate in the European Union. Records are held in per-purpose databases rather than one undifferentiated store, which is what makes the table below possible to write honestly: money records are kept apart from usage counters, which are kept apart from the work itself. Copies leave that infrastructure only for the five purposes listed on sub-processors.

What is stored, and for how long

StoreWhat it holdsHow long we keep it
Account and session recordsYour email address, when the account was created and verified, the plan it is on, and the sessions signed in to it. Sign-in links are single-use and expire minutes after they are sent.While the account is open; deleted 30 days after closure.
Product, claim and offer recordsProducts claimed, held or passed, the evidence recorded with a find, offer and pricing figures, and the reasons the engine recorded for its choices.While the account is open; deleted 30 days after closure.
Store recordsGenerated pages and copy, section order and the rationale for it, domain settings, and whether payments on the store are live or in sandbox.While the account is open; deleted 30 days after closure.
Usage countersHow many actions each tool has performed in the current rolling window, and the entitlement checks behind them. Counters are counts, not copies of the work.13 months, then deleted.
Payment and ledger recordsAmount, currency, status, time, plan, the provider's transaction reference, and each movement of an advertising balance with the reason for it. No card numbers.8 years, as Hungarian accounting law requires. This is the one category account closure does not delete.
Referral recordsYour referral code, the visitor sessions that opened it, and the milestone each reached. Not the identity of the person invited.24 months from the last recorded milestone.
Store orders and support mailOrders recorded against your store, satisfaction samples, and email your buyers send to the support address issued to your store, with the rules you configured for it.While the account is open, or until you delete it; deleted 30 days after closure.
Supplier and payout settingsSupplier connection settings and the payout destination for store revenue.While the account is open; then retained only as long as accounting law requires.
Technical logsIP address, user agent, request path, timestamps, errors and rate-limit events.90 days, extended only for a specific incident under investigation.

What we do not do with it

Deletion, and what deletion actually means

When you delete an object in the product, it stops being reachable immediately and is removed from the live databases. When you close an account, the same happens to everything in it except the payment and ledger records, which Hungarian accounting law requires us to retain for eight years — we cannot delete those on request, and we would be wrong to say we could.

Backups are the honest complication. Encrypted snapshots are taken so that a failure does not destroy your work, and a deleted record persists in a snapshot until that snapshot rotates out, within 30 days. We do not restore an individual record from a backup to bring deleted data back, and data in a backup remains subject to the same protections until it is gone.

Export

You can export your work from the product at any time while the account is open. Do it before you close the account, because closure starts the deletion schedule above. A machine-readable copy of the personal data we hold about you is available on request under clause 9 of the privacy policy — write to [email protected] and we answer within a month.

If something goes wrong

Where a breach is likely to create a risk to people, the supervisory authority is notified within 72 hours and affected individuals without undue delay where the risk is high; business customers are told within 48 hours. What we do while an incident is live is on availability commitment, and the measures meant to prevent one are on security.