Service privacy policy

This page covers the HideMyDrop application served at app.hidemydrop.com. The marketing site hidemydrop.com has its own privacy policy. The French version of this page is the authoritative one.

Who processes your data

The service is published by GRT Ventures OÜ, a company incorporated in Estonia. Questions on this page are handled by the legal representative of GRT Ventures OÜ, reachable at the contact address at the bottom of this page.

GRT Ventures OÜ acts in two distinct roles. For the data of merchants who open an account, it is the data controller. For the data of the buyers of those merchants' shops, it acts as a data processor, on the merchant's instructions. The merchant remains the controller towards their own customers.

Data processed on the merchant side

Data processed about end buyers

When a shop connects the service, the service receives the following buyer data for each order.

The service neither receives nor stores the buyer's postal address or phone number.

Purposes

Legal bases

Merchant data is processed to perform the contract between the merchant and the service. Buyer data is processed on the merchant's instructions, under that same contract. The merchant is responsible for the legal basis that applies to their own customers. Technical logs are kept under the legitimate interest of securing the service.

Sub-processors

The service relies on the following providers.

Integrations enabled by the merchant

The service can send tracking data to third-party tools, in particular Klaviyo, Gorgias and outbound webhooks configured by the merchant. These integrations are off by default. They only run when the merchant decides to enable them, chooses the recipient and remains responsible for how the data is used in that tool.

Retention periods

Merchant account data and the related buyer data are kept for the duration of the contract. They are purged when the account is deleted, subject to legal retention obligations, in particular billing records. Technical logs are kept for 180 days. The sign-in history of the merchant account (date, authentication method, IP address, browser, success or failure) is kept for 365 days, then purged automatically.

Your rights

You have the rights of access, rectification, erasure, restriction, objection and portability provided by the General Data Protection Regulation.

If you are a merchant, send your request directly to the contact address at the bottom of this page.

If you bought from a shop that uses the service, send your request to that merchant. They are your data controller, and the service assists them in answering. For Shopify shops, the service receives and handles the requests forwarded by the platform's compliance webhooks, which cover data access and data erasure.

Complaints

You can lodge a complaint with the Estonian data protection authority, the Andmekaitse Inspektsioon (www.aki.ee), or with the supervisory authority of your country of residence.

Changes

This page may evolve with the service. The date of the last update is shown at the bottom. If a sub-processor changes, the list above is updated before the corresponding processing starts.