Please note: This is a courtesy translation. Only the German version of this privacy policy is legally binding. In case of any discrepancies, the German version prevails.
1. Overview
General Information
The following information provides a simple overview of what happens to your personal data when you visit our website (pricepirate.com) or use our Shopify app. Personal data is any data that can be used to personally identify you.
This privacy policy is divided into two parts:
- Part A covers visits to our website (pricepirate.com),
- Part B covers the use of our Shopify app.
Information on the Responsible Party
The party responsible for processing within the meaning of the GDPR is:
UCX Media - Sergei Gaponik
c/o Online-Impressum.de #6171
Europaring 90
53757 Sankt Augustin
Germany
E-Mail: info@gaponik.com
The responsible party is the natural or legal person who, alone or jointly with others, decides on the purposes and means of processing personal data.
Your Rights
You have the right at any time to receive free information about the origin, recipients, and purpose of your stored personal data (Art. 15 GDPR).
You also have the right to request the correction (Art. 16 GDPR), deletion (Art. 17 GDPR), or restriction of the processing (Art. 18 GDPR) of this data, the right to data portability (Art. 20 GDPR), and the right to lodge a complaint with the competent supervisory authority (Art. 77 GDPR).
Where processing is based on your consent, you may withdraw it at any time with effect for the future (Art. 7 (3) GDPR). Where processing is based on our legitimate interest (Art. 6 (1) lit. f GDPR), you may object at any time (Art. 21 GDPR), e.g. by email to info@gaponik.com.
Data Protection
We take the protection of your personal data very seriously. Processing is carried out in accordance with the statutory data protection regulations and this privacy policy.
We would like to point out that data transmission over the Internet and within cloud-based platforms may have security vulnerabilities. Complete protection of data against access by third parties is not possible.
Part A: Website (pricepirate.com)
A.1 Website Hosting
Our website is hosted by Cloudflare:
Cloudflare, Inc.
101 Townsend Street
San Francisco, CA 94107
United States of America
When you access the website, Cloudflare processes technically necessary data such as IP address, date and time of access, pages accessed, browser type, and operating system (server log files). This processing is based on our legitimate interest in a secure, stable, and efficient provision of the website (Art. 6 (1) lit. f GDPR). Cloudflare is certified under the EU-US Data Privacy Framework; standard contractual clauses are also in place. A data processing agreement (DPA) pursuant to Art. 28 GDPR has been concluded with Cloudflare.
The fonts used on the website are loaded locally from our own servers; no data is transmitted to third parties in this context.
A.2 Cookies and Consent Management
Our website uses cookies and similar technologies. We only use cookies that are not technically necessary (analytics, marketing) with your consent (Sec. 25 (1) TDDDG, Art. 6 (1) lit. a GDPR).
On your first visit, a consent banner appears (consent tool “vanilla-cookieconsent”, embedded locally, no data transmitted to third parties). Your selection is stored in a cookie (cc_cookie, stored for approx. 6 months); this cookie is technically necessary (Sec. 25 (2) TDDDG).
You can change or withdraw your consent at any time via the “Cookie settings” link in the website footer.
A.3 Web Analytics with PostHog
We use the analytics service PostHog on our website:
PostHog, Inc.
2261 Market Street #4008
San Francisco, CA 94114
United States of America
Analytics data is processed exclusively on servers within the European Union (EU cloud, Frankfurt). A data processing agreement (DPA) pursuant to Art. 28 GDPR has been concluded with PostHog.
PostHog records, among other things, pages accessed, interactions, technical device information, and the origin of the visit (e.g. UTM parameters). Session replays of interactions with our website may also be created.
Without your consent, analytics runs cookieless: no cookies are set and no identifiers are stored persistently on your device; no cross-page recognition beyond the individual page view takes place. The legal basis is our legitimate interest in reach-related analysis of our website (Art. 6 (1) lit. f GDPR).
With your consent (category “Analytics” in the cookie banner), PostHog stores an identifier in cookies or your browser’s local storage in order to recognize you on repeat visits. The legal basis is your consent (Art. 6 (1) lit. a GDPR, Sec. 25 (1) TDDDG).
If you submit a request via our contact form, we link your email address to your PostHog profile in order to trace and process your request in the context of contract initiation. The legal bases are Art. 6 (1) lit. b GDPR (pre-contractual measures) and our legitimate interest in evaluating our sales channels (Art. 6 (1) lit. f GDPR).
A.4 Meta Pixel
With your consent (category “Marketing” in the cookie banner), we use the Meta pixel on our website, a service of:
Meta Platforms Ireland Limited
Merrion Road, Dublin 4
D04 X2K5, Ireland
The Meta pixel makes it possible to address visitors of our website as a target group for advertisements on Meta platforms (Facebook, Instagram) and to measure the performance of our advertisements. In doing so, cookies are set (including _fbp) and data such as IP address, browser information, and pages visited are transmitted to Meta. Meta may also process this data in the USA; Meta is certified under the EU-US Data Privacy Framework.
The legal basis is your consent (Art. 6 (1) lit. a GDPR, Sec. 25 (1) TDDDG). You can withdraw your consent at any time via the cookie settings.
Insofar as personal data is transmitted to Meta in the context of the Meta pixel and Meta processes this data for its own purposes, we are joint controllers with Meta (Art. 26 GDPR). Further information can be found in Meta’s privacy policy.
A.5 Meta Conversions API for Contact Requests
When you submit our contact form (“Get Started”), we transmit a conversion event to Meta via the server-side Meta Conversions API in order to measure the performance of our advertising campaigns — even if you have not accepted marketing cookies. In this case, no cookies are set on your device and your device is not accessed; the transmission takes place exclusively from our server to Meta.
The following data is transmitted:
- your email address in hashed form (SHA-256, not in plain text),
- technical data of the request (IP address, user agent, page accessed),
- if applicable, an ad click identifier (fbclid), if you reached our website via a Meta advertisement.
The legal basis is our legitimate interest in measuring and accounting for the effectiveness of our advertising campaigns (Art. 6 (1) lit. f GDPR). Our interest lies in being able to trace which advertising expenditure leads to customer inquiries; by hashing the email address and not using cookies, the processing is limited to what is necessary. You may object to this processing at any time (Art. 21 GDPR), e.g. by email to info@gaponik.com.
A.6 Contact Form
When you submit our contact form, the data you enter (email address, information about your shop such as shop system, domain, product categories, and target markets, optional message) as well as visit origin data (e.g. UTM parameters, referring page) and the PostHog identifiers mentioned in A.3 are transmitted directly to our server and processed by us.
Processing is carried out to handle your request and to implement pre-contractual measures (Art. 6 (1) lit. b GDPR) and in our legitimate interest in evaluating our sales channels (Art. 6 (1) lit. f GDPR).
A.7 Appointment Booking (Calendly)
After submitting the contact form, you can book an appointment with us via an embedded widget. The provider is:
Calendly LLC
271 17th St NW
Atlanta, GA 30363
United States of America
The Calendly widget is only loaded once you have actively submitted the contact form. When used, the data you enter (name, email address, selected appointment) as well as technical data is transmitted to Calendly and may be processed in the USA. Calendly is certified under the EU-US Data Privacy Framework.
The legal basis is the implementation of pre-contractual measures at your request (Art. 6 (1) lit. b GDPR).
Part B: Shopify App
B.1 Data Collection Within the App
How do we collect your data?
On the one hand, your data is collected when you provide it to us in the course of using the app, e.g. through entries, configurations, or support requests.
Other data is collected automatically or with your consent through the technical use of the app within the Shopify platform. This particularly concerns technical data (e.g. shop ID, API accesses, timestamps of app actions).
What do we use your data for?
Processing is carried out exclusively in order to:
- provide the functionality of the app,
- store configurations and settings,
- process support requests,
- and ensure the security and stability of the app.
The data is not used for advertising or marketing purposes unless this is expressly stated and authorized.
B.2 Hosting and Technical Infrastructure of the App
The app is technically operated via external servers. The personal data processed in the course of using the app is stored on the servers of the hosting provider. This may in particular include the following data:
- Shopify shop information (e.g. shop domain, shop ID)
- technical metadata and log information
- configuration and settings data of the app
- support communication
Hosting is carried out:
- to fulfill the contract (Art. 6 (1) lit. b GDPR),
- as well as in the legitimate interest of a secure, stable, and efficient provision of the app (Art. 6 (1) lit. f GDPR).
Hosting provider used:
Railway Technologies, Inc.
2261 Market Street #4485
San Francisco, CA 94114
United States of America
A data processing agreement (DPA) pursuant to Art. 28 GDPR is in place with the hosting provider.
B.3 Storage Duration
Personal data is only stored for as long as is necessary for the respective purpose.
After the app is uninstalled, all associated data is deleted, unless there are statutory retention obligations.
B.4 Communication and Support
If you contact support by email or via Shopify, your information, including all personal data arising from it, will be stored and processed exclusively for the purpose of handling your request.
Legal basis:
- Art. 6 (1) lit. b GDPR (contractual or pre-contractual measures)
- Art. 6 (1) lit. f GDPR (legitimate interest in efficient support)
B.5 Data Processing Within the Shopify Platform
The app is operated exclusively within Shopify’s technical infrastructure. In this context, Shopify’s data protection provisions apply additionally.
The app only accesses the data that is strictly necessary for its respective function and that is transparently presented during the app installation process.