Privacy Policy
Draft — not yet in force. These documents are shared for transparency and are pending legal review. They are not the final, binding terms until published at launch.
DRAFT for legal review — not final, not in force. See 00-README. GDPR-core, with global sections (CCPA/CPRA §12, US states §13, UK §14). `` = lawyer to verify. A Turkish (KVKK) supplement is deferred to the TR localization pack (see 09, deferred). Cookies: see the Cookie Policy.
Controller (for CIQRA's own processing): CIQRA OÜ, registry code 16465907, Veskiposti tn 2, Kesklinna linnaosa, Tallinn, Harju maakond, 10138, Estonia.
Privacy contact: privacy@ciqra.com · DPO: a Data Protection Officer will be appointed and named here — CIQRA's core activities (large-scale, systematic processing across a multi-tenant e-commerce platform, plus ad-tech and AI) likely trigger GDPR Art. 37(1)(b). **Representatives:** CIQRA is **established in the EU (Estonia)**, so **no GDPR Art. 27 EU representative** is required. If CIQRA targets **UK** data subjects, a **UK GDPR Art. 27 representative** will be appointed (EU establishment does not cover the UK).
Version: 1.0-draft · Last updated: 2026-07-08
1. Scope and our two roles
CIQRA operates a multi-tenant e-commerce/CMS platform. Our privacy role depends on whose data it is:
- CIQRA as CONTROLLER. For personal data we determine the purposes/means of: Merchant account and billing data, our website visitors, prospects/leads, support interactions, platform security and fraud prevention, aggregate/operational analytics, and our own marketing. This Policy governs that processing.
- CIQRA as PROCESSOR. For personal data in a Merchant's Storefront (that Merchant's Customers, orders, marketing lists, etc.), the Merchant is the controller and CIQRA processes on the Merchant's behalf and instructions under the Data Processing Agreement. For that data, the Merchant's own privacy notice applies to the Customer, and CIQRA acts only as described in the DPA.
If you are a Customer shopping on a Merchant's store, the Merchant is your primary controller; contact that Merchant for its privacy notice and to exercise rights over your order data. This Policy still tells you how CIQRA operates the underlying platform.
2. Personal data we process (as controller)
| Category | Examples | Source |
|---|---|---|
| Identity & account | name, business name, role, username, password (hashed) | you / your team |
| Contact | email, phone, address, country | you |
| Verification / KYC-KYB | business registration, beneficial owners, identity documents (via Stripe), tax IDs | you / Stripe |
| Billing & transactions | plan, invoices, commission, payout metadata, ledger entries (no raw card numbers — SAQ A) | you / Stripe |
| Usage & device | log data, IP, device/browser, pages, feature usage, cookies/identifiers | automatic |
| Support & comms | tickets, emails, chat, call notes | you |
| Marketing & preferences | consent status, subscriptions, campaign interactions | you |
| Security & fraud | authentication events, risk/fraud signals, abuse reports | automatic / third parties |
| Website visitor & prospect | lead data, form submissions, analytics | you / automatic |
We generally do not seek special-category data as controller. We do not knowingly process children's data as controller (see §11).
3. Purposes and legal bases (GDPR Art. 6)
| Purpose | Legal basis |
|---|---|
| Provide, operate and maintain the Services; manage your account | Contract (Art. 6(1)(b)) |
| Billing, commission, payouts, collections | Contract; Legal obligation (accounting/tax) |
| KYC/KYB, sanctions/AML screening, fraud prevention, trader traceability | Legal obligation; Legitimate interests (security, fraud prevention, DSA) |
| Security, abuse prevention, logging, backups | Legitimate interests; Legal obligation |
| Support and service communications | Contract; Legitimate interests |
| Product analytics and improvement (aggregated where possible) | Legitimate interests |
| Direct marketing to Merchants/prospects (double opt-in) | Consent and/or Legitimate interests, with opt-out |
| Cookies/tracking and ad pixels/CAPI (non-essential) | Consent (see Cookie Policy) |
| Legal compliance, disputes, enforcing terms | Legal obligation; Legitimate interests |
Where we rely on legitimate interests, we balance them against your rights and you may object (§9). Where we rely on consent, you may withdraw it at any time without affecting prior processing. ``
4. AI features and how your data is handled
4.1 CIQRA offers AI-assisted features (e.g. AI product-description/SEO generation, semantic search and recommendations, image generation/editing, and an AI chatbot), delivered via third-party AI/LLM providers accessed through an AI gateway.
4.2 Data-minimisation and safeguards. We are contractually and technically committed to:
- sending AI providers only the input needed for the requested feature, and avoiding sending personal data / PII to models except where strictly necessary and disclosed;
- no-training and minimised retention — under providers' business/commercial terms, customer inputs/outputs are not used to train their models, and retention is minimised (e.g. short-term abuse-monitoring only, or zero-data-retention where configured);
- content moderation / safety filtering on inputs and outputs; and
- transparency — where you interact with an AI system (e.g. chatbot) or where content is AI-generated/synthetic, this is disclosed/marked as required by the EU AI Act (Reg. (EU) 2024/1689) Art. 50.
4.3 You remain responsible for reviewing AI outputs before publishing. When CIQRA acts as processor on Merchant data, these AI safeguards are mirrored in the DPA.
5. Advertising pixels, analytics and server-side tracking
5.1 CIQRA and Merchants may use analytics and advertising integrations — e.g. Google Analytics 4 / Google Tag Manager, Meta (Facebook) Pixel & Conversions API (CAPI), TikTok, and similar — including server-side tracking and conversion APIs.
5.2 These are non-essential and consent-based. Advertising/analytics cookies and equivalent tracking (including server-side event forwarding that shares personal data such as hashed email, IP, or event data with ad platforms) run only after the user gives consent via the cookie/consent banner. Server-side tracking does not bypass the consent requirement: if consent is refused or withdrawn, such sharing does not occur. See the Cookie Policy. ``
5.3 On a Merchant's Storefront, the Merchant configures and is the controller for its own marketing pixels/CAPI; CIQRA provides the tooling and consent gating.
6. Who we share data with (recipients & subprocessors)
We share personal data with service providers acting for us, and with partners, only as needed:
- Payments: Stripe (incl. Stripe Connect) — payment processing, KYC/KYB, fraud, payouts (Stripe is an independent controller/processor for payment data).
- Cloud hosting / infrastructure: Microsoft Azure — Germany West Central (Frankfurt) primary + Germany North DR (compute, database, media storage, secrets/keys). All core data stays in the EU.
- CDN / security / DNS: Cloudflare (edge; EU data-localization for EU traffic).
- Email / transactional messaging: Azure Communication Services (primary); Amazon SES (EU region, fallback).
- Error monitoring / observability: Sentry (EU region); Grafana Cloud (EU) via OpenTelemetry.
- Search: Typesense (self-hosted on Azure, EU — internal component).
- AI / LLM: AI gateway (LiteLLM, self-hosted) + model providers (OpenAI, Anthropic) under zero-retention / no-training terms.
- Advertising / analytics platforms: Google, Meta, TikTok, etc. — consent-based (§5).
- Marketplace channels (future feature; if enabled): where a Merchant connects a sales channel (e.g. Amazon, Etsy), order/customer data is shared with that channel operator as needed for listing/fulfilment, subject to that operator's terms and transfer safeguards. ``
- Professional advisers, auditors, authorities — where legally required or to establish/defend legal claims.
- Corporate transactions — in a merger, acquisition or reorganisation, subject to confidentiality.
The authoritative, current Subprocessor List (with entities, locations and roles) is maintained separately and incorporated into the DPA. We do not sell personal data (and, for California, honor opt-out of "sharing" — see §13).
7. International data transfers
7.1 Personal data is stored and processed in the EU/EEA — core hosting is Microsoft Azure in Germany (West Central primary, North DR); there is no transfer of core personal data outside the EU/EEA for hosting, compute, database, storage or secrets.
7.2 Where a recipient/subprocessor is outside the EEA (or a Merchant enables a non-EEA integration/channel), we use an appropriate Art. 46 safeguard — principally the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), together with any required supplementary measures and, where available, reliance on an EU adequacy decision. A copy of the relevant safeguards is available on request at privacy@ciqra.com. ``
8. How long we keep data
We keep personal data only as long as needed for the purposes above or as required by law. Summary (full matrix in the Data Retention policy):
- Order / invoice / tax / accounting records — 7 years (Estonian Accounting Act).
- Merchant account data — for the account's life and 90 days after closure (then deleted/anonymised), subject to legal holds.
- Payment/chargeback records — 13 months+ (dispute windows).
- Support tickets & logs — 12–24 months.
- Marketing consent & preferences — until consent withdrawal / objection.
- Backups — 30–35 days rolling.
9. Your rights (GDPR)
Subject to conditions and exemptions, you have the right to: access; rectification; erasure ("right to be forgotten"); restriction; data portability; object (incl. to legitimate-interest processing and to direct marketing at any time); and rights relating to automated decision-making (we do not make solely-automated decisions producing legal/similarly significant effects about you without a lawful basis and safeguards). Where processing is based on consent, you may withdraw it at any time.
To exercise rights (where CIQRA is controller): email privacy@ciqra.com. We respond within one month (extendable by two months for complexity), free of charge unless manifestly unfounded/excessive. Where CIQRA is processor (Storefront Customer data), please contact the relevant Merchant (the controller); we will assist that Merchant as required by the DPA.
Complaints. You may lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, https://www.aki.ee) or your local supervisory authority. ``
10. Security
We implement appropriate technical and organisational measures, including tenant isolation with PostgreSQL row-level security and per-tenant scoping, encryption in transit (and at rest where applicable), access controls and least privilege, secrets management, logging/monitoring, backups, and a documented incident-response and breach-notification process (see doc 07). No system is perfectly secure; we cannot guarantee absolute security. Card data is handled on a PCI DSS SAQ A basis (raw PAN never touches CIQRA). ``
11. Children
The Services (as sold by CIQRA to Merchants) are not directed to children, and CIQRA does not knowingly collect children's data as controller. On Storefronts, the digital-consent age is applied per market (GDPR 16; Estonia 13; some jurisdictions 13–15); a Merchant offering services to children must have a lawful basis and, where required, parental consent. ``
12. California privacy rights (CCPA/CPRA)
This section applies to California residents and supplements the above. Under the CCPA (as amended by the CPRA):
- Our roles. For personal information CIQRA processes on a Merchant's behalf, CIQRA is a "service provider" under a written contract; for CIQRA's own account/billing data, CIQRA is a "business."
- Your rights: to know/access, delete, correct, opt out of the sale or "sharing" (cross-context behavioral advertising) of personal information, limit the use of sensitive personal information (SPI), and non-discrimination for exercising rights.
- "Do Not Sell or Share" & Global Privacy Control. We do not sell personal information for money. Where advertising cookies/pixels (e.g. GA4, Meta) constitute "sharing" for cross-context behavioral advertising, you may opt out via our "Do Not Sell or Share My Personal Information" control, and we honor the Global Privacy Control (GPC) browser signal as a valid opt-out. ``
- Sensitive PI. We do not use SPI for purposes requiring a "Limit" link beyond permitted business purposes; a "Limit the Use of My Sensitive Personal Information" control is provided where applicable.
- Notice at collection & retention. Categories of PI/SPI collected, purposes, whether sold/shared, and retention criteria are described in §§2, 3, 8.
- Automated decision-making (ADMT). Where CIQRA uses automated decision-making/AI within the CCPA ADMT rules (effective 2026), we provide the required pre-use notice and opt-out/appeal rights. ``
- How to exercise / authorized agents. Email privacy@ciqra.com; you may use an authorized agent. We verify requests and do not discriminate. We respond within CCPA timelines.
13. Other US state privacy rights
If you reside in a US state with a comprehensive privacy law (e.g. Virginia, Colorado, Connecticut, Utah, Texas, Oregon and others), you generally have rights to access, correct, delete, obtain a portable copy, and opt out of targeted advertising, sale, and certain profiling. We honor recognized universal opt-out signals (GPC) where required. To exercise these rights, contact privacy@ciqra.com; an appeal mechanism is available where the law requires one. ``
14. UK privacy rights (UK GDPR)
For UK data subjects, processing is governed by the UK GDPR + Data Protection Act 2018. Your rights mirror §9. The supervisory authority is the Information Commissioner's Office (ICO, https://ico.org.uk**)**. For restricted transfers out of the UK, we use the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU SCCs. If CIQRA offers services to UK data subjects without a UK establishment, it will appoint a UK Art. 27 representative. ``
15. Changes and contact
We may update this Policy; material changes will be notified (email or in-dashboard) before taking effect, and the "last updated" date will change. Questions or requests: privacy@ciqra.com or CIQRA OÜ at the postal address above.
End of Privacy Policy (draft). See also: Cookie Policy · DPA + subprocessors · Subprocessor List · Data Retention & Breach · AI Terms.