Privacy Policy
Last updated: May 25, 2026
1. Data Controller
The controller of personal data collected through the emerce website (emerce.store) is:
REGON: 52772017200000
Ul. Korzenna 3B/16, 81-587 Gdynia, Poland
Email: [email protected]
2. Data We Collect
emerce is a pre-launch website. We do not offer user accounts. We collect personal data only in the following situations:
- AI Readiness Report request: the email address you submit so we can deliver the report, and an optional consent flag if you choose to receive product updates.
- Audit metadata: the store URL you submit for analysis, the resulting score and findings, the timestamp of the request, and your IP address and browser user-agent (collected automatically for abuse prevention and analytics).
- Technical data: standard server logs and, if you accept analytical cookies, anonymous traffic data via Google Analytics, Meta Pixel (Facebook) and LinkedIn Insight Tag.
We do not collect names, addresses, payment data, or account credentials, because emerce currently does not offer registration.
3. Purposes of Processing
Personal data is processed for the following purposes:
- Delivering the AI Readiness Report you requested (Art. 6(1)(b) GDPR — performance of a service requested by you).
- Sending occasional product updates and emerce insights, only if you ticked the optional consent (Art. 6(1)(a) GDPR — consent).
- Fulfilling legal obligations of the Controller (Art. 6(1)(c) GDPR).
- Analyzing and improving the Service, preventing abuse of the audit endpoint (Art. 6(1)(f) GDPR — legitimate interest).
4. Cookies
The Service uses cookies and similar storage for the following purposes:
- Essential: ensuring proper operation of the Service (CSRF token, the cookie consent decision itself).
- Analytical: collecting anonymous data about how the Service is used (Google Analytics, Meta Pixel, LinkedIn Insight Tag) — only with your consent.
You can manage your cookie preferences using the cookie banner displayed on your first visit, or at any time via the "Cookie settings" link in the page footer. You can also clear or block cookies in your browser settings.
5. Data Retention
- Email address submitted for an AI Readiness Report — until you request deletion or, if you also gave marketing consent, until you withdraw it.
- Audit results (score, findings, submitted URL) — up to 24 months, then deleted or fully anonymized.
- Server logs and IP / user-agent data — up to 12 months for abuse prevention and security purposes.
- Analytics data (Google Analytics) — up to 14 months for user-level data (Google Analytics defaults).
- Analytics data (Meta Pixel) — according to Meta's data retention policy (typically up to 180 days for event data used in ad targeting).
- Analytics data (LinkedIn Insight Tag) — according to LinkedIn's data retention policy (typically up to 90 days for conversion data; aggregated and anonymized data may be retained longer).
6. Your Rights
You have the right to:
- Access your personal data.
- Rectify your data.
- Erase your data ("right to be forgotten").
- Restrict processing.
- Data portability.
- Object to processing carried out on the basis of legitimate interest.
- Withdraw consent at any time (without affecting the lawfulness of processing carried out before withdrawal).
- Lodge a complaint with a supervisory authority. For users in Poland: the President of the Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warsaw, Poland.
To exercise any of these rights, contact us at [email protected].
7. Data Sharing
Personal data may be shared with third-party service providers acting on behalf of the Controller (hosting, transactional email delivery, analytics), only to the extent necessary to fulfill the purposes described in this Policy. We do not sell personal data to third parties.
8. International Data Transfers
When using service providers located outside the European Economic Area (e.g., cloud or analytics services), data transfers are based on Standard Contractual Clauses approved by the European Commission, or on an adequacy decision.
9. Data Security
We implement appropriate technical and organizational measures to protect personal data, including encryption in transit (SSL/TLS), encryption at rest, and access controls.
10. Changes to This Policy
We reserve the right to update this Privacy Policy. Material changes will be communicated through a notice on the Service. The current version is always available at emerce.store/privacy, with the "Last updated" date shown at the top of this page.