Skip to main content

Privacy policy

What we collect, why, who else sees it, and what you can do about it. Each clause opens with a plain sentence; the full wording follows it. Short version: we take what it takes to run your scans, and no more.

Last updated 25 September 2026. We post the date on every change, and we will not change it quietly.

1. Who is responsible

MB Stickest decides what happens to your data. Write to us about anything on this page.

Data controller: MB Stickest, company code 306055280, Stadiono g. 7-385, 85374 Akmenė, Lithuania. For any privacy enquiry or general question, use our contact form or email support@storeverifier.com. We have not appointed a data protection officer; the same address reaches the people responsible.

StoreVerifier is not meant for anyone under 16.

2. What we collect

The stores you scan, your account details if you have one, what you write to us, and ordinary server logs. We never see your card number.

Scan data: URLs you submit for scanning, scan results, and timestamps. To produce the results we read the store's public pages, which can include personal details the store itself publishes, such as its owner's name, address or phone number.

Account data: your email address, and your name if you give it. An account is also made for the email address you pay with, or the one you give us to keep a report, if none exists yet.

Payment data: Stripe collects your card details on its own payment page. We receive the payment's status, amount and currency and the email address you paid with — never your card number.

Messages: what you send through the contact form or to our email address.

Server logs: Standard server logs including IP address, browser type, and pages visited, and, for each email we send, the address it went to. We use this to maintain service reliability.

Visit records, only if you allow Analytics: the page, the page you came from, your browser, and a salted one-way hash of your IP address — not the address itself.

3. Why we use it, and on what basis

To run what you asked for, to keep the service safe, and — only if you say yes — to count visits. We do not sell it, and we do not advertise with it.

To run your scans and deliver what you buy, including your account and the emails it needs (reports, sign-in and password links, monitoring alerts): to perform our contract with you (GDPR Article 6(1)(b)).

To take payments and keep the records the law requires: our contract with you, and our legal obligations (Article 6(1)(c)).

To keep the service secure and working, using server logs: our legitimate interest in running a safe service (Article 6(1)(f)).

To answer your messages: our legitimate interest in replying to you, or our contract with you when the message is about something you bought.

To count visits, only if you allow Analytics: your consent (Article 6(1)(a)), which you can withdraw at any time from the cookie banner's Manage control.

We make no decision about you by automated means that has legal or similarly significant effects: a scan assesses a website, not a person. We do not use your data for advertising, and we do not sell it.

4. Who receives it

Only the companies that run parts of the service for us, each for its own part. Nobody buys it.

Our hosting provider, which runs our servers in the European Union.

Stripe, which processes payments (Stripe for billing). Stripe's own privacy notice covers what it does as a payment provider.

Brevo, in France, which sends our emails.

Google, which provides the AI models that read the text of a scanned store's pages (Gemini), checks the address of a scanned store against its Safe Browsing list of unsafe sites, and hosts the mailbox where messages from our contact form arrive. The scan opens a store's pages in a browser, but no screenshot of them is sent to any AI provider. The AI receives the store's public content, never your account details or your messages.

Nobody else receives it, unless the law requires us to disclose it.

5. Transfers outside the European Union

Some of it is handled in the United States, under the framework the European Commission accepts. Nowhere else.

Stripe and Google may process data in the United States. Both take part in the EU-US Data Privacy Framework, which the European Commission has found gives personal data an adequate level of protection.

Nothing is sent to a country the European Commission has made no adequacy decision for. Until 20 September 2026 the AI that reads scanned pages ran in China; it is Google's now, and the data it receives is covered by that framework.

6. How long we keep it

Detailed findings are wiped after 90 days. Server logs go after 14 days, visit records after 13 months. Your account stays until you delete it.

Detailed scan findings are retained for 90 days from the scan date, after which they are automatically cleared. A summary record (score, URL, and scan date) is kept afterward as part of your account history. Account data is retained for as long as your account is active.

Server logs are kept for 14 days. Visit records are deleted after 13 months. Sign-in links work once and expire after 7 days, password links after an hour; both are deleted 30 days after they expire. Messages are kept for as long as we need them to deal with what you asked.

If you delete your account, your profile, scan history, and reports are removed immediately; payment records held by our payment processor (Stripe) are retained by them as required for financial record-keeping. Deleted data can remain in our nightly database backups for up to 15 days, until those backups are deleted in turn.

7. Your rights under GDPR

You can download everything we hold on you, or delete the lot, from your own dashboard. Neither needs to go through us.

If you are based in the UK or EU, you have the right to: access the personal data we hold about you, request correction or deletion, object to or restrict processing, and request data portability. You can object at any time to processing based on our legitimate interests, and withdraw any consent you gave, without affecting what was done before.

You can download a full copy of your data or permanently delete your account at any time from the Account & data section of your dashboard — both are immediate and self-serve. For anything else (corrections, objections, restriction requests), use our contact form or email support@storeverifier.com, and we will respond within 30 days.

You also have the right to lodge a complaint with a data protection supervisory authority. Ours is the State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija, VDAI).

8. Security

Everything travels encrypted, passwords are never stored as written, and card details never reach us.

Every page and every payment goes over an encrypted HTTPS connection. Passwords are stored only as salted bcrypt hashes. Sign-in and password links are stored only as hashes and work once. Card details are handled by Stripe and never reach our servers.

9. Google Merchant Center data

We do not connect to your Merchant Center account, so we hold none of your feed data.

StoreVerifier does not currently connect to your Google Merchant Center account, so no Merchant Center product-feed or account data is collected. Feed-comparison checks are still in development; if they become available, this section will be updated to describe exactly what is collected, how it is used, and how long it is kept.

10. Cookies

Four essential entries keep you signed in, open a report you have just bought, and remember your consent choice; two functional ones remember settings and progress. None of them is an analytics or advertising cookie.

We use browser storage, not tracking cookies: your signed-in session, your consent choice, and a few preferences. If you allow Analytics, a record of the visit is sent to our own server and no analytics cookie is set. Our fonts and scripts are served from our own server, so viewing a page sends nothing to another company. Our Cookie Policy lists every one by name, what it is for, and how long it lasts.

11. Changes to this policy

When this policy changes, the date at the top changes. If a change needs your consent, we ask for it.

We may update this policy. The date at the top of this page shows when it last changed. If a change would need your consent, we ask for it before it applies to you.