Privacy and your data
StoreCalm is operated by KP Design, CVR 41134194, VAT DK41134194, Bavnehøjen 5, 4690 Haslev, Denmark. Contact: contact@storecalm.com.
What we process
Account email, workspace membership, verified store addresses, monitoring results and connector events are used to provide and secure the service. Connector events contain software versions and pseudonymous order status signals. Customer names, addresses and payment card information must not be sent.
Cookies and hosting
Essential authentication and security cookies support sign-in. This site uses no advertising trackers. The application runs on KP Design's Contabo server in the EU. Google provides optional analytics and form security. The providers and purposes are listed below.
Optional analytics
If you choose “Allow analytics”, Google Analytics measures visits to public marketing pages. No analytics script or measurement request is sent before you agree. Account pages, authenticated sessions and dashboards are excluded. We remove query strings and fragments from measured page addresses and do not send store URLs, email addresses or account identifiers. Advertising signals and enhanced measurement are disabled. Google processes network and device information and may process data outside the EU under its applicable data protection terms.
You can change your choice using “Privacy choices” on public pages. Refusing optional analytics does not affect your use of StoreCalm. Your choice is stored on this browser for 180 days. Analytics cookies expire after 180 days. Withdrawing consent removes these cookies and reloads the page to stop the analytics runtime.
Form security
Public scans, registration and email recovery forms use Google reCAPTCHA to prevent automated abuse. The widget loads when you select “Load security check”. Google receives network, device and interaction information for this check. Its Privacy Policy and Terms of Service apply. This check is separate from optional analytics. Contact us if you cannot use the check.
Retention and requests
Automated retention keeps detailed checks and connector events for seven days on Free and 30 days on paid plans. Diagnostic screenshots expire after three days on Free and 14 days on paid plans. Usage accounting and security audit entries are retained for 13 months. Account deletion, export and privacy requests can be sent to the contact above. Full encrypted application backups expire after 14 days on the server and 30 days on KP Design's separate Synology storage. Frequent database snapshots expire after two days. Shared mail-system backups follow the existing 100-day backup cycle; this does not extend monitoring-data retention. Identity exports are available in account settings. Workspace deletion requests are handled by support, with billing and monitoring stopped before deletion. After closing your workspaces, you can delete your personal account in account settings. Deletion records prevent erased data being reintroduced from an older backup.
Purposes, legal bases and your rights
KP Design acts as controller for account administration, billing, support and website security. We process information to perform the service contract, meet legal obligations and pursue legitimate interests in preventing abuse and maintaining a secure service. Optional analytics uses your consent, which can be withdrawn through Privacy choices. Store-related personal data processed on your business's behalf is covered by the data processing agreement.
You may request access, correction, erasure, restriction or portability where applicable, and object to processing based on legitimate interests. Contact us using the account email where possible so we can verify ownership. We normally respond within one month. You may complain to the Danish Data Protection Agency, Datatilsynet. Statutory invoice and accounting records are retained for the applicable legal period, generally five years from the end of the financial year. We do not make decisions with legal or similarly significant effects solely through automated monitoring.
Providers and transfers
| Provider | Purpose and data |
|---|---|
| Contabo | EU application hosting, databases, diagnostic storage and mail infrastructure. |
| Stripe | Hosted payment processing, billing identity, invoices, subscriptions and tax calculation. Card details are entered directly with Stripe and are not stored by StoreCalm. |
| Google Analytics | Optional public-page usage analytics after consent. No account or dashboard tracking. |
| Google reCAPTCHA | Form abuse protection, loaded on request. Network and interaction information may be processed by Google. |
| KP Design Synology storage | Primary encrypted offsite recovery archives on owner-controlled storage, transferred with verified TLS. Decryption keys are stored separately. |
Stripe and Google may process data outside the EEA. Applicable provider agreements and lawful transfer mechanisms apply, including adequacy decisions or standard contractual clauses where required. See Stripe privacy information, Google privacy information and the data processing agreement.
Support information
Send only the details necessary to explain a support issue. Do not email passwords, license keys, card data or your customers' personal information. StoreCalm does not sell personal data.