COLMINK

Privacy policy

This document describes how COLMINK works in relation to your data and your use of the service.

Who this is for

This explains what COLMINK does with personal data: yours, if you run a store here, and your customers', when they start an order on a store. It is written to be read, not to be survived.

What we collect about you

Your email address and password (stored hashed, never readable), the country and language you chose, your store's details, your catalogue, the plan you are on and the payments you made. If you buy a paid plan: the billing details you give us (legal or business name, address and, optionally, a tax ID) — they appear on your payment receipts. If you join the waitlist or the newsletter: your email and the record of your consent. If you write to support, what you wrote. If you rate the platform, your rating. If you arrived through one of our partners’ links, we record which partner referred you, so that we can credit them. We also record, in aggregate, which application features you use as a merchant — for example: creating a product, adding a photo, downloading the QR, saving your store settings, checking orders, completing (or skipping) an onboarding step, and opening a feature your plan does not include. We keep the name of the action and the device class (mobile/tablet/desktop), never the content of what you write or upload, never your IP address, never screen recordings. It is used only to understand how the application is used and to improve it, and is kept for at most 13 months.

What we collect about your customers

Only what an order needs: what they chose, an optional note, whether they want pickup or delivery, the address when they chose delivery, the name and WhatsApp number when they gave them. We do not build profiles of them, do not track them across other sites, and do not sell anything about them.

How your store's numbers are counted

We count events like page views, product views and orders started so you can see how your store is doing. These counts are about the store, not about individuals: no advertising identifiers, no cross-site tracking, and location is used only at country level.

Why we are allowed to do this

To provide the service you asked for and to perform our agreement with you; to meet legal duties such as issuing and keeping invoices; and, for a small number of things like keeping the platform secure and understanding whether a feature works, because we have a legitimate interest that does not override your rights. Where we rely on your consent — non-essential cookies, for example — you can withdraw it at any time. Recording which partner referred you rests on our legitimate interest in knowing where accounts come from and paying whoever brings us customers; it is never used to profile you and never shared with third parties.

Cookies

One essential cookie keeps you signed in. Non-essential categories are switched off until you accept them, and you can change your choice at any time from the banner or your account. See the Cookie policy for the detail.

Who else sees the data

The companies that run our infrastructure — hosting, database, file storage, email delivery, error monitoring — and the payment providers that take your subscription payment. They act on our instructions and only for these purposes. We do not sell personal data to anyone.

Where the data is

We use service providers in the European Union and in other countries, including the United States (for example for hosting, file storage, email delivery, error monitoring and payments). Where personal data is processed outside the EU/EEA, the transfer is protected by the safeguards the law requires — such as the European Commission's Standard Contractual Clauses or the provider's certification under the EU-U.S. Data Privacy Framework — and we prefer EU-based storage where the provider offers it. We apply this same standard of protection to every user, wherever in the world they are. The current list of providers — who they are, what they do for us and where they process — is always published at colmink.com/legal/subprocessors.

How long we keep it

Your account data stays while your account exists. Orders and store content stay while your store exists. Records we must keep for accounting — the amounts, dates and invoice numbers — are kept for the period the law requires, separately and reduced to the minimum, and destroyed when that period ends.

Inactive accounts

If a free account stays unused for a long period, we warn you several times by email, then the store is taken offline and a window opens for you to come back or take your data. Only after that window are eligible data erased. Signing in stops the process. Accounts with an active subscription are never deleted for inactivity.

Your rights

You can see and correct your data in your account, download a copy of it as a file, and delete your account. You may also object to or ask us to restrict certain processing, and you may complain to your national data protection authority. Write to [email protected] and we will answer.

Children

COLMINK is a tool for businesses and is not directed at children. Opening a merchant account requires the legal capacity to enter contracts — you must be at least 18. We do not ask for a date of birth; if we learn that an account belongs to a child, we delete it. Visitors who browse a store or start an order do not create a COLMINK account, and the little they type (such as a name for the order) is handled for the store they are buying from.

Changes

If we change this policy in a way that matters, we will say so with reasonable notice rather than quietly replacing the text.

Who we are

The service is operated by COLMINK, under the law of applicable law. For anything about your data, write to [email protected].

Operator & contact

Operator:
COLMINK
Governing law:
applicable law
Contact:
[email protected]