Этот документ составлен на английском и испанском языках. Преимущественную силу имеет английская версия.
Idovio Commerce is a service for running an online shop: it connects the stores, marketplaces, suppliers, payment providers and other accounts a merchant chooses, and works on the data those accounts hold. This policy says what Idovio Labs Ltd does with personal data when you use Idovio Commerce (the web app at idovio.app, the desktop and Android apps) and the website idovio.com.
Idovio Labs Ltd, a company registered in England and Wales under number 17474686, operates Idovio Commerce. Its registered office is the one published at Companies House under that number. For anything about personal data write to privacy@idovio.com.
For your account, your subscription and your use of the service, Idovio Labs Ltd decides why and how the data is processed (it is the controller). For the personal data of your own customers that reaches Idovio Commerce through the accounts you connect — the buyers of your shop — you are the controller and Idovio Labs Ltd processes it only on your instructions, under the Data Processing Addendum.
Account data: your name, e-mail address, password (stored only as a salted scrypt hash), the two-step verification secret if you turn it on, and the workspaces you belong to with your role in each.
Subscription and billing data: the plan, its status and dates, and the invoices. Card and bank details are entered on Stripe's own page and stay with Stripe; we receive only what is needed to know that a payment was made.
Security and connection data: the devices signed in to your account with the time of last use, a shortened network address (the first part of the IP address, not the full one), the browser or app version, and a log of security-relevant actions in your workspace (sign-ins, changes of role, connections made and removed).
Workspace data: what you choose to keep on Idovio servers so that it follows you to another device — catalogue, orders, suppliers, settings and the rules you set. You can instead choose to keep the workspace only on your device; then this data is not sent to us.
Credentials of the accounts you connect: access tokens and API keys. They are stored encrypted (AES-256-GCM, with a separate key per workspace) and are never shown again, not even to you.
Support messages: what you write to us and what we answer.
The record of your acceptance of these documents: your account, the date, the language and the version accepted.
Website: idovio.com keeps your language and theme in your browser's local storage. It uses no advertising or analytics cookies, and there is no tracking across sites.
When you connect a store, marketplace, supplier, payment provider, ad account or mailbox, Idovio Commerce reads from it what is needed for the functions you use: orders and their lines, the buyer's name, contact details and delivery address where the platform provides them, products, stock, prices, shipments, returns, advertising results, and the messages of a mailbox you connect for customer support. It writes to those accounts only what you ask for or approve: a published product, a changed price or stock, a shipment marked with its tracking number, a refund.
This data is used to provide the service to you and for nothing else. We do not sell it, we do not use it for advertising, we do not use it to build profiles of your customers, and we do not use it to train artificial intelligence models.
Google: Idovio Commerce's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Gmail access is read-only and is used only to show you the messages of the mailbox you connect inside the support inbox; no person at Idovio reads them unless you ask for help with a specific message, and they are not used for advertising.
Microsoft: access to an Outlook mailbox through Microsoft Graph is read-only and is used only for the same purpose.
Amazon: the Amazon integration does not request buyers' personal information. It works with order facts (what was ordered, quantities, amounts, fulfilment status) and refuses the restricted fields of the Selling Partner API.
Meta, Google Ads and TikTok Ads: campaign structure and results are read to show them to you; a campaign is paused or its budget changed only when you ask for it or approve it.
Shopify, eBay, Etsy, TikTok Shop and the other platforms: data is handled under each platform's developer terms. When a platform sends us a request to delete a shop's or a customer's data (for example Shopify's privacy requests or eBay's account deletion notices), we receive it automatically and act on it.
Artificial intelligence: the AI functions are optional. If you connect an AI provider with your own key, the text needed for the request you make is sent to that provider under your account with it. If you run a model on your own device, nothing is sent.
To provide the service you signed up for and keep your account working — performance of the contract.
To take payment and keep invoices — performance of the contract and legal obligation.
To keep the service secure: detecting abuse, limiting sign-in attempts, keeping the security log — our legitimate interest in a safe service, and yours.
To answer you when you write to us — our legitimate interest in replying, or the contract when it is about your subscription.
We send no marketing e-mail unless you ask for it. We take no decision about you by automated means that has legal or similarly significant effects.
The database of the service is in Frankfurt, Germany. Files are stored in the European Union. Some sub-processors are established in the United States; transfers to them rest on the European Commission's standard contractual clauses and the UK addendum, or on an adequacy decision where one applies.
Account and workspace data: while your account is open. When a subscription ends, the workspace becomes read-only and its data is kept for 90 days so that you can come back to it; after that it may be deleted. You can ask for deletion at any time and we complete it within 30 days.
Credentials of a connection: deleted when you disconnect it.
Sessions: a session ends after 30 days without use and at the latest 180 days after it was started.
Invoices: for the period tax law requires, which prevails over a deletion request.
Security log: for as long as the workspace exists.
The page “How to delete your data” explains each way of removing data, step by step.
You can ask to see your data, to have it corrected or deleted, to restrict or object to its processing, and to receive it in a format you can take elsewhere. Write to privacy@idovio.com from the address of your account; we answer within one month. You can also complain to the data protection authority of your country — in the United Kingdom, the Information Commissioner's Office.
If you are a customer of a shop that uses Idovio Commerce, that shop decides what happens to your data: contact it first. If you write to us, we pass your request to the shop.
The measures that protect the data are described on the Security page. If a breach affects your personal data we tell you without undue delay, and the authority where the law requires it.
Idovio Commerce is a tool for businesses and is not directed at children. We do not knowingly process data of anyone under 16.
We date every version. When a change matters — a new purpose, a new kind of data, a new sub-processor — we tell account owners by e-mail before it applies. This version is dated 2026-10-06.