Privacy Policy
Last updated: February 2026 · Ecom Store Growth
1. Introduction
Ecom Store Growth ("we", "us", "our") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, and protect your personal information when you use the StoreScan platform and visit our website at ecomstoregrowth.com.
This policy is in compliance with the General Data Protection Regulation (GDPR) (EU) 2016/679 and applicable Dutch privacy legislation.
Controller: Ecom Store Growth
Address: Kamille 8, 7425R Deventer, Netherlands
KvK: 80886515
Email: mark@ecomstoregrowth.com
2. What data we collect
We collect the following categories of personal data:
Account & contact data
- Name and email address (provided at registration)
- Company name and website URL
- Billing address and payment information (processed by our payment provider)
Usage & technical data
- IP address, browser type, and device information
- Pages visited and features used within the platform
- Log data and error reports
Store data
- Data from the e-commerce store you connect to StoreScan (product pages, checkout flows, performance data)
- This data is used solely to generate your audit reports
Communication data
- Emails and messages you send to us via the contact form or email
3. How we use your data
We process your personal data for the following purposes and legal bases:
| Purpose | Legal basis |
|---|---|
| Providing and operating the StoreScan service | Performance of a contract (Art. 6(1)(b) GDPR) |
| Processing payments and managing your subscription | Performance of a contract (Art. 6(1)(b) GDPR) |
| Sending transactional emails (invoices, service updates) | Performance of a contract (Art. 6(1)(b) GDPR) |
| Responding to your support requests | Legitimate interest (Art. 6(1)(f) GDPR) |
| Improving the platform and fixing bugs | Legitimate interest (Art. 6(1)(f) GDPR) |
| Sending marketing emails (waitlist, launch news) | Consent (Art. 6(1)(a) GDPR) |
| Complying with legal obligations | Legal obligation (Art. 6(1)(c) GDPR) |
4. Data retention
We retain your personal data for as long as necessary to fulfill the purposes described above:
- Account data: retained for the duration of your account plus 2 years after deletion.
- Financial records: retained for 7 years as required by Dutch tax law.
- Marketing consent: until you withdraw consent.
- Log data: maximum 12 months.
5. Sharing your data
We do not sell your personal data. We may share data with trusted third parties only where necessary:
- Payment processors (e.g., Pay.nl) — for processing payments securely.
- Hosting and infrastructure providers — for storing and serving the platform.
- Analytics tools — for understanding how the platform is used (anonymized or pseudonymized where possible).
- Legal authorities — when required by applicable law.
All third-party processors are bound by data processing agreements in line with GDPR requirements.
6. International transfers
Your data is primarily processed within the European Economic Area (EEA). If data is transferred outside the EEA, we ensure adequate protection is in place through standard contractual clauses (SCCs) or other appropriate mechanisms as required by GDPR.
7. Cookies
We use the following cookies on our website:
- Essential cookies: required for the platform to function (session management, authentication). These do not require consent.
- Analytics cookies: used to understand visitor behavior. Only placed with your consent.
You can manage your cookie preferences at any time via your browser settings.
8. Your rights
Under the GDPR, you have the following rights regarding your personal data:
- Right of access — you may request a copy of the personal data we hold about you.
- Right to rectification — you may ask us to correct inaccurate or incomplete data.
- Right to erasure — you may request deletion of your personal data ("right to be forgotten"), subject to legal retention obligations.
- Right to restriction — you may ask us to restrict processing in certain circumstances.
- Right to data portability — you may request your data in a structured, machine-readable format.
- Right to object — you may object to processing based on legitimate interest or for direct marketing purposes.
- Right to withdraw consent — where processing is based on consent, you may withdraw it at any time without affecting prior lawful processing.
To exercise any of these rights, please contact us at mark@ecomstoregrowth.com. We will respond within 30 days.
9. Complaints
If you believe we have not handled your personal data correctly, you have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens):
Autoriteit Persoonsgegevens
PO Box 93374, 2509 AJ The Hague, Netherlands
Website: autoriteitpersoonsgegevens.nl
10. Security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These include encryption in transit (TLS), access controls, and regular security reviews.
11. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email or through a notice on our website. The date at the top of this page reflects the most recent update.
12. Contact
For any privacy-related questions, please contact us:
Ecom Store Growth
Kamille 8, 7425R Deventer, Netherlands
KvK: 80886515