Privacy Policy
Version 1.0 · Effective Date: 31 July 2026 · Ionian Logic OÜ, Estonia
This Privacy Policy explains how Ionian Logic OÜ ("e-emporion", "we", "us") collects, uses, and protects the personal data of Merchants using the e-emporion platform. It applies to all Merchants who register for and use the Platform. It does not cover the personal data of End Users (your customers) — that data is processed by e-emporion as a Data Processor on your behalf, governed by our Data Processing Agreement.
1. Who We Are
| Field | Detail |
|---|---|
| Company | Ionian Logic OÜ |
| Registered in | Republic of Estonia (Registration No: 17564698) |
| Registered address | Harju maakond, Tallinn, Kesklinna linnaosa, Narva mnt 5, 10117, Estonia |
| Contact email | privacy@e-emporion.eu |
| Website | https://e-emporion.eu |
| Data Controller | Ionian Logic OÜ is the Data Controller for Merchant account data. Each Merchant is a separate Data Controller for their End User data. |
| Supervisory Authority | Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) |
2. What Data We Collect About Merchants
We collect only data that is necessary to provide the Platform and manage our commercial relationship with you. We do not sell your data to third parties.
2.1 Account Data
When you create an account or manage your Merchant profile, we collect:
- Name (individual or organisation name)
- Email address (used for authentication and communications)
- Organisation name and details provided during onboarding
- Store configuration: store name, preferred language, logo, brand colours
- VAT/tax identification numbers (used for invoicing only)
2.2 Billing Data
We collect billing information to process Subscription Fees. Card details are processed and stored exclusively by Stripe (Ireland). We receive and retain:
- Billing email address
- Country of establishment (for VAT purposes)
- Payment status and subscription tier
- Invoice records for legal retention obligations
We never see, store, or process your payment card numbers.
2.3 Platform Usage Data
We collect technical data to operate, secure, and improve the Platform:
- Login timestamps and IP addresses (security logging)
- Dashboard feature usage (e.g., pages visited, products added) — aggregate analytics only
- Error and performance logs (do not include personal or product content)
- Browser type and operating system (for compatibility)
2.4 Support Communications
If you contact our support team, we retain the content of your communications and any data you provide to resolve your query.
2.5 Data You Do Not Need to Provide
We do not require sensitive personal data (health data, biometric data, etc.) for any purpose. Do not include such data in support tickets or product descriptions.
3. How We Use Your Data
| Purpose | Lawful Basis (GDPR Art. 6) | Retention |
|---|---|---|
| Providing Platform services and your Storefront | Art. 6(1)(b) — Contract performance | Duration of subscription + 30 days |
| Processing Subscription Fees and issuing invoices | Art. 6(1)(b) — Contract performance | 7 years (Estonian accounting law) |
| Sending service and billing notifications | Art. 6(1)(b) — Contract performance | Duration of subscription |
| Security logging and fraud prevention | Art. 6(1)(f) — Legitimate interest | 90 days rolling |
| Platform improvement and analytics | Art. 6(1)(f) — Legitimate interest (aggregated, not personal) | 12 months rolling |
| Responding to support requests | Art. 6(1)(b) — Contract performance | 3 years from last contact |
| Compliance with legal obligations (tax records) | Art. 6(1)(c) — Legal obligation | 7 years (Estonian law) |
| Marketing communications (optional) | Art. 6(1)(a) — Consent (you can unsubscribe at any time) | Until consent withdrawn |
4. Who We Share Your Data With
We share your data only as necessary to provide the Platform, and only with parties who are contractually bound to protect it. We do not sell your personal data.
4.1 Sub-processors
The following service providers process Merchant account data on our behalf under Data Processing Agreements:
- Clerk Inc. (USA) — authentication and identity management — SCCs (EU 2021/914)
- Supabase Ireland Ltd. (Ireland, EU) — database hosting — EU-based, no transfer
- Stripe Payments Europe Ltd. (Ireland, EU) — payment processing — EU-based, no transfer
- Vercel Inc. (USA) — application hosting — SCCs (EU 2021/914)
- Cloudflare Inc. (USA) — DNS and DDoS protection — SCCs (EU 2021/914)
4.2 Legal Requirements
We may disclose your data where required by applicable law, court order, or regulatory authority. Where permitted by law, we will notify you before complying.
4.3 Business Transfers
In the event of a merger, acquisition, or sale of substantially all of our assets, Merchant data may be transferred to the acquirer. We will notify you at least 30 days in advance and ensure the acquirer assumes obligations equivalent to those in our DPA.
5. International Data Transfers
Our primary data storage is in Ireland (EU), within the European Economic Area. When we transfer personal data to service providers in the United States (Clerk, Vercel, Cloudflare, Anthropic), we rely on Standard Contractual Clauses (EU Commission Decision 2021/914 — Module 2, Controller to Processor) as the transfer mechanism. Copies of applicable SCCs are available on request at privacy@e-emporion.eu.
The competent Supervisory Authority for international transfer matters is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon).
6. Your Rights as a Data Subject
Under GDPR, you have the following rights regarding your personal data. To exercise any right, contact us at privacy@e-emporion.eu. We will respond within 30 days (GDPR Art. 12(3)).
| Right | What it means |
|---|---|
| Access (Art. 15) | Request a copy of all personal data we hold about you and information about how we use it. |
| Rectification (Art. 16) | Request correction of inaccurate or incomplete data. You can update most account data directly in the Dashboard. |
| Erasure (Art. 17) | Request deletion of your personal data where there is no legal obligation to retain it. |
| Portability (Art. 20) | Receive your data in a structured, machine-readable format (JSON or CSV) for transfer to another provider. |
| Restriction (Art. 18) | Ask us to pause processing your data while a dispute is resolved. |
| Object (Art. 21) | Object to processing based on legitimate interests. We will stop unless we have compelling legitimate grounds. |
| Withdraw consent | Where processing is based on consent (e.g., marketing emails), you may withdraw consent at any time via the unsubscribe link or by contacting us. |
| Lodge a complaint | You have the right to lodge a complaint with the Estonian Data Protection Inspectorate (www.aki.ee) or the supervisory authority in your country of residence. |
7. Cookies and Tracking
The Merchant Dashboard uses the following cookies:
- Session cookies: strictly necessary to maintain your authenticated session. These cannot be disabled. They expire when you close your browser or after 24 hours of inactivity.
- Preference cookies: store your UI preferences (language, dark/light mode). These expire after 12 months.
We do not use advertising cookies, third-party tracking pixels, or behavioural profiling cookies on the Merchant Dashboard. If we introduce optional analytics cookies in future, we will seek your consent first.
Merchant Storefronts served to end customers use only strictly necessary session cookies (authentication state, age verification status). Merchants who independently add analytics to their storefront are responsible for their own cookie compliance.
8. Data Security
We take the security of your data seriously and implement the following measures:
- AES-256 encryption at rest for all database content (Supabase, Ireland)
- TLS 1.2+ encryption in transit for all Platform connections
- Row-Level Security at database level enforcing strict account isolation
- Multi-factor authentication for all administrative access
- Regular security assessments and access reviews
- Documented incident response procedure; breach notification within 72 hours
Despite these measures, no system is entirely secure. If you discover a security vulnerability, please report it responsibly to privacy@e-emporion.eu.
9. Data Retention
We retain personal data only as long as necessary for the purposes set out in this Policy or as required by law:
- Account data: retained for the duration of your Subscription and deleted 30 days after termination (allowing you to export first)
- Billing and invoice records: retained for 7 years as required by Estonian accounting law
- Security logs: retained for 90 days on a rolling basis
- Support communications: retained for 3 years from last contact
- Marketing consent records: retained until consent is withdrawn, plus 3 years for audit purposes
Where we are legally required to retain data beyond these periods, we will maintain minimum necessary data and restrict access.
10. Children
The Platform is intended for business users aged 18 and over. We do not knowingly collect personal data from individuals under 18. If you believe we have inadvertently collected such data, please contact us at privacy@e-emporion.eu and we will delete it promptly.
11. AI Translation Service
When you use the AI-powered product translation feature, the text you submit (product names and descriptions) is sent to Anthropic PBC (USA) for processing. We instruct Anthropic not to use submitted content for training its models. Product content sent for translation should not include personal data. This transfer is governed by Standard Contractual Clauses. See Annex A of our Terms of Service for details.
12. Changes to this Policy
We may update this Privacy Policy from time to time. For material changes, we will notify you by email at least 30 days in advance. The "Effective Date" at the top of this Policy indicates when the current version applies. We encourage you to review this Policy periodically. Continued use of the Platform after the effective date constitutes acceptance of the updated Policy.
13. Contact Us
For any questions, requests, or concerns regarding this Privacy Policy or your personal data, contact our Privacy Team:
| Privacy email | privacy@e-emporion.eu |
| Subject line | Please include "Privacy Request — [your name/account]" |
| Response time | Within 30 days of receipt (GDPR Art. 12(3)) |
| Supervisory Authority | Estonian Data Protection Inspectorate — www.aki.ee — info@aki.ee |
Version 1.0 · e-emporion.eu · Ionian Logic OÜ, Estonia · Effective 31 July 2026
