HomePrivacy policy

Privacy policy

Last updated: August 23, 2026

Scope of this policy

This policy describes the processing of personal data relating, on the one hand, to the website www.hidemydrop.com and, on the other hand, to the HideMyDrop application offered to merchants using Shopify or WooCommerce. The service is reserved for professionals.

Who is responsible for processing

For the website and for merchants’ account data, GRT Ventures OÜ (Tartu mnt 67/1-13b, Kesklinna linnaosa, 10115 Tallinn, Estonia) acts as data controller.

For the tracking data of merchants’ end customers, each merchant is the data controller. GRT Ventures OÜ then acts as a processor within the meaning of Article 28 of the GDPR and processes this data solely on the merchant’s behalf and instructions. We do not use this data for our own purposes.

The website

The website sets no advertising tracking cookies and contains no data collection form.

Our hosting providers generate technical logs (including IP addresses and request timestamps), which are necessary for the security and proper operation of the site. These logs are kept for a limited period.

The application

Merchants’ account data

We process the data needed to manage your account: e-mail address, service settings, security parameters (two-factor authentication, passkey), and login history with an approximate location derived from the IP address.

Data of merchants’ end customers

On behalf of merchants, we process the tracking data of their orders: order number, tracking reference, delivery events, destination country, and the end customer’s e-mail address when the merchant enables notifications.

The application only uses cookies that are strictly necessary for authentication and security.

Purposes and legal bases

  • Provision of the service and account management: performance of the contract.
  • Billing and accounting: compliance with our legal obligations.
  • Security, abuse prevention and technical logging: legitimate interest.
  • Processing of end customers’ tracking data: the merchant’s instructions, under the contract between us.

Recipients and hosting

Data is accessible to our hosting providers: o2switch SAS (France) for the website and Hetzner Online GmbH (Germany) for the application. Application data is therefore hosted in the European Union.

Subscription billing is handled by Stripe or Shopify Billing, which process payment data under their own policies. We have no access to your card numbers. We do not sell your data.

Retention periods

  • Account data: for the duration of your use of the service, then deleted at the end of the 30-day grace period following an account deletion request.
  • End customers’ tracking data: processed according to the merchant’s instructions and deleted at the latest when the merchant’s account is deleted.
  • Billing data: kept for as long as applicable accounting and tax obligations require.
  • Technical logs: limited period, as needed for security.

Your rights

You have the rights of access, rectification, erasure, restriction, objection and portability under the conditions set out in the GDPR. To exercise them, write to contact@hidemydrop.com.

If you are the end customer of a merchant using HideMyDrop, please first address your request to that merchant, who is the controller of your data. If you contact us directly, we will forward your request to the merchant concerned and help them respond.

Complaints

You may lodge a complaint with the Estonian data protection authority, the Andmekaitse Inspektsioon. Persons located in France may also contact the CNIL.

Contact

For any question about this policy: contact@hidemydrop.com.