Quomerce
How it works Pricing For agencies Blog Sample report
EN PL
Buy an audit →
Legal

Privacy Policy

Effective: 12.08.2026

In this document

1. Who is responsible2. What we collect, and why3. Where your report can be read4. Agency matching, and what agencies receive5. Who else processes your data6. How long we keep things7. Your rights8. Automated decision-making9. Children10. Changes

This explains what we do with personal data when you buy an audit and when we audit your shop. It is written to be read, not to be survived.

1. Who is responsible

The controller is QUOMERCE SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ, ul. Henryka Sienkiewicza 85/87 lok. 1, NIP 7252368482, 0001251814.

Data-protection questions and requests: privacy@quomerce.com. We reply within one month.

We have not appointed a Data Protection Officer, because we are not required to. Requests go to the address above and are handled by us directly.

2. What we collect, and why

When you order an audit

DataWhyLawful basis
Shop address (URL)It is the thing being auditedContract, Art. 6(1)(b)
Company name, contact first and last nameTo issue the invoice and address youContract
Work e-mailTo send the audit-started and audit-ready e-mails and the report linkContract
Phone number (optional)Contact about your audit; passed to an agency only if you asked for matchingContract / consent
Invoice address, country, tax identifierLegally required invoice content; determines the VAT rateLegal obligation, Art. 6(1)(c)
VAT number and VIES consultation numberEvidence for the rate we charged, if we are ever asked to prove itLegal obligation
Payment status, amount, currency, transaction idAccounting; matching your payment to your auditLegal obligation

We ask for what the invoice needs and what it takes to reach you. There is no marketing profile.

When we audit your shop

The audit produces a report about a website, not about a person. But a website contains whatever its owner put there, so a report can incidentally contain personal data — a name in the footer, an address on a contact page, a staff photo. Two parts deserve naming outright:

  • Screenshots of the pages the agent visited, stored with the report.
  • A session replay of the agent’s own browsing — a reconstruction of what our automated browser saw and did, so you can watch how a finding was reached. It records our agent’s session on your public storefront. It does not record your customers or your staff.

For a check that includes the transactional requirements, the agent places a test order using a disposable mailbox we control. Your shop’s confirmation e-mail is retrieved and stored with the report, including its HTML, because it is the evidence for the finding. If that e-mail contains personal data your shop put in it, that data ends up in the report — the name on the order is our test identity, not a real customer’s.

Basis: performance of our contract with you. Where a report incidentally contains a third party’s personal data, our basis is legitimate interest, Art. 6(1)(f) — delivering an audit that its subject asked for.

3. Where your report can be read

Your report is unlisted, not private. /audits/<id> needs no login. The id is a random UUID so it cannot be guessed or enumerated, and we do not index reports or link to them publicly — but anyone you send the link to can open it, pass it on, and open it again a year later.

Treat the link like a document, not a password. Tell us if you want one revoked.

4. Agency matching, and what agencies receive

If you consented to agency matching when you ordered, your completed audit can be listed on our marketplace. An agency that buys access receives:

  • generated audit report,
  • your shop address,
  • your company name,
  • your contact first name, work e-mail and phone number.

That last line is why this is opt-in and not a default. Our basis is your consent, Art. 6(1)(a), given by ticking a box at checkout that starts empty. Leaving it empty is not a refusal you have to justify — it is simply the answer we assume.

You can withdraw at any time, by e-mailing privacy@quomerce.com. We de-list the lead as soon as possible. Withdrawal does not guarantee agencies already holding your details will stop contacting you, because we cannot control their records — but we will pass your withdrawal on.

Agencies are independent controllers for what they do with your details afterwards. They are contractually barred from using them for anything other than contacting you about the audit report.

If you did not consent, none of this happens. Your audit is not listed, and no agency sees anything about you. Your report is exactly the same either way.

5. Who else processes your data

Processors acting on our instructions:

WhoWhat they handleWhere
Cloudflare (R2)Temporary report storageEU
OpenAIPage content and screenshots sent to the model that performs the auditUS, SCCs
DeepLReport text, for translationEU
ResendSending the two e-mailsEU/US, SCCs
PostHogProduct analyticsEU
Google AnalyticsWebsite analyticsGlobal
LangSmithTraces of agent runs, for debuggingUS, SCCs
HetznerData processing, customers and reports dataEU

Independent controllers, not processors:

  • tPay (Krajowy Integrator Płatności S.A.) — your payment. They decide how they handle it; their privacy policy governs. We receive a transaction id and a status, never your card number.
  • The European Commission (VIES) — we send an EU VAT number to confirm it is registered.
  • Agencies we share contact information with, as described above.

Transfers outside the EEA rely on Standard Contractual Clauses. We do not sell personal data to anyone other than as described in section 4, which needs your consent.

Content sent to the AI model may be used to train it by OpenAI. Data exchanged with OpenAI contains no personal information.

6. How long we keep things

WhatHow long
Audit reports and findings12 months from delivery
Screenshots and session replay12 months from delivery
Test-order e-mails captured during a compliance check12 months
Invoices, payments and VAT evidence5 years from the end of the tax year, as Polish law requires

You can ask us to delete a report sooner. We cannot delete an invoice before its statutory period ends — that is a legal obligation, not a preference.

7. Your rights

Under the GDPR you can ask us to:

  • tell you what we hold and give you a copy,
  • correct anything wrong,
  • delete it, where we are not required to keep it,
  • restrict or object to processing based on legitimate interest,
  • hand it over in a portable format,
  • withdraw consent, at any time, without affecting what was lawful before.

E-mail privacy@quomerce.com. We do not charge, and we do not require a particular form. We may ask you to confirm who you are, so we do not hand your data to someone else.

8. Automated decision-making

The audit itself is automated: an AI agent decides whether a requirement passes, fails, or cannot be established. That is a judgement about your website, not about you, and it has no legal effect on any person — so it is not automated decision-making about individuals under Art. 22.

We do not profile you, score you, or make automated decisions about people.

If you think a finding is wrong, tell us. A human will look at it.

9. Children

Quomerce is for businesses. We do not knowingly collect data from anyone under 18. If you believe we have, tell us and we will delete it.

10. Changes

We will post any new version here with a new effective date. If a change materially affects how we use your data, we will e-mail you before it takes effect, and where the law requires consent we will ask for it rather than assume it.

Terms of Service Back to quomerce.com

Still interested in One Click Return?

One Click Return

Back to the offer →
Quomerce

A store audit from the shopper's point of view: buying, trust, promotions and checkout.

Product
  • How it works
  • What we check
  • Pricing
  • Blog
  • Sample report
Partners
  • For agencies
  • White-label
  • Credits & pricing
Company
  • Contact
  • Privacy
  • Terms
  • Audit bot
Quomerce Sp. z o.o., ul. Henryka Sienkiewicza 85/87 lok. 1, 90-057 Łódź, Poland KRS 0001251814 NIP 7252368482 REGON 545168861
© 2026 Quomerce. For stores that want to know where shoppers may get stuck