Privacy Policy
Effective: 12.08.2026
This explains what we do with personal data when you buy an audit and when we audit your shop. It is written to be read, not to be survived.
1. Who is responsible
The controller is QUOMERCE SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ, ul. Henryka Sienkiewicza 85/87 lok. 1, NIP 7252368482, 0001251814.
Data-protection questions and requests: privacy@quomerce.com. We reply within one month.
We have not appointed a Data Protection Officer, because we are not required to. Requests go to the address above and are handled by us directly.
2. What we collect, and why
When you order an audit
| Data | Why | Lawful basis |
|---|---|---|
| Shop address (URL) | It is the thing being audited | Contract, Art. 6(1)(b) |
| Company name, contact first and last name | To issue the invoice and address you | Contract |
| Work e-mail | To send the audit-started and audit-ready e-mails and the report link | Contract |
| Phone number (optional) | Contact about your audit; passed to an agency only if you asked for matching | Contract / consent |
| Invoice address, country, tax identifier | Legally required invoice content; determines the VAT rate | Legal obligation, Art. 6(1)(c) |
| VAT number and VIES consultation number | Evidence for the rate we charged, if we are ever asked to prove it | Legal obligation |
| Payment status, amount, currency, transaction id | Accounting; matching your payment to your audit | Legal obligation |
We ask for what the invoice needs and what it takes to reach you. There is no marketing profile.
When we audit your shop
The audit produces a report about a website, not about a person. But a website contains whatever its owner put there, so a report can incidentally contain personal data — a name in the footer, an address on a contact page, a staff photo. Two parts deserve naming outright:
- Screenshots of the pages the agent visited, stored with the report.
- A session replay of the agent’s own browsing — a reconstruction of what our automated browser saw and did, so you can watch how a finding was reached. It records our agent’s session on your public storefront. It does not record your customers or your staff.
For a check that includes the transactional requirements, the agent places a test order using a disposable mailbox we control. Your shop’s confirmation e-mail is retrieved and stored with the report, including its HTML, because it is the evidence for the finding. If that e-mail contains personal data your shop put in it, that data ends up in the report — the name on the order is our test identity, not a real customer’s.
Basis: performance of our contract with you. Where a report incidentally contains a third party’s personal data, our basis is legitimate interest, Art. 6(1)(f) — delivering an audit that its subject asked for.
3. Where your report can be read
Your report is unlisted, not private. /audits/<id> needs no login. The id is a random UUID
so it cannot be guessed or enumerated, and we do not index reports or link to them publicly — but
anyone you send the link to can open it, pass it on, and open it again a year later.
Treat the link like a document, not a password. Tell us if you want one revoked.
4. Agency matching, and what agencies receive
If you consented to agency matching when you ordered, your completed audit can be listed on our marketplace. An agency that buys access receives:
- generated audit report,
- your shop address,
- your company name,
- your contact first name, work e-mail and phone number.
That last line is why this is opt-in and not a default. Our basis is your consent, Art. 6(1)(a), given by ticking a box at checkout that starts empty. Leaving it empty is not a refusal you have to justify — it is simply the answer we assume.
You can withdraw at any time, by e-mailing privacy@quomerce.com. We de-list the lead as soon as possible. Withdrawal does not guarantee agencies already holding your details will stop contacting you, because we cannot control their records — but we will pass your withdrawal on.
Agencies are independent controllers for what they do with your details afterwards. They are contractually barred from using them for anything other than contacting you about the audit report.
If you did not consent, none of this happens. Your audit is not listed, and no agency sees anything about you. Your report is exactly the same either way.
5. Who else processes your data
Processors acting on our instructions:
| Who | What they handle | Where |
|---|---|---|
| Cloudflare (R2) | Temporary report storage | EU |
| OpenAI | Page content and screenshots sent to the model that performs the audit | US, SCCs |
| DeepL | Report text, for translation | EU |
| Resend | Sending the two e-mails | EU/US, SCCs |
| PostHog | Product analytics | EU |
| Google Analytics | Website analytics | Global |
| LangSmith | Traces of agent runs, for debugging | US, SCCs |
| Hetzner | Data processing, customers and reports data | EU |
Independent controllers, not processors:
- tPay (Krajowy Integrator Płatności S.A.) — your payment. They decide how they handle it; their privacy policy governs. We receive a transaction id and a status, never your card number.
- The European Commission (VIES) — we send an EU VAT number to confirm it is registered.
- Agencies we share contact information with, as described above.
Transfers outside the EEA rely on Standard Contractual Clauses. We do not sell personal data to anyone other than as described in section 4, which needs your consent.
Content sent to the AI model may be used to train it by OpenAI. Data exchanged with OpenAI contains no personal information.
6. How long we keep things
| What | How long |
|---|---|
| Audit reports and findings | 12 months from delivery |
| Screenshots and session replay | 12 months from delivery |
| Test-order e-mails captured during a compliance check | 12 months |
| Invoices, payments and VAT evidence | 5 years from the end of the tax year, as Polish law requires |
You can ask us to delete a report sooner. We cannot delete an invoice before its statutory period ends — that is a legal obligation, not a preference.
7. Your rights
Under the GDPR you can ask us to:
- tell you what we hold and give you a copy,
- correct anything wrong,
- delete it, where we are not required to keep it,
- restrict or object to processing based on legitimate interest,
- hand it over in a portable format,
- withdraw consent, at any time, without affecting what was lawful before.
E-mail privacy@quomerce.com. We do not charge, and we do not require a particular form. We may ask you to confirm who you are, so we do not hand your data to someone else.
8. Automated decision-making
The audit itself is automated: an AI agent decides whether a requirement passes, fails, or cannot be established. That is a judgement about your website, not about you, and it has no legal effect on any person — so it is not automated decision-making about individuals under Art. 22.
We do not profile you, score you, or make automated decisions about people.
If you think a finding is wrong, tell us. A human will look at it.
9. Children
Quomerce is for businesses. We do not knowingly collect data from anyone under 18. If you believe we have, tell us and we will delete it.
10. Changes
We will post any new version here with a new effective date. If a change materially affects how we use your data, we will e-mail you before it takes effect, and where the law requires consent we will ask for it rather than assume it.