Privacy Policy
This policy explains how personal data is processed under the EU General Data Protection Regulation (GDPR) when you use Urivo. It applies to Urivo’s own application; a merchant who runs a storefront generated with Urivo is the controller for the personal data of their own customers.
Controller
buildwithmb
Mörikestraße 79, 73092 Heiningen, Germany
Email: [email protected]
What data we process, and on what legal basis
Account & authentication data (email, password hash, display name, sign-in state) — to create and secure your account and provide the service. Legal basis: performance of the contract, Art. 6(1)(b) GDPR.
Store, product and brand data you create or generate, and the ideas and business descriptions you enter — to generate and manage your storefronts. Legal basis: Art. 6(1)(b) GDPR.
Your customers’ order and checkout data collected through your storefront — processed on your behalf so you can sell. Legal basis: Art. 6(1)(b) GDPR (and, between you and your customers, your own basis as their controller).
Billing metadata (subscription status, plan, payment confirmations; card data is handled solely by Stripe, never by us) — to operate subscriptions. Legal basis: Art. 6(1)(b) GDPR, and Art. 6(1)(c) GDPR for retaining invoice records to meet statutory tax and accounting obligations.
Technical logs, security and error data, and traffic-attribution data — to keep the service reliable and secure and to attribute sales to the campaigns that produced them. Legal basis: our legitimate interests in a secure, functioning, measurable service, Art. 6(1)(f) GDPR.
Feedback and support messages you send us — to answer and improve the product. Legal basis: Art. 6(1)(f) GDPR.
Analytics and marketing emails — only with your consent, which you can withdraw at any time. Legal basis: Art. 6(1)(a) GDPR (and § 25 TDDDG for any non-essential storage on your device).
Processors and recipients
We use the following service providers, each acting as a processor on our behalf, and share with each only the data needed for its purpose:
Supabase — authentication and database (your account, store and product data).
Anthropic — AI generation; the ideas and business descriptions you enter are sent to generate your store text.
Higgsfield / Google (Gemini) — AI product-image generation; whichever provider is configured receives the product and brand context needed to render images.
Stripe — payment processing for subscriptions and for your storefront checkout; Stripe handles card data as its own controller.
Resend — transactional and (with consent) marketing email delivery; receives the recipient address and message.
Railway — application hosting.
Cloudflare — content delivery, DNS and custom-domain routing.
Sentry — error monitoring; receives technical diagnostic data when something fails.
International transfers
Some of these providers are based outside the European Economic Area (for example in the United States). Where personal data is transferred to a third country, we require an appropriate safeguard under Chapter V GDPR to be in place — an adequacy decision of the European Commission (including the EU–US Data Privacy Framework where the provider is certified) or the European Commission’s Standard Contractual Clauses. You can request details of the safeguard that applies to a specific provider using the contact details above.
How long we keep data
We keep your account, store, product and order data for as long as your account exists. When you delete your account, this data is erased. Billing and invoice records are kept for as long as statutory tax and commercial-law retention obligations require (in Germany, generally up to ten years). Traffic-attribution (click) data is kept for up to 90 days. All other data — including technical logs, error diagnostics and support messages — is kept only for as long as necessary for the purpose for which it was collected, and then deleted.
Your rights
You have the right to access, rectification, erasure, restriction, data portability and objection, and the right to withdraw consent at any time with effect for the future. You can delete your account and all associated data yourself at any time from Settings. To exercise any right, contact us using the details above.
Right to lodge a complaint
You have the right to lodge a complaint with a supervisory authority. The authority competent for us is the State Commissioner for Data Protection and Freedom of Information Baden-Württemberg (Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg), Lautenschlagerstraße 20, 70173 Stuttgart, Germany.
Cookies & analytics
We use necessary cookies to keep you signed in (set by our authentication provider) and, on generated storefronts, a necessary session cookie (“urivo_cs”) that maintains the shopping cart and attributes a sale to the visit that produced it. Your consent choice is stored in your browser’s local storage, not in a cookie.
Analytics is optional and runs only after you choose “Accept” in our consent banner; declining is a single click and sets a “denied” state that we honour, so no analytics is loaded and no analytics cookies are set. When enabled, analytics is provided by PostHog. Analytics is not active on Urivo at this time; if that changes, this policy and the consent banner will reflect it. Necessary cookies do not require consent.