Privacy policy
Last updated: 2026-05-15
1. Introduction and scope
This privacy policy describes how Prestaworks AB, operating under the Storeborn brand, processes personal data in connection with the Storeborn e-commerce platform (the "Service"). The policy applies to:
(a) merchants who register and operate stores via the Service, (b) representatives, employees and other individuals associated with a merchant's account, (c) visitors to storeborn.se, and (d) individuals who contact us via support channels, social media or other contact routes.
We process personal data in accordance with the EU General Data Protection Regulation (GDPR), the Swedish Data Protection Act (2018:218) and other applicable data-protection legislation. Section 3 describes how, depending on the category of data, we act either as data controller or as data processor.
Personal data of End Customers processed in a merchant's store is not governed by this policy — there the merchant is the data controller and provides its own privacy policy. Storeborn acts as data processor in such processing, as described in section 3 and in the data-processing agreement that forms an integral part of the Terms of Service.
2. Data controller and contact
The data controller for the processing described in this policy is:
Prestaworks AB Company registration number: 556786-1561 Registered office: Västerås, Sweden Email: privacy@storeborn.se
Storeborn has assessed that a formal Data Protection Officer (DPO) is not required under Article 37 GDPR, since our core activity does not consist of large-scale systematic monitoring of data subjects or large-scale processing of special categories of personal data. Questions about personal-data processing are handled by our data-protection function at privacy@storeborn.se. Other legal contact takes place via legal@storeborn.se and security matters via security@storeborn.se.
3. Our two roles: data controller and data processor
Storeborn has two separate roles under the GDPR depending on which personal data is processed:
**Data controller** — we determine the purposes and means of the processing. This applies to:
(a) the merchant's own data (account data, billing details, support communications, security and activity logs, consent records), (b) representatives and team members granted access to the merchant's account, (c) visitors to storeborn.se and similar public websites, and (d) individuals who contact us via support, social media or sales channels.
**Data processor** — we process data on the merchant's documented instructions. This applies to:
(a) End Customers' personal data submitted in the merchant's store (names, addresses, email, phone numbers, orders, payment details, customer accounts), and (b) other material in the store that may contain personal data (comments, reviews, contact-form data).
For the processor activity, the merchant enters into a data-processing agreement with Storeborn that forms an integral part of the Terms of Service. The agreement governs, among other things, security measures, the engagement of sub-processors, assistance with data-subject rights and procedures in the event of personal-data breaches.
4. What personal data we process
In our role as data controller, we process the following categories:
**Account data:** First and last name, email address, phone number, encrypted password, login history, IP address at login, two-factor-authentication details and security events.
**Business data:** Company name, company registration number, VAT number, registered address, billing address and contact person.
**Usage data:** Logins, feature usage, changes to store settings, navigation patterns in the admin panel and technical data such as IP address, browser, operating system and device type.
**Transaction and billing data:** Sales amounts, order volumes, billing and accounting records, payment status, and bank-account or other payout details associated with the merchant's account.
**Support communications:** Contents of tickets, email conversations, chat history and, where expressly notified, recordings of customer-service calls.
**Marketing and communication data:** Consent and preferences for newsletters, click-and-open patterns in marketing emails, and any unsubscribes.
**Website data:** Information collected via cookies and similar technologies when you visit storeborn.se. See our cookie policy for details.
We do not knowingly process sensitive personal data (health, ethnic origin, religious or political beliefs, biometric or genetic data). If such data nevertheless appears in material received by us (e.g. in a support ticket), it is deleted or minimised as soon as possible.
Payment-card data is never stored by Storeborn. Such data is handled directly by the relevant payment provider in a PCI-DSS-certified environment.
5. Where the data comes from
Personal data is collected from the following sources:
**Directly from you:** When you register an account, update store settings, contact support, subscribe to our newsletter, or otherwise actively provide information.
**Automatically from your use of the Service:** Logs, IP addresses, click and navigation patterns, events in the admin panel and error reports.
**From third parties:** Where necessary we may supplement account data with publicly available company information from the Swedish Companies Registration Office (Bolagsverket), credit-reference agencies or equivalent, primarily in connection with billing and fraud/risk checks. When you log in via Google, Facebook or Microsoft (SSO), your name and email address are retrieved from the relevant identity provider according to your settings there.
**From payment and shipping providers:** To the extent you have activated third-party integrations, those may return transaction or delivery status to the Service.
6. Purposes and legal basis
We process personal data for the following purposes, each with a specific legal basis under the GDPR:
**(a) Provision of the Service** — account creation, authentication, store operation, order management, support and maintenance. Legal basis: performance of contract (Art. 6.1.b).
**(b) Billing and payment handling** — calculation of the Service Fee, invoicing, collection and receipts. Legal basis: performance of contract (Art. 6.1.b) and legal obligation (Art. 6.1.c, Bookkeeping Act).
**(c) Accounting and regulatory compliance** — retention of accounting records, VAT reporting and handling of authority requests. Legal basis: legal obligation (Art. 6.1.c).
**(d) Security and fraud prevention** — security logging, monitoring of suspicious activity, blocking of malicious traffic and incident handling. Legal basis: legitimate interests (Art. 6.1.f) and legal obligation (Art. 6.1.c) for reporting duties.
**(e) Operations, troubleshooting and further development of the Service** — analysis of usage patterns in aggregated form, error reports, A/B tests and platform improvements. Legal basis: legitimate interests (Art. 6.1.f).
**(f) Communications about the Service** — operational notices, security alerts, material product changes, billing correspondence and other service emails needed to perform the agreement. Legal basis: performance of contract (Art. 6.1.b) and legitimate interests (Art. 6.1.f).
**(g) Direct marketing and newsletters** — communications about new features, campaigns and inspiration to merchants who have consented to such communications. Legal basis: consent (Art. 6.1.a) — consent may be withdrawn at any time.
**(h) Handling of legal claims** — proving and defending in disputes, claims from authorities or courts. Legal basis: legitimate interests (Art. 6.1.f) and legal obligation (Art. 6.1.c).
**(i) Business transfer** — in the event of a merger, sale or reorganisation, personal data may need to be shared with an acquirer. Legal basis: legitimate interests (Art. 6.1.f).
7. Legitimate interests — further specification
Where we base processing on legitimate interests (Art. 6.1.f), we have carried out a balancing test between our purposes and the rights and freedoms of data subjects. We have assessed that the following interests are legitimate and do not override the individual's interests in the normal use of the Service:
(a) operating and improving the Service and ensuring stable, secure operation, (b) protecting the Service, other merchants and End Customers from fraud, abuse and security incidents, (c) communicating with merchants about changes and news that affect their use of the Service, (d) defending and asserting legal claims and meeting evidentiary requirements in disputes, and (e) being able to transfer the business in the event of a corporate transaction.
You always have the right to object to processing based on legitimate interests under section 12 below. Upon objection, we will cease the processing unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or unless the processing is required for the establishment, exercise or defence of legal claims.
8. How long we keep the data
We retain personal data only for as long as it is necessary for the purpose for which it was collected, and thereafter for the period necessary to comply with legal obligations or defend legal claims.
**Main principles:**
(a) **Account and business data** — processed for the duration of the agreement and a reasonable period thereafter to allow for reactivation, customer service, final invoicing and handling of any subsequent claims.
(b) **Invoice and accounting material** — retained in accordance with the Swedish Bookkeeping Act (currently seven years after the end of the financial year to which the material relates).
(c) **Security and activity logs** — retained for a limited period sufficient to detect and investigate security incidents, and deleted or anonymised thereafter.
(d) **Support communications** — retained for a reasonable period after the case is closed to allow for follow-up and service improvement.
(e) **Marketing data and consent records** — data tied to newsletter consent is retained until the consent is withdrawn or, if longer, for as long as required as evidence of the lawful basis for messages already sent.
(f) **Inactive accounts** — if an account is inactive for a continuous period, suspension and deletion measures are taken automatically in accordance with section 17 of the Terms of Service.
When the retention period expires, data is deleted or anonymised. Anonymised aggregates (with no possibility of re-identification) may be used for long-term statistics and product development without time limit.
9. Recipients and sub-processors
We never share personal data with third parties for their own marketing purposes and never sell personal data. Personal data may, however, be shared with the following categories of recipients, always supported by a data-processing agreement or other appropriate legal basis:
**Sub-processors** — providers that process personal data on our behalf under instruction and bound by data-processing agreements:
(a) hosting provider in Sweden for operation of servers and databases, (b) CDN, security and DDoS-protection provider, (c) email infrastructure for outbound service and system emails, (d) error- and performance-monitoring provider, (e) tools for support tickets, customer communications and customer service, and (f) approved Storeborn Partners (web agencies and resellers) that the merchant has chosen to work with — such a partner may access the merchant's store data, including customer data, solely to service that merchant's store, bound by sub-processor terms in the Storeborn Partner Agreement; the merchant can turn off the partner's access to the store admin at any time in the store settings.
**Other recipients** — separate data controllers with whom we share data when necessary:
(a) payment providers activated by the merchant (to handle payments in the store), (b) accounting systems and billing partners when the merchant has activated such an integration, (c) collection-agency and credit-reference providers in the event of non-payment, (d) advisors, auditors and legal counsel as needed, and (e) authorities where required by law, court order or governmental decision.
A current list of our sub-processors can be obtained on request via privacy@storeborn.se. We reserve the right to add or change sub-processors and notify merchants of such changes within a reasonable time where required under the data-processing agreement.
10. Transfers to third countries
We aim primarily to choose sub-processors within the EU/EEA. Where a transfer to a country outside the EU/EEA nevertheless takes place — for example, when a provider has global support functions or redundancy — we ensure a level of protection equivalent to the GDPR through one of the following tools:
(a) an adequacy decision by the European Commission for the relevant country, (b) the European Commission's Standard Contractual Clauses (SCCs) combined with supplementary measures (transfer impact assessment) where required, or (c) another approved transfer mechanism under GDPR Chapter V.
Information about where a specific category of data is processed, and which transfer mechanism applies, can be obtained on request via privacy@storeborn.se.
11. Security and personal-data breaches
We implement appropriate technical and organisational security measures to protect personal data against unauthorised access, alteration, loss and unlawful processing. The measures include, among other things:
(a) encryption of data in transit (TLS) and encryption at rest for sensitive data categories, (b) hashed passwords (argon2) and support for two-factor authentication, (c) strict access control and the principle of least privilege for employees and providers, (d) logging of administrative actions and security monitoring, (e) regular security updates, patch management and vulnerability monitoring, (f) database-level segmentation (row-level security) that logically isolates each merchant's data, (g) regular backups and tested restore procedures, and (h) internal policies and training of staff on confidentiality and data protection.
**Personal-data breach:** If we suspect or determine that a personal-data breach has occurred, we follow procedures in line with the GDPR. In our role as data controller, we notify the Swedish Authority for Privacy Protection (IMY) within 72 hours where required, and inform affected data subjects without undue delay where the breach is likely to result in a high risk to them. In our role as data processor, we notify the affected merchant without undue delay so that the merchant can fulfil its own notification obligations.
12. Your rights
Under the GDPR you have the following rights regarding your personal data:
**Access (Art. 15):** Obtain confirmation as to whether we process your data and receive a copy of it (subject access request).
**Rectification (Art. 16):** Request correction of inaccurate or incomplete data.
**Erasure (Art. 17, the "right to be forgotten"):** Request that your data be erased, subject to statutory obligations to retain certain data (e.g. accounting material under the Bookkeeping Act).
**Restriction (Art. 18):** Request that processing be restricted while an objection or rectification request is being investigated.
**Objection (Art. 21):** Object to processing based on legitimate interests. You also have an unconditional right to object to processing for direct marketing — following such an objection, marketing communications will stop.
**Data portability (Art. 20):** Receive data you have provided to us in a structured, commonly used and machine-readable format, or request transmission directly to another data controller where technically feasible.
**Withdraw consent (Art. 7.3):** Where processing is based on consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
**Lodge a complaint with a supervisory authority (Art. 77):** You always have the right to lodge a complaint with a data-protection authority, in particular in the EU country of your habitual residence, place of work or the alleged infringement. In Sweden, the supervisory authority is the Swedish Authority for Privacy Protection (IMY), Box 8114, 104 20 Stockholm, imy.se. We would appreciate, however, if you first contact us so that we have the opportunity to address any shortcomings.
Requests are normally answered within one month from the date we receive a sufficiently identifiable request. For complex or numerous requests, the period may be extended by a further two months, in which case we will inform you of the extension and the reasons. Requests can be sent to privacy@storeborn.se. To protect your data, we may need to verify your identity before responding.
End Customers in a store operated on the Storeborn platform exercise their rights toward the merchant operating the store (the data controller for the End Customers' data). We provide tools for data export and anonymisation that the merchant can use to meet its obligations.
13. Automated decision-making and profiling
We do not use automated decision-making or profiling that produces legal or similarly significant effects on individuals within the meaning of Article 22 GDPR. Automated processes such as Service Fee calculation, lifecycle management, security analysis and fraud-related blocking are based on objective rules, can be reviewed manually and do not affect the individual's rights in an intrusive manner.
If we introduce such processing in the future, we will update this policy and inform affected data subjects about their right to request human intervention, express their view and contest the decision.
14. Children
The Service is intended for businesses and is not aimed at persons under 18 years of age. We do not knowingly collect personal data from children. If we become aware that data has been provided by a person under 18, the data is deleted without undue delay.
For End Customers in a merchant's store, the merchant as data controller is responsible for handling any processing of data relating to minors in accordance with the GDPR and Swedish data-protection law.
15. Direct marketing and communications from us
We divide our communications to merchants into two categories:
**Transactional and operational communications:** Invoices, payment reminders, security alerts, password resets, material changes to the Service and other correspondence required to perform the user agreement. These are sent regardless of marketing consent because they are based on contract performance or legitimate interests respectively.
**Newsletters, product news and campaigns:** Information about new features, inspiration, tips and offers. Such communications are sent only after your active consent at registration or in your account settings. You can withdraw consent at any time by clicking the unsubscribe link in an email or via the settings in the admin panel. Withdrawal does not affect the lawfulness of messages already sent.
We never use your data for third-party marketing. We also do not share your data with marketing platforms in a way that identifies you as an individual without your consent.
17. Changes to the privacy policy
We may update this privacy policy when necessary — for example, in connection with changes to the Service, new legal requirements or amended processing purposes. For material changes, we will notify you by email and/or a notice in the admin panel at least 30 days before the effective date. Minor editorial changes and clarifications may be published directly.
The latest update date is always shown at the top of this page, and a history of changes can be provided on request.
18. Contact us and complaints
If you have questions about this privacy policy or how we process your personal data, you can contact us:
**Data controller:** Prestaworks AB Company registration number: 556786-1561 Registered office: Västerås, Sweden Email for data protection: privacy@storeborn.se Email for legal matters: legal@storeborn.se Email for security matters: security@storeborn.se
We normally respond to requests within one month. For complex or numerous requests, the period may be extended by a further two months.
**Supervisory authority:** You always have the right to lodge a complaint with the Swedish Authority for Privacy Protection (IMY): Postal address: Box 8114, 104 20 Stockholm Website: imy.se Email: imy@imy.se
We would appreciate, however, if you first contact us so that we have the opportunity to address any shortcomings.