NodeShop
Legal

Privacy policy

What NodeShop collects, why, who else sees it, and what you can ask us to do about it. This describes the platform. If you are the customer of a business selling on NodeShop, that business decides how your data is used — this page explains our part.

effective [Effective date]

01Who is responsible for what

NodeShop is a whitelabel platform, so there are two relationships and they are governed differently.

For an operator’s own account — the business reselling capacity — [Legal entity name] is the data controller.

For an operator’s customers, the operator is the controller and we act as their processor. We hold that data to run the portal on their behalf and for no purpose of our own. The terms of that arrangement are in our data processing agreement.

02What we hold

CategoryWhat it isHow long
AccountEmail address, display name, and the portal it belongs toFor as long as the account exists
SessionsIP address and browser user agent at sign-inUntil the session expires or is revoked
BillingBilling email, country and tax identifier where suppliedAs long as tax law requires the record
UsageAggregated request counts, bandwidth and connection counts per keyRolled up; raw samples are not retained indefinitely
AvailabilityProbe results against endpoints we serve90 days, then deleted automatically
SupportTicket contents and correspondenceFor as long as the account exists
AuditAdministrative actions, who took them and whenRetained as a security record

We do not hold card numbers. Payment details are handled by our payment provider and never reach our systems.

03Why we hold it

To provide the service you asked for, to bill for it, to keep it secure and available, and to meet legal obligations such as tax record keeping. We do not sell personal data, we do not use it to train models, and we do not use it for advertising.

[Counsel: state the lawful bases explicitly — contract, legitimate interests, legal obligation — and map each to the categories above.]

04Who else sees it

Only the providers we need to run the service. Each is bound to use the data solely to provide their service to us.

ProviderWhat they doWhat they receive
eezeCheckout, payment processing and merchant of recordOrder and billing details, billing email, country, tax identifier
ResendTransactional email — sign-in codes, receipts, alertsEmail address, message content
CloudflareAuthoritative DNS for platform and operator domainsDomain names only; no customer records
Let's EncryptTLS certificate issuanceHostnames only
OpenRouterThe in-product help assistant, when an operator enables itThe question asked and the page context it was asked from
TeraSwitch (Frankfurt, Germany)Application and database hostingAll service data, at rest in the EU

Service data is stored in the European Union. Where a provider processes data outside the EU, that transfer is covered by appropriate safeguards. [Counsel: confirm the transfer mechanism for each provider.]

05The help assistant

Where an operator enables the in-product help assistant, the question asked and the page it was asked from are sent to OpenRouter to generate an answer. Do not put credentials or secrets into it. It is off unless an operator turns it on.

06Your rights

You can ask us for a copy of your data, to correct it, to delete it, or to stop a particular use of it. If you are the customer of a business selling on NodeShop, ask them first — they decide, and we act on their instruction.

Requests to [privacy@nodeshop.app — confirm this address exists]. You also have the right to complain to a supervisory authority. [Counsel: name the lead authority once the entity is established.]

07Security

Each portal’s rows are isolated in the database by row-level security enforced by Postgres itself, not by application code — one portal cannot read another’s data even if a query forgets to filter. Sign-in is by one-time code rather than stored passwords. Administrative access is separated from application access and every administrative action is recorded.

08Contact

[Legal entity name], [Registered address]. [privacy@nodeshop.app — confirm this address exists].