Legal
Privacy Policy
Last updated: 26 August 2026
Aveqra is operated by Antreprenor Independent "Victor Agapie", an independent entrepreneur registered in the Republic of Moldova ("we", "us") — the data controller for the processing described here. This policy covers the website aveqra.com and our Shopify app Aedify. It is short because we collect very little.
What we don't do
- No tracking cookies. We set no cookies of our own — that is why there is no cookie banner. Cloudflare, which sits in front of the site (see below), may set a strictly necessary security cookie when it filters suspicious traffic; it is never used for tracking.
- No trackers. No analytics scripts, no pixels, no fingerprinting, no third-party JavaScript. The only JavaScript the site ships is a small first-party script for the colour-theme switcher; it stores your theme choice in your browser's local storage and sends nothing anywhere.
- No selling of data. We do not sell, rent, or share your personal data for advertising — ever.
What we collect on the website
Contact form. When you use the contact form we collect your name, e-mail address, subject, and message. We use them solely to reply to you.
Form submissions are stored in a database on a private server we control, and a notification carrying the submission is delivered to us over Telegram. The legal basis is taking steps at your request prior to entering into a contract, and our legitimate interest in answering the people who write to us (GDPR art. 6(1)(b) and 6(1)(f)).
Server logs. Like almost every web server, ours records standard access logs (IP address, requested page, time, browser user-agent). We use them for security and for aggregate, privacy-preserving traffic statistics generated on our own server, based on our legitimate interest in keeping the service secure (GDPR art. 6(1)(f)). Logs stay on that server and are not linked to form submissions.
How long we keep it
- Form submissions: up to 24 months from submission, then deleted.
- Server logs: up to 90 days, then deleted.
The Aedify app
Aedify is installed by Shopify merchants. We process data about the merchant's store as needed to run the app, on the legal basis of performing our contract with you (GDPR art. 6(1)(b)). We do not collect personal data about the merchant's own customers (shoppers). Aedify has no access to orders, customer records, or checkout data, and requests no such API scopes.
When you install Aedify, we store:
- Your store's
myshopify.comdomain and the app's installation state (plan tier, setup status, timestamps). - The store owner's contact e-mail address (as provided by Shopify), used only for a small number of transactional e-mails about your installation — for example, a notice when your subscription is put on hold. No marketing, no sharing.
- Shopify API access tokens issued to the app, used to read and write the content you manage in Aedify. Tokens are encrypted at rest (AES-256-GCM) and are never displayed or logged in plain text.
The content you create in Aedify (FAQ text, testimonials, specifications, and so on) is stored in your own Shopify store as Shopify custom data (metaobjects) — not in a separate Aedify database.
We keep store and token data for as long as the app is installed, and we honour Shopify's mandatory GDPR webhooks: customers/data_request and customers/redact are acknowledged with nothing to return or erase, since Aedify holds no shopper data; on shop/redact — sent by Shopify about 48 hours after you uninstall — we delete your store's record, including its encrypted tokens. Uninstalling the app stops all further access immediately.
Where your data lives
The website, our apps, and their databases run on a server we control at Hetzner in Germany (EU) — that is where form submissions, server logs, and app data are stored. Traffic to our domains passes through Cloudflare, which provides DNS, content delivery, and protection against attacks, and processes visitors' IP addresses and request metadata for that purpose. As the operator, we access this data from the Republic of Moldova, which has its own data-protection law.
Who else sees it
We use a small set of processors to run the service:
- Hetzner — hosting in Germany (EU) for the website, the apps, and their databases.
- Cloudflare — DNS, content delivery, and security in front of our domains.
- Telegram — delivers form-submission notifications to us through its Bot API.
- E-mail delivery (currently Resend) — transmits the apps' transactional e-mails.
- Shopify — the platform our apps run on and where your Aedify content is stored.
Each processes data only on our instructions. There are no other recipients.
Security
All traffic is served over TLS. App access tokens are encrypted at rest. Access to production systems is restricted.
Your rights
Under the GDPR you can ask us to access, correct, delete, or export the personal data we hold about you, restrict or object to its processing, and withdraw consent where processing is based on it. Write to contact@aveqra.com and we will respond within one month. You can also lodge a complaint with your local data protection authority.
Changes
If this policy changes, we will update this page and the date at the top. Questions? contact@aveqra.com.