1. Controller
ProWebSolutions GmbH Aurelienstr. 48 04177 Leipzig Germany Email: info@prowebsolutions.de Telephone: +49 176 10347813
2. Website and server logs
When you access this website, our systems process technically necessary connection and log data. This may include IP address, timestamp, requested URL, HTTP status, transferred volume, referrer and user agent. We use these data to deliver and stabilise the service, investigate errors and prevent abuse under Article 6(1)(f) GDPR.
Web and browser services run on Hetzner infrastructure in the EU. Production logs rotate by size; the verified configuration retains up to ten compressed rotations per log with a 10 MiB threshold. This does not produce a fixed number of days, so actual duration depends on traffic. Security and audit events are generally retained for up to 365 days where required for accountability, abuse prevention and operations.
3. Strictly necessary cookies
StoreVigil currently uses only strictly necessary first-party cookies. It does not use analytics, marketing or advertising cookies requiring consent, so no cookie banner is currently displayed.
- sv_session: authentication, session and CSRF protection; Secure, HttpOnly, SameSite=Lax; normal idle limit of 2 hours or up to 30 days when “remember me” is selected.
- __Host-sv_registration_csrf: registration protection; Secure, HttpOnly, SameSite=Strict, path /; up to 30 minutes and deleted after use.
- sv_operator_session: protected internal operator access; Secure, HttpOnly, SameSite=Strict; normally up to 8 hours with a 30-minute idle limit or up to 30 days when remembered.
- sv_operator_trusted_device: optional internal trusted-device marker; Secure, HttpOnly, SameSite=Strict, path /operator; up to 30 days.
- Locale is stored server-side; StoreVigil currently uses no localStorage, sessionStorage or IndexedDB.
4. Free store check without an account
For a free check we process the submitted domain or URL, normalised and redirected URLs, timestamps, language, a cryptographically protected check reference, selected scope, technical resources, results and, where applicable, screenshots and Visual Evidence. The initiator IP is not stored in plain text in the scan record; it is pseudonymised using a server-side key and supports rate limiting together with self-hosted abuse protection.
The check is read-only and covers up to three representative public pages. Check records and related evidence expire within 24 hours and are removed from the database and evidence storage by the cleanup process. The random result link is designed to be unguessable but should still not be shared. We rely on Article 6(1)(b) GDPR for the requested check and Article 6(1)(f) GDPR for security and abuse prevention.
5. Account, sign-in and password reset
For registration and account use we process email address, password hash, account status, email verification, language, time zone, registration and sign-in timestamps, sessions and acceptance records. Passwords are never stored in plain text. Security references to IP address and user agent are pseudonymised or hashed.
For password reset we process the email address, a single-use reference stored only as a hash, expiry and use timestamps, and security logs. Reset references expire after no more than one hour; expired or used records are removed after seven days. Verification references expire after 24 hours. The bases are Article 6(1)(b) GDPR and Article 6(1)(f) GDPR for account security.
6. Trial and monitoring
After explicit authorisation, StoreVigil records the workspace, store domain, authorisation evidence, and the start and end of the seven-day trial. The trial analyses and monitors the complete authorised public storefront inventory within the technically permitted scope and provides a dashboard, rechecks and email notifications. It never converts automatically into a paid contract.
Under Core, StoreVigil continues that authorised public monitoring scope within the booked and technically permitted scope. The customer selects the domain and must be authorised to monitor it. Article 6(1)(b) GDPR applies to account and contract data; Article 6(1)(f) GDPR applies to operational security.
7. Browser analysis and Visual Evidence
StoreVigil automatically loads authorised public store pages, sometimes in a real browser. Depending on the check, we collect HTTP and network status, rendered elements, technical errors, performance values, images, links and resources, plus baseline accessibility and SEO signals. Suitable findings may include screenshots, bounded annotated crops and element context. Public pages can contain names, images, contact details, reviews or other personal data.
Evidence is stored for the relevant customer and check. Access is restricted to the authorised customer and purpose-bound, logged support or operations access. Under the standard trial, evidence expires after seven days; under Core it normally expires after 30 days. Expressly agreed pilot profiles may have other documented periods. Raw availability data is normally retained for 30 days, snapshots for 90 days and aggregated time series for up to 400 days.
8. Roles and processing on behalf of customers
ProWebSolutions GmbH determines purposes and means for accounts, product security, billing and its own operations and acts as controller for those activities. Where a customer instructs StoreVigil to render selected public pages and store potentially personal page content solely for the customer’s monitoring purposes, ProWebSolutions GmbH may act as processor.
The precise allocation and an Article 28 GDPR data processing agreement will be resolved separately and conclusively before a broader paid rollout. Customers remain responsible for the lawfulness of the instructed domain and scope.
9. Email and support
We send necessary messages for registration, verification, password reset, trial, outage alerts, recovery, reports, billing and invoices. We process recipient address, language, message type, relevant content, and delivery or error status. The currently configured mail service runs on self-managed Hetzner infrastructure in the EU. A 30-day configuration exists for delivery metadata, but the audit could not prove complete automated enforcement of that period.
Authorised personnel may open a time-limited, purpose-bound read-only customer view for support and operations. The reason, scope and material actions are logged. Regular support access expires after 15 minutes by default.
10. Payments through Mollie
For a Direct Web payment initiated by a business customer, we send Mollie B.V. the company name, billing email, language, amount, currency, technical customer and checkout references, payment description and status references. Mollie provides the payment methods actually offered at checkout and processes payment information for payment execution, security and legal duties under its own responsibility. StoreVigil does not store full card details.
StoreVigil receives and stores provider references, payment method where reported, and payment, mandate, refund and chargeback status. Mollie’s current notices determine which subprocessors or international transfers it may use in a particular case.
11. Invoices and tax records
For invoices and corrections we process company, billing address, billing email, VAT ID where supplied, invoice number, service period, net, tax and gross amounts, payment status, invoice documents and correction documents. Electronic documents are made available in the customer account and/or sent by email.
Invoice and accounting vouchers are generally retained for eight years from the end of the relevant calendar year. Commercial books, inventories, opening balances and annual accounts are generally subject to ten years; received or sent commercial correspondence is generally subject to six years. A category or pending proceeding may require longer retention. Required invoice data may therefore remain restricted after account deletion. The basis is Article 6(1)(c) GDPR together with German commercial and tax law.
12. Recipients and locations
Recipient categories include Hetzner as infrastructure and hosting provider, Mollie as payment service provider, legally or fiscally required recipients, and specifically authorised employees and support staff. Core services and the currently configured mail service run within the EU.
International processing by Mollie cannot be excluded solely from StoreVigil source code. Mollie’s current information and safeguards apply. Other recipients receive data only where necessary for a contract, legal duty, security or legal claims.
13. Retention and deletion
We keep personal data only as long as required for its purpose, contractual evidence, security interests or legal duties. Account sessions and tokens are normally removed seven days after expiry or revocation. Account deletion removes or disconnects account and access data, while legally required billing and invoice records remain restricted. Specific product periods are stated in the relevant sections above.
14. Your rights
Subject to the statutory conditions, you have rights of access, rectification, erasure, restriction and data portability. You may object, on grounds relating to your particular situation, to processing based on legitimate interests. You may withdraw consent with future effect where processing relies on consent; the core processing described here does not currently rely on marketing consent.
Send requests to info@prowebsolutions.de. You may also complain to a data protection supervisory authority, in particular the Saxon Commissioner for Data Protection and Transparency.
15. Security and changes
We use appropriate technical and organisational safeguards, including transport encryption, hashed credentials, access separation, time-limited references, logging and restricted evidence permissions. No internet service can guarantee absolute security.
We update this notice when the product, recipients, retention periods or legal requirements materially change. The applicable version and date appear above.
16. Shopify app channel
When a merchant installs StoreVigil as an embedded Shopify app, StoreVigil processes the Shopify Shop ID, myshopify domain, public primary storefront domain, app user subject, encrypted expiring offline access and refresh tokens, installation and webhook state, and the notification email expressly confirmed by the merchant. These data support authentication, storefront mapping, monitoring, notifications and plan-state verification.
StoreVigil requests no customer, order or product read scopes for this product scope. It monitors authorised public storefront pages. The paid Shopify channel uses Shopify App Pricing; StoreVigil retains technical subscription references, the plan handle, billing period, and the price and currency snapshot verified through the Shopify Partner API. This creates neither Mollie data nor a second direct StoreVigil invoice.
Uninstall stops monitoring and notifications and removes tokens. The Shopify shop/redact webhook removes channel monitoring and evidence data. Minimal billing and audit evidence required by law or for legal claims may remain restricted and pseudonymised. A separately existing Direct Web storefront is never deleted without a distinct safe linkage decision.