DRAFT — NOT YET REVIEWED BY A LAWYER
This document is a starting point drafted to cover the obvious ground. It is not legal advice and it has not been reviewed by a qualified adviser. Have a solicitor check it against how EasyRetale actually operates before relying on it, and delete this notice once they have.
Privacy policy
Last updated 21 July 2026
Who this covers
This policy explains how EasyRetale handles personal data about the people who use our service — business owners, their staff, and visitors to this website. EasyRetale is the data controller for that data.
It does not cover shoppers who buy from a business using EasyRetale. For that data the retailer is the controller and we are their processor; their own privacy notice applies, published on their shop page.
What we collect
- Account details — name, email, phone, password (hashed, never stored in readable form).
- Business details — trading name, addresses, VAT number, subscription tier.
- Usage and security records — sign-in times, trusted devices, IP address, audit entries for actions taken in the app.
- Billing data — handled by our payment provider. We store a customer reference and subscription status, never full card numbers.
- Support correspondence — what you send us when you ask for help.
Why we use it, and our lawful basis
- To provide the service — necessary to perform our contract with you.
- To keep accounts secure — our legitimate interest in preventing unauthorised access and fraud.
- To take payment and keep records — contract, and compliance with tax law.
- To send service messages (outages, billing, security) — contract. These are not marketing and cannot be opted out of while you hold an account.
- To send marketing — only with your consent, which you can withdraw at any time in the dashboard.
How long we keep it
Account data is kept while your subscription is active. After closure we delete or anonymise personal data within 90 days, except records we are legally required to keep — principally invoices and accounting records, retained for the period Irish tax law requires. Security logs are kept for 12 months.
Who we share it with
We use a small number of providers to run the service:
- Hosting and database infrastructure
- Payment processing for subscriptions
- Transactional email delivery
- Error monitoring and diagnostics
Each is bound by contract to process data only on our instructions. We do not sell personal data and we do not share it for anyone else’s marketing.
Where your data is held
Data is stored within the European Economic Area. Where a provider processes data outside the EEA, we rely on the European Commission’s standard contractual clauses.
Your rights
You can, free of charge:
- Get a copy of your personal data
- Have inaccurate data corrected
- Have your data erased, subject to records we must keep by law
- Object to or restrict how we use it
- Withdraw marketing consent at any time
- Ask for your data in a portable format
Most of these are self-service in Dashboard → Settings → Privacy & data, including an immediate download of everything we hold about your account. Anything else: privacy@easyretale.com. We respond within one month.
You may also complain to your data protection authority. In Ireland that is the Data Protection Commission, dataprotection.ie.
Security
Passwords are hashed with bcrypt. Staff PINs and payment provider credentials are encrypted at rest. Access tokens are short-lived and held in memory rather than browser storage. Two-factor authentication is available on every account.
Cookies
We set only what is necessary to sign you in and keep the app working. Optional cookies are set only if you accept them — see the cookie policy.
Changes
If we make a material change we will tell account holders by email before it takes effect. The date at the top of this page always reflects the current version.