PrestaOne Privacy Policy

Effective date: 2026-08-06 Last updated: 2026-09-10

1. Who we are

PrestaOne is a mobile application and companion service that lets PrestaShop store owners and their staff manage their own store from a phone. PrestaOne is operated by:

MB "Elevio" Company code: 306653242 Registered address: Šilutės pl. 35G-36, LT-94105 Klaipėda, Lithuania VAT code: LT100016572716 Email: [email protected]

We refer to MB "Elevio" as "PrestaOne", "we" or "us" in this policy. This policy covers the PrestaOne mobile application (iOS and Android), the prestaone.app website and the account.prestaone.app customer portal.

2. What this policy does and does not cover

This policy describes the personal data for which we act as the data controller: your PrestaOne account, your devices and app diagnostics, your billing information, and your visits to our websites.

This policy does not apply to data we handle on behalf of our customers as a data processor, or to data that never reaches us at all. That boundary matters for PrestaOne more than for most products, so we spell it out in the next section. Processing we perform on a customer's behalf is governed by our Data Processing Agreement.

3. The three kinds of data around PrestaOne

a) Your account and app data: we are the controller. Described in this policy.

b) Your store's full business records: they never reach our servers. The PrestaOne app talks directly to the PrestaOne module installed on your PrestaShop server over an encrypted connection. Your orders, products, customer records, buyers' personal data and statistics travel between your phone and your server. Our infrastructure does not receive, see or store those full records. To support offline use, the app may keep a size-limited, encrypted local cache of records already fetched from your server. The encryption key is held in the device's secure storage, and the cache is removed when you sign out or remove the Store from the app.

c) Signaling metadata: we are your processor. To deliver push notifications and manage store connections, minimal event metadata (for example, an internal store ID, an order number and amount) passes through our infrastructure. An internal reference or order amount may be personal data where the Customer can link it to a buyer. This is processed on your behalf under the Data Processing Agreement, not this policy.

4. Data we collect from you as an app user

4.1 Account

There are no PrestaOne passwords. You can sign in with a one-time code (OTP) sent to your email, with Google, or with Apple where that option is available. We receive your verified email address and the provider-specific account identifier needed to keep the login linked. Google may also supply a display name or profile image to Firebase Authentication; PrestaOne does not use those optional profile fields for marketing or store data. We request only the email scope from Apple. If you use Apple's Hide My Email option, we receive the Apple relay address instead of your private address.

To operate the one-time code login we temporarily store a cryptographic hash (never the code itself in plain text after issuance) together with attempt counters, and a hash of your IP address (SHA-256) for abuse prevention. The one-time code stops working after 10 minutes. We schedule the code record for deletion after 48 hours and the IP-hash rate-limit record after 2 hours. The infrastructure provider's TTL process may complete physical deletion later.

4.2 Devices and store connections

When you pair the app with a store, we store: a random per-account device identifier; a pseudonymous stability key derived on the device from your account and an operating-system installation identifier; device platform and model (e.g. "iPhone 14"); a push notification token (if you enable notifications); and a connection record (which device is paired with which store, with which permissions). We do not receive an advertising identifier or the raw operating-system identifier used to derive the stability key. Connection and device records are kept while needed to provide the connection, subject to the deletion rules in §11.

4.3 Push notifications

Push notifications are off by default. If you enable them, we store your push token and route notification events through Expo's push service to Google (FCM) or Apple (APNs). Notification payloads deliberately contain no personal data of your buyers, only event type, internal references and, for orders, the amount and currency. Those references and amounts can nevertheless be indirectly personal data when linked to your Store's records. To make delivery reliable, PrestaOne keeps encrypted-access-controlled retry and delivery records for up to 30 days; Expo then holds message content only in delivery queues until handoff, and clears push receipts after 24 hours.

4.4 Optional app usage and technical diagnostics

With your optional consent, the app shares account-linked session events: screen names, named actions, flow steps, operation outcomes, timings, error codes and app/device metadata. Authorised operators can inspect these records to investigate problems and improve the app. Session records are scheduled for deletion after 30 days and removed by daily cleanup. The encrypted local queue is limited to 1,000 events and cleared on withdrawal, account change or app restart. No pre-consent session events are collected or backfilled.

Operational crash and error reports, including native crashes, are handled separately by Sentry, our error-monitoring provider, ingested and stored in the EU (Germany). This reporting starts with the app independently of the optional usage choice. Reports can include stack traces, device/OS and app/build metadata, an internal store identifier and technical breadcrumbs. Native reports may be cached for later delivery. Default PII is disabled and JavaScript reports are sanitised to remove account email, raw IP addresses, input contents and authentication tokens. Sentry retention is plan-dependent and is no longer than 90 days under our current service configuration. Optional performance tracing and replay are not enabled.

You can decline without losing app features or withdraw in Settings → Usage and diagnostics. Withdrawal stops new optional event collection immediately and clears pending session events; offline withdrawal is retried when connected. It does not retrospectively erase reports already sent. Your choice, disclosure version and time are stored with your account separately from Terms acceptance. Operational crash/error reporting, authentication, security, connection and billing records are not controlled by the optional usage setting. See Usage and diagnostics for details.

4.5 Free trial eligibility records

The free trial is available once per email address and once per store. To enforce that without keeping a list of everyone who has ever tried the product, we store a keyed cryptographic fingerprint (HMAC-SHA256) of your email address, of the store identifier and of the store address, together with your account identifier and the trial's status and dates. The fingerprints cannot be reversed to the original values by anyone who does not hold the server-side key, and the original email address and store address are not stored in these records. They are kept for as long as needed to prevent repeated trials.

5. Data we collect from you as a paying customer

Subscriptions are purchased on account.prestaone.app and processed by Stripe. Stripe collects payment method details, billing name/company, billing email and address, country, tax identifiers, invoices, transaction and fraud-prevention data. Card details never touch our application servers. Our application database keeps Stripe customer/subscription/price references, subscription and entitlement status, seat quantity, billing-period/trial/grace dates, and billing event audit metadata. Stripe may act as our processor and as an independent controller where it has its own legal or regulatory obligations. Accounting and tax records are retained where and for as long as applicable law requires.

6. Data we collect from website visitors

6.1 Optional website analytics. If you select Accept analytics, we load Google Analytics 4 on the public prestaone.app website to understand visits and traffic sources. Before that choice, and if you reject analytics, we do not load Google's analytics tag or send analytics events to Google. The customer portal, operator console, review and demo pages are excluded. Website analytics does not collect store business data from the app.

Google receives page views, permitted campaign labels, referring site origin, pseudonymous cookie and session identifiers, and browser/device information. Google processes your IP address to derive approximate location. Google states that it does not log or store individual IP addresses from EU, Switzerland or UK visitors. We strip other URL query parameters and fragments before measurement. Google Signals, advertising personalisation and enhanced measurement are disabled. See how Google uses information from sites using its services.

6.2 Cookies and your choice. You can use Cookie settings on the public website to accept or reject analytics at any time. Withdrawing consent stops collection, removes the analytics cookies set by this site and reloads the page. It does not affect the lawfulness of earlier processing. Your choice is stored locally under prestaone_analytics_consent_v1 for up to 180 days. If you accept, the first-party _ga and _ga_* cookies identify visits and sessions and are configured to expire within 180 days, without extending that period on each visit. Rejecting analytics does not restrict website features.

Our previous first-party pageview counter no longer collects new records. Historical records remain subject to the existing 14-month retention period.

6.3 Waitlist. If you enter your email address in the waitlist form, we store that address together with the form location and the date, so that we can tell you when the product opens. We ask for nothing else. We keep the address until three months after we send the launch message, and in any event no longer than 24 months from the day you signed up. To be removed sooner, email [email protected].

6.4 Customer portal sign-in. The account.prestaone.app portal uses browser local storage or IndexedDB strictly as needed for Firebase Authentication to remember your signed-in session. This authentication state normally persists until you sign out or clear browser data. Google and Apple sign-in open the provider's own authentication surface and are also subject to that provider's privacy terms.

7. Data we do not collect

Because it is unusual, it is worth stating plainly. We do not:

8. Purposes, legal bases and retention

ActivityDataLegal basis (GDPR Art. 6)Retention
Providing your account and sign-inEmail, provider account identifier and optional provider profile fields; OTP hashes and attempt counters when email-code login is used6(1)(b) contractAccount identity until deletion; OTP record scheduled for deletion after 48 h
Abuse and fraud prevention on loginIP address hash6(1)(f) legitimate interest (service security)Scheduled for deletion after 2 h
Store pairing and access controlDevice ID, pseudonymous stability key, platform/model, connection records6(1)(b) contractWhile needed for the connection; successful unpair/account deletion removes operational records, subject to audit/legal exceptions
Push notificationsPush token, notification settings6(1)(b) contract (feature you enable)Until disabled / unpair / token invalid
Push delivery reliabilityInternal reference, amount/currency, recipient/push routing data, delivery status6(1)(b) contract (processed on the Customer's behalf under the DPA)Up to 30 days, then scheduled for TTL deletion
Optional app usageAccount-linked session identifiers, screen/action names, flow outcomes, timings and app/device metadata6(1)(a) consentScheduled for deletion after 30 days; daily cleanup
Operational crash and error diagnosticsJavaScript/native stack traces, device/OS and app/build metadata, internal store ID and technical breadcrumbs6(1)(f) legitimate interest (service reliability and security)Plan-dependent, no longer than 90 days under the current configuration
Billing and taxProvider references, subscription/seat status and billing event metadata; payment and invoice data held by Stripe6(1)(b) contract; 6(1)(c) legal obligation (accounting, tax)Operational subscription data for the account lifecycle; accounting/tax records for applicable statutory periods
Free trial eligibilityKeyed fingerprints of email, store ID and store address; account ID; trial status and dates6(1)(f) legitimate interest (preventing repeated free trials)As long as needed to prevent repeated trials
Optional website analytics (Google Analytics 4)Page views, campaign labels, referring origin, pseudonymous cookie/session identifiers, browser/device and approximate location6(1)(a) consentEvent data: 2 months. User data: 14 months, renewed on new activity. These settings do not limit standard aggregated reports. Cookies and consent choice: up to 180 days
Historical first-party website pageview countsPage path, referrer, campaign parameters, country code, browser language, mobile flag6(1)(f) legitimate interest14 months; no new records
WaitlistEmail address, form location, date6(1)(a) consentThree months after the launch message, and no longer than 24 months from sign-up
Responding to your requestsCorrespondence6(1)(f) legitimate interest; 6(1)(c) where legally requiredAs needed to resolve the request and protect legal rights; ordinarily up to 2 years, longer where required for a legal claim

9. Who we share data with

We use a small number of service providers to run PrestaOne: the backend database and functions (Google Firebase, EU region), the server hosting our websites and customer portal (Hetzner, Finland), transactional email (Resend), push delivery (Expo, Google FCM, Apple APNs), error monitoring (Sentry, EU ingest), payments (Stripe) and edge networking (Cloudflare). The current list, including each provider's role, location and transfer safeguard and legal relationship, is maintained at: Service provider and sub-processor list.

We may also disclose data where required by law or to protect our legal rights. We do not sell personal data.

10. International transfers

Our primary infrastructure is located in the European Union: the service database and backend run in Google Cloud's EU region (Belgium/Netherlands), and crash diagnostics are ingested and stored in Germany. Where a provider processes data in the United States (Expo for push delivery, Resend for transactional email, Stripe, Inc. for certain payment operations), the transfer relies on the EU–US Data Privacy Framework and/or Standard Contractual Clauses, as listed per provider in the service provider and sub-processor list.

11. Your rights

Under the GDPR you have the right to access, rectify, erase, restrict and object to the processing of your personal data, the right to data portability, and the right to withdraw consent where processing is based on consent.

If you are a buyer in a store that uses PrestaOne: your data is controlled by that store's merchant, not by us. Please direct requests to the merchant.

12. Security

Security measures include: no-password authentication with short-lived one-time codes or provider-signed Google/Apple credentials; an OTP verification step before a provider can be linked to an existing account with the same email; secure storage of credentials and the local cache encryption key on your device; encrypted offline business-data cache; TLS on all connections; signed (HMAC) server-to-server messages; deny-by-default database access rules; strict access tokens with 24-hour expiry; and rate limiting throughout. A detailed summary of technical and organisational measures is provided in Annex B of the DPA.

13. Children

PrestaOne is a business tool and is not directed at children. We do not knowingly collect data from anyone under 16.

14. Changes to this policy

We will post changes on this page and update the "Last updated" date. Where required or appropriate, we will give advance notice of material changes by email or in-product notice. Changes required by law, security needs, or to protect users may take effect sooner.

15. Contact

MB "Elevio" · Šilutės pl. 35G-36, LT-94105 Klaipėda, Lithuania · [email protected]