Privacy Policy

Last updated: 27 August 2026

This Privacy Policy explains, in accordance with Articles 13 and 14 of the General Data Protection Regulation (GDPR) and the Data Protection Act 2018 (Ireland), which personal data we process on ie.shopilo.com, the purposes for which we do so, the legal bases we rely on and the rights you have. We take the protection of your data seriously and process personal data only to the extent strictly necessary.

1. Data controller

The controller within the meaning of Article 4(7) GDPR for the processing of personal data on ie.shopilo.com is:

DontPayFull SRL
Str. Zece Mese Nr. 9, Ap. 1
024061 Bucharest
Romania

Trade register entry: J40/14765/2015 (Romanian Trade Register — Registrul Comerțului, Bucharest)
VAT number: RO35294618

Legal representatives: Andrei Vasilescu (CEO), Adrian Cristea (CTO)

Email: [email protected]
Telephone: +40 748 316 698

1.1 Data Protection Officer

Based on our assessment, the appointment of a Data Protection Officer under Article 37 GDPR is not currently mandatory for our company. For all data protection queries, please contact [email protected].

1.2 What we do NOT collect

The website ie.shopilo.com expressly does not collect:

  • Payment or bank details — purchases are completed exclusively on the retailers’ websites
  • Special categories of personal data (Article 9 GDPR), e.g. health data, ethnic origin, political opinions
  • The contents of shopping baskets at any retailer
  • Affiliate tracking cookies — these are set exclusively by retailers on their own domains; ie.shopilo.com sets no affiliate cookies itself

The Shopilo mobile app additionally does not collect mobile advertising identifiers (Apple IDFA / Google Advertising ID) and embeds no advertising SDKs and no third-party analytics SDKs. Google Analytics 4 and Meta Pixel run only on the website, not in the app.

2. What data do we process and why?

The following table gives an overview of all processing activities on ie.shopilo.com:

Data categorySpecific dataPurpose of processingLegal basisRetention
A. Usage dataAnonymised navigation history, city and country (derived from the IP address; the IP is subsequently truncated on an EU proxy server and never stored in full), browser type, operating system, screen resolution, pages visited, session duration, referring URLAnalysis of website usage (Google Analytics 4), service optimisation, error diagnosisArticle 6(1)(a) GDPR — consent, in conjunction with Regulation 5(3) of S.I. No. 336 of 2011; collected only after you accept “Analytics” in the cookie banner14 months (maximum GA4 user-data retention setting)
B. Cookie/consent dataConsent preferences and timestamp of consent, stored by CookieScriptEvidencing and managing cookie consent in accordance with Regulation 5 of S.I. No. 336 of 2011 and Article 7 GDPRArticle 6(1)(c) GDPR — legal obligation6 months (consent is then requested again, per DPC guidance)
C. Marketing dataPage views, conversion events via Meta Pixel (active only where consent has been given)Audience analysis and reach measurement for marketing campaignsArticle 6(1)(a) GDPR — consent (obtained via CookieScript)90 days
D. Account dataEmail address, display name, saved search preferences (only where you voluntarily register an account)Provision of personalised service features (favourites list, search history, price alert management)Article 6(1)(b) GDPR — performance of a contractDuration of the account + 30 days after account closure
E. Price alert dataEmail address for price notifications, desired product and target price (only where you expressly sign up)Sending price notification emails when the price falls below your targetArticle 6(1)(a) GDPR — consent; withdrawable at any timeUntil you unsubscribe from the price alert

2.1 Legitimate interests (Article 6(1)(f) GDPR)

We rely on legitimate interests only to a limited extent: to operate the service in a technically stable and secure manner, to detect and prevent abuse, and to maintain short-lived security logs. In line with the Data Protection Commission’s guidance on cookies, we do not rely on legitimate interest for analytics — Google Analytics 4 runs only with your consent. In our balancing test we have taken into account that usage data is anonymised server-side before being passed to Google Analytics 4 (IP truncation via an EU proxy, Google Signals disabled) and that no data is passed to third parties for their own purposes.

2.2 Price alerts and newsletters — double opt-in

Price alerts require your express consent via a double opt-in procedure, in accordance with Article 6(1)(a) GDPR. Should we offer a newsletter in the future, the same will apply; consent will be obtained in accordance with Regulation 13 of S.I. No. 336 of 2011 (unsolicited electronic communications) in conjunction with Article 6(1)(a) GDPR. Legitimate interest is expressly excluded as a legal basis for email marketing.

2.3 Children

The website ie.shopilo.com is not directed at children or young people under 16. Under section 31 of the Data Protection Act 2018, which gives effect to Article 8 GDPR, the age of digital consent in Ireland is 16 years. We do not knowingly collect personal data from persons under 16. Should we become aware that such data has been collected, we will delete it without delay.

In addition, section 30 of the Data Protection Act 2018 prohibits the processing of children’s personal data for the purposes of direct marketing, profiling or micro-targeting. This website does not carry out any direct marketing, profiling or micro-targeting directed at children.

Shopilo mobile app — additional processing

In addition to the processing described above, the following applies when you use the Shopilo mobile app (iOS and Android). Sign-in to the app is passwordless: a one-time code or magic link is sent to your email address. Your account, followed stores and newsletter preferences are the same account data as on the website (see category D above).

Data categorySpecific dataPurpose of processingLegal basisRetention
F. Push notification dataPush token (Expo push token), device model and operating system version, app platform and language, notification permission statusDelivery of push notifications in the app (e.g. updates from stores you follow)Article 6(1)(a) GDPR — consent, given via the operating system’s notification permission prompt; withdrawable at any time in your device settingsUntil you revoke notification permission, sign out or delete your account; invalid tokens are removed automatically
G. Device and security dataStable app-installation identifier (used for guest sessions before you sign in), device integrity attestation (Apple App Attest / Google Play Integrity), crash and error diagnostics (device model, operating system version, app version, technical error details)Secure operation of the app and its API, prevention of abuse and fraud, app stability and error diagnosisArticle 6(1)(f) GDPR — legitimate interest in a secure and stable serviceInstallation identifier: for the duration of the app installation; attestation verdicts: short-lived (per session); crash diagnostics: 90 days

The processing carried out in the app on the basis of legitimate interest (Article 6(1)(f) GDPR) comprises: the stable app-installation identifier used to provide guest sessions and secure API access, the device integrity attestation performed via Apple App Attest and Google Play Integrity to protect our services against abuse and automated attacks, and crash and error diagnostics used to keep the app stable. Crash diagnostics are processed exclusively on our own self-hosted error-monitoring infrastructure (Sentry, operated by DontPayFull SRL on servers under our control). None of this data is used for advertising or profiling.

3. Processors and recipients

We use the following processors in accordance with Article 28 GDPR. Data processing agreements (DPAs) have been concluded with all processors:

ProcessorAddressPurposeCountryTransfer legal basisPrivacy information
Google LLC1600 Amphitheatre Pkwy, Mountain View, CA 94043, USAGoogle Analytics 4 (web analytics)USAEU-US Data Privacy Framework (DPF)policies.google.com/privacy
Meta Platforms Inc.1 Hacker Way, Menlo Park, CA 94025, USAMeta Pixel (marketing, only with consent)USAEU-US Data Privacy Framework (DPF)facebook.com/privacy/policy
Hetzner Online GmbHIndustriestr. 25, 91710 Gunzenhausen, GermanyHosting and server operation (incl. EU proxy for GA4)Germany (EU)Article 28 GDPR (DPA in place) — intra-EUhetzner.com/legal/privacy-policy
Cloudflare Inc.101 Townsend St., San Francisco, CA 94107, USACDN, DDoS protection, web securityUSA (processing via EU PoPs)EU-US DPF + Standard Contractual Clauses (SCCs)cloudflare.com/privacypolicy
CookieScriptEUCookie consent management (Consent Management Platform)EUArticle 28 GDPR (DPA in place) — intra-EUcookie-script.com/privacy-policy

Other third parties receive your personal data only where this is required by law (e.g. at the request of law enforcement authorities on production of a legally binding order) or where you have expressly consented.

Shopilo mobile app — additional recipients

If you enable push notifications in the Shopilo mobile app, a push token is generated via the Expo Push Service (650 Industries, Inc., USA) and notifications are delivered through the notification service of your device platform — Apple Push Notification service (Apple Inc.) on iOS or Firebase Cloud Messaging (Google LLC) on Android. The push token is a technical routing identifier; it is not used for advertising or cross-app tracking. To protect our API against abuse, the app verifies the integrity of the device and of the app installation using Apple App Attest (iOS) and the Google Play Integrity API (Android); in the course of this check, Apple or Google receives a technical attestation request from your device. The app also periodically checks for application updates via Expo’s EAS Update service, which technically involves transmitting your IP address to Expo’s servers.

Processor / recipientPurpose (mobile app)CountryTransfer legal basisPrivacy information
650 Industries, Inc. (“Expo”)Expo Push Service (routing of push notifications) and EAS Update (delivery of app updates)USAStandard Contractual Clauses (SCCs), Article 46(2)(c) GDPRexpo.dev/privacy
Apple Inc.Apple Push Notification service (delivery of push notifications on iOS) and App Attest (device integrity checks)USAEU-US Data Privacy Framework (DPF)apple.com/legal/privacy
Google LLCFirebase Cloud Messaging (delivery of push notifications on Android) and Play Integrity API (device integrity checks)USAEU-US Data Privacy Framework (DPF)policies.google.com/privacy

4. International data transfers

Some of our processors are established outside the European Economic Area (EEA). For such third-country transfers we ensure the level of protection required by Articles 44 et seq. GDPR as follows:

4.1 Google LLC and Meta Platforms Inc. — EU-US Data Privacy Framework

Google LLC and Meta Platforms Inc. are certified under the EU-US Data Privacy Framework (DPF), recognised by the European Commission in its adequacy decision of 10 July 2023 (C(2023) 4745). Transfers to the USA are therefore permitted under Article 45 GDPR. The current certifications can be viewed at dataprivacyframework.gov.

4.2 Google Analytics 4 — additional technical safeguards

We have configured Google Analytics 4 with the following privacy-friendly settings:

  • IP anonymisation: active — the IP address is truncated on our EU proxy server (Hetzner, Germany) before transmission to Google, so no full IP value ever reaches Google
  • Server-side tagging: enabled — data points are first processed and filtered on our EU server
  • Google Signals: disabled — no cross-device user identification by Google

4.3 Cloudflare Inc. — DPF and Standard Contractual Clauses

Cloudflare is also certified under the EU-US DPF. In addition, Standard Contractual Clauses (SCCs) under Article 46(2)(c) GDPR have been agreed. The majority of data processing takes place via European points of presence (PoPs) within the EEA.

4.4 Hetzner Online GmbH and CookieScript — intra-EU

Hetzner Online GmbH (Germany) and CookieScript (EU) process data exclusively within the EEA. No specific third-country transfer safeguards are required for these processors.

Apple Inc. and 650 Industries, Inc. (Expo) — mobile app

For the Shopilo mobile app, Apple Inc. (Apple Push Notification service, App Attest) and Google LLC (Firebase Cloud Messaging, Play Integrity) are certified under the EU-US Data Privacy Framework (DPF); transfers to the USA are therefore permitted under Article 45 GDPR. 650 Industries, Inc. (“Expo”, USA) processes push tokens and app-update requests; these transfers are safeguarded by Standard Contractual Clauses (SCCs) under Article 46(2)(c) GDPR, concluded as part of Expo’s data processing agreement.

5. Cookies and tracking

The Shopilo mobile app itself sets no cookies and embeds no third-party tracking, advertising or analytics SDKs. This section concerns the website only.

Applicable Irish law — ePrivacy Regulations 2011: the use of cookies and similar technologies in Ireland is governed by the European Communities (Electronic Communications Networks and Services) (Privacy and Electronic Communications) Regulations 2011 (S.I. No. 336 of 2011), supervised by the Data Protection Commission. Non-essential cookies are set exclusively on the basis of your express consent (Regulation 5(3)). Strictly necessary cookies, without which the service could not operate, are used on the basis of the exemption in Regulation 5(5).

5.1 Consent management via CookieScript

On your first visit to ie.shopilo.com, a cookie banner provided by CookieScript is displayed. There you can give or refuse consent for individual cookie categories; refusing is as easy as accepting, no boxes are pre-ticked, and browsing or scrolling is never treated as consent. Your preferences are stored and can be withdrawn or changed at any time via the cookie settings link in the footer. Withdrawal does not affect the lawfulness of processing based on consent before its withdrawal.

5.2 Cookie categories

Strictly necessary cookies (no opt-in required, Regulation 5(5) of S.I. No. 336 of 2011): these cookies are essential for the operation of the service, e.g. to store your consent decision (CookieScript session cookie) or to provide basic security functions (Cloudflare).

Analytics cookies (opt-in under Regulation 5(3) of S.I. No. 336 of 2011 + Article 6(1)(a) GDPR): Google Analytics 4 — active only if you have consented. In line with DPC guidance, analytics is never run without consent.

Marketing cookies (opt-in under Regulation 5(3) of S.I. No. 336 of 2011 + Article 6(1)(a) GDPR): Meta Pixel — active exclusively if you have explicitly consented.

5.3 Affiliate cookies

The website ie.shopilo.com sets no affiliate tracking cookies of its own. If you click a retailer link and visit the retailer’s website, the retailer or the relevant affiliate network may set cookies on their own domains. These are governed exclusively by the privacy policy of the relevant retailer or network, not by this Privacy Policy.

5.4 Google Analytics 4 opt-out

In addition to consent management via CookieScript, you can disable data collection by Google Analytics 4 using Google’s browser add-on: tools.google.com/dlpage/gaoptout

Detailed information on all cookies used, their durations and providers can be found in our Cookie Policy.

6. Retention periods

Personal data is deleted or anonymised as soon as the purpose of processing no longer applies and no statutory retention obligations require otherwise. The following table summarises the periods:

Data categoryRetention periodReason / source
A. Usage data (GA4)14 monthsMaximum GA4 user-data retention setting; automatic deletion by Google thereafter
B. Cookie/consent data (CookieScript)6 monthsEvidence of consent; consent renewed after expiry, in line with DPC guidance (April 2020)
C. Marketing data (Meta Pixel)90 daysMeta default for pixel event data
D. Account dataAccount duration + 30 days after deletionArticle 6(1)(b) GDPR (performance of a contract); 30-day buffer for accidental deletion requests
E. Price alert dataUntil you unsubscribeConsent withdrawable; immediate deletion thereafter
Server logs (security)7 days (Cloudflare) / 30 days (Hetzner)Security logging; automatically overwritten thereafter

Statutory retention obligations (e.g. tax retention obligations under Romanian tax law) may justify longer retention periods in individual cases. In such cases, processing is limited to the extent required by law.

7. Your rights

As a data subject you have the following rights against DontPayFull SRL. To exercise your rights, please contact [email protected]. We respond to your request within one month (Article 12(3) GDPR).

7.1 Rights under the GDPR (Articles 15-22)

RightLegal basisContent
AccessArticle 15 GDPRConfirmation of whether we process personal data about you; a copy of the data and information about the processing
RectificationArticle 16 GDPRCorrection of inaccurate personal data or completion of incomplete personal data
ErasureArticle 17 GDPRErasure of your personal data, unless a statutory retention obligation prevents it
RestrictionArticle 18 GDPRRestriction of processing in the cases provided for by law (e.g. while a rectification request is being examined)
Data portabilityArticle 20 GDPRReceipt of your data in a structured, commonly used, machine-readable format and transmission to another controller (applies to automated processing based on consent or contract)
ObjectionArticle 21 GDPRObjection to processing based on legitimate interests (Article 6(1)(f)); we cease processing unless we can demonstrate compelling legitimate grounds
Withdrawal of consentArticle 7(3) GDPRWithdrawable at any time with effect for the future, without giving reasons; withdrawal does not affect the lawfulness of previous processing
No automated decision-makingArticle 22 GDPRWe take no decisions based solely on automated processing that produce legal effects concerning you

7.2 Additional protections under the Data Protection Act 2018 for persons in Ireland

In addition to your GDPR rights, the Data Protection Act 2018 provides in particular:

  • Section 31 DPA 2018 — the age of digital consent in Ireland is 16 years; we do not knowingly process the data of anyone under that age (see section 2.3)
  • Section 30 DPA 2018 — a prohibition on processing children’s personal data for direct marketing, profiling or micro-targeting, which we fully comply with
  • Complaint to the DPC — you may lodge a complaint with the Data Protection Commission free of charge, using the online form at www.dataprotection.ie (see section 8.2)

7.3 No obligation to provide data

Use of the basic functions of ie.shopilo.com does not require you to provide any personal data. Where the use of certain features (account, price alerts) requires data, you will be informed of this at the point of entry. Not providing this data simply means that the relevant feature cannot be used.

8. Supervisory authorities

You have the right to complain to a data protection supervisory authority about our processing of your personal data (Article 77 GDPR).

8.1 Lead supervisory authority (one-stop-shop)

The competent lead supervisory authority under Article 56 GDPR (one-stop-shop mechanism) is the Romanian data protection authority:

ANSPDCP — Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal
(National Supervisory Authority for Personal Data Processing, Romania)
B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, 010336 Bucharest, Romania
Website: www.dataprotection.ro

8.2 Local supervisory authority for users in Ireland

Users in Ireland can also contact the Irish supervisory authority; a complaint can be submitted via the online form on its website:

Data Protection Commission (DPC)
21 Fitzwilliam Square South, Dublin 2, D02 RD28, Ireland
Website: www.dataprotection.ie

The right to complain to a supervisory authority is without prejudice to any other remedy available to you.

9. Contact and data protection requests

For all data protection questions, to exercise your rights or for data protection notifications, please contact:

DontPayFull SRL — Data Protection
Str. Zece Mese Nr. 9, Ap. 1
024061 Bucharest
Romania

Email: [email protected]
Telephone: +40 748 316 698

We respond to data protection requests free of charge within one month (Article 12(3) GDPR). For complex or numerous requests, we may extend this period by a further two months, in which case we will inform you in advance.

9.1 Proof of identity for data subject requests

To protect your data from unauthorised access, we may request reasonable proof of identity for data subject requests. We will use the identification data collected exclusively to process your request and will delete it afterwards.

9.2 Changes to this Privacy Policy

We reserve the right to amend this Privacy Policy where legislation, technical circumstances or our service change. We will announce material changes at least 14 days before they take effect by means of a clear notice on ie.shopilo.com or, where possible, by email to registered users. Changes are not deemed accepted through continued use of the service; instead, we will ask you to actively acknowledge them. The date of the last update at the top of this page will be adjusted accordingly.

Further legal information can be found in our Legal Notice, the Terms and Conditions and the Cookie Policy.


As of: 27 August 2026 — DontPayFull SRL, Bucharest, Romania — J40/14765/2015 — VAT no. RO35294618