GDPR Compliance Statement
General Data Protection Regulation (GDPR) Compliance
1. Overview
Whaleal is committed to complying with the General Data Protection Regulation (GDPR) (EU) 2016/679. This statement outlines our compliance measures and your rights under GDPR.
Effective Date: October 4, 2026
2. Data Controller
For the purposes of GDPR, the data controller is Whaleal. We determine the purposes and means of processing personal data collected through the Whaleal Cart application.
Contact: support@mail.whaleal.com
3. Legal Basis for Processing
We process personal data under the following legal bases:
- Contract Performance: Processing necessary to provide abandoned cart recovery services
- Legitimate Interests: Analytics, service improvement, and fraud prevention
- Consent: Where explicitly obtained for specific purposes
- Legal Obligation: Compliance with applicable laws and regulations
4. Data Subject Rights
Under GDPR, you have the following rights:
4.1 Right to Access
You have the right to request access to your personal data and information about how we process it.
4.2 Right to Rectification
You have the right to request correction of inaccurate or incomplete personal data.
4.3 Right to Erasure ("Right to be Forgotten")
You have the right to request deletion of your personal data in certain circumstances.
4.4 Right to Restriction of Processing
You have the right to request restriction of processing in certain circumstances.
4.5 Right to Data Portability
You have the right to receive your personal data in a structured, commonly used, machine-readable format.
4.6 Right to Object
You have the right to object to processing based on legitimate interests.
To exercise these rights, contact us at support@mail.whaleal.com
5. Data Processing Activities
| Purpose | Data Types | Legal Basis |
|---|---|---|
| Cart Recovery (Email & SMS) | Email, Phone Number, Name, Cart Items | Contract Performance |
| Email Delivery | Email Address | Contract Performance |
| SMS Delivery | Phone Number | Contract Performance |
| Analytics | Usage Data, Statistics | Legitimate Interests |
| Customer Support | Contact Information | Contract Performance |
6. International Data Transfers
Data may be transferred outside the European Economic Area (EEA). We ensure appropriate safeguards are in place:
- Standard Contractual Clauses (SCCs): EU-approved contractual protections with subprocessors where applicable
- Adequacy Decisions: Transfers to countries recognized by the European Commission as providing adequate protection
7. Data Minimization
We collect only data necessary for abandoned cart recovery: checkout and customer fields received from Shopify webhooks and Admin API (e.g. email, phone number, name, cart contents). We do not track general storefront visitors or use personal data for unrelated purposes.
8. Data Security Measures
We implement technical and organizational measures:
- Encryption in Transit: HTTPS/TLS for all App and API communication
- Encryption at Rest: Production data and backups stored on encrypted cloud infrastructure
- Access Controls: Shopify Session Token authentication; shop-level data isolation; no internal staff customer search UI
- Employee Access: Production systems accessible only to authorized personnel on a need-to-know basis
- Environment Separation: Separate development and production databases
- Automated Deletion: Customer records are deleted after the retention period (maximum 180 days) or upon uninstall / GDPR redact requests
9. Security Incident Response
We maintain procedures to detect, investigate, and respond to security incidents involving personal data, including merchant notification when required by GDPR Articles 33–34, remediation, and cooperation with Shopify and supervisory authorities.
10. Data Retention Periods
Personal data is kept no longer than necessary. The maximum retention period for customer checkout and email records is 180 days.
- Active Stores: Duration of App installation, subject to the 180-day maximum
- Customer Checkout, Email & SMS Data: Up to 180 days, then deleted
- Uninstalled App: Deleted via
shop/redact(within 30 days maximum, per Shopify) - Support Communications: Up to 2 years for record-keeping
11. Third-Party Processors
We engage the following third-party processors:
- Email Delivery: Resend (email service provider)
- SMS Delivery: Your own SMS provider account, used only when you enable the SMS recovery channel
- Hosting: Shopify (platform infrastructure)
- Website Analytics: Google Analytics, used on whaleal.com only and only after the visitor accepts. Advertising cookies and audience building are never used, and no analytics is collected on merchant storefronts or customer checkouts
All processors are bound by data processing agreements complying with GDPR Article 28.
12. Automated Decision-Making
Whaleal does not use automated decision-making or profiling that produces legal effects or similarly significant effects on individuals.
13. Children's Data
The App is not intended for children under 16 (or 13 in certain jurisdictions). We do not knowingly collect personal data from children.
14. Right to Lodge a Complaint
You have the right to lodge a complaint with a supervisory authority if you believe our processing violates GDPR. Contact your local data protection authority.
15. Contact Information
For GDPR-related inquiries:
- Email: support@mail.whaleal.com
- Response Time: Within 30 days
16. Shopify Data Protection Commitments
For Shopify Partner and merchant review, Whaleal Cart confirms compliance with standard data protection requirements:
- Minimum necessary processing: Yes — Section 7
- Merchant transparency: Yes — Sections 2, 3, 5, and 10
- Purpose limitation: Yes — cart recovery and related analytics only
- Merchant agreement: Yes — Privacy Policy + Terms of Service on install
- Customer consent & opt-out: Yes — unsubscribe links and GDPR webhooks
- Data sale / automated legal decisions: Not applicable
- Retention (max 180 days): Yes — Section 10
- Encryption, backups, test/prod separation, DLP: Yes — Section 8
- Employee access limits & strong passwords: Yes — Section 8
- Access logging & incident response: Yes — Sections 8 and 9
Full mapping table: Privacy Policy Section 15
17. Updates to This Statement
We may update this GDPR Compliance Statement periodically. Check this page for the latest version.