GDPR: How we handle your customers' data

For merchants using RetailPilot: roles, sub-processors, EU data residency, and data deletion.

Last updated: July 2026

1. The roles: you are the controller, we are the processor

When you use RetailPilot, some of your own customers' data passes through the platform — for example, a return order in ReturnFlow includes the end customer's name and email address.

For this data, under the GDPR, you (the merchant) are the data controller and RetailPilot acts as a data processor: we process the data exclusively on your behalf and according to your instructions, as expressed through your use of the platform.

2. Which of your customers' data we process

  • Order and return details synced from your WooCommerce webshop (names, email addresses, order information).
  • Customer details that appear in TicketFlow tickets (such as name and communication history).
  • Data your staff enters while operating the modules (for example, register receipts in SyncRegister).

We process only what is necessary for the modules you use to function.

3. Only on your instructions

We do not use your customers' data for our own purposes. We do not sell it, rent it, or use it for advertising. Our staff's access is limited to what is required for technical support and maintenance.

4. Sub-processors

We use the following sub-processors to operate the service:

  • Hetzner — hosting of the platform and databases in data centers in Germany (EU).
  • Cloudflare — CDN and DNS management.
  • Resend — delivery of emails related to the operation of the platform.
  • Stripe — processing of your own subscription payments (not your customers' payments).

If we add a new sub-processor, this page is updated.

5. EU data residency

Your platform data is stored on Hetzner infrastructure in Germany and remains within the European Union.

6. Security and data isolation

  • Each business has its own, isolated database (full per-account separation).
  • All connections are encrypted (TLS/HTTPS).
  • Passwords are always stored hashed.
  • Sensitive actions are protected by PIN authorization; returns keep a full audit trail.

7. Data deletion

When our cooperation ends and your account is terminated, your business data — including your customers' data — is deleted from the platform within a reasonable period. If you need your data before deletion, contact us at support@retailpilot.io.

8. How this supports your own GDPR duties

As the controller, you have your own obligations towards your customers. RetailPilot makes them easier to meet:

  • Data subject requests: your customers' data lives in your own account; if you need help locating, correcting, or deleting a specific customer's data, our team is available at support@retailpilot.io.
  • Records of processing: this page and the sub-processor list help you complete your own records of processing activities (Article 30 GDPR).
  • EU residency: hosting in Germany simplifies your obligations regarding data transfers outside the EU.

9. Contact

For questions about data processing or a data processing agreement (DPA), contact support@retailpilot.io.

This page is provided for information and does not constitute legal advice.

For questions about data processing: support@retailpilot.io

Try RetailPilot for free

14-day free trial — no credit card required. Cancel anytime.

Start Free Trial