Legal · Last updated 8 Sep 2026

Privacy Policy

How QAIMOS LTD processes data for the GDPR Cookie Banner Shopify app — for merchants and for visitors to these marketing pages.

UK / EU GDPR · Operator QAIMOS LTD

1. Who we are

This Privacy Policy applies to the GDPR Cookie Banner Shopify application and related marketing pages hosted at https://gdpr-production-5d03.up.railway.app.

The controller is QAIMOS LTD, a company registered in the United Kingdom. Director: Vasilij Sviridov.

Contact (placeholders for support / general): support@qaimos.co.uk (support) · hello@qaimos.co.uk (general).

2. What this app does

GDPR Cookie Banner is a Shopify embedded app with a Theme App Embed. Merchants design a cookie consent banner in Shopify admin and publish it to the storefront. The app logs anonymous visitor consent decisions for compliance evidence.

3. Data we process

3.1 Merchant / shop data

3.2 Storefront consent logs (anonymous)

We do not store Shopify customer PII profiles (no customer email, phone, or name dossiers from Shopify Customer objects for consent logging).

3.3 Marketing pages (this site)

These static pages are informational. They may set strictly necessary cookies required for hosting/security, and any analytics cookies only if clearly disclosed and consented where required. Prefer browsing without non-essential trackers; contact us if you need a cookie inventory for a specific deployment.

4. Purposes

5. Legal bases (UK GDPR / EU GDPR)

Merchants remain controllers for how the banner is presented on their storefront and for their own privacy notices. QAIMOS LTD processes shop and consent-log data as described here to operate the app.

6. Retention

7. Processors & subprocessors

8. International transfers

Hosting and subprocessors may process data in the UK, EEA, United States, or other countries. Where required, we rely on appropriate safeguards such as adequacy decisions or Standard Contractual Clauses offered by providers, plus technical measures (encryption in transit, hashed IPs for consent logs).

9. Your rights

Merchants: you may access, correct, or delete shop configuration by using the app and/or uninstalling; uninstall and Shopify shop/redact flows remove shop-associated data from our database as implemented.

Store visitors: the merchant’s store privacy policy is primary. Our consent logs are anonymous (visitor_id, hashed IP, user agent). Where a Shopify customer data request/redact webhook provides a customer id that matches a stored visitor_id, we search and redact matching consent rows.

Under UK/EU GDPR you may have rights to access, rectification, erasure, restriction, portability, and objection, and to lodge a complaint with the ICO (UK) or your local supervisory authority. Contact support@qaimos.co.uk.

10. Children

The app is directed at Shopify merchants (businesses), not children.

11. Changes

We may update this policy. The “Last updated” date at the top will change. Material changes may also be noted in the app changelog.

12. Contact

QAIMOS LTD · Director Vasilij Sviridov
Support: support@qaimos.co.uk (placeholder labelled for support)
General: hello@qaimos.co.uk (placeholder labelled for general enquiries)

Last updated: 8 September 2026