Privacy policy
Last updated: 10 September 2026
This site sets no cookies, uses no advertising trackers and does not measure its audience. There is nothing to accept and nothing to refuse: the page you are reading is static HTML. The only data we receive is what you type into a form.
1. Who processes your data
DiGiFoxy LLC, 30 N Gould St Ste R, Sheridan, WY 82801, United States, EIN 98-1969868, is the controller for the processing described below. Contact: [email protected].
2. Two roles, not to be confused
Digifoxy sells online shops; it does not run them. That splits into two distinct situations.
- Your data, when you are a prospect or a customer of Digifoxy
- We are the controller. That is what this policy covers.
- The data of shoppers on a shop we deployed
- The operator of that shop is the controller; Digifoxy acts only as a technical processor, on that operator's instructions. To exercise your rights against a shop, contact its operator, whose details appear on its own legal pages — we are not allowed to act on their data in their place.
3. What we collect, and why
| Situation | Data | Purpose | Legal basis | Retention |
|---|---|---|---|---|
| Demo request form | Name, email address, phone and company if you fill them in, what you sell, your message, the language of the page | Reply to you and prepare a demonstration | Our legitimate interest in handling a commercial enquiry you started | Three years after the last exchange |
| Creating a demo shop | Your name, your email address, the shop name you chose | Create the trial shop and email you its access | Performance of the demonstration you asked for | The demo shop is switched off 24 hours after it is created and its data is removed within the following seven days; contact details are kept three years after the last exchange |
| Subscribing to an offer | Name, email address, phone, shop name, desired domain names, offer and billing period chosen | Form and perform the contract, deploy the shop, invoice | Performance of the contract | For the term of the contract, then the statutory retention period for accounting records |
| Payment | Transaction reference, amount, country, last four digits of the card | Collect payment, prevent fraud, issue the invoice | Performance of the contract and accounting obligations | Statutory retention period for accounting records |
| Email support | The content of your messages | Handle your request and keep a record of what was done | Performance of the contract | Three years after the request is closed |
| Technical logs | IP address, timestamp, page requested, response code | Security, abuse rate limiting, fault diagnosis | Our legitimate interest in protecting the service | Twelve months at most |
We never collect your card number. It is entered directly on Stripe's pages and does not pass through our servers.
We process no special category data within the meaning of Article 9 GDPR, and our services are not intended for children under sixteen.
4. Cookies and analytics
None. digifoxy.com sets no cookie, writes nothing to your browser's local storage, loads no third-party font or script, and uses neither Google Analytics nor any equivalent. That is why there is no consent banner: there is nothing to consent to.
The shops we deploy for customers do use strictly functional local storage — cart, chosen language, shopper session. Those uses are described on each shop's own legal pages.
5. Who else sees your data
We do not sell data, we do not rent it, and we disclose it to no one for advertising. We use the following providers, each for one specific job:
| Provider | Role | Data involved |
|---|---|---|
| Stripe | Collecting subscription payments and preventing fraud | Billing details, transaction data |
| Brevo | Sending transactional email | Name, email address, content of the message sent |
| Cloudflare | Content delivery, DNS, protection against attacks | IP address, request headers |
| Infrastructure provider | Hosting the servers and the database | All of the above, at rest |
| Groq | The shop assistant, where its operator has enabled it | The text of the question asked and the catalogue extract needed to answer it |
We may also disclose data where the law requires it, or to establish or defend a legal claim.
6. Transfers outside the European Union
Digifoxy is established in the United States, and some of its providers are too. Your data may therefore be processed outside the European Economic Area. Those transfers rely on the standard contractual clauses adopted by the European Commission, entered into with the providers concerned.
7. Security
Traffic to the site and the API is encrypted in transit. Secrets and licence keys are encrypted at rest with dedicated keys held separately from the database. Passwords are never stored in clear text. Server access is restricted and authenticated, and each shop's data is partitioned at the database level: one shop cannot read another's data.
8. Your rights
You have the right to access, rectify, erase, restrict, object to and port your data, and to withdraw your consent where processing relies on it. You may also opt out of our commercial messages at any time.
Write to [email protected]. We answer within one month. If our answer does not satisfy you, you may complain to the data protection authority of your country of residence.
If your request concerns a purchase made on a shop we deployed, we pass it to the operator of that shop and tell you we have done so: it is their decision, not ours, what happens to that data.
9. Automated decisions
We take no decision producing legal effects concerning you based solely on automated processing. Risk scores computed by Stripe during a payment may lead to a transaction being declined; you can then write to us for a human review.
10. Changes
This policy may change. The date at the top of the page shows the current version. Any substantial change is announced by email to active customers before it takes effect.
11. Contact
DiGiFoxy LLC — 30 N Gould St Ste R, Sheridan, WY 82801, United States
[email protected]