Privacy Policy

Last updated: 24 August 2026

This Privacy Policy explains, in accordance with Articles 13 and 14 of the General Data Protection Regulation (GDPR), which personal data we process on www.shopilo.com and in the Shopilo mobile app, the purposes for which we do so, the legal bases we rely on and the rights you have. We take the protection of your data seriously and process personal data only to the extent strictly necessary.

1. Data controller

The controller within the meaning of Article 4(7) GDPR for the processing of personal data on www.shopilo.com and in the Shopilo mobile app is:

DontPayFull SRL
Str. Zece Mese Nr. 9, Ap. 1
024061 Bucharest
Romania

Trade register entry: J40/14765/2015 (Romanian Trade Register — Registrul Comerțului, Bucharest)
VAT number: RO35294618

Legal representatives: Andrei Vasilescu (CEO), Adrian Cristea (CTO)

Email: [email protected]
Telephone: +40 748 316 698

1.1 Data Protection Officer

Based on our assessment, the appointment of a Data Protection Officer under Article 37 GDPR is not currently mandatory for our company. For all data protection queries, please contact [email protected].

1.2 What we do NOT collect

The website www.shopilo.com and the Shopilo mobile app expressly do not collect:

  • Payment or bank details — purchases are completed exclusively on the retailers’ websites
  • Special categories of personal data (Article 9 GDPR), e.g. health data, ethnic origin, political opinions
  • The contents of shopping baskets at any retailer
  • Affiliate tracking cookies — these are set exclusively by retailers on their own domains; www.shopilo.com sets no affiliate cookies itself
  • Mobile advertising identifiers (Apple IDFA / Google Advertising ID) — the Shopilo mobile app contains no advertising SDKs and no third-party analytics SDKs; Google Analytics 4 and Meta Pixel run only on the website, not in the app

2. What data do we process and why?

The following table gives an overview of all processing activities on www.shopilo.com and in the Shopilo mobile app:

Data categorySpecific dataPurpose of processingLegal basisRetention
A. Usage dataAnonymised navigation history, city and country (derived from the IP address; the IP is subsequently truncated on an EU proxy server and never stored in full), browser type, operating system, screen resolution, pages visited, session duration, referring URLAnalysis of website usage (Google Analytics 4), service optimisation, error diagnosisArticle 6(1)(a) GDPR — consent, in conjunction with Article 5(3) of the ePrivacy Directive 2002/58/EC; collected only after you accept “Analytics” in the cookie banner14 months (maximum GA4 user-data retention setting)
B. Cookie/consent dataConsent preferences and timestamp of consent, stored by CookieScriptEvidencing and managing cookie consent in accordance with Article 5(3) of the ePrivacy Directive 2002/58/EC and Article 7 GDPRArticle 6(1)(c) GDPR — legal obligation6 months (consent is then requested again, in line with supervisory-authority guidance)
C. Marketing dataPage views, conversion events via Meta Pixel (active only where consent has been given)Audience analysis and reach measurement for marketing campaignsArticle 6(1)(a) GDPR — consent (obtained via CookieScript)90 days
D. Account dataEmail address, display name, saved search preferences, followed stores and newsletter preferences (only where you voluntarily register an account; sign-in is passwordless — via a one-time code or magic link sent to your email address)Provision of personalised service features (favourites list, search history, price alert management)Article 6(1)(b) GDPR — performance of a contractDuration of the account + 30 days after account closure
E. Price alert dataEmail address for price notifications, desired product and target price (only where you expressly sign up)Sending price notification emails when the price falls below your targetArticle 6(1)(a) GDPR — consent; withdrawable at any timeUntil you unsubscribe from the price alert
F. Push notification data (mobile app)Push token (Expo push token), device model and operating system version, app platform and language, notification permission statusDelivery of push notifications in the Shopilo mobile app (e.g. updates from stores you follow)Article 6(1)(a) GDPR — consent, given via the operating system’s notification permission prompt; withdrawable at any time in your device settingsUntil you revoke notification permission, sign out or delete your account; invalid tokens are removed automatically
G. Device and security data (mobile app)Stable app-installation identifier (used for guest sessions before you sign in), device integrity attestation (Apple App Attest / Google Play Integrity), crash and error diagnostics (device model, operating system version, app version, technical error details)Secure operation of the app and its API, prevention of abuse and fraud, app stability and error diagnosisArticle 6(1)(f) GDPR — legitimate interest in a secure and stable serviceInstallation identifier: for the duration of the app installation; attestation verdicts: short-lived (per session); crash diagnostics: 90 days

2.1 Legitimate interests (Article 6(1)(f) GDPR)

We rely on legitimate interests only to a limited extent: to operate the service in a technically stable and secure manner, to detect and prevent abuse, and to maintain short-lived security logs. In line with EU supervisory authorities’ guidance on cookies, we do not rely on legitimate interest for analytics — Google Analytics 4 runs only with your consent. In our balancing test we have taken into account that usage data is anonymised server-side before being passed to Google Analytics 4 (IP truncation via an EU proxy, Google Signals disabled) and that no data is passed to third parties for their own purposes.

In the Shopilo mobile app, the processing carried out on the basis of legitimate interest (Article 6(1)(f) GDPR) comprises: the stable app-installation identifier used to provide guest sessions and secure API access, the device integrity attestation performed via Apple App Attest and Google Play Integrity to protect our services against abuse and automated attacks, and crash and error diagnostics used to keep the app stable (see categories F and G in the table above and Section 3). None of this data is used for advertising or profiling.

2.2 Price alerts and newsletters — double opt-in

Price alerts require your express consent via a double opt-in procedure, in accordance with Article 6(1)(a) GDPR. Should we offer a newsletter in the future, the same will apply; consent will be obtained in accordance with Article 13 of the ePrivacy Directive 2002/58/EC (unsolicited communications) in conjunction with Article 6(1)(a) GDPR. Legitimate interest is expressly excluded as a legal basis for email marketing.

2.3 Children

The website www.shopilo.com and the Shopilo mobile app are not directed at children or young people under 16. Under Article 8 GDPR, the age of digital consent is 16 years, unless the law of an EU/EEA Member State provides for a lower age. We do not knowingly collect personal data from persons under 16. Should we become aware that such data has been collected, we will delete it without delay.

In addition, we do not process children’s personal data for the purposes of direct marketing, profiling or micro-targeting. Neither the website nor the app carries out any direct marketing, profiling or micro-targeting directed at children.

3. Processors and recipients

We use the following processors in accordance with Article 28 GDPR. Data processing agreements (DPAs) have been concluded with all processors:

ProcessorAddressPurposeCountryTransfer legal basisPrivacy information
Google LLC1600 Amphitheatre Pkwy, Mountain View, CA 94043, USAGoogle Analytics 4 (web analytics, website only); Firebase Cloud Messaging (delivery of push notifications on Android) and Play Integrity API (device integrity checks) for the mobile appUSAEU-US Data Privacy Framework (DPF)policies.google.com/privacy
Meta Platforms Inc.1 Hacker Way, Menlo Park, CA 94025, USAMeta Pixel (marketing, only with consent)USAEU-US Data Privacy Framework (DPF)facebook.com/privacy/policy
Hetzner Online GmbHIndustriestr. 25, 91710 Gunzenhausen, GermanyHosting and server operation (incl. EU proxy for GA4)Germany (EU)Article 28 GDPR (DPA in place) — intra-EUhetzner.com/legal/privacy-policy
Cloudflare Inc.101 Townsend St., San Francisco, CA 94107, USACDN, DDoS protection, web security, contact form bot protection (Turnstile)USA (processing via EU PoPs)EU-US DPF + Standard Contractual Clauses (SCCs)cloudflare.com/privacypolicy
CookieScriptEUCookie consent management (Consent Management Platform)EUArticle 28 GDPR (DPA in place) — intra-EUcookie-script.com/privacy-policy
650 Industries, Inc. (“Expo”)USAExpo Push Service (routing of mobile push notifications) and EAS Update (delivery of app updates) for the Shopilo mobile appUSAStandard Contractual Clauses (SCCs), Article 46(2)(c) GDPRexpo.dev/privacy
Apple Inc.One Apple Park Way, Cupertino, CA 95014, USAApple Push Notification service (delivery of push notifications on iOS) and App Attest (device integrity checks) for the mobile appUSAEU-US Data Privacy Framework (DPF)apple.com/legal/privacy

Messages submitted through the contact form on www.shopilo.com are protected against automated abuse by Cloudflare Turnstile (Cloudflare Inc., see above) and are delivered to us by email via Twilio SendGrid (Twilio Inc., USA; certified under the EU-US Data Privacy Framework). The data you provide there is used solely to handle your enquiry.

For the stability of the Shopilo mobile app we process crash and error diagnostics (device model, operating system version, app version and the technical error details) on the basis of Article 6(1)(f) GDPR. This data is processed exclusively on our own self-hosted error-monitoring infrastructure (Sentry, operated by DontPayFull SRL on servers under our control) and is not shared with any third-party analytics provider.

If you enable push notifications in the Shopilo mobile app, a push token is generated via the Expo Push Service (650 Industries, Inc., USA) and notifications are delivered through the notification service of your device platform — Apple Push Notification service (Apple Inc.) on iOS or Firebase Cloud Messaging (Google LLC) on Android. The push token is a technical routing identifier; it is not used for advertising or cross-app tracking. In addition, to protect our API against abuse, the app verifies the integrity of the device and of the app installation using Apple App Attest (iOS) and the Google Play Integrity API (Android); in the course of this check, Apple or Google receives a technical attestation request from your device. The app also periodically checks for application updates via Expo’s EAS Update service, which technically involves transmitting your IP address to Expo’s servers.

Other third parties receive your personal data only where this is required by law (e.g. at the request of law enforcement authorities on production of a legally binding order) or where you have expressly consented.

4. International data transfers

Some of our processors are established outside the European Economic Area (EEA). For such third-country transfers we ensure the level of protection required by Articles 44 et seq. GDPR as follows:

4.1 Google LLC, Meta Platforms Inc. and Apple Inc. — EU-US Data Privacy Framework

Google LLC (Google Analytics 4 on the website; Firebase Cloud Messaging and Play Integrity for the mobile app), Meta Platforms Inc. (Meta Pixel, website only) and Apple Inc. (Apple Push Notification service and App Attest for the mobile app) are certified under the EU-US Data Privacy Framework (DPF), recognised by the European Commission in its adequacy decision of 10 July 2023 (C(2023) 4745). Transfers to the USA are therefore permitted under Article 45 GDPR. The current certifications can be viewed at dataprivacyframework.gov.

4.2 Google Analytics 4 — additional technical safeguards

We have configured Google Analytics 4 with the following privacy-friendly settings:

  • IP anonymisation: active — the IP address is truncated on our EU proxy server (Hetzner, Germany) before transmission to Google, so no full IP value ever reaches Google
  • Server-side tagging: enabled — data points are first processed and filtered on our EU server
  • Google Signals: disabled — no cross-device user identification by Google

4.3 Cloudflare Inc. — DPF and Standard Contractual Clauses

Cloudflare is also certified under the EU-US DPF. In addition, Standard Contractual Clauses (SCCs) under Article 46(2)(c) GDPR have been agreed. The majority of data processing takes place via European points of presence (PoPs) within the EEA.

4.4 Hetzner Online GmbH and CookieScript — intra-EU

Hetzner Online GmbH (Germany) and CookieScript (EU) process data exclusively within the EEA. No specific third-country transfer safeguards are required for these processors.

4.5 650 Industries, Inc. (Expo) — Standard Contractual Clauses

650 Industries, Inc. (“Expo”, USA) processes push tokens and app-update requests for the Shopilo mobile app. These transfers are safeguarded by Standard Contractual Clauses (SCCs) under Article 46(2)(c) GDPR, concluded as part of Expo’s data processing agreement.

5. Cookies and tracking

Applicable EU law — ePrivacy Directive: the use of cookies and similar technologies in the EU/EEA is governed by Directive 2002/58/EC (ePrivacy Directive), as implemented in the national law of the Member States, supervised by the national data protection authorities. Non-essential cookies are set exclusively on the basis of your express consent (Article 5(3) ePrivacy Directive). Strictly necessary cookies, without which the service could not operate, are used on the basis of the exemption in Article 5(3).

The Shopilo mobile app itself sets no cookies and embeds no third-party tracking, advertising or analytics SDKs. The remainder of this section concerns the website www.shopilo.com.

5.1 Consent management via CookieScript

On your first visit to www.shopilo.com, a cookie banner provided by CookieScript is displayed. There you can give or refuse consent for individual cookie categories; refusing is as easy as accepting, no boxes are pre-ticked, and browsing or scrolling is never treated as consent. Your preferences are stored and can be withdrawn or changed at any time via the cookie settings link in the footer. Withdrawal does not affect the lawfulness of processing based on consent before its withdrawal.

5.2 Cookie categories

Strictly necessary cookies (no opt-in required, exemption in Article 5(3) of the ePrivacy Directive 2002/58/EC): these cookies are essential for the operation of the service, e.g. to store your consent decision (CookieScript session cookie) or to provide basic security functions (Cloudflare).

Analytics cookies (opt-in under Article 5(3) of the ePrivacy Directive 2002/58/EC + Article 6(1)(a) GDPR): Google Analytics 4 — active only if you have consented. In line with supervisory-authority guidance, analytics is never run without consent.

Marketing cookies (opt-in under Article 5(3) of the ePrivacy Directive 2002/58/EC + Article 6(1)(a) GDPR): Meta Pixel — active exclusively if you have explicitly consented.

5.3 Affiliate cookies

The website www.shopilo.com and the Shopilo mobile app set no affiliate tracking cookies of their own. If you click a retailer link and visit the retailer’s website, the retailer or the relevant affiliate network may set cookies on their own domains. These are governed exclusively by the privacy policy of the relevant retailer or network, not by this Privacy Policy.

5.4 Google Analytics 4 opt-out

In addition to consent management via CookieScript, you can disable data collection by Google Analytics 4 using Google’s browser add-on: tools.google.com/dlpage/gaoptout

Detailed information on all cookies used, their durations and providers can be found in our Cookie Policy.

6. Retention periods

Personal data is deleted or anonymised as soon as the purpose of processing no longer applies and no statutory retention obligations require otherwise. The following table summarises the periods:

Data categoryRetention periodReason / source
A. Usage data (GA4)14 monthsMaximum GA4 user-data retention setting; automatic deletion by Google thereafter
B. Cookie/consent data (CookieScript)6 monthsEvidence of consent; consent renewed after expiry, in line with supervisory-authority guidance
C. Marketing data (Meta Pixel)90 daysMeta default for pixel event data
D. Account dataAccount duration + 30 days after deletionArticle 6(1)(b) GDPR (performance of a contract); 30-day buffer for accidental deletion requests
E. Price alert dataUntil you unsubscribeConsent withdrawable; immediate deletion thereafter
F. Push notification data (mobile app)Until permission is revoked, you sign out or the account is deletedConsent withdrawable via device settings; invalid tokens removed automatically at the next registration sync
G. Device and security data (mobile app)Installation identifier: duration of the installation; attestation verdicts: short-lived (per session); crash diagnostics: 90 daysSecurity and stability logging on self-hosted infrastructure; automatic deletion thereafter
Server logs (security)7 days (Cloudflare) / 30 days (Hetzner)Security logging; automatically overwritten thereafter

Statutory retention obligations (e.g. tax retention obligations under Romanian tax law) may justify longer retention periods in individual cases. In such cases, processing is limited to the extent required by law.

7. Your rights

As a data subject you have the following rights against DontPayFull SRL. To exercise your rights, please contact [email protected]. We respond to your request within one month (Article 12(3) GDPR).

7.1 Rights under the GDPR (Articles 15-22)

RightLegal basisContent
AccessArticle 15 GDPRConfirmation of whether we process personal data about you; a copy of the data and information about the processing
RectificationArticle 16 GDPRCorrection of inaccurate personal data or completion of incomplete personal data
ErasureArticle 17 GDPRErasure of your personal data, unless a statutory retention obligation prevents it
RestrictionArticle 18 GDPRRestriction of processing in the cases provided for by law (e.g. while a rectification request is being examined)
Data portabilityArticle 20 GDPRReceipt of your data in a structured, commonly used, machine-readable format and transmission to another controller (applies to automated processing based on consent or contract)
ObjectionArticle 21 GDPRObjection to processing based on legitimate interests (Article 6(1)(f)); we cease processing unless we can demonstrate compelling legitimate grounds
Withdrawal of consentArticle 7(3) GDPRWithdrawable at any time with effect for the future, without giving reasons; withdrawal does not affect the lawfulness of previous processing
No automated decision-makingArticle 22 GDPRWe take no decisions based solely on automated processing that produce legal effects concerning you

7.2 Additional protections and complaint options

In addition to your GDPR rights, please note in particular:

  • Age of digital consent (Article 8 GDPR) — we do not knowingly process the data of anyone under 16 years of age (see section 2.3)
  • Children’s data — we do not process children’s personal data for direct marketing, profiling or micro-targeting
  • Complaint to a supervisory authority — you may lodge a complaint free of charge with the supervisory authority of the EU/EEA Member State in which you live or work, or with ANSPDCP as our lead supervisory authority (see section 8)

7.3 No obligation to provide data

Use of the basic functions of www.shopilo.com and the Shopilo mobile app does not require you to provide any personal data. Where the use of certain features (account, price alerts) requires data, you will be informed of this at the point of entry. Not providing this data simply means that the relevant feature cannot be used.

8. Supervisory authorities

You have the right to complain to a data protection supervisory authority about our processing of your personal data (Article 77 GDPR).

8.1 Lead supervisory authority (one-stop-shop)

The competent lead supervisory authority under Article 56 GDPR (one-stop-shop mechanism) is the Romanian data protection authority:

ANSPDCP — Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal
(National Supervisory Authority for Personal Data Processing, Romania)
B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, 010336 Bucharest, Romania
Website: www.dataprotection.ro

8.2 Your local supervisory authority

You can also contact the supervisory authority of the EU/EEA Member State of your habitual residence, place of work or the place of the alleged infringement (Article 77(1) GDPR). A list of all national data protection authorities is available on the website of the European Data Protection Board: edpb.europa.eu

The right to complain to a supervisory authority is without prejudice to any other remedy available to you.

9. Contact and data protection requests

For all data protection questions, to exercise your rights or for data protection notifications, please contact:

DontPayFull SRL — Data Protection
Str. Zece Mese Nr. 9, Ap. 1
024061 Bucharest
Romania

Email: [email protected]
Telephone: +40 748 316 698

We respond to data protection requests free of charge within one month (Article 12(3) GDPR). For complex or numerous requests, we may extend this period by a further two months, in which case we will inform you in advance.

9.1 Proof of identity for data subject requests

To protect your data from unauthorised access, we may request reasonable proof of identity for data subject requests. We will use the identification data collected exclusively to process your request and will delete it afterwards.

9.2 Changes to this Privacy Policy

We reserve the right to amend this Privacy Policy where legislation, technical circumstances or our service change. We will announce material changes at least 14 days before they take effect by means of a clear notice on www.shopilo.com and in the Shopilo mobile app or, where possible, by email to registered users. Changes are not deemed accepted through continued use of the service; instead, we will ask you to actively acknowledge them. The date of the last update at the top of this page will be adjusted accordingly.

Further legal information can be found in our Legal Notice, the Terms and Conditions and the Cookie Policy.


As of: 11 August 2026 — DontPayFull SRL, Bucharest, Romania — J40/14765/2015 — VAT no. RO35294618