Privacy Policy
Effective Date: May 24, 2026
1. Introduction
This Privacy Policy explains how AlexDev ("we," "us," or "our"), based in Croatia, collects, uses, and protects your information when you use the Sply24 platform. We are committed to protecting your personal data in accordance with the General Data Protection Regulation (GDPR) and other applicable privacy laws.
2. Information We Collect
A. Personal and Business Information:
We collect personal and company information that you provide when registering, creating a business storefront, or managing your account. Instead of listing every specific data point, our policy is simple: we collect the data you explicitly provide and manage through your dashboard.
You can view, edit, and manage all of your personal and business data at any time by visiting your profile settings at /profile and the respective sections of your personal account.
B. Payment Configuration Data (For Sellers):
If you configure payment methods (such as Stripe ACH or Stripe SEPA) to accept payments from your Buyers, you will need to provide integration keys (e.g., Stripe Secret Key and Webhook Secret). To ensure maximum security, we store these sensitive keys in a strictly encrypted format. We do not store your Buyers' credit card or bank account details on our servers.
C. Automatically Collected and Security Information:
- System logs, IP addresses, browser types, and device information required for platform stability.
- Authentication tokens (JWT) and verification codes used to secure your account access.
3. How We Use Your Information
We use the collected data for the following purposes:
- To provide and maintain the Sply24 platform features.
- To facilitate interactions between Sellers and Buyers (e.g., displaying catalogs and processing order requests).
- To generate automated documents such as PDF invoices and order confirmations.
- To send essential system notifications and updates via email.
- To manage Seller subscriptions and prevent fraud.
4. Data Sharing and Disclosure
We do not sell your personal data. We share information only in the following cases:
- Between Sellers and Buyers: Necessary data (names, order details) is shared between parties to facilitate B2B transactions.
- Service Providers: We share data with trusted third-party providers (e.g., hosting services, Stripe) strictly to perform platform functions.
- Legal Obligations: If required by Croatian or EU law, or in response to valid requests by public authorities.
5. Data Retention and Deletion
We retain your data as long as your account is active. Important for Sellers: If a subscription expires and remains unpaid for more than thirty (30) days, all company-related data, including catalogs and settings, will be permanently deleted from our servers and cannot be recovered.
6. Your Rights (GDPR)
As a user in the EU (or interacting with an EU-based entity), you have the following rights:
- The right to access: You can request copies of your personal data.
- The right to rectification: You can request that we correct any inaccurate information.
- The right to erasure: You can request that we erase your personal data under certain conditions.
- The right to data portability: You have the right to request that we provide the personal data you have provided to us in a structured, commonly used, and machine-readable format (e.g., CSV or JSON), so you can transfer it to another service provider where technically feasible.
7. Cookies
We use cookies to keep you logged in, remember your preferences, and ensure the correct routing of requests through tenant subdomains. You can manage cookie settings in your browser, but some features of the platform may not function correctly without them.
8. Contact Information
If you have any questions about this Privacy Policy or wish to exercise your data protection rights, please contact us at: