Legal

Privacy policy

Last updated: 2 October 2026

We take the protection of your data seriously. This policy explains which personal data we process, why, how long we keep it, who we may share it with and what rights you have. It applies to the sync.imode.si website, the inquiry form and the order analytics application.

  1. 1. Data controller

    The controller of personal data collected through this website and the inquiry form is the provider of the sync.imode.si service (hereinafter “provider”, “we”).

    Contact for data protection questions: info@imode.si.

    For data that a client imports from its online store into the application (orders, customers, carts), the client is the controller and the provider acts as processor. See the “GDPR and data processing” document for details.

  2. 2. What data we collect

    • Inquiry form: full name, company, email address, phone, store URL, approximate number of orders and your message.
    • User account: email address, encrypted password, role (viewer or editor) and login times.
    • Client store data: orders, products, customers (name, email, phone, city), carts and shipments that the application imports through the store’s API.
    • Store access data: administrator email and API key, stored encrypted.
    • Technical data: a hashed (irreversibly transformed) form of the IP address to protect the form from abuse, device and browser data and error logs.
  3. 3. Purpose and legal basis

    • Replying to inquiries and preparing offers — steps prior to entering into a contract (Art. 6(1)(b) GDPR).
    • Providing the analytics service — performance of the contract with the client (Art. 6(1)(b)) and the data processing agreement (Art. 28).
    • Security and abuse prevention (form protection, rate limiting) — legitimate interest (Art. 6(1)(f)).
    • Invoicing and accounting — legal obligation (Art. 6(1)(c)).
    • News and updates — only with your consent (Art. 6(1)(a)), which you can withdraw at any time.
  4. 4. Retention

    • Inquiries that did not lead to a contract: up to 12 months from the last contact.
    • User account data: while the account is active, then deleted within 30 days.
    • Client store data: for the duration of the contract; deleted within 30 days after termination unless the client requests an export first.
    • Accounting records: 10 years after the end of the year they relate to, as required by law.
    • Technical logs: up to 90 days.
  5. 5. Who we share data with

    We do not sell data or share it with third parties for advertising. Access is limited to authorised service providers who help us run the service:

    • the hosting provider for the application and database (servers in the European Union),
    • the email delivery provider (when enabled),
    • an accounting service for invoicing.

    All providers are bound by contracts that guarantee the same level of data protection. We may also disclose data to competent authorities where required by law.

  6. 6. Transfers outside the EU

    We store data in the European Union. If a provider ever processed data outside the EU/EEA, this would only happen with appropriate safeguards (a European Commission adequacy decision or standard contractual clauses).

  7. 7. Data security

    • Encrypted connection (HTTPS) for all traffic.
    • Store API keys are stored encrypted (AES-256).
    • Each client’s data is kept separate; database rules prevent one client from seeing another’s data.
    • Access to the application only with a personal account and roles (viewer, editor).
    • The application has read-only access to the store.
    • Regular backups and access monitoring.
  8. 8. Cookies and local storage

    The website does not use third-party advertising or tracking cookies. We only use strictly necessary browser local storage to:

    • keep you logged in to the application,
    • remember your chosen theme (light/dark) and saved table views,
    • remember the selected client in the application.

    No consent is required for this data because it is necessary for the service to work.

  9. 9. Your rights

    Under the GDPR you have the right to:

    • access your personal data and obtain a copy,
    • rectify inaccurate data,
    • erasure (“right to be forgotten”),
    • restriction of processing,
    • data portability in a machine-readable format,
    • object to processing based on legitimate interest,
    • withdraw consent at any time, without affecting the lawfulness of prior processing.

    Send your request to info@imode.si. We reply within one month at the latest. If you believe we are breaching the rules, you can lodge a complaint with the Information Commissioner of the Republic of Slovenia (Dunajska cesta 22, 1000 Ljubljana, www.ip-rs.si).

  10. 10. Customers of our clients

    If you are a customer of an online store that uses our service, that store is responsible for your data. Exercise your rights with the store; we will help it do so. We do not use your data for our own purposes.

  11. 11. Changes to this policy

    We may update this policy when the service or legislation changes. The date of the last update is shown at the top. We notify clients of material changes by email.

Send questions about this document to info@imode.si.