Privacy Policy
Updated 2026-07-06
How makseong handles personal data under the EU GDPR - kept short, because we collect very little.
On this page
Who is responsible
The controller is Maksym Burkhan (ФОП), reachable at [email protected] - full details in the Imprint.
What we collect
Waitlist: the email address you give us to be notified. Free tools (store and feed scans): the store URL you enter and the public pages we fetch to run the scan. Site visit: standard server logs (e.g. IP, timestamp) needed to serve the site securely. Analytics: only if you accept it in the cookie banner, Google Analytics records pseudonymous usage statistics (see Cookies). Otherwise: no accounts, no profiles, no tracking.
Why we use it
To run the free tools and send a report you ask for (Art. 6(1)(b)); to add you to the waitlist and email launch news, with your consent via double opt-in and withdrawable anytime (Art. 6(1)(a)); and to keep the site secure (Art. 6(1)(f)).
Who we share it with
Email delivery: Brevo (Sendinblue), an EU provider, under a data-processing agreement. Hosting: our EU-based provider in Germany. Analytics: Google Analytics, only with your consent - data is processed by Google and may be transferred to the US (see Cookies). Alerts: we deliver notifications through Telegram (Telegram Messenger Inc.). If you turn on Telegram alerts in one of our apps, we store the chat ID you provide so we can message you, and remove it when you disable alerts or uninstall. We never sell your data.
Where it’s stored
On EU-based servers in Germany. makseong is run from Ukraine, but your data stays within the EU. The one exception is Google Analytics, which - only with your consent - may transfer pseudonymous usage data to the US (see Cookies).
How long we keep it
Your waitlist email is kept until you unsubscribe or ask us to delete it. We don’t store the results of the free website and feed scans, and we don’t run customer accounts. Data processed by our apps is covered below.
Order data processed by our apps (Stellaforge)
Our Shopify app Stellaforge builds a birth-chart poster when a store that uses it receives a paid order. For that store we process the birth details the buyer enters (name if given, birth date, birth time, and birthplace, resolved to coordinates) only to create and deliver the poster the buyer ordered. To convert the birthplace into coordinates, the store page sends the place name the buyer types to Open-Meteo (open-meteo.com), a key-free geocoding service; only the typed place name is sent there. Here the merchant is the controller and makseong acts as their processor, on their instructions. We deliver the download link through the store’s own order notification; if that is unavailable we email it to the buyer through Brevo (EU). We keep the birth details and the finished file for up to 30 days so the buyer can re-download it, then delete them automatically. We never use this data for anything else and never sell it. Rendering runs on our own EU servers in Germany. Buyers should send access or deletion requests to the store they bought from; we act on the store’s request and honor Shopify’s customer-data-request, customer-redact, and shop-redact signals.
Google Merchant Center data processed by our app (Feed Guard)
Our Shopify app Feed Guard connects to your Google Merchant Center account when you authorize it through Google sign-in (read-only content scope). We use this access only to run the features you ask for: scanning your product feed for policy issues, monitoring it, suggesting or applying fixes, and drafting a re-review request letter. From Google we read your product feed data (product listings and their fields), the feed diagnostics Google returns (disapprovals and demotions), and your Merchant Center account ID and display name. Your Google OAuth access and refresh tokens are encrypted at rest with AES-256-GCM before they reach our database, all traffic runs over TLS, and access is restricted to the app’s own signed internal requests. We keep a snapshot of your latest scored scans so we can compare them over time and alert you to changes, and we do not store your Google data for any other purpose. We do not sell your Google user data, use it for advertising, or build profiles from it. Our EU hosting provider in Germany processes it as our infrastructure sub-processor. If you use the optional re-review letter feature, the relevant feed details for that request (your store domain, the issue codes, the affected product identifiers, and the field values you corrected) are sent to an AI language-model provider that drafts the letter, and that provider may process the data outside the EU; nothing is sent to the AI provider unless you trigger the letter yourself. You can disconnect Google at any time from the app, which deletes the stored connection; when you uninstall the app or your store is redacted, we deactivate the connection and purge the associated data, and we honor Shopify’s shop-redact and customer-redact signals. makseong’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Your rights
You can ask us to access, correct, delete or export your data, or object to its use; where we rely on consent, you can withdraw it at any time. Just email [email protected].
Complaints
You can lodge a complaint with an EU data-protection authority - typically where you live or work.
Changes
We update this policy if our processing changes; the date above is the current version. When customer accounts launch, we’ll expand it to cover them.
Configuration and automation, not legal advice.