Legal

Privacy Policy

Last updated: 4 June 2026

1. Introduction

This Privacy Policy explains how Martin Bekkhus, a sole trader established in Sweden and trading as Butikk (“Butikk”, “we”, “us”) collects, uses, and protects personal data when you use butikk.app and related services (the “Service”) — a platform that lets creators and businesses build a storefront page to share links, sell products, and take bookings.

We are committed to protecting your personal data and processing it in accordance with the EU General Data Protection Regulation (GDPR) and Swedish data protection law.

2. Who we are (Data Controller)

DetailInformation
ControllerMartin Bekkhus (sole trader, Sweden), trading as Butikk — butikk.app
Privacy contacthello@butikk.app

We have not appointed a Data Protection Officer; privacy enquiries are handled by the contact above.

3. Who this policy applies to — and our role

This policy covers three groups:

  • Account holders (“Sellers”) — people who register and build a storefront.
  • Customers (“Buyers”) — people who buy products or book sessions through a Seller’s page.
  • Visitors — anyone who views a public Butikk page.

Our role. We are the data controller for operating the platform, billing Sellers, securing the Service, and our own analytics and marketing. When a Buyer purchases from or books with a Seller, that Seller is an independent controller of their customer relationship, and we act as a data processor on the Seller’s behalf for storing that order and booking data. Each Seller is responsible for their own privacy practices toward their customers.

4. Personal data we collect

From Sellers:

  • Identity & account: name, email address, and authentication credentials (passwords are stored hashed by our authentication provider — we never see them).
  • Profile content you publish: display name, handle, bio, avatar image, social links, and the products, prices, and images you upload.
  • Billing data: your subscription and payment details, processed by Stripe (see §7). We receive confirmation of payment and limited billing metadata, not your full card number.
  • Usage data: how you interact with the dashboard.

From Buyers:

  • Name, email address, and the details of your order or booking (item, quantity, booking time, amount).
  • Payment is processed directly by Stripe (including Klarna). Butikk does not store your full card number.

From Visitors (automatically):

  • Device and usage data: IP address, browser type, pages viewed, referring page, and approximate location.
  • Cookies and similar technologies (see §6).

5. Why we use your data and our legal basis

PurposeLegal basis (GDPR Art. 6)
Provide and operate the Service, accounts, storefronts, orders and bookingsPerformance of a contract (6.1.b)
Process Seller subscription paymentsPerformance of a contract (6.1.b)
Keep accounting and invoice recordsLegal obligation (6.1.c) — Swedish Bookkeeping Act (Bokföringslagen)
Secure the Service, prevent fraud and abuseLegitimate interests (6.1.f)
Product analytics to improve the ServiceConsent (6.1.a), via the cookie banner
Advertising and measuring ad performanceConsent (6.1.a)
Send Sellers service/transactional emailsPerformance of a contract (6.1.b)
Send Sellers marketing emailsConsent or legitimate interests (6.1.a/f), with opt-out in every message
Send Buyers order/booking confirmationsPerformance of a contract / processing for the Seller
Comply with legal requestsLegal obligation (6.1.c)

You can withdraw consent at any time without affecting processing already carried out.

6. Cookies and tracking technologies

We use:

  • Strictly necessary cookies — sign-in/session, security, and storing your cookie choices. These do not require consent.
  • Analytics cookies (PostHog) — to understand product usage and improve the Service.
  • Advertising cookies (Meta Pixel) — to measure and target advertising on Meta platforms.

Analytics and advertising technologies load only after you opt in through our cookie-consent banner. You can change or withdraw your choices at any time via the “Cookie settings” link in the site footer, or through your browser settings.

7. Who we share data with (recipients & sub-processors)

We share personal data only with service providers that process it on our behalf, or where legally required:

RecipientPurposeLocation
SupabaseDatabase, authentication, file storageEU / US
CloudflareHosting, content delivery, securityGlobal edge
StripeBuyer payments (incl. Klarna)EU / US
StripeSeller subscription billingEU / US
PostHogProduct analyticsEU / US
Meta PlatformsAdvertising (Meta Pixel)EU / US
ResendTransactional and marketing email deliveryEU / US

Stripe: For seller subscriptions, Stripe handles billing, tax, and invoicing on our behalf.

We may also disclose data to authorities where required by law, and to a successor entity in the event of a merger, acquisition, or sale of assets. We do not sell your personal data.

8. International data transfers

Some recipients process data outside the EU/EEA (e.g., in the United States). Where they do, we rely on appropriate safeguards: the EU-US Data Privacy Framework where applicable, and the European Commission’s Standard Contractual Clauses with supplementary measures. You can request a copy of these safeguards via our privacy contact.

9. How long we keep data

DataRetention
Account & profile dataDeleted within 30–90 days after you close your account
Payment & invoice records7 years (Swedish Bookkeeping Act)
Order & booking recordsFor the Seller relationship, then per the Seller's instructions
Server & analytics logsUp to 12 months
Marketing consent recordsUntil you withdraw consent, plus a short proof period

10. Your rights

Under the GDPR you have the right to: access your data; rectify inaccurate data; request erasure; restrict or object to processing; data portability; and withdraw consent at any time.

To exercise any right, email hello@butikk.app. We respond within one month. For requests about data held by a Seller about you as their customer, please also contact that Seller directly.

You may lodge a complaint with the Swedish supervisory authority: Integritetsskyddsmyndigheten (IMY) — Box 8114, 104 20 Stockholm — imy.se

11. Security

We use technical and organisational measures including encryption in transit, access controls, row-level security on our database, and hashed credentials. No system is perfectly secure, but we work to protect your data and will notify you and the authorities of a qualifying breach as required by law.

12. Children

The Service is intended for users aged 18 and over and is not directed at children. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it.

13. Third-party links

Seller storefronts contain links to external sites and social platforms. We are not responsible for the privacy practices of those third parties; review their policies separately.

14. Changes to this policy

We may update this policy from time to time. We will post the new version here with an updated date and, for material changes, notify Sellers by email.

15. Contact us

Questions about this policy or your data: hello@butikk.app · Martin Bekkhus, trading as Butikk (butikk.app), Sweden.