1. Introduction
Welcome to DaraNode ("we," "our," or "us"). We respect your privacy and are committed to protecting your personal data in accordance with the EU General Data Protection Regulation (GDPR) and other applicable European data protection laws. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our SaaS platform.
By using DaraNode, you acknowledge that you have read and understood this policy. Your continued use constitutes acceptance of our data processing practices.
2. Information We Collect
2.1 Personal Information (GDPR Article 4(1))
We collect personal data that you provide directly to us, including:
- Account Information: Email address, company name, subdomain, first and last name, phone number (optional), country, date of birth
- Authentication Data: Login codes, JWT tokens, session information
- Billing Information: Payment details processed by Stripe (we do not store credit card numbers)
- Profile Information: User role, preferences, settings
2.2 Product and Business Data
Information you upload or create within the platform:
- Product catalogs (titles, descriptions, prices, images)
- Vendor information
- Email templates and signatures
- Team member information
- Integration credentials (Shopify API keys)
2.3 Usage Information
We automatically collect certain information about your device and usage:
- Log Data: IP address, browser type, operating system, pages visited
- Usage Data: Features used, actions performed, timestamps
- Device Information: Device type, screen resolution, language preferences
- Cookies: See our Cookie Policy below
3. How We Use Your Information
We use the collected information for the following purposes:
- Service Provision: To provide, maintain, and improve our platform
- Authentication: To verify your identity and manage access
- Billing: To process payments and manage subscriptions
- Communication: To send you service updates, security alerts, and support messages
- Analytics: To understand how users interact with our platform and improve features
- Security: To detect, prevent, and address fraud, abuse, and security issues
- Legal Compliance: To comply with legal obligations and enforce our policies
4. Data Storage and Security
4.1 Data Storage
Your data is stored on secure servers located within the European Union provided by:
- Render.com: Backend application and PostgreSQL database (EU region - Frankfurt, Germany)
- Stripe: Payment and billing information (PCI-DSS compliant, GDPR compliant)
We ensure all data storage and processing complies with EU data residency requirements under GDPR.
4.2 Security Measures (GDPR Article 32)
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk:
- Encryption: Data in transit (HTTPS/TLS 1.3) and at rest (AES-256)
- Authentication: Passwordless authentication with time-limited codes
- Multi-Tenancy: Row-Level Security (RLS) ensuring complete data isolation between tenants
- Access Control: Role-based permissions (Admin, User, Viewer) with principle of least privilege
- Input Validation: Protection against XSS, SQL injection, and CSRF attacks
- Rate Limiting: Protection against brute force and DDoS attacks
- Regular Backups: Automated encrypted database backups stored in EU data centers
- Security Audits: Regular security assessments and penetration testing
4.3 Data Retention (GDPR Article 5(1)(e))
We retain your personal data only for as long as necessary for the purposes for which it was collected:
- Active Accounts: Data retained while account is active
- After Account Closure: Data deleted within 30 days unless legal obligation requires retention
- Billing Records: Retained for 10 years as required by EU tax and accounting laws
- Backup Data: Automatically deleted from backup systems within 90 days
You may request deletion of your data at any time by exercising your right to erasure (see Section 7 below).
5. Data Sharing and Disclosure
We do not sell your personal data. We may share your information in the following circumstances:
5.1 Service Providers
We share data with third-party service providers who assist us:
- Stripe: Payment processing (subject to Stripe's Privacy Policy)
- Render.com: Hosting and infrastructure
- Email Service: Transactional emails (authentication codes, notifications)
5.2 Shopify Integration
If you connect your Shopify store, we access and sync data according to permissions you grant. This data is used solely for synchronization purposes.
5.3 Legal Requirements
We may disclose your information if required by law or to:
- Comply with legal process or government requests
- Enforce our Terms of Service
- Protect our rights, privacy, safety, or property
- Prevent fraud or abuse
5.4 Business Transfers
In the event of a merger, acquisition, or sale of assets, your data may be transferred. We will notify you before your data is transferred and becomes subject to a different privacy policy.
6. Cookies and Tracking Technologies
We use cookies and similar technologies to:
- Essential Cookies: Authentication (JWT tokens), session management
- Functional Cookies: Remember your preferences and settings
- Analytics Cookies: Understand usage patterns (if analytics enabled)
You can control cookies through your browser settings. Disabling essential cookies may affect platform functionality.
7. Your Rights Under GDPR
As a data subject in the European Union, you have the following rights under the General Data Protection Regulation:
- Right of Access (Article 15): Request a copy of your personal data we hold
- Right to Rectification (Article 16): Correct inaccurate or incomplete data
- Right to Erasure (Article 17): Request deletion of your data ("right to be forgotten")
- Right to Restriction of Processing (Article 18): Request we limit processing of your data
- Right to Data Portability (Article 20): Receive your data in a structured, machine-readable format (CSV, JSON)
- Right to Object (Article 21): Object to processing based on legitimate interests
- Right to Withdraw Consent (Article 7(3)): Withdraw consent at any time without affecting lawfulness of prior processing
- Right to Lodge a Complaint (Article 77): File a complaint with your national Data Protection Authority
To exercise your rights, contact our Data Protection Officer:
Email: [email protected]
Privacy Email: [email protected]
We will respond within 30 days as required by GDPR Article 12(3).
8. International Data Transfers (GDPR Chapter V)
Your data is primarily stored and processed within the European Economic Area (EEA). In limited circumstances, data may be transferred to third countries:
- Stripe (Payment Processing): Uses Standard Contractual Clauses (SCCs) approved by the European Commission
- Service Providers: All third-party processors have signed Data Processing Agreements (DPAs) and comply with GDPR Article 28
We ensure all international data transfers comply with GDPR requirements through:
- European Commission adequacy decisions (Article 45)
- Standard Contractual Clauses (SCCs) (Article 46(2)(c))
- Binding Corporate Rules where applicable
9. Children's Privacy (GDPR Article 8)
Our platform is not intended for children under 16 years of age (or the minimum age required in your EU member state). We do not knowingly collect personal data from children without parental consent. The minimum age for account registration is 13 years with verified parental consent where required by local law.
If you believe we have collected data from a child without appropriate consent, please contact us immediately at [email protected]. We will delete such data within 72 hours.
10. Third-Party Links
Our platform may contain links to third-party websites (e.g., Shopify, Stripe). We are not responsible for the privacy practices of these sites. We encourage you to read their privacy policies.
11. Data Breach Notification (GDPR Articles 33 & 34)
In the event of a personal data breach that poses a risk to your rights and freedoms, we will:
- Notify Supervisory Authority: Within 72 hours of becoming aware of the breach (Article 33)
- Notify You Directly: Without undue delay if the breach poses a high risk to you (Article 34)
- Document the Breach: Maintain records of all breaches including facts, effects, and remedial action taken
Notification will include: nature of breach, categories and number of data subjects affected, contact details of our Data Protection Officer, likely consequences, and measures taken or proposed.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by:
- Email notification to your registered address
- Prominent notice on our platform
- Updating the "Last Updated" date above
Continued use of the platform after changes constitutes acceptance of the updated policy.
13. Contact Us and Data Protection Officer
If you have questions about this Privacy Policy or our data practices, please contact us:
DaraNode Privacy Team
Data Protection Officer: [email protected]
Privacy Email: [email protected]
Support: [email protected]
Response Time: Within 30 days (GDPR Article 12(3))
EU Representative:
[Your EU Representative Name if applicable]
[Address within the EU]
Supervisory Authority:
You have the right to lodge a complaint with your national Data Protection Authority. Find your authority at: European Data Protection Board
14. Legal Basis for Processing (GDPR Article 6)
We process your personal data based on the following legal grounds under GDPR Article 6(1):
- Contract Performance (Article 6(1)(b)): Processing necessary to provide our services as per our Terms of Service
- Legitimate Interests (Article 6(1)(f)): To improve our platform, prevent fraud, ensure security, and conduct analytics. Your rights and freedoms do not override these interests.
- Consent (Article 6(1)(a)): Where you have given explicit, freely given consent (e.g., marketing communications, optional features). You may withdraw consent at any time.
- Legal Obligation (Article 6(1)(c)): To comply with EU and member state laws (e.g., tax, accounting, anti-money laundering)
We conduct Data Protection Impact Assessments (DPIAs) for high-risk processing activities as required by Article 35.
15. Automated Decision-Making and Profiling (GDPR Article 22)
We do not engage in automated decision-making or profiling that produces legal effects or similarly significantly affects you. Any automated processing (e.g., fraud detection algorithms) includes human oversight and the right to contest decisions.
16. Data Protection by Design and Default (GDPR Article 25)
We implement data protection principles into our platform design:
- Pseudonymization: Where appropriate, we pseudonymize personal data
- Minimization: We collect only data necessary for specified purposes
- Privacy Settings: Privacy-friendly default settings are applied to all accounts
- Encryption: Built-in encryption for data at rest and in transit
This Privacy Policy is effective as of January 10, 2026 and complies with EU GDPR (Regulation (EU) 2016/679).
View our Terms of Service