Home / Privacy Policy
We handle other people's data for a living — stores, customers, analytics. So we hold ourselves to the same standard we engineer for our clients: collect only what's needed, protect it properly, and be straight about how it's used.
This Privacy Policy explains how MageMinds Global LLC ("MageMinds", "we", "us", "our") collects, uses, discloses and safeguards personal information when you visit our website, contact us, purchase our extension products, or engage us for services — and the rights you have over that information.
MageMinds Global LLC is an e-commerce development and support agency providing web development, maintenance and upgrades, platform migration, systems integration, AI solutions, digital marketing and data services to clients worldwide. We also develop and sell ready-made extensions and plugins for e-commerce platforms.
For the purposes of applicable data protection law (including the EU/UK GDPR), MageMinds Global LLC is the data controller for personal information collected through this website and in the course of our sales and marketing activities. When we process data on behalf of a client as part of a service engagement (for example, working inside the client's store or analytics accounts), we act as a data processor — see Section 7.
Registered entity: MageMinds Global LLC
Privacy contact: [email protected]
We use personal information only for purposes we can justify:
What we never do: we do not sell your personal information, we do not rent or trade contact lists, and we do not use client store data for any purpose other than the engagement it was provided for.
If you are in the European Economic Area or the United Kingdom, we process your personal data under these lawful bases:
Our website uses cookies and similar technologies. Here's what they do and the choices you have:
| Category | Purpose | Examples | Your choice |
|---|---|---|---|
| Strictly necessary | Make the site work — security, load balancing, form sessions. | Session cookies, CSRF tokens | Always on — the site won't function without them. |
| Analytics | Understand aggregate usage so we can improve content and navigation. | Google Analytics (GA4) | Optional — controlled via the cookie banner or browser settings. |
| Functional | Remember preferences (e.g. cookie choices, region). | Preference cookies | Optional — site works without them, just less conveniently. |
| Marketing | Measure campaign effectiveness; avoid showing you irrelevant ads. | Google Ads / Meta pixels | Optional — only set with your consent. |
You can withdraw or change cookie consent at any time via the cookie settings link in our footer, and most browsers let you block or delete cookies entirely. Blocking some categories may affect site functionality.
We share personal information only with:
We do not sell personal information, and we do not share it with third parties for their own independent marketing purposes.
Our work often requires access to client systems — store admin panels, servers, analytics accounts, CRMs, marketplaces. Because this is unusual among businesses, we spell it out:
We keep personal information only as long as there is a genuine reason:
| Data type | Typical retention |
|---|---|
| Inquiries that don't become projects | Up to 24 months, then deleted or anonymized. |
| Client contracts & project records | Duration of the engagement plus the period required by tax/contract law (typically 7 years). |
| Extension purchase & license records | Life of the license plus statutory accounting periods. |
| Support tickets | Up to 36 months for quality and continuity. |
| Marketing subscriptions | Until you unsubscribe (plus a suppression record so we don't re-add you). |
| Website analytics | Aggregated/pseudonymous, per tool defaults (e.g. 14 months in GA4). |
When retention ends, data is securely deleted or irreversibly anonymized. Backup copies cycle out on their normal rotation schedule.
Security is our day job — we maintain and harden e-commerce infrastructure for clients, and we apply the same practices internally:
No method of transmission or storage is 100% secure, and we won't pretend otherwise. If a breach ever affects your personal data, we will notify you and the relevant authorities as required by law, quickly and without spin.
We serve clients worldwide and work with service providers in multiple countries, so your information may be processed outside your country of residence — including in countries whose data protection laws differ from yours.
Where we transfer personal data out of the EEA/UK, we rely on appropriate safeguards: adequacy decisions where available, otherwise Standard Contractual Clauses (and the UK addendum) with the recipient, plus supplementary measures where required. You may request a copy of the relevant safeguards via the contact details in Section 16.
Depending on where you live, you have some or all of the following rights over your personal information:
Request a copy of the personal data we hold about you, in a commonly used, machine-readable format.
Ask us to fix inaccurate or incomplete information.
Ask us to erase your data where there's no ongoing legal or contractual reason to keep it.
Limit how we use your data, or object to processing based on legitimate interests or direct marketing.
Where processing is based on consent, withdraw it at any time — it won't affect prior lawful processing.
Lodge a complaint with your local data protection authority. (We'd appreciate the chance to fix things first.)
You have the right to know what personal information we collect, use and disclose; to request deletion and correction; to opt out of the sale or sharing of personal information (we don't sell or share it for cross-context behavioral advertising); and to not be discriminated against for exercising these rights.
Email [email protected] with the subject "Privacy Request". We may need to verify your identity (and, for agents, your authority) before acting. We respond within the time required by applicable law — usually 30 days, and we'll tell you if we need an extension. There is no fee unless a request is manifestly unfounded or excessive.
There is no industry standard for responding to browser "Do Not Track" signals, so our site does not currently respond to them. You can achieve the same effect — and more — through the cookie choices described in Section 5. We honor the Global Privacy Control (GPC) signal where legally required.
Our website and communications may link to third-party sites — platform marketplaces, partner sites, tools we recommend. Those sites have their own privacy policies, which we don't control and aren't responsible for. This policy also does not cover the privacy practices of the platforms our extensions run on (Adobe Commerce, Shopify, etc.) — please review their policies separately.
Our website, services and products are directed at businesses and are not intended for anyone under 16. We do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us and we will delete it promptly.
We may update this Privacy Policy as our services, tooling or legal obligations evolve. The "Last updated" date at the top of the page always reflects the current version. For material changes, we'll make a reasonable effort to give advance notice — a notice on the site or, where appropriate, an email to subscribed contacts. Continued use of the site or services after an update takes effect constitutes acceptance of the revised policy.
Questions, requests or concerns about this policy or how we handle data? We'd rather hear from you directly:
MageMinds Global LLCWe aim to acknowledge privacy requests within two business days and resolve them within the statutory timeframe.
Privacy questions go straight to the team responsible for data protection. Everything else — a project, a quote, a second opinion — is welcome too.
Prefer email? Write to us at [email protected] or WhatsApp
Fields marked * are required.