Home / Privacy Policy

Privacy Policy

We handle other people's data for a living — stores, customers, analytics. So we hold ourselves to the same standard we engineer for our clients: collect only what's needed, protect it properly, and be straight about how it's used.

This Privacy Policy explains how MageMinds Global LLC ("MageMinds", "we", "us", "our") collects, uses, discloses and safeguards personal information when you visit our website, contact us, purchase our extension products, or engage us for services — and the rights you have over that information.

1 Who We Are

MageMinds Global LLC is an e-commerce development and support agency providing web development, maintenance and upgrades, platform migration, systems integration, AI solutions, digital marketing and data services to clients worldwide. We also develop and sell ready-made extensions and plugins for e-commerce platforms.

For the purposes of applicable data protection law (including the EU/UK GDPR), MageMinds Global LLC is the data controller for personal information collected through this website and in the course of our sales and marketing activities. When we process data on behalf of a client as part of a service engagement (for example, working inside the client's store or analytics accounts), we act as a data processor — see Section 7.

Registered entity: MageMinds Global LLC

Privacy contact: [email protected]

2 Information We Collect

2.1 Information you give us directly

  • Contact & inquiry data: name, email address, phone number, company, store URL and the contents of your message when you submit a form, email us, request a quote or book a consultation.
  • Account & purchase data: name, email, billing address and order details when you purchase an extension or plugin. Payment card details are processed directly by our payment processor — we never see or store full card numbers.
  • Project data: information you share during a service engagement — business requirements, access credentials (handled per Section 7), brand assets, and correspondence.
  • Support data: tickets, screenshots, logs and communications when you ask us for product or service support.
  • Marketing preferences: your subscription choices and communication preferences.

2.2 Information collected automatically

  • Usage data: pages visited, links clicked, time on page, referring URLs and approximate location (derived from IP).
  • Device & technical data: IP address, browser type and version, operating system, screen resolution and language settings.
  • Cookies & similar technologies: see Section 5 for details and choices.

2.3 Information from third parties

  • Payment processors confirm successful transactions (never full card data).
  • Analytics providers (e.g. Google Analytics) provide aggregated, pseudonymous site statistics.
  • Public sources & partners: if a partner refers you to us, or we verify business details from public registries for due diligence.

3 How We Use Information

We use personal information only for purposes we can justify:

  • To respond to you: answering inquiries, preparing quotes, running free audits or assessments you request.
  • To deliver our services and products: fulfilling extension orders, issuing licenses and updates, providing support, performing contracted work.
  • To run our business: invoicing, accounting, contract management, quality assurance, internal record-keeping.
  • To improve our website and offerings: understanding which content is useful, diagnosing technical issues, keeping the site secure.
  • Marketing (with consent where required): sending occasional updates about services, products or articles we believe are relevant to you. Every marketing email includes an unsubscribe link, and we honor it promptly.
  • Legal & safety: complying with legal obligations, enforcing agreements, preventing fraud and abuse.

What we never do: we do not sell your personal information, we do not rent or trade contact lists, and we do not use client store data for any purpose other than the engagement it was provided for.

4 Legal Bases for Processing (EEA & UK)

If you are in the European Economic Area or the United Kingdom, we process your personal data under these lawful bases:

  • Contract: processing necessary to provide services or products you've requested, or to take steps before entering a contract (e.g. preparing a quote).
  • Legitimate interests: running and improving our business, securing our systems, and limited B2B marketing — balanced against your rights, and never overriding them.
  • Consent: for optional cookies, newsletter subscriptions and any processing that requires it. You may withdraw consent at any time.
  • Legal obligation: tax, accounting and regulatory compliance.

5 Cookies & Tracking Technologies

Our website uses cookies and similar technologies. Here's what they do and the choices you have:

Category Purpose Examples Your choice
Strictly necessary Make the site work — security, load balancing, form sessions. Session cookies, CSRF tokens Always on — the site won't function without them.
Analytics Understand aggregate usage so we can improve content and navigation. Google Analytics (GA4) Optional — controlled via the cookie banner or browser settings.
Functional Remember preferences (e.g. cookie choices, region). Preference cookies Optional — site works without them, just less conveniently.
Marketing Measure campaign effectiveness; avoid showing you irrelevant ads. Google Ads / Meta pixels Optional — only set with your consent.

You can withdraw or change cookie consent at any time via the cookie settings link in our footer, and most browsers let you block or delete cookies entirely. Blocking some categories may affect site functionality.

6 How We Share Information

We share personal information only with:

  • Service providers (processors): hosting and infrastructure, email delivery, CRM, payment processing, and analytics vendors — each bound by contract to use data only on our instructions and to protect it appropriately.
  • Professional advisers: accountants, lawyers and insurers, under confidentiality obligations.
  • Authorities: where required by law, regulation, or valid legal process, or to protect rights, safety and property.
  • Business transfers: if MageMinds is involved in a merger, acquisition or asset sale, data may transfer as part of that transaction — you will be notified of any change in ownership or use.

We do not sell personal information, and we do not share it with third parties for their own independent marketing purposes.

7 Client & Store Data (Agency-Specific)

Our work often requires access to client systems — store admin panels, servers, analytics accounts, CRMs, marketplaces. Because this is unusual among businesses, we spell it out:

  • We act as a data processor. When we handle personal data within your systems (e.g. your customers' orders during a migration), you remain the controller; we process it only on your documented instructions.
  • Data Processing Agreements available. We gladly sign a DPA (including EU Standard Contractual Clauses where needed) before any engagement that involves personal data.
  • Access is need-to-know. Only team members assigned to your project receive credentials, stored in an encrypted password manager — never in email, spreadsheets or chat.
  • NDA by default. All client engagements are covered by confidentiality obligations, whether or not a separate NDA is signed.
  • Offboarding is clean. At the end of an engagement we hand over documentation, transfer ownership of accounts and assets to you, and revoke or ask you to rotate our access.
  • No secondary use. We never use client store data — customer lists, order histories, analytics — for our own marketing, benchmarking with identifiers, or any purpose beyond your project.

8 Data Retention

We keep personal information only as long as there is a genuine reason:

Data type Typical retention
Inquiries that don't become projects Up to 24 months, then deleted or anonymized.
Client contracts & project records Duration of the engagement plus the period required by tax/contract law (typically 7 years).
Extension purchase & license records Life of the license plus statutory accounting periods.
Support tickets Up to 36 months for quality and continuity.
Marketing subscriptions Until you unsubscribe (plus a suppression record so we don't re-add you).
Website analytics Aggregated/pseudonymous, per tool defaults (e.g. 14 months in GA4).

When retention ends, data is securely deleted or irreversibly anonymized. Backup copies cycle out on their normal rotation schedule.

9 How We Protect Data

Security is our day job — we maintain and harden e-commerce infrastructure for clients, and we apply the same practices internally:

  • Encrypted transport (TLS) everywhere; encrypted storage for credentials and sensitive project material.
  • Least-privilege access controls, MFA on internal systems, and access reviews when projects end or roles change.
  • Credential handling via an encrypted team password manager — shared access is revoked and rotated at offboarding.
  • Vendor due diligence — we assess the security posture of the processors we rely on.
  • Staff confidentiality obligations and privacy/security awareness as part of onboarding.

No method of transmission or storage is 100% secure, and we won't pretend otherwise. If a breach ever affects your personal data, we will notify you and the relevant authorities as required by law, quickly and without spin.

10 International Data Transfers

We serve clients worldwide and work with service providers in multiple countries, so your information may be processed outside your country of residence — including in countries whose data protection laws differ from yours.

Where we transfer personal data out of the EEA/UK, we rely on appropriate safeguards: adequacy decisions where available, otherwise Standard Contractual Clauses (and the UK addendum) with the recipient, plus supplementary measures where required. You may request a copy of the relevant safeguards via the contact details in Section 16.

11 Your Privacy Rights

Depending on where you live, you have some or all of the following rights over your personal information:

Access & portability

Request a copy of the personal data we hold about you, in a commonly used, machine-readable format.

Correction

Ask us to fix inaccurate or incomplete information.

Deletion

Ask us to erase your data where there's no ongoing legal or contractual reason to keep it.

Restriction & objection

Limit how we use your data, or object to processing based on legitimate interests or direct marketing.

Withdraw consent

Where processing is based on consent, withdraw it at any time — it won't affect prior lawful processing.

Complain

Lodge a complaint with your local data protection authority. (We'd appreciate the chance to fix things first.)

For California residents (CCPA/CPRA)

You have the right to know what personal information we collect, use and disclose; to request deletion and correction; to opt out of the sale or sharing of personal information (we don't sell or share it for cross-context behavioral advertising); and to not be discriminated against for exercising these rights.

How to exercise your rights

Email [email protected] with the subject "Privacy Request". We may need to verify your identity (and, for agents, your authority) before acting. We respond within the time required by applicable law — usually 30 days, and we'll tell you if we need an extension. There is no fee unless a request is manifestly unfounded or excessive.

12 Do Not Track Signals

There is no industry standard for responding to browser "Do Not Track" signals, so our site does not currently respond to them. You can achieve the same effect — and more — through the cookie choices described in Section 5. We honor the Global Privacy Control (GPC) signal where legally required.

14 Children's Privacy

Our website, services and products are directed at businesses and are not intended for anyone under 16. We do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us and we will delete it promptly.

15 Changes to This Policy

We may update this Privacy Policy as our services, tooling or legal obligations evolve. The "Last updated" date at the top of the page always reflects the current version. For material changes, we'll make a reasonable effort to give advance notice — a notice on the site or, where appropriate, an email to subscribed contacts. Continued use of the site or services after an update takes effect constitutes acceptance of the revised policy.

16. Contact Us About Privacy

Questions, requests or concerns about this policy or how we handle data? We'd rather hear from you directly:

MageMinds Global LLC
Privacy inquiries: [email protected]
General inquiries: [email protected]

We aim to acknowledge privacy requests within two business days and resolve them within the statutory timeframe.

Questions?

Talk to us — about privacy, or anything else

Privacy questions go straight to the team responsible for data protection. Everything else — a project, a quote, a second opinion — is welcome too.

  • Privacy requests acknowledged within two business days
  • DPA available on request for service engagements
  • NDA by default — your details stay private
  • Honest answers, no legal runaround

Send Us a Message

Fields marked * are required.