Legal
Privacy Notice
Version 1.5 · In effect from 2026-08-31 · Version history
This notice is operated by Peci Kft., 2119 Pécel, Aradi u. 5, Hungary (Cg. 13-09-089813; adószám HU12761609) ("Company", "we", "us", "our"). The Company is established in the European Union and acts as data controller for everything described below — it is collected directly from you for the Company's own purpose, not on behalf of any Shopify merchant.
What we collect and why
| Category | What | Why | Legal basis |
|---|---|---|---|
| Email address | The email address you enter | Sending the specific content you asked for (e.g. checklist results) and occasional related updates about the same product, as described at sign-up | Consent |
| Consent record | Timestamp and version of the consent text you saw | Evidencing consent — so we can always show exactly what you agreed to, even if the wording changes later | Consent |
| Attribution | UTM parameters (source, medium, campaign, term, content) and the page you signed up from | Understanding which channel drove sign-ups, for our own marketing measurement | Legitimate interest |
We do not collect payment information, physical addresses, or phone numbers on this website, and we do not use this data for anything beyond what the consent text describes at the time of sign-up. We do not sell or share it with third parties.
Spam prevention. The sign-up form includes a hidden field that only automated bots fill in. If it is filled in, the submission is discarded and nothing is stored.
Where this data is stored
Sign-up data is stored in a dedicated database, separate from the Persistent Cart application's own production data. We use the following providers to run the website and store this data:
- Vercel Inc. — hosts the website and the sign-up form (United States)
- Neon, LLC (a Databricks, Inc. company) — hosts the sign-up database (United States)
- Cloudflare, Inc. — provides the website's privacy-focused, cookieless analytics (Cloudflare Web Analytics), which counts page views without cookies or cross-visit identifiers (United States). See our Cookie Policy.
Data in transit is encrypted (HTTPS/TLS). Data at rest is encrypted by the database provider. Because these providers are located in the United States, transfers are safeguarded under the EU–US Data Privacy Framework where the provider is certified, with Standard Contractual Clauses as a fallback.
How results are sent
Given the current, low sign-up volume, results and updates are currently sent by us manually rather than through an additional email-sending service. This is an operational detail, not a change to what data we collect or why.
Your rights
You can access, correct, restrict, or ask us to delete your data, or object to how we use it, at any time, by writing to privacy@peci.io. We will respond within 30 days. You can also unsubscribe from any email we send, or ask us to delete your data entirely — we keep it only until you do so.
You can also ask us for a copy of the data you gave us, in a common machine-readable format, to keep or to pass to someone else. Where we rely on your consent, you can withdraw it at any time — for example by unsubscribing from any email we send. Withdrawing your consent does not affect the lawfulness of anything we did with your data before you withdrew it.
You have the right to lodge a complaint with a supervisory authority — in Hungary, the Nemzeti Adatvédelmi és Információszabadság Hatóság (naih.hu) — or with the authority in your own country of residence.
Changes to this notice
We will update the effective date above whenever this notice changes materially.
Contact
2119 Pécel, Aradi u. 5, Hungary
General contact: hello@peci.io
Data / privacy matters: privacy@peci.io
Version history
Each version of this page is listed below with the period it was in effect and a copy of the text as it stood. Version numbers for anything before 2026-08-31 were assigned on 2026-08-31, when this register was created, to text states evidenced by the site's source repository — the page did not display those numbers while they were live.
| Version | In effect | What changed | Copy |
|---|---|---|---|
| 1.5 | 2026-08-31 – current | Cloudflare, Inc. named among the recipients (it provides the site's cookieless analytics, which our Cookie Policy already described). The right to data portability added to the list of rights. Withdrawal of consent stated as a right, with the point that withdrawing it does not make earlier processing unlawful. A version number, this version history, and archived copies of the earlier versions added. | this page |
| 1.4 | 2026-08-28 – 2026-08-31 | utm_term and utm_content named individually among the campaign fields recorded with a sign-up. | v1.4 as published |
| 1.3 | 2026-08-24 – 2026-08-28 | Revenue Radar named in the scope note, so the exclusion of the Shopify apps names both apps rather than one. | v1.3 as published |
| 1.2 | 2026-08-15 – 2026-08-24 | The Bot Health Check waitlist added to the sign-ups this notice covers. | v1.2 as published |
| 1.1 | 2026-08-01 – 2026-08-15 | The Persistent Cart update sign-up added to the sign-ups this notice covers. | v1.1 as published |
| 1.0 | 2026-07-29 – 2026-08-01 | First published site-level privacy notice: what the sign-up forms collect, who it is shared with, how long it is kept, and the rights that apply. Replaced a placeholder page that carried no notice. | v1.0 as published |