Integritetspolicy
Senast uppdaterad: 13 September 2026
Protecting your data matters to us. This privacy policy explains, in accordance with the General Data Protection Regulation (GDPR) and the Austrian Data Protection Act (DSG), which personal data we process when operating mrupsell.com, the MrUpsell dashboard, the MrUpsell WooCommerce plugin and the MrUpsell Shopify app (together the "Service").
1. Controller
FM2 network GmbH
Heuweg 10
8041 Graz
Austria
Email: info@mrupsell.com · Phone: +43 676 3264227
A data protection officer is not legally required and has not been appointed. Please direct privacy requests to the email address above.
2. What we process and why
2.1 Visiting the website
When you open the website, our hosting provider processes technically necessary data (IP address, time, requested page, user agent) in server log files to deliver the page, keep it secure and analyse errors. The legal basis is our legitimate interest in secure operation (Art. 6(1)(f) GDPR). Log files are deleted after 14 days at the latest.
2.2 Account and workspace
For your MrUpsell account we process your email address, name, password (hashed only), language preference, session data and the name of your workspace in order to provide the Service and perform the contract (Art. 6(1)(b) GDPR). For Shopify merchants we create the account automatically when the app is installed, using the store owner email held by Shopify; sign-in works via magic link.
2.3 Connected shops and usage data
For every connected shop we store the shop URL or myshopify domain, platform, plugin, WordPress, WooCommerce and PHP versions, the time of last contact and aggregated statistics (offer impressions, accepted and declined offers, revenue per rule and payment method). As the billing basis the plugin also reports every paid upsell order with order number, amount, currency, refunds and time. Personal data of your end customers (names, addresses, email addresses, payment details) is never transmitted to MrUpsell. The legal basis is performance of the contract (Art. 6(1)(b) GDPR).
2.4 Billing
To bill the revenue share we process your billing profile (company, billing email, address, country, VAT ID), the customer ID assigned by Stripe, a reference to the saved payment method (card brand and last four digits or PayPal email), invoice numbers and amounts. Full card or PayPal details are processed exclusively by Stripe and never reach our servers. VAT IDs are verified via Stripe against the EU VAT Information Exchange System (VIES). Legal bases are performance of the contract (Art. 6(1)(b) GDPR) and our tax and commercial law obligations (Art. 6(1)(c) GDPR, § 132 Austrian Federal Fiscal Code, § 212 Austrian Commercial Code).
2.5 Emails
We send transactional emails (sign-in links, confirmations, invoice and payment notices, notices about the operation of your shops) to your account or billing email. Marketing emails are only sent with your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time.
2.6 Contacting us
If you contact us by email, we process the details you provide to handle your request (Art. 6(1)(b) or (f) GDPR).
3. Cookies and local storage
We only use strictly necessary cookies: a session cookie for signing in to the dashboard and a cookie that remembers your language. No tracking, analytics or advertising cookies are used and no third-party trackers are embedded, so no consent is required (§ 165(3) Austrian Telecommunications Act 2021).
4. Recipients and processors
We only share data where necessary to operate the Service. Data processing agreements under Art. 28 GDPR are in place with all processors.
- Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany – hosting of servers and databases (Nuremberg data centre, EU).
- Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Dublin 2, Ireland – payment processing, storage of the payment method, invoicing and VAT ID verification. For payment processing Stripe acts partly as an independent controller; see stripe.com/privacy.
- PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, 2449 Luxembourg – if you choose PayPal as your payment method.
- Shopify International Ltd., Victoria Buildings, 1-2 Haddington Road, Dublin 4, Ireland – provision of the Shopify app, billing of Shopify merchants via Shopify Billing and transfer of store data through the Shopify APIs.
- Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland – sending and receiving email via Google Workspace.
- Resend, Inc., San Francisco, USA – fallback delivery route for transactional email. A transfer to the USA only happens in that case and is based on the EU standard contractual clauses (Art. 46(2)(c) GDPR).
Beyond that we only disclose data where legally obliged to or with your consent.
5. Roles regarding end-customer data
Processing of your end customers' data in the course of upsell offers (displaying the offer, charging via the existing payment session) takes place entirely in your shop and at your payment provider. You are the controller for that processing. MrUpsell does not receive personal data of your end customers from it. Should processing on your behalf become necessary in an individual case, we will conclude a data processing agreement under Art. 28 GDPR on request.
6. Retention
- Account and workspace data: until you delete your account, then erased within 30 days.
- Aggregated statistics: 24 months.
- Upsell orders as billing basis, invoices and accounting records: 7 years under § 132 Austrian Federal Fiscal Code and § 212 Austrian Commercial Code.
- Server log files: 14 days.
- Shopify: after the app is uninstalled we receive Shopify's privacy webhooks and delete the store data within 48 hours unless statutory retention duties apply.
7. Security
All connections are TLS-encrypted. Communication between the plugin or app and the hub is signed with a shop-specific secret. Passwords are stored as hashes only. Access to production systems is restricted to the management.
8. Your rights
You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21), and the right to withdraw consent at any time. Contact info@mrupsell.com. You may also lodge a complaint with the Austrian Data Protection Authority: Datenschutzbehörde, Barichgasse 40–42, 1030 Vienna, www.dsb.gv.at.
9. Changes
We update this privacy policy when the Service or the legal situation changes. The current version is always available at mrupsell.com/privacy.