Privacy Policy

Checkivo’s Privacy Notice

This privacy notice explains how E-Commerce Productions (trading as Checkivo), Bizetpad 1, 2324 JP Leiden, The Netherlands (“Checkivo”, “we”, “us”) processes personal data when you visit our websites, communicate with us, or use our merchant-facing software products for checkout, subscriptions and related e-commerce tools.

This notice is directed primarily at website visitors, trial users, Customer contacts and prospects. Processing of shopper data inside a merchant’s Checkivo-powered checkout or portal is generally performed on behalf of that merchant as described in our DPA; those shoppers should review the merchant’s privacy policy.

Contact for privacy questions: [email protected] or [email protected].

Last updated: July 2026.

Your data is in good hands with us... - this is why

We process personal data in line with the EU General Data Protection Regulation (GDPR) and applicable Dutch privacy law. We apply need-to-know access, contractual safeguards with processors, and security measures appropriate to the risk.

We do not sell personal data. We use data to operate Checkivo, communicate with you, improve our products and meet legal obligations.

Where we rely on consent (for example certain cookies or marketing emails), you may withdraw consent at any time without affecting prior lawful processing.

Where we rely on legitimate interests (for example securing our Services or B2B direct outreach), you may object as described under Data Subject Rights.

We keep personal data only as long as needed for the purposes collected, including statutory retention for invoices and correspondence, then delete or anonymise it.

We store and process your personal data:

Website and marketing: IP address, device/browser data, pages viewed, referrer, and cookie identifiers as described in our cookie information; contact-form content you submit; newsletter preferences if you subscribe.

Sales and account: name, business email, phone if you choose to provide it, company name, role, billing details, support tickets and meeting notes related to your Checkivo evaluation or contract.

Product usage (merchant users): account credentials, admin user profiles, audit logs, configuration metadata, and technical logs required to provide and secure the Services.

Shopper/End Customer data: if you are a shopper of a Checkivo merchant, your data is typically controlled by that merchant. Checkivo hosts or processes it as a processor according to the merchant’s instructions (for example order identifiers, subscription status, portal login).

Legal bases include performance of a contract (Art. 6(1)(b) GDPR), legitimate interests (Art. 6(1)(f)), legal obligations (Art. 6(1)(c)) and consent (Art. 6(1)(a)) where required.

Purposes include providing the Services, authenticating users, preventing fraud/abuse, customer support, product analytics, billing, marketing to business contacts where permitted, and improving checkout/subscription features.

We may create aggregated statistics that do not identify individuals.

If you apply for a job with us, we process application data to evaluate candidacy and will provide additional notice in the careers flow where relevant.

Trusted third parties who process your data

We use carefully selected service providers (processors) such as cloud hosting, email delivery, customer-support tooling, analytics, error monitoring and payment partners for our own fees.

These providers process data only on our instructions and under data-processing terms. A current overview can be requested via our privacy email.

Independent controllers may receive data where required (for example accountants, lawyers, authorities) or when you interact with third-party platforms like Shopify under their own terms.

If you pay Checkivo with a card, card data is typically processed by our payment provider; Checkivo does not store full card numbers on its own servers.

International Data Transfers

We primarily aim to process data in the EEA/UK. Where vendors process data outside the EEA, we implement appropriate safeguards such as adequacy decisions or Standard Contractual Clauses, supplemented by technical measures where appropriate.

You may request more information about transfer safeguards via our privacy contact.

How we use cookies

Our websites use necessary cookies to run the site and security features. Analytics and marketing cookies are used only with your consent where required, managed via our cookie settings banner.

You can change non-essential cookie choices at any time via Cookie settings on our website (https://checkivo.com/cookie-instellingen/). Browser settings may also block cookies, which can affect site functionality.

For details of cookie categories and vendors, see the Cookie settings page and the consent management platform presented on our site.

Data Protection Officer

For privacy requests you can contact us at the address above or by email. Where a statutory data protection officer is appointed, contact details will be published here; otherwise privacy requests are handled by our privacy contact team.

Email: [email protected]

Postal: E-Commerce Productions, Attn. Privacy, Bizetpad 1, 2324 JP Leiden, The Netherlands

We do not publish a phone number for privacy requests; please use email so we can authenticate and document your request.

Data Subject Rights

Be informed about your privacy rights

Subject to applicable law, you may have the right to access, rectify, erase, restrict or object to processing, and the right to data portability. Where processing is based on consent, you may withdraw consent at any time.

You also have the right to lodge a complaint with a supervisory authority. In the Netherlands this is the Autoriteit Persoonsgegevens. You may also contact the authority of your habitual residence or place of work in the EEA.

To exercise rights, email [email protected] with enough detail to identify you and your request. We may ask for additional information to verify your identity.

If your request relates to data processed for a merchant customer inside the product, we may redirect you to that merchant as the controller.

We respond within the timelines required by law. Some rights are limited where we must retain data for legal claims, bookkeeping or security.

Related documents:

Terms: https://checkivo.com/algemene-voorwaarden/

Privacy (this page): https://checkivo.com/privacy-policy/

Dutch privacy URL: https://checkivo.com/privacybeleid/

Cookie settings: https://checkivo.com/cookie-instellingen/

Legal notice / imprint: https://checkivo.com/legal-notice/

Security overview: https://checkivo.com/security/

Customer should retain copies of order forms, invoices, SOWs and configuration exports for its records. Checkivo may provide account statements or invoices digitally via email or the Customer account.

Support is provided via the channels stated on the Checkivo website or in the Customer account during local business hours unless a higher support tier is purchased. Response times for standard support are targets, not guaranteed SLAs, unless an order form states otherwise.

Marketing examples, demos and case studies illustrate typical outcomes and do not constitute a binding service commitment for Customer’s specific store, catalogue, traffic volume or payment provider setup.

Where the Services allow export of configuration or Customer Data, Customer should perform exports before cancelling a subscription or deleting a connected store. Checkivo is not obliged to retain exports indefinitely after the retention window described in the DPA or documentation.

Checkivo may verify account ownership and authority before making sensitive configuration changes, issuing refunds of platform fees, or disclosing account information. Security challenges may include email verification to known admin addresses.

API rate limits, webhook delivery retries and fair-use rules may apply to protect platform stability for all merchants. Sustained abuse or automated scraping of the Services may result in throttling or suspension after notice where practicable.

Customer must ensure that scripts, pixels and third-party tags installed on its storefront do not impair security, performance or accessibility obligations Customer owes to End Customers, and do not circumvent Checkivo or Shopify security controls.

Notices under the agreement may be sent by email to the addresses associated with the Customer account or the order form. Customer shall keep notice emails current. Notices to Checkivo should be sent to [email protected] unless a dedicated legal address is stated.

Translations of these terms are provided for convenience. Unless a local-language version is expressly designated as binding for a locale, the English version prevails, except where mandatory local law requires otherwise for that provision.

References to Shopify, Stripe or other brands are for interoperability description only and do not imply partnership, endorsement or joint liability beyond publicly available platform integrations and each party’s separate terms with those providers.

Customer remains solely responsible for consumer-facing legal texts on its storefront, including terms of sale, cancellation policies, imprint and privacy information required in the countries where it offers goods or services.

If Customer enables multiple stores or markets under one Checkivo account, usage metrics and fees may be aggregated as described in the plan. Checkivo may require separate subscriptions where fair-use or technical isolation requires it.

Force majeure events—including major cloud-provider outages, war, epidemic, government action or failure of third-party platforms—excuse performance for the duration of the event, provided the affected party uses reasonable efforts to mitigate.

Nothing in the agreement creates a partnership, joint venture or employment relationship. Neither party may bind the other to third parties except as expressly authorised in writing.

Headings are for convenience only and do not affect interpretation. Words in the singular include the plural and vice versa where the context allows.

Customer should retain copies of order forms, invoices, SOWs and configuration exports for its records. Checkivo may provide account statements or invoices digitally via email or the Customer account.

Support is provided via the channels stated on the Checkivo website or in the Customer account during local business hours unless a higher support tier is purchased. Response times for standard support are targets, not guaranteed SLAs, unless an order form states otherwise.

Marketing examples, demos and case studies illustrate typical outcomes and do not constitute a binding service commitment for Customer’s specific store, catalogue, traffic volume or payment provider setup.

Where the Services allow export of configuration or Customer Data, Customer should perform exports before cancelling a subscription or deleting a connected store. Checkivo is not obliged to retain exports indefinitely after the retention window described in the DPA or documentation.

Checkivo may verify account ownership and authority before making sensitive configuration changes, issuing refunds of platform fees, or disclosing account information. Security challenges may include email verification to known admin addresses.

API rate limits, webhook delivery retries and fair-use rules may apply to protect platform stability for all merchants. Sustained abuse or automated scraping of the Services may result in throttling or suspension after notice where practicable.

Customer must ensure that scripts, pixels and third-party tags installed on its storefront do not impair security, performance or accessibility obligations Customer owes to End Customers, and do not circumvent Checkivo or Shopify security controls.

Notices under the agreement may be sent by email to the addresses associated with the Customer account or the order form. Customer shall keep notice emails current. Notices to Checkivo should be sent to [email protected] unless a dedicated legal address is stated.

Translations of these terms are provided for convenience. Unless a local-language version is expressly designated as binding for a locale, the English version prevails, except where mandatory local law requires otherwise for that provision.

References to Shopify, Stripe or other brands are for interoperability description only and do not imply partnership, endorsement or joint liability beyond publicly available platform integrations and each party’s separate terms with those providers.

Customer remains solely responsible for consumer-facing legal texts on its storefront, including terms of sale, cancellation policies, imprint and privacy information required in the countries where it offers goods or services.

If Customer enables multiple stores or markets under one Checkivo account, usage metrics and fees may be aggregated as described in the plan. Checkivo may require separate subscriptions where fair-use or technical isolation requires it.

Force majeure events—including major cloud-provider outages, war, epidemic, government action or failure of third-party platforms—excuse performance for the duration of the event, provided the affected party uses reasonable efforts to mitigate.

Nothing in the agreement creates a partnership, joint venture or employment relationship. Neither party may bind the other to third parties except as expressly authorised in writing.

Headings are for convenience only and do not affect interpretation. Words in the singular include the plural and vice versa where the context allows.

Customer should retain copies of order forms, invoices, SOWs and configuration exports for its records. Checkivo may provide account statements or invoices digitally via email or the Customer account.

Support is provided via the channels stated on the Checkivo website or in the Customer account during local business hours unless a higher support tier is purchased. Response times for standard support are targets, not guaranteed SLAs, unless an order form states otherwise.

Marketing examples, demos and case studies illustrate typical outcomes and do not constitute a binding service commitment for Customer’s specific store, catalogue, traffic volume or payment provider setup.

Where the Services allow export of configuration or Customer Data, Customer should perform exports before cancelling a subscription or deleting a connected store. Checkivo is not obliged to retain exports indefinitely after the retention window described in the DPA or documentation.

Checkivo may verify account ownership and authority before making sensitive configuration changes, issuing refunds of platform fees, or disclosing account information. Security challenges may include email verification to known admin addresses.

API rate limits, webhook delivery retries and fair-use rules may apply to protect platform stability for all merchants. Sustained abuse or automated scraping of the Services may result in throttling or suspension after notice where practicable.

Customer must ensure that scripts, pixels and third-party tags installed on its storefront do not impair security, performance or accessibility obligations Customer owes to End Customers, and do not circumvent Checkivo or Shopify security controls.

Notices under the agreement may be sent by email to the addresses associated with the Customer account or the order form. Customer shall keep notice emails current. Notices to Checkivo should be sent to [email protected] unless a dedicated legal address is stated.

Translations of these terms are provided for convenience. Unless a local-language version is expressly designated as binding for a locale, the English version prevails, except where mandatory local law requires otherwise for that provision.

References to Shopify, Stripe or other brands are for interoperability description only and do not imply partnership, endorsement or joint liability beyond publicly available platform integrations and each party’s separate terms with those providers.

Customer remains solely responsible for consumer-facing legal texts on its storefront, including terms of sale, cancellation policies, imprint and privacy information required in the countries where it offers goods or services.

If Customer enables multiple stores or markets under one Checkivo account, usage metrics and fees may be aggregated as described in the plan. Checkivo may require separate subscriptions where fair-use or technical isolation requires it.

Force majeure events—including major cloud-provider outages, war, epidemic, government action or failure of third-party platforms—excuse performance for the duration of the event, provided the affected party uses reasonable efforts to mitigate.

Nothing in the agreement creates a partnership, joint venture or employment relationship. Neither party may bind the other to third parties except as expressly authorised in writing.

Headings are for convenience only and do not affect interpretation. Words in the singular include the plural and vice versa where the context allows.

Customer should retain copies of order forms, invoices, SOWs and configuration exports for its records. Checkivo may provide account statements or invoices digitally via email or the Customer account.

Support is provided via the channels stated on the Checkivo website or in the Customer account during local business hours unless a higher support tier is purchased. Response times for standard support are targets, not guaranteed SLAs, unless an order form states otherwise.

Marketing examples, demos and case studies illustrate typical outcomes and do not constitute a binding service commitment for Customer’s specific store, catalogue, traffic volume or payment provider setup.

Where the Services allow export of configuration or Customer Data, Customer should perform exports before cancelling a subscription or deleting a connected store. Checkivo is not obliged to retain exports indefinitely after the retention window described in the DPA or documentation.

Checkivo may verify account ownership and authority before making sensitive configuration changes, issuing refunds of platform fees, or disclosing account information. Security challenges may include email verification to known admin addresses.

API rate limits, webhook delivery retries and fair-use rules may apply to protect platform stability for all merchants. Sustained abuse or automated scraping of the Services may result in throttling or suspension after notice where practicable.

Customer must ensure that scripts, pixels and third-party tags installed on its storefront do not impair security, performance or accessibility obligations Customer owes to End Customers, and do not circumvent Checkivo or Shopify security controls.

Notices under the agreement may be sent by email to the addresses associated with the Customer account or the order form. Customer shall keep notice emails current. Notices to Checkivo should be sent to [email protected] unless a dedicated legal address is stated.

Translations of these terms are provided for convenience. Unless a local-language version is expressly designated as binding for a locale, the English version prevails, except where mandatory local law requires otherwise for that provision.

References to Shopify, Stripe or other brands are for interoperability description only and do not imply partnership, endorsement or joint liability beyond publicly available platform integrations and each party’s separate terms with those providers.

Customer remains solely responsible for consumer-facing legal texts on its storefront, including terms of sale, cancellation policies, imprint and privacy information required in the countries where it offers goods or services.

If Customer enables multiple stores or markets under one Checkivo account, usage metrics and fees may be aggregated as described in the plan. Checkivo may require separate subscriptions where fair-use or technical isolation requires it.

Force majeure events—including major cloud-provider outages, war, epidemic, government action or failure of third-party platforms—excuse performance for the duration of the event, provided the affected party uses reasonable efforts to mitigate.

Nothing in the agreement creates a partnership, joint venture or employment relationship. Neither party may bind the other to third parties except as expressly authorised in writing.

Headings are for convenience only and do not affect interpretation. Words in the singular include the plural and vice versa where the context allows.

Customer should retain copies of order forms, invoices, SOWs and configuration exports for its records. Checkivo may provide account statements or invoices digitally via email or the Customer account.

Support is provided via the channels stated on the Checkivo website or in the Customer account during local business hours unless a higher support tier is purchased. Response times for standard support are targets, not guaranteed SLAs, unless an order form states otherwise.

Marketing examples, demos and case studies illustrate typical outcomes and do not constitute a binding service commitment for Customer’s specific store, catalogue, traffic volume or payment provider setup.

Where the Services allow export of configuration or Customer Data, Customer should perform exports before cancelling a subscription or deleting a connected store. Checkivo is not obliged to retain exports indefinitely after the retention window described in the DPA or documentation.

Checkivo may verify account ownership and authority before making sensitive configuration changes, issuing refunds of platform fees, or disclosing account information. Security challenges may include email verification to known admin addresses.

API rate limits, webhook delivery retries and fair-use rules may apply to protect platform stability for all merchants. Sustained abuse or automated scraping of the Services may result in throttling or suspension after notice where practicable.

Customer must ensure that scripts, pixels and third-party tags installed on its storefront do not impair security, performance or accessibility obligations Customer owes to End Customers, and do not circumvent Checkivo or Shopify security controls.

Notices under the agreement may be sent by email to the addresses associated with the Customer account or the order form. Customer shall keep notice emails current. Notices to Checkivo should be sent to [email protected] unless a dedicated legal address is stated.

Translations of these terms are provided for convenience. Unless a local-language version is expressly designated as binding for a locale, the English version prevails, except where mandatory local law requires otherwise for that provision.

References to Shopify, Stripe or other brands are for interoperability description only and do not imply partnership, endorsement or joint liability beyond publicly available platform integrations and each party’s separate terms with those providers.

Customer remains solely responsible for consumer-facing legal texts on its storefront, including terms of sale, cancellation policies, imprint and privacy information required in the countries where it offers goods or services.

If Customer enables multiple stores or markets under one Checkivo account, usage metrics and fees may be aggregated as described in the plan. Checkivo may require separate subscriptions where fair-use or technical isolation requires it.

Force majeure events—including major cloud-provider outages, war, epidemic, government action or failure of third-party platforms—excuse performance for the duration of the event, provided the affected party uses reasonable efforts to mitigate.

Nothing in the agreement creates a partnership, joint venture or employment relationship. Neither party may bind the other to third parties except as expressly authorised in writing.

Headings are for convenience only and do not affect interpretation. Words in the singular include the plural and vice versa where the context allows.

Customer should retain copies of order forms, invoices, SOWs and configuration exports for its records. Checkivo may provide account statements or invoices digitally via email or the Customer account.