Try for free Login Home Features Pricing Demo
Platforms

Privacy Policy

Last updated: July 10, 2026 · Effective: July 10, 2026
Contents
  1. Who we are
  2. What we collect
  3. Legal bases for processing (GDPR)
  4. End-visitor data
  5. Cookies and similar technologies
  6. How we use your data
  7. Sharing and subprocessors
  8. International transfers
  9. Security
  10. Your rights under GDPR (EU/UK/EEA)
  11. California residents (CCPA/CPRA)
  12. Children
  13. Retention
  14. Automated decisions
  15. Changes
  16. Contact and complaints

StoreLoWidget ("we", "us", "our") provides a hosted store-locator service. This Privacy Policy explains what information we collect when you use our website (storelowidget.com), our dashboard, and the locator widget you embed on your own website. We aim to comply with the EU General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act as amended by the CPRA (CCPA/CPRA), the FTC Act, and other applicable laws.

1. Who we are

The data controller is Robin Wessels, a sole proprietorship (eenmanszaak) established in the Netherlands and the operator of StoreLoWidget. Dutch Chamber of Commerce (KvK) number: 42030276. VAT ID: NL005442905B92. Contact: info@robinwessels.com. We do not currently appoint a separate Data Protection Officer because we are below the threshold of GDPR Art. 37; the contact above handles all privacy requests.

2. What we collect

Information you give us

Information collected automatically

3. Legal bases for processing (GDPR Art. 6)

4. End-visitor data (visitors to your embedded widget)

When a visitor to a site that embeds our widget performs a search, we process their search query and, if they explicitly grant browser permission, their approximate GPS location in order to return nearby results. We act as the processor and you (our customer) act as the controller for that data. The terms of that processing are set out in our Data Processing Agreement (GDPR Art. 28). We do not build advertising profiles of end-visitors and we do not sell their data. You should disclose this processing in your own privacy policy.

5. Cookies and similar technologies

Our marketing site (storelowidget.com) uses only essential cookies needed to remember your cookie preference. The dashboard uses a strictly necessary session cookie to keep you signed in and a CSRF token cookie. The embeddable widget itself does not set any cookies by default; if you enable optional analytics in your widget settings, we disclose this in the widget UI.

Consent management. Non-essential cookies on the marketing site are controlled by a central consent service operated by the site owner (Robin Wessels) at consent.robinwessels.com. It shows a cookie banner on every marketing page, applies Google Consent Mode v2 with all non-essential storage denied by default, and lets you accept or reject analytics and marketing separately — nothing non-essential loads until you opt in. Your choice is remembered for 12 months, after which we ask again. You can change or withdraw it at any time via the "Cookie settings" link in the footer; when you withdraw consent, further measurement stops and the measurement cookies this site has set are deleted.

Analytics cookies (Google Analytics 4). With your consent we use Google Analytics 4, loaded as a tag through Google Tag Manager, to understand how visitors find and use our marketing site — for example which pages are viewed, how visitors navigate, and which features draw interest — so that we can measure and improve the site. This sets cookies named _ga and _ga_VJEPSMLJE6 (default lifetime up to 2 years) and processes pseudonymised usage data, including a truncated/anonymised IP address; usage data is retained in Google Analytics for a maximum of 14 months. The provider is Google Ireland Ltd / Google LLC, acting as our processor under a data-processing agreement; data may be transferred to the United States under the EU-US Data Privacy Framework and Standard Contractual Clauses (see sections 7 and 8). Google Consent Mode is enabled, so no analytics cookies are set and no analytics data is sent until you enable "Analytics" in the cookie banner. If you reject, or make no choice, Google Analytics is never loaded.

Marketing cookies (Meta pixel). With your consent we use the Meta pixel, loaded as a tag through Google Tag Manager, for ad measurement — to see whether our advertising on Meta platforms (Facebook, Instagram) leads to visits and sign-ups — and to build advertising audiences so we can show relevant ads to similar or returning visitors. The pixel sets cookies such as _fbp (lifetime up to 90 days) and processes page-view and event data. The provider is Meta Platforms Ireland Ltd / Meta Platforms, Inc., and data may be transferred to the United States under the EU-US Data Privacy Framework and Standard Contractual Clauses (see sections 7 and 8). The Meta pixel is never loaded until you explicitly enable "Marketing" in the cookie banner.

Marketing cookies (Google Ads). With your consent we use Google Ads conversion tracking and remarketing cookies to measure whether our advertising leads to sign-ups or purchases, and to show you relevant ads on other sites. These cookies (e.g. _gcl_au, _gcl_aw) are set by Google and may have a lifetime of up to 90 days. The provider is Google Ireland Ltd / Google LLC, acting as our processor under the same data-processing agreement and transfer safeguards described above. Google Consent Mode is enabled: no marketing cookies are set and no ad-related data is sent until you explicitly enable "Marketing" in the cookie settings.

Proof of consent. When you make or change a cookie choice, the consent service records that choice anonymously — the record contains the choice, a timestamp, and the consent-text version, but no IP address and no user agent — and keeps it for 24 months as evidence of consent (see section 13).

The table below is generated automatically from the current cookie configuration of this site, so it always reflects the exact cookies and tags in use:

You can manage or withdraw consent at any time by clicking "Cookie settings" in the footer; withdrawing consent stops any further analytics and marketing data collection.

6. How we use your data

7. Sharing and subprocessors

We share data with vetted subprocessors that help us run the service. Each is bound by a data-processing agreement (DPA) and processes data only on our instructions. Current subprocessors include:

An up-to-date subprocessor list is available on request via info@robinwessels.com. We do not sell or rent personal data.

8. International transfers

Some subprocessors are based in the United States. Where personal data leaves the EEA/UK, we rely on the EU Commission's Standard Contractual Clauses (2021/914) and, where applicable, the EU-US Data Privacy Framework. We assess each transfer and implement additional safeguards (encryption, pseudonymisation, access controls) where required.

9. Security

We use industry-standard safeguards: TLS in transit, encryption at rest for sensitive data, hashed and salted passwords (bcrypt/argon2), parameterised database queries to prevent SQL injection, least-privilege access controls, audit logging, and two-factor authentication for staff and customer accounts. No system is perfectly secure; if we become aware of a personal-data breach affecting your data we will notify the competent supervisory authority within 72 hours where required (GDPR Art. 33) and notify you without undue delay (Art. 34) where the breach is likely to result in high risk.

10. Your rights under GDPR (EU/UK/EEA)

You have the right to:

To exercise any of these rights, email info@robinwessels.com. We respond within 30 days. We may ask you to verify your identity before disclosing or deleting data.

11. California residents (CCPA / CPRA)

If you are a California resident, you have the following rights under the California Consumer Privacy Act as amended by the CPRA:

To exercise these rights, email info@robinwessels.com with the subject "CCPA request". You may designate an authorised agent to make a request on your behalf; we will require written proof of authority.

Categories of personal information collected (CCPA categories): identifiers (name, email, IP); commercial information (subscription, billing); internet activity (usage logs); geolocation (approximate, from IP or end-visitor consent); professional information (company, role). Categories disclosed to subprocessors: identifiers, commercial information, internet activity, for the business purposes described in section 6.

12. Children

StoreLoWidget is not directed at children under 16. We do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, contact us and we will delete it. This aligns with COPPA (United States) and GDPR Art. 8.

13. Retention

Account data is retained while your account is active and for up to 12 months after cancellation, after which it is deleted or anonymised. Search and analytics events (the search queries and approximate locations recorded when visitors use a store locator) are retained for up to 14 months and then deleted. Cookie-consent records are logged anonymously in the central consent service (no IP address, no user agent — see section 5) and retained for up to 24 months as evidence of consent, then deleted; legacy consent records collected on this site before July 2026 are purged on the same 24-month schedule. Invoicing and tax records are retained for seven years as required by Dutch law. Backups are retained for 30 days. Aggregate, fully anonymised statistics that cannot be linked to an individual may be retained longer.

14. Automated decisions and profiling

We do not make decisions about you that produce legal or similarly significant effects on the basis of automated processing alone.

15. Changes to this policy

We may update this policy from time to time. We will post the updated version on this page and update the "Last updated" date above. For material changes we will notify you by email or via the dashboard at least 30 days before the change takes effect.

16. Contact and complaints

Privacy questions, rights requests, and complaints: info@robinwessels.com.

EU/EEA residents have the right to lodge a complaint with their national supervisory authority. The Dutch authority is the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl). UK residents may contact the Information Commissioner's Office (ico.org.uk).