ToolsTemplatesPricingBlog
Start free
ToolsTemplatesPricingBlog
Start free
Glevu
Launch your business online today
The AI-native commerce OS for local business. Store, salon, or restaurant, live in minutes, run by chat.
Get started

Product

  • Tools
  • Templates
  • Pricing
  • Restaurants
  • Salons
  • Shops

Company

  • Blog
  • Help
  • Contact

Legal

  • Privacy policy
  • Terms of service
  • Cookie policy
  • Imprint
  • Accessibility
2026 Glevu. Built in Europe. All rights reserved.
Legal

Privacy policy

This policy explains what personal data Glevu processes, why, and the rights you have. It covers glevu.com and merchant accounts. Shopper data on a merchant site is handled under that merchant's own policy, with Glevu acting as their processor.

Last updated: 3 July 2026

Contents

  1. 1.Who we are
  2. 2.Controller and processor: an important split
  3. 3.What data we process
  4. 4.Why we are allowed to process it (legal bases)
  5. 5.Who we share data with (subprocessors)
  6. 6.International transfers
  7. 7.How long we keep data
  8. 8.Your rights
  9. 9.How we protect data
  10. 10.Children
  11. 11.Changes to this policy

1.Who we are

Glevu is a platform that lets local businesses build a website and run their operations online. This policy explains how we handle personal data for the people who visit glevu.com, the merchants who run a business on Glevu, and the shoppers who interact with a merchant site.

The data controller for this website and for merchant accounts is Glevu. Our published company and contact details are set out in the Imprint. You can reach us about privacy at privacy@glevu.com.

2.Controller and processor: an important split

Glevu plays two different roles, and it matters which one applies to a given piece of data.

  • Glevu as controller. For visitors to glevu.com and for the merchant account holders who sign up with us, we decide why and how data is processed. We are the controller. This policy governs that data.
  • Glevu as processor. For the shopper and customer data that a merchant collects through their own Glevu site (orders, bookings, contact messages, reviews), the merchant is the controller and Glevu is the processor. We process that data only on the merchant's documented instructions, under the data processing terms in our Terms of service. If you are a shopper asking about data a specific business holds, contact that business first; we will support them in responding.

3.What data we process

Merchant account data

When you create a Glevu account we process your name, email address, password (stored only as a secure hash), business name, and the settings and content you add to your site. We also process operational records such as sign in times and support correspondence.

Billing data

Payments for Glevu subscriptions are handled by Stripe. We do not store full card numbers. We keep the billing records needed to issue invoices and meet our bookkeeping obligations, such as plan, billing period, amount, and invoice history.

Website and product usage

We use privacy friendly, cookieless analytics to understand aggregate usage of glevu.com and the admin. This does not build a profile of you across other sites. Server logs record technical data such as IP address and browser type for security and to keep the service running.

Shopper data processed for merchants

When a shopper buys from, books with, or contacts a merchant site, we process the data needed to deliver that (for example name, contact details, order or booking details) as the merchant's processor, not for our own purposes. Merchants can use their Glevu admin dashboard to export or anonymize a shopper's personal data upon request.

4.Why we are allowed to process it (legal bases)

Under the GDPR and the equivalent Bosnian and Swedish law, we rely on the following bases:

  • Performance of a contract (Art. 6(1)(b)): to create and run your account and provide the platform you signed up for.
  • Legitimate interests (Art. 6(1)(f)): to keep the service secure, prevent abuse, and improve the product using aggregate usage data.
  • Legal obligation (Art. 6(1)(c)): to keep accounting and tax records for the periods the law requires.
  • Consent (Art. 6(1)(a)): where we ask for it, for example optional product emails. You can withdraw consent at any time.

5.Who we share data with (subprocessors)

We do not sell personal data. We use a small set of trusted providers to run the platform. Each acts under a data processing agreement and processes data only for us:

  • Vercel: application hosting and content delivery.
  • Neon: the managed Postgres database.
  • Vercel Blob: storage for uploaded media (logos, product images).
  • Stripe: payment processing for Glevu subscriptions.
  • Resend: transactional email delivery.
  • Umami: privacy friendly, cookieless analytics.

The current subprocessor list is maintained here. We will update it before adding a new subprocessor that handles personal data.

6.International transfers

We aim to keep data in the European Union or European Economic Area where practical. Where a provider processes data outside the EEA, we rely on an adequacy decision or on the European Commission's Standard Contractual Clauses, together with additional safeguards where needed, so your data keeps an equivalent level of protection.

7.How long we keep data

We keep account data for as long as your account is active and for a short period afterwards to handle wind down. Invoices and other accounting records are retained for the statutory bookkeeping period. When a business is closed on Glevu, personal data is purged after a grace window (default 30 days), while invoices and order records are retained in anonymized form for the period the law requires (typically 11 years for accounting). Backups roll off on their own schedule.

8.Your rights

You have the right to:

  • access the personal data we hold about you;
  • have inaccurate data corrected;
  • have data erased where the law allows;
  • restrict or object to certain processing;
  • receive your data in a portable format;
  • withdraw any consent you gave, without affecting past processing.

To exercise these rights, contact us at privacy@glevu.com. You can also complain to a supervisory authority. In Bosnia and Herzegovina this is the Personal Data Protection Agency (Agencija za zaštitu ličnih podataka, AZLP). In Sweden it is the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY).

9.How we protect data

We use encryption in transit, hashed passwords, tenant isolation so one business cannot see another's data, least privilege access for our team, and audited change control on the database. No system is perfectly secure, but we work to protect your data and to detect and respond to issues quickly.

10.Children

Glevu is a tool for businesses and is not directed at children. We do not knowingly collect personal data from children through glevu.com.

11.Changes to this policy

We may update this policy as the platform evolves or the law changes. We will post the new version here with an updated date, and for material changes we will notify account holders by email or in the admin.