Private betainstoor is currently open to invited beta testers only. Request beta access →
logo
brand
Legal · Privacy policy

Your data stays yours.

What we collect, why we need it, and how you stay in control. Hosted in the EU, under GDPR.

VERSION1.0
EFFECTIVE2026-10-01
LANGUAGEEN
01 / Who this policy is for

Who this policy is for

In short

This policy explains what we do with personal data: yours as a shop owner, and that of visitors to our website.

This Privacy Policy describes how Villaratio BV, with registered office at Oude Kapellestraat 14, 8700 Tielt, Belgium, enterprise number BE 0728.924.019 ("instoor", "we", "us") processes personal data when you visit instoor.com, create an account, or contact us.

It does not cover the data your own customers give to your store. For that data, you are in charge and we only work on your behalf (see section 03).

02 / Who is responsible

Who is responsible

In short

For your account data, we are the controller. For your customers’ data, you are, and we are your processor.

We are controller for

Your merchant account, billing details, support messages and visits to instoor.com.

We are processor for

Orders, bookings and subscriptions of your customers in your store. You decide, we follow your instructions.

Our role as processor is set out in the Data Processing Agreement, which is part of our Terms of service.

03 / Your customers’ data

Your customers’ data

In short

Your customers’ data belongs to you. We never sell it, and we never use it to market to them ourselves.

We store and process customer data only to run your store: showing products, taking bookings, renewing subscriptions and sending the messages you set up.

We do not combine customer data across stores, and we do not use it for our own advertising.

04 / What we collect and why

What we collect and why

In short

Only what we need to run your account, bill you and answer your questions.

Data Why Legal basis Kept for
Name, email, password Your account and login Contract As long as your account exists
Business and billing details Invoices for your plan Contract, legal duty 10 years (Belgian accounting law)
Support messages Answering your questions Legitimate interest 1 year
Technical logs Security and fixing errors Legitimate interest 1 month
Website statistics Improving our website Consent 3 months
05 / Payments

Payments

In short

Payments run through your own Mollie account. We never see or store full card numbers.

Your customers’ payments are handled by Mollie B.V. under its own privacy policy. We receive only the status of a payment (for example “paid” or “failed”) so your store can confirm an order or booking.

For your instoor plan, we use Mollie B.V. (Netherlands) to process your payments to us.

06 / Who we share data with

Who we share data with

In short

A short list of service providers who help us run instoor. All under contract, all held to GDPR.

  • Hosting · Hetzner Online GmbH (Germany) EU
  • Email delivery · Mailjet SAS (France) EU
  • Billing · Mollie B.V. (Netherlands) EU
  • Website statistics · In-house developed (Belgium) EU

We do not sell personal data. We share data with authorities only when the law requires it.

07 / Where data is stored

Where data is stored

In short

In the European Union. We don’t move it outside the EU.

Your data is stored on servers in Germany, within the EU. If a provider ever processes data outside the European Economic Area, we use the European Commission’s Standard Contractual Clauses or an adequacy decision.

08 / Cookies

Cookies

In short

Essential cookies keep you logged in. Statistics cookies are only set if you say yes. Guest visitors remain anonymous.

We use strictly necessary cookies for login and security, and statistics cookies only with your consent. You can change your choice at any time via the cookie settings link in the footer.

Your store sets its own cookies for the shopping cart and bookings. These are necessary for your store to work.

Guest visitors remain anonymous. Web analytics will not store ip addresses, and uses asymmetric encrypted client data to identify visitors.

09 / Security

Security

In short

We protect data with encryption, limited access and regular backups.

Data is encrypted in transit (TLS) and at rest. Only team members who need access for their work have it, and access is logged. We make regular backups and test that we can restore them.

If a data breach affects you, we inform you without undue delay and, where required, notify the Belgian Data Protection Authority within 72 hours.

10 / Your rights

Your rights

In short

You can see, correct, export or delete your data. Ask us and we answer within one month.

Access

Get a copy of the data we hold about you.

Correction

Fix data that is wrong or incomplete.

Deletion

Ask us to delete your data.

Export

Receive your data in a common format.

Objection

Object to processing based on legitimate interest.

Withdraw consent

Change your mind about statistics cookies at any time.

If you are a customer of a store on instoor, please contact that store first. We will help them answer your request.

You can also file a complaint with the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit / Autorité de protection des données), dataprotectionauthority.be.

11 / Changes to this policy

Changes to this policy

In short

If we change something important, we email you before it applies.

We may update this policy when our services or the law change. The date at the top always shows the latest version. For important changes, we notify account holders by email in advance.