GDPR & Data Rights

Last updated: April 17, 2026

Overview

Shopvibes Media is committed to GDPR compliance and protecting the data rights of all users, regardless of location. This page explains your rights under GDPR, how we protect your data, and how to exercise those rights.

Questions? Email contact@shopvibesmedia.com with "GDPR Request" in the subject line.

Your Rights Under GDPR (Articles 15-22)

If you're in the EU, UK, or anywhere your data is processed, you have the following statutory rights:

Right What It Means How to Request
Right of Access (Article 15) You can request all data we hold about you in machine-readable format Email contact@shopvibesmedia.com
Right to Rectification (Article 16) You can correct inaccurate information we hold Email contact@shopvibesmedia.com
Right to Erasure / "Right to be Forgotten" (Article 17) You can request we delete your data (except where legal obligations require retention) Email contact@shopvibesmedia.com
Right to Restrict Processing (Article 18) You can limit how we use your data while a dispute is resolved Email contact@shopvibesmedia.com
Right to Data Portability (Article 20) You can request your data in a portable, machine-readable format Email contact@shopvibesmedia.com
Right to Object (Article 21) You can object to processing for specific purposes (e.g., marketing) Email contact@shopvibesmedia.com
Right to Withdraw Consent (Article 7(3)) If we rely on your consent, you can withdraw it anytime Email contact@shopvibesmedia.com or click "unsubscribe" in emails

How to Exercise Your Data Rights

  1. Email contact@shopvibesmedia.com
  2. Include your full name and the email address associated with your account
  3. Specify which right you're exercising (access, delete, export, object, etc.)
  4. We will respond within 30 days (the legal deadline under GDPR Article 12)

Subject line example: "GDPR Request: Right to Access My Data"

We do not charge for exercising your rights (except in cases of manifestly unfounded or excessive requests, which are rare). Our response includes all data we hold about you in a format you can easily use or transfer to another service.

Data Processing Agreements (DPAs)

If you work with us as a business or if you're managing users' data on our platform, we have executed Data Processing Agreements (DPAs) with our service providers:

Our Data Processors:

All processors are GDPR-compliant and operate under contractual obligations to protect your data. We can provide copies of DPAs upon request.

Standard Contractual Clauses (SCCs)

For any data transfers from the EU/UK to the United States, we use Standard Contractual Clauses (SCCs) as approved by the European Commission. These clauses ensure that your data receives the same level of protection regardless of where it's processed.

Standard Contractual Clauses provide:

Shopvibes has executed SCCs with all US-based service providers (Stripe, GoHighLevel, Mailgun) and EU-based providers (where applicable).

Data Retention & Deletion

We retain your data only as long as necessary for the purposes we collected it:

Data Type Retention Period Reason
Contact information (name, email) Until you request deletion Service delivery and communication
Payment records 7 years Tax and accounting legal requirement (US)
Email engagement data 26 months (GA default) Analytics and service improvement
Session cookies Until you close your browser Keeping you logged in during your visit

Upon deletion request: We remove your personal data within 30 days. Financial records required by law are anonymized (transaction date and amount only, no names or contact info).

Complaints to Your Data Protection Authority

If you're in the EU/UK and believe we've violated your GDPR rights, you have the right to lodge a complaint with your national data protection authority (DPA):

Filing a complaint does not affect your ability to pursue a civil claim in your local courts.

International Data Transfers

Shopvibes is a US-based company (Delaware LLC). If you're outside the US and provide us data:

Adequacy Decisions: The US has not been granted an EU "adequacy decision," meaning US data protection laws don't automatically meet GDPR standards. We bridge this gap through Standard Contractual Clauses and contractual commitments with our processors.

Contact & Oversight

For any GDPR-related inquiries, data subject requests, or complaints:

Shopvibes Media
Email: contact@shopvibesmedia.com
Subject: "GDPR Request: [Your Request Type]"
Response time: 30 days maximum

Updates to This Page

Date Change
April 17, 2026 Initial publication