PANOpeak is a Buy Box repricer for European marketplace sellers: it connects to your bol, Amazon, Kaufland, eMAG and TikTok Shop seller accounts and adjusts your prices automatically, inside limits you set. This policy covers both this website and the product at app.panopeak.app, and explains what we collect, why, where it goes, how long we keep it, and what you can ask us to do about it. It replaces the earlier waitlist-only version of this policy. If anything here is unclear, email founder@panopeak.app and a real person will answer.
1. Who we are
The controller of your data is Anton Panainte, trading as PANOpeak, based in the Netherlands and registered with the Dutch Chamber of Commerce (KVK) under number 42165111. A VAT number will be added here once it is issued. You can reach us at founder@panopeak.app for anything relating to your data or this policy.
2. What we collect
What we process depends on whether you are a visitor to this website or a PANOpeak customer:
| Source | What | Personal data? |
|---|---|---|
| Your PANOpeak account | Name, work email, password (stored as a salted hash, never in plain text), role, and, if you enable it, a two-factor authentication secret. Your workspace's billing contact and invoice history, handled by Stripe. | Yes |
| Marketplace connections | The API credentials or OAuth tokens for the marketplace seller accounts you connect, stored encrypted, and used only to read and adjust your own listings on our instruction from you. We never see or need the marketplace account holder's own consumer-facing personal data. | Sometimes |
| Catalogue, pricing & competitor data | Your listings, prices, floor and ceiling guardrails, and the public offer data (prices, seller names) of other sellers competing on the same listings: business data, not data about individual consumers. This competitor data reaches us from each marketplace's own public listings, not from the individuals themselves. | Rarely |
| Waitlist signup | If you join the waitlist rather than starting a trial directly: your email address; optionally the marketplaces you sell on and your SKU-range band; the timestamp of your consent; UTM parameters and the referring page; and a salted SHA-256 hash of your IP address. We never store the raw IP. | Yes |
| Website analytics | Aggregated, cookieless usage stats for this marketing site via Plausible: page views and referrers, with no personal data, no cross-site tracking, and no fingerprinting. That includes which options you try in the pricing configurator: the marketplaces and SKU band you select and the indicative figure they produce, sent as an aggregate event with nothing attached that identifies you or your device. The product itself (app.panopeak.app) runs no analytics at all. |
No |
| Security & audit telemetry | Cloudflare processes your IP transiently to serve pages and block abuse. Inside the product, an append-only audit log records who did what and when (logins, connection changes, exports, DPA and terms acceptance) for security and accountability. | Yes / transient |
The cookies and browser storage the product itself uses, all functional or strictly necessary and never advertising or tracking, are listed in-app under Settings → What we store on your device, kept in sync with the code that sets them. Our Cookie Policy lists the same entries for this website.
We do not collect data from children. PANOpeak is a business tool sold to marketplace sellers, is not directed at children, and requires account holders to be at least 18 and acting for a business. We do not knowingly process the personal data of a child; if you believe we hold any, email founder@panopeak.app and we will delete it.
3. Why we process it, and our legal bases
Under the GDPR we need a lawful basis for each purpose:
- Contract, Art. 6(1)(b). Your account, marketplace connections, and the repricing itself exist to perform the agreement you enter into when you start a trial or subscription. We cannot provide the product without this data.
- Legal obligation, Art. 6(1)(c). Invoices and billing records are kept to meet Dutch tax and accounting law, which currently requires financial records to be retained for seven years.
- Legitimate interest, Art. 6(1)(f). Audit logs, hashed IPs, rate limiting and Cloudflare's protection keep the product and the signup form secure and free of abuse; this is low-impact processing you would reasonably expect from a paid business tool.
- Consent, Art. 6(1)(a). We email waitlist members about PANOpeak's launch and early access only because they ticked the consent box and confirmed via a double opt-in link. That confirmation is also our proof of consent.
PANOpeak does not use automated decision-making that produces legal or similarly significant effects on a natural person. The repricing engine only changes the prices on your own listings, within floor and ceiling guardrails you configure yourself and can change at any time; it makes no decision about a competing seller, so Article 22 GDPR does not apply to how we use their public offer data.
4. Controller or processor: who decides what
For your account and billing data, and for this website's visitors, PANOpeak is the controller: we decide why that data is processed. For the catalogue, pricing and marketplace data you connect to the product, PANOpeak is a processor acting on your instructions, and you (or the business you represent) are the controller. That relationship is governed by our Data Processing Agreement, which every workspace admin accepts before a marketplace can be connected, and which sets out our obligations in full: security measures, sub-processors, breach notification and your rights as controller.
5. Where your data goes
We work with a small, named set of sub-processors, chosen for EU processing wherever possible. The version below is a summary; the DPA and your workspace's Settings → Data Processing Agreement page carry the authoritative, versioned list:
| Sub-processor | Purpose | Location |
|---|---|---|
| Railway | Compute, primary data store and job queue state | EU (Amsterdam) |
| Cloudflare | DNS, CDN, WAF and bot protection | EU network, US company (Standard Contractual Clauses) |
| Stripe | Billing and payments | EU + US (Standard Contractual Clauses) |
| Resend | Transactional email | EU |
We do not sell your data, and we do not share it with advertising networks. Where a sub-processor is outside the EU (Stripe, Cloudflare), Standard Contractual Clauses are in place. Adding a marketplace as a sub-processor (eMAG, TikTok Shop) is currently drafted and pending a legal determination on whether it is a sub-processor or an independent recipient of your instructed data; either way, we transmit only what you have configured us to transmit, on your instruction.
We may disclose data where required to comply with a legal obligation, a valid court order, or a lawful request from a public authority, or where necessary to protect our rights, our users, or the public from fraud or harm. Where we are not legally prohibited from doing so, we will tell you before or promptly after any such disclosure.
6. How long we keep it
Account and billing data: for as long as your workspace exists, plus the statutory retention period for financial records (currently seven years under Dutch law) for invoices specifically.
Operational data (listings, price history, competitor snapshots): kept for the history window your plan includes: 30 days on Starter, 90 days on Growth, and 730 days on Professional and Enterprise, after which it ages out automatically. No plan retains it longer than 730 days.
Deleting your workspace: an admin can request deletion at any time from Settings. We schedule it rather than acting immediately, so you have 30 days to change your mind before it becomes permanent; you can cancel the request at any point in that window. Once it runs, your workspace, its users, connections, listings and history are permanently removed.
Waitlist data: kept until launch conversion or unsubscribe. An unconfirmed signup expires automatically with its 7-day confirmation token.
7. Your rights
The GDPR gives you the right to access your data, correct it, have it erased, receive a copy of it (portability), object to processing, and withdraw your consent at any time. You can request account erasure yourself, self-serve, from Settings (see above); for everything else, email founder@panopeak.app and we will respond within the legal timeframe. You also have the right to complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens.
8. How we protect it
The product and this site are served over TLS only, with security headers enabled. Every tenant's data is isolated at the database level (row-level security), so one workspace's data is not reachable through another's session even in the event of an application bug. Marketplace credentials are stored encrypted, and passwords are never stored in plain text. We practise data minimisation, asking for as little as possible. We do not yet have a dedicated security disclosure address; until we do, report a security issue to founder@panopeak.app.
9. Changes to this policy
We will update the "last updated" date and version at the top whenever this policy changes materially, and existing customers are shown a notice in the product when the version they accepted is no longer current. This does not interrupt your service; see the Terms of Service for how that works.