Privacy Notice
How Jepsi collects, uses, shares and protects personal data.
This notice connects each main use of personal data to its purpose, legal basis, recipients and retention criteria.
Who we are and scope
This Privacy Notice explains how Jepsi collects and uses personal data when you visit jepsi.no, create an account, buy or sell digital products, contact us or otherwise use the marketplace.
The controller for Jepsi’s own processing is HANSIVAR.NO BENDIKSEN, Norwegian organisation number 983 987 532 (“Jepsi”, “we”, “us”). Our address is Bølstadveien 37, 3430 Spikkestad, Norway. Contact: contact@jepsi.no.
A seller is normally an independent controller for buyer data it receives to fulfil an order, provide support, meet tax or accounting duties and handle legal claims. The seller’s own privacy information may therefore also apply.
Our privacy principles
We process personal data lawfully, fairly and transparently. We limit collection to what is relevant, use data for stated purposes, take reasonable steps to keep it accurate and secure, and do not retain it longer than necessary.
Please do not submit sensitive personal data unless Jepsi specifically requests it and a lawful basis has been explained.
Data we collect
Depending on how you use Jepsi, we may collect:
- Identity and account data: name, username, email address, password hash, account settings and Google account identifier if you choose Google sign-in;
- Order and payment data: products, seller, price, tax, billing details, payment status, transaction identifiers, refunds and digital-delivery records. Full card details are handled by the payment provider and are not stored by Jepsi;
- Seller data: store details, contact person, organisation and tax details, payout information, verification records, listings and licences;
- Content and communications: reviews, product content, support requests, reports and messages;
- Technical and usage data: IP address, device and browser information, timestamps, security events, cookie identifiers, pages viewed, referrals and interaction data; and
- Preference data: consent choices, language, favourites and marketing preferences.
Where data comes from
Most data comes directly from you. We may also receive data from:
- sellers and buyers involved in the same transaction;
- payment, authentication, email and fraud-prevention providers;
- Google when you choose Google sign-in;
- public business registers for seller verification;
- your device and browser through technologies necessary to provide and secure the website; and
- authorities or other parties reporting suspected illegality, fraud or rights violations.
Purposes and legal bases
We use data only where we have an identified legal basis:
- Provide accounts, orders, downloads, stores and support: necessary to perform a contract or take requested pre-contract steps (GDPR Article 6(1)(b));
- Store-following and requested store updates: necessary to provide the feature you choose to activate (Article 6(1)(b));
- Accounting, tax, consumer, sanctions and lawful authority requests: necessary to comply with legal obligations (Article 6(1)(c));
- Security, fraud prevention, service administration, dispute handling and protecting legal rights: our legitimate interests in operating a safe and reliable marketplace (Article 6(1)(f));
- Non-essential analytics and optional integrations: consent where required (Article 6(1)(a)); and
- Public listings and reviews: performance of the requested service and our legitimate interest in operating a transparent marketplace.
Where we rely on legitimate interests, we consider necessity, proportionality and your rights. You may ask for more information about the relevant assessment.
Required and optional data
Fields marked as required are needed to create the requested account, complete a transaction or meet legal duties. If required data is not provided, we may be unable to supply that function.
Optional profile fields, reviews, store following and non-essential cookies are voluntary. Refusing or disabling them does not prevent access to unrelated core services.
Payments and orders
Payment information is sent securely to the payment provider used at checkout. Jepsi receives limited payment and transaction information needed to confirm the order, provide the download, administer refunds, reconcile accounts and prevent fraud.
Relevant order details are shared with the identified seller so the seller can deliver the product, honour the licence, provide support and handle legal obligations. Buyers and sellers must use this data only for legitimate transaction purposes.
Public content
Store names, seller information required by law, listings, profile elements and reviews may be publicly visible. Do not publish private contact details, confidential information or personal data about others unless you are entitled to do so.
Images may contain metadata such as location information. Remove unnecessary metadata before uploading. Public material may be indexed by search engines or copied by others before it is removed.
Google sign-in and technical performance
Jepsi does not currently use Google Analytics or another visitor analytics service on the public website. If optional analytics is introduced later, it will not be activated before valid consent where consent is required, and this notice will be updated.
If you choose Sign in with Google, Google provides the identifiers and profile details shown during authorisation, normally including name and email address. Google sign-in is optional, and the authorisation can also be managed in your Google account.
PageSpeed Insights may be used to assess technical page performance. This is used for aggregate technical testing and is not intended to create individual marketing profiles.
Service emails and store-follow notifications
Jepsi does not currently operate a general newsletter. We send operational messages needed for accounts, security, orders, downloads, support and legal notices.
If you choose to follow a store, we record your user ID, the store ID and follow or unfollow timestamps. The relevant seller can see your name and when you followed, and may receive an email when you follow or unfollow the store.
Active followers may receive periodic emails about newly published products and relevant store coupons. These messages are part of the store-follow feature you requested, not a general Jepsi newsletter. You can stop future store updates at any time by unfollowing the store in your account or on the store page.
Who receives personal data
We disclose only what is reasonably necessary to:
- the seller or buyer involved in a transaction;
- hosting, website, email, authentication, payment, accounting, security and customer-support providers acting under contract;
- professional advisers, auditors and insurers where necessary;
- public authorities, courts or law enforcement where disclosure is legally required or necessary to protect legal rights; and
- a successor in a genuine merger, restructuring or transfer of the Jepsi business, subject to confidentiality and applicable notice requirements.
Current service categories include WordPress and WooCommerce infrastructure, optional Google sign-in, and the payment provider displayed at checkout. Providers may change as the service develops.
We do not sell personal data.
International transfers
Some providers or their sub-processors may process data outside Norway or the EEA. Where this occurs, we use a lawful transfer mechanism such as an adequacy decision, the EU Standard Contractual Clauses, or another mechanism permitted by GDPR, together with supplementary safeguards where required.
You may contact us for information about the mechanism relevant to a particular provider. The former EU-US Privacy Shield is not relied upon as a transfer basis.
How long we keep data
Retention depends on purpose, legal duties and risk:
- account and profile data is normally kept while the account is active; inactive accounts may be reviewed for deletion after three years;
- store-follow relationships are kept while active; follow and unfollow timestamps may remain with the account for a limited period for preference, security and dispute records, then are deleted or anonymised when no longer needed;
- orders, payments, refunds, consent records and accounting documentation are retained for statutory accounting, tax, consumer and limitation periods;
- seller verification and contract records are retained for the relationship and applicable statutory or claim periods;
- support, complaint and dispute records are normally retained for up to three years after closure, longer where a claim or legal duty requires it;
- security logs are normally kept for up to twelve months, longer where needed to investigate an incident;
- analytics retention follows the configured provider setting and your consent; and
- backups are overwritten on a rolling schedule and isolated data may remain until the relevant backup expires.
We may anonymise data instead of deleting it where it can no longer identify you.
Security and breaches
We use proportionate technical and organisational safeguards, including access controls, encryption in transit, updates, backups, logging and provider management. No online system can be guaranteed completely secure.
If a personal-data breach creates a risk to individuals, we will assess it, notify the relevant authority where required and inform affected individuals when the law requires it.
Automated decisions
Technical tools may help detect spam, fraud, security risks or unusual transactions. Jepsi does not currently make decisions based solely on automated processing that produce legal or similarly significant effects on users.
If this changes, we will provide required information about the logic, significance, consequences and available human review before such processing begins.
Your privacy rights
Subject to the conditions and exceptions in applicable law, you may:
- request access to your personal data and a copy;
- correct inaccurate or incomplete data;
- request deletion;
- request restriction of processing;
- object to processing based on legitimate interests and object at any time to direct marketing;
- receive data you provided in a portable format where the portability right applies;
- withdraw consent at any time without affecting earlier lawful processing; and
- request human intervention where applicable automated-decision rights apply.
Send requests to contact@jepsi.no. We may request proportionate information to verify identity, but you do not normally need to send a full identity-document copy. We normally respond within one month and will explain any lawful refusal or extension.
Questions and complaints
Please contact us first at contact@jepsi.no so we can investigate. You also have the right to complain to the Norwegian Data Protection Authority (Datatilsynet): datatilsynet.no.
If you live elsewhere in the EEA, you may also contact the supervisory authority in your country of residence, work or the place of the alleged infringement.
Changes to this notice
We may update this Privacy Notice when services, providers or legal requirements change. The current version and effective date will be published here. We will give prominent or direct notice of material changes where appropriate.
