This privacy policy explains how Jaapi AB (a Swedish company, org. no. 559387-9421) handles your personal data when you use a store we host. Most people reading it work for an organization that runs a store with us, or are accepting a gift sent from one. Your organization is the controller of the data in its store: it decides why that data is processed, and Jaapi is its processor, acting on its instructions. Jaapi is the controller of what it holds about its own customers: contacts, contracts and billing. Visitors to our website, people who book a demo and prospective customers are covered by the separate website privacy notice.
What Information We Handle
Data in your organization's store. Your account (name, email address, role and department), the shipping addresses you enter, your order history, your credit balance and its history, and any support correspondence. Your account is created when your organization provisions users from its identity provider or HR system, when an administrator invites you, when you sign in, when you create an account yourself on a store that allows it, or when you claim a credit-gift code. Your organization must give us a name and email address to open your account, and you must enter a shipping address to receive an order; without them the store cannot serve you. A gift sent to you as a link tells us who you are only from the address you enter when accepting it. For a gift campaign, the sender gives us your name and email address, which we store on the gift and use to send you the invitation. Payment card details go to our payment processor and never reach our systems.
The stores are for adults at work. We do not knowingly process the data of anyone under 16; if you believe a child has entered data into a store, contact us and we will remove it.
Technical data. Each request to a store is logged with your IP address, the page requested and your browser's identification string, for security and debugging. Your IP address is also resolved to a country so that the store can suggest your region.
Data about our customers. The names and contact details of the people at your organization we deal with, the agreement, and the invoices.
In the categories US state privacy laws use, this is identifiers (name, email address, phone number, IP address), professional or employment-related information (role and department), commercial information (orders and credit), internet or other electronic network activity (the request log) and coarse geolocation (the country resolved from your IP address). We collect no sensitive personal information as those laws define it: no card numbers, government identifiers, precise location, health data or biometric data.
How We Use Your Information
We process the data in a store to run it: to sign you in, to take your orders and their payment, to have the orders produced and delivered, to answer support requests, and to keep the platform secure and working. Your organization sets the purposes for its store's data and instructs us; why it gives you a store, on what legal basis, and how long it keeps your account are explained in its own privacy notice, so ask its administrator or privacy team. For the processing we do on our own behalf, each purpose has its own legal basis: managing the relationship with your organization, its contacts and administrators rests on our legitimate interest in running that business relationship, or on the contract where you signed it yourself; invoicing and keeping the accounts rests on our legal obligations under Swedish bookkeeping law; and logging requests and blocking abuse rests on our legitimate interest in keeping the platform secure and running. Where we rely on a legitimate interest, we have weighed it against your interests, and that assessment is available from lynn@jaapi.store.
Manufacturing suppliers. Your order is produced and shipped by a curated network of approved on-demand manufacturing suppliers, usually one near you. The supplier receives your name, shipping address, email address and phone number, any customs tax identifier you entered for delivery, and the product details of the order, and passes your name, address and contact details to its carrier for delivery. A supplier may use this data only to produce and deliver your order. Suppliers whose systems accept orders automatically are under data processing agreements; the rest are small local producers that take orders manually and are bound by the order terms alone. Your organization can ask us to restrict its store to suppliers under data processing agreements. Supplier identities are commercially confidential; your organization can ask us for the current list.
Automated decisions. We make no decisions about you based solely on automated processing that have legal or similarly significant effects. Automated tools sort incoming support email and limit repeated sign-in attempts; a person reviews every support ticket, and a block is temporary.
Your Privacy Rights
You have the right to access the personal data we hold about you, to have it corrected or erased, to restrict or object to its processing, and to receive the data you gave us in a portable format.
How to make requests. For data in your organization's store, contact your organization's administrator: your organization is the controller, and the store's administration tools let it view and correct your data and close your account. Erasing what remains after that is done by Jaapi at your organization's request: your identity and profile, the recipient details on gifts you sent, your sessions and any queued email. Three things stay: the order records the Bookkeeping Act requires; the entries in the store's audit trail, which records credit and security history, cannot be edited or deleted, and so keeps the email address it was written with; and your support correspondence, which stays with its ticket until your organization asks us to remove it. If you write to us instead, we pass your request on and help with anything the tools do not cover. If you have left the organization and can no longer sign in, write to lynn@jaapi.store and we pass your request to the organization. For data Jaapi controls, email lynn@jaapi.store. We answer within one month, as GDPR Article 12 requires. Where a request is complex or we receive many at once, we may take up to two further months, and we will tell you why within the first month.
Complaints. You can lodge a complaint with the supervisory authority in the country where you live or work, such as the ICO in the UK or the FDPIC in Switzerland. The authority for Jaapi is Integritetsskyddsmyndigheten (IMY), the Swedish Authority for Privacy Protection, at imy.se.
California and other US state residents. Where a US state privacy law such as the CCPA applies to your data, the organization whose store you use is the business and we are its service provider: we process your personal information only to run its store, we do not sell or share it, and we will not treat you differently for exercising a privacy right. Requests to know, access, correct, delete or limit go to your organization, or to lynn@jaapi.store and we forward them; the business may verify your identity first, you may use an authorized agent, and the law gives the business 45 days to respond, once extendable by 45 days with notice. The sources of your data are described under "What Information We Handle" and its recipients under "Service Providers & International Transfers".
Security & Protection
- In transit: every connection is encrypted and authenticated: your browser to the store, the store to the services it calls, and our servers to each other. The stores accept only encrypted connections and refuse protocol versions with known weaknesses.
- At rest: database backups are encrypted on the server that makes them, before they leave it. The live database volumes are not block-encrypted; each is reachable only from its own server. The platform's secrets are encrypted in the source repository.
- Access: data is separated per store at the database layer, and a session is bound to one store. Jaapi staff read customer data through the platform's viewers and a read-only query lane; there is no write channel outside the service APIs and an audited mutation lane.
- Location: each store is hosted in one home region, in the EU unless your organization's agreement with us places its store in the United States. Backups for every store stay in the EU.
- People: everyone with access acknowledges our security policies before they get access and every year after, and attends the Security Officer's annual security briefing.
- Assurance: Jaapi is certified to ISO 27001:2022 (audited January 2026). An external party penetration tests the platform every year, the founders act on the platform's monitoring alerts, the server, TLS and repository configuration is verified every quarter, and our incident response plan is tested annually.
Cookies & Tracking
The stores set only cookies the service needs to work, such as the one that keeps you signed in and the one that remembers the region you chose. None of them is used for analytics or advertising, and there are no analytics or advertising trackers on the stores. Product images are served through a content delivery network that sees the requesting IP address in transit. Blocking cookies in your browser will stop the store from working.
Service Providers & International Transfers
These sub-processors handle personal data on our behalf:
- Hetzner (Germany, with a US data centre for US-hosted stores) hosts the stores, their databases and their backups.
- Stripe (Ireland) processes payments and holds card details.
- MailerSend (Belgium) delivers the email a store sends you.
- Google Workspace (EU) carries our own email, which can contain your data when you or your organization write to support.
- Slack (US) carries our internal communication, the platform's operational alerts and the notes our support tooling posts about orders and tickets, which can include your name and order details.
- Cloudflare (US, global edge) caches the product images your browser loads and sees the requesting IP address in transit; images only, no store data.
- Vercel (US) carries the traffic of stores served on a customer-owned domain that still points at our previous edge network. The data passes through in transit; Vercel keeps only its edge request logs, under its own retention.
The current register, with each provider's location and what it holds, is at trust.jaapi.com/vendors. Each sub-processor in the register is under a data processing agreement, and your organization may object to one on reasonable data protection grounds. Manufacturing suppliers are not in the register; the section above describes how they are bound.
Our bank, Juni (Sweden), receives our sales and purchase records, which can include a shipping address. It is an independent controller of what it holds under banking law, not a processor acting on our instructions.
Transfers outside the EEA, the UK and Switzerland. Store data is hosted in its home region, and backups are kept in the EU for every store. A supplier's shipment notices and reads by our support staff may briefly be processed in the other region. Where personal data leaves the European Economic Area, the United Kingdom or Switzerland, because your organization's store is placed in the United States, because a sub-processor is in the US, or because your order is produced by a supplier under a data processing agreement in another country, the transfer is covered by the European Commission's standard contractual clauses or an adequacy decision; for data under the UK GDPR the clauses carry the UK International Data Transfer Addendum, and for data under the Swiss FADP the amendments the Swiss commissioner requires. An order produced by a supplier bound by order terms alone goes to that supplier in your own country so that it can be delivered to you; your organization can exclude such suppliers from its store.
How Long We Keep Information
We keep data for as long as your organization uses the service, and after that only what the law requires.
| Data | Kept |
|---|---|
| Account, addresses, credit balance, gift links and support correspondence | Until your organization's store is deleted |
| Closed account (you left the organization) | Kept, with its credit reclaimed to your organization, until your organization asks us to erase it or its store is deleted |
| Audit trail of credit and security events, including the email address each entry was written with | Until your organization's store is deleted; entries are never edited or removed, so an erased account's past entries remain |
| Order records behind an invoice, with the recipient's name and address | Seven years after the end of the financial year, as the Swedish Bookkeeping Act requires, then deleted in the next annual purge |
| Request logs and expired sessions | 30 days |
| Record of an email the store sent you | 30 days after delivery; 90 days if it could not be delivered |
| In-store notifications | One month |
| Stored copy of an incoming support email | 90 days; the ticket keeps the text |
| Daily database backup | 30 days |
| Monthly database backup | 24 months |
Data deleted from a database remains in its encrypted backups until they expire. Backups are restored only to recover the platform, never to bring deleted data back into service. When your organization stops using the service, we export the store's data in a standard format (such as JSON or CSV) on request, delete its personal data within 30 days of your organization's request and in any case within 90 days, and confirm the deletion to your organization. Only the order records the Bookkeeping Act requires remain, for the period above.
Security Incidents
If a security incident affects personal data we process for your organization, we notify your organization without undue delay, and within 48 hours, after becoming aware of it. The notice states the nature of the breach, the data and people affected, the likely consequences and the measures taken, so that your organization can meet its own obligations; we do not notify authorities or the people affected on its behalf unless it asks us to. If an incident affects data Jaapi controls, we notify IMY within 72 hours where the law requires it, and the people affected where the risk to them is high. Every incident is recorded with its root cause and the steps taken, and what it taught changes our controls.
Contact Us
Questions about your privacy? Lynn Smeria, our Security Officer, is the data protection contact for privacy questions, data subject requests and security incidents. You can reach Lynn at lynn@jaapi.store. Jaapi has not appointed a data protection officer, as the conditions of Article 37 GDPR do not apply to us.
For questions about your account or orders, contact your organization's administrator or use the support channel in your store.
Legal Entity Information
Jaapi AB Swedish organization number: 559387-9421 Asplyckevägen 32, 41729 Gothenburg, Sweden
Updates to This Policy
We revise this policy when our practices or the law change. We announce a material change to your organization's administrators by a notice on the platform, which stays until one of them acknowledges it, and post the revised policy here. The date at the top shows the latest revision.