ZweiHost
PrivacyTermsData processingData deletion
Български

Privacy Policy

Version v0.6 · Last updated: 20 August 2026

ZweiHost is a Website-as-a-Service (WaaS) platform: small businesses run online shops and sites on our infrastructure. This Policy describes how ZweiHost processes personal data of two groups: shoppers who sign in with Facebook or Google on a shop built with ZweiHost (section 2), and our direct customers - the merchants (sections 3 onwards).

1. Who we are

The ZweiHost platform is operated by Zwei Soft Ltd. („Цвай Софт" ЕООД), the company that acts as data controller for the personal data described in this Policy.

Zwei Soft Ltd. (operator of the ZweiHost platform)
Registered seat: 2 Asenovgradsko shose St., entr. E, apt. 52, Plovdiv 4004, Bulgaria
UIC (ЕИК): 208515196 · VAT: BG208515196 · Manager: Ivaylo Ivov Ivanov
Contact: support@zweisoft.com

2. Sign in with Facebook & Google (for shoppers)

Some shops built with ZweiHost let shoppers sign in with Facebook or Google. ZweiHost operates a single, central sign-in integration on behalf of all those shops - which is why the Facebook and Google consent screens show the name “ZweiHost”.

When you choose “Continue with Facebook” or “Continue with Google”, we receive from the provider only:

  • your name;
  • your email address;
  • and a stable provider user identifier (your Facebook/Google user ID).

We use this data solely to create or sign you in to your customer account on the specific shop where you used the button. We do not receive your password, your friends/contacts, your posts, or any other profile data, and we do not post anything on your behalf.

Your account (together with the data above) is stored separately for each shop you sign in to: the shop is the controller of that account, and ZweiHost acts as its processor. We keep it for as long as your account on that shop exists, and you can delete it at any time - see Data deletion. Questions about social login: support@zweisoft.com.

3. Data we process about merchants

  • Account data: email, name, phone.
  • Business data: legal entity name, EIK, address.
  • Payment data: handled by Stripe - we only receive an identifier and status, never card numbers.
  • Usage data: login logs, IP, browser, BackOffice actions.
  • Communications: emails and support messages.

Newsletter subscribers (zweihost.com visitors): if you subscribe to our newsletter, we process your email address and the site language on the basis of your consent, to send you news, articles and advice on selling online. Tsvai Soft Ltd is the controller of this data; delivery is via Amazon SES (see section 5). You can unsubscribe at any time with one click from any email.

4. Purposes and legal bases (GDPR Art. 6)

PurposeBasis
Service delivery (incl. shopper sign-in)Contract (Art. 6(1)(b))
Invoicing and accountingLegal obligation (c)
Security and abuse preventionLegitimate interest (f)
Marketing newsletterConsent (a)
Customer testimonials and references (section 11)Consent (a)
Honouring an unsubscribe (suppression record)Legitimate interest (f)

5. Recipients

  • Stripe (payments) - Ireland / USA (SCC).
  • Cloudflare (R2 file storage, Workers hosting and CDN, traffic protection and IP addresses; inbound email forwarding for shops that enable business email forwarding - email content passes through in transit only, no storage on our side) - EU / global edge.
  • Amazon Web Services (Amazon SES) (email) - EU (eu-central-1) / USA (SCC).
  • Railway (API, admin panel and PostgreSQL database) - EU West (Amsterdam, Netherlands).
  • Functional Software, Inc. (Sentry) (error tracking and diagnostics - technical error data only; request bodies, cookies, credentials and user identifiers are stripped before sending) - EU (Germany) / USA (SCC).
  • Meta Platforms and Google LLC - for Facebook/Google sign-in and, with consent, advertising/analytics; they act as independent controllers under their own policies - USA (EU–US Data Privacy Framework).
  • Borica AD - card payments for Bulgarian merchants, once activated.
  • Government bodies where legally required.

6. International transfers

Where data is transferred outside the EEA, we use an applicable GDPR mechanism: an adequacy decision, the European Commission's Standard Contractual Clauses, or another mechanism permitted under Art. 46 GDPR. Information on the specific safeguards can be requested at support@zweisoft.com, to the extent that providing it does not breach trade secrecy or the security of the service.

7. Retention

  • Shopper account (incl. Facebook/Google sign-in data): for as long as the account exists on that shop.
  • Custom-print uploads (a photo or image you upload to personalise a product): if you never place the order, the file is deleted after 7 days. If you do order, the shop needs it to produce your item, and it is deleted 90 days after the order. A small preview of your finished design and its text description are kept with the order so your order history and the shop's records stay complete.
  • Support messages (storefront chat): the email you give in order to message a shop, your name if you add it, and the content of the conversation - including a snapshot of any preceding chat with the shop's assistant. The shop is the controller of these messages and ZweiHost acts as its processor; the basis is responding to your enquiry (Art. 6(1)(b)/(f)) - no marketing and no separate consent. A conversation is deleted 30 days after its last message; the customer record it is attached to is kept under the account rule above.
  • Marketing-recipient record, created when you subscribe to a newsletter or otherwise give marketing consent: it holds only your email address (and your name, if you gave one). If you withdraw consent and that record has no orders and no registered account attached, it is deleted. If it has orders or a registration, the record is kept and the marketing consent is marked as withdrawn.
  • After you unsubscribe we keep a minimal suppression record (your email address and the fact that you unsubscribed) so that we do not send you marketing again. Legal basis: legitimate interest (Art. 6(1)(f)) - specifically, honouring your opt-out.
  • Merchant account data: until contract termination + 30 days.
  • Accounting documents: 10 years (Bulgarian Accounting Act).
  • Security logs: 12 months.
  • Operational request logs - technical records of the requests to and from our API, kept for security, debugging and abuse prevention. Personal data in them is masked and credentials are removed before anything is written; they are retained only for our hosting provider's (Railway) log-retention window and then rotated out automatically.

8. Whether data is required, and automated decision-making

Account, business, payment and technical-security data are necessary to conclude and perform the contract and to comply with legal obligations; if not provided, the service may be unavailable. ZweiHost does not use automated decision-making that produces legal effects or similarly significantly affects you, unless expressly stated in a separate module or policy.

9. Your rights

You may access, correct, delete, restrict, port, or object to processing, and withdraw consent, without affecting the lawfulness of processing before withdrawal. You have the right to complain to the Bulgarian Data Protection Authority (CPDP), 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592, cpdp.bg.

Shoppers can export or delete their own data from their account on the relevant shop - see Data deletion. Merchants can do so from BackOffice → Settings → “Your data & privacy”. For anything else: support@zweisoft.com (response within 30 days). ZweiHost has not currently appointed a Data Protection Officer; this will be reviewed if the scale, risk or nature of processing changes.

10. Cookies

ZweiHost uses strictly necessary cookies and similar technologies (session, CSRF, language) needed to provide the service and for security. We do not place marketing or analytics cookies on zweihost.com without prior consent and an opt-out. Where an individual merchant's shop uses additional cookies, the merchant is responsible for its own notice and consent, unless ZweiHost expressly provides a central consent-management module. On a shop that has enabled storefront chat, a strictly-necessary cookie (about 180 days) remembers your open conversation so you can continue it on the same device; it carries no marketing or analytics data and needs no consent.

Measurement tools on zweihost.com. Only after your explicit consent via the cookie banner do we load:

  • Google Analytics 4 (“statistics” category) - pages visited, referral source, approximate location from IP, device and browser type.
  • Meta Pixel and the Meta Conversions API(“advertising” category) - pages visited and enquiry-form submissions. When you submit the form we additionally send Meta your cryptographically hashed (SHA-256) name and phone number from our server, so Meta can connect the enquiry to the ad you saw. Meta receives only the irreversibly hashed values, never the phone number or name itself.
  • Google Ads (“advertising” category) - records a submitted form as a conversion from an ad campaign.

Legal basis: consent (GDPR Art. 6(1)(a)). If you decline, none of the above loads and no request is made to Google or Meta. Withdrawal: clear this site’s cookies in your browser - the banner reappears and you can choose again. Withdrawal takes effect going forward. Retention: your choice is stored for up to 12 months; retention at Google and Meta is governed by their own policies - for this data they act as independent controllers (see section 5).

11. Customer testimonials and references

With the merchant's explicit written consent we publish customer testimonials on zweihost.com (the landing page and the “Reviews” page): the shop's trade name, its business category, a link to the shop, the testimonial text, a screenshot of the storefront and, where provided, a logo; if the testimonial is personally signed, the person's name as well. Only where the merchant has separately ticked this in the consent form may the same content also be used on ZweiHost's social media profiles and in our advertising.

Legal basis: consent (GDPR Art. 6(1)(a)); the final wording of the testimonial is agreed with the merchant before publication. Retention: the publication stays up until consent is withdrawn or our relationship ends. Withdrawal: at any time, free of charge, at support@zweisoft.com - we take the testimonial down from the site and our social profiles without undue delay (within 14 days) and stop including it in new advertising; ad impressions already served cannot be recalled retroactively. Withdrawal does not affect the lawfulness of publication before it.

12. Changes

Changes are posted on this page and take effect 14 days after publication.

© 2026 ZweiHostPrivacyTermsData processingData deletion