OrderFlow
Back to website

Website docs

Store guides and reference pages

Practical guides for your WooCommerce and Allegro store.

Privacy Policy

Last updated: 2026-09-14

This policy explains how the Lolisoft OrderFlow website processes personal data when someone browses the public pages, reads the documentation, requests a trial, completes Stripe checkout, returns to the secure download page, or contacts the business about the plugin package.

Controller

  • Business name: Hayk Jomardyan FHU Real Trade
  • Registered address: ul. Henryka Sienkiewicza 101/109, lok. 154, 90-301 Łódź, Poland
  • NIP: 7252325001
  • REGON: 523554618
  • Electronic delivery address: AE:PL-75498-88203-WBRTI-22
  • Product website: https://orderflow.lolisoft.eu
  • Contact email: info@lolisoft.eu

What this policy covers

This policy covers website-side processing connected with the public OrderFlow product site. It does not replace the separate privacy notices of third-party providers such as Stripe, hosting providers, analytics vendors, email providers, or marketplace platforms.

Categories of personal data

Depending on how you use the website, the following categories may be processed:

  • technical and security data such as IP address, browser, device data, request timestamps, logs, and anti-abuse signals
  • website interaction and attribution data such as page visits, referral source, campaign parameters, and tag identifiers
  • trial request data such as name, email address, company name, store URL, Allegro profile, and message content
  • checkout, billing, and invoice data such as email address, billing address, phone number, business name, tax ID or VAT number, region, and payment confirmation metadata
  • download verification data used to unlock or recover short-lived download links after a verified Stripe payment
  • withdrawal, refund, complaint, and statutory-remedy request data such as order identifiers, request timestamps, reasons voluntarily provided, acknowledgement records, and resolution history
  • support and pre-sales correspondence sent by email

Sources of the data

The data usually comes from:

  • your browser or device when you visit the website
  • forms submitted directly on the website
  • Stripe checkout, payment, invoice, and return-page events
  • messages you send during pre-sales, support, refund, withdrawal, complaint, or compliance communication

Purposes and legal bases

Personal data may be processed for the following purposes:

  • to operate, secure, and diagnose the website and download flow
  • to answer trial requests and pre-contract questions
  • to process a purchase, verify payment, issue an invoice, and deliver the downloadable plugin package
  • to prevent fraud, abuse, chargebacks, unauthorized download attempts, or other misuse
  • to maintain accounting, tax, withdrawal, refund, complaint, and legal compliance records
  • to measure website performance, demand, and campaign effectiveness

Depending on context, the legal basis may be:

  • performance of a contract or steps requested before entering into a contract
  • legitimate interests in operating, securing, improving, and measuring the website
  • compliance with legal obligations
  • consent where required for specific tracking or communications

Recipients and service providers

The website may share relevant data with service providers that support the business, including:

  • Stripe for checkout, payment confirmation, invoicing, fraud screening, and secure purchase verification
  • hosting, CDN, DNS, server, and infrastructure providers used to keep the website available
  • Google tag (gtag.js) and any measurement or advertising tags configured through it, requested only after the visitor opts in
  • email, communications, accounting, and support tooling used to reply to customers and keep records

Each provider applies its own contractual and privacy terms to the data it receives.

International transfers

Some providers may process data outside your country or outside the EEA. Where GDPR applies, the business expects such providers to rely on appropriate transfer mechanisms and safeguards when required by law.

Retention

The operational retention periods are:

  • checkout-attempt records: 90 days
  • download-event records, trial requests, email logs, and completed or failed purchase-delivery records: 365 days
  • expired or used customer authentication tokens: deleted 30 days after expiry or use
  • purchase, invoice, accounting, and other legally required records: for the period required by applicable tax, bookkeeping, and legal obligations, typically 5 years from the end of the relevant calendar year
  • customer accounts and their linked purchase history: while the account remains active and afterward only for as long as applicable legal obligations require

An erasure request will be handled without undue delay, subject to legal exceptions that require or permit continued retention. Records may be kept longer where necessary for a legal hold, a dispute, or the establishment, exercise, or defence of legal claims.

Your rights

Where applicable, you may have the right to request:

  • access to your personal data
  • rectification of inaccurate or incomplete data
  • erasure of data that is no longer needed
  • restriction of processing
  • objection to processing based on legitimate interests
  • portability of data you provided directly
  • withdrawal of consent where processing depends on consent
  • the right to complain to a competent supervisory authority (in Poland, the Prezes Urzędu Ochrony Danych Osobowych — uodo.gov.pl)

Requests can be sent to info@lolisoft.eu. Where GDPR applies, the business aims to respond within one month, subject to lawful extensions where necessary.

Security

Reasonable technical and organizational measures are used to protect the website, checkout return flow, and stored business records. No internet-facing system can be guaranteed completely risk-free.

Cookies and tracking

The website may use cookies, local storage, pixels, tags, and similar technologies for essential operation, purchase continuity, security, analytics, and attribution. Optional Google analytics or advertising code can run only after opt-in. Once accepted it also runs on the purchase-return and account pages so that purchases and trial requests can be measured, with checkout session identifiers, download tokens, and email addresses removed from the address reported to Google. See the Cookie and Tracking Notice for more detail.

Automated decisions and profiling

Personal data processed in connection with this website is not used for automated decision-making that produces legal or similarly significant effects. No profiling that generates such legal effects is applied.

Microsoft Clarity

Microsoft Clarity is our website analytics provider. After opt-in, we and Microsoft collect behavioral data such as clicks, scrolling and page interactions. Heatmaps aggregate activity, while session replay reconstructs browsing interactions so we can find usability problems, improve OrderFlow and evaluate product marketing. Clarity uses first-party and third-party cookies and similar tracking technologies to connect activity and understand which pages visitors use. Microsoft explains its own collection, use and protection of this data in the Microsoft Privacy Statement.

After you accept optional cookies, the marketing landing page loads Microsoft Clarity for heatmaps and session recordings to understand clicks, scrolling, and website usage. The trial form is explicitly masked. Clarity runs on the marketing landing page only: it does not load on the documentation, purchase-return, download, account, or token-bearing pages.

Clarity uses first-party _clck and _clsk identifiers and may use Microsoft third-party identifiers. Microsoft documents their purpose and current configuration in its cookie information and Privacy Statement. Withdrawing consent also sends a denial to Clarity, removes readable _clck and _clsk cookies, and reloads the page without Clarity. This notice update requires a fresh choice before analytics can load.

Contact

Questions about this policy or data handling on the website can be sent to info@lolisoft.eu.