Privacy Policy
Effective Date: June 1, 2026
Last Updated: July 15, 2026
CANISMAJORIS21 SRL, Tudor Arghezi 15, Brașov, Romania
Contact: hello@net21.app
1. Who We Are
net21 is a product operated by CANISMAJORIS21 SRL, a Romanian legal entity registered at Tudor Arghezi 15, Brașov, Romania. This Privacy Policy describes what personal data we collect, how we use it, with whom we share it, how long we retain it, and what rights you have as a user of the platform. This document is drafted in compliance with Regulation (EU) 2016/679 (GDPR). Contact for any privacy-related matter: hello@net21.app.
2. What net21 Is and How It Works
net21 is a platform that connects ecommerce brands with consumers through relevant offers. The primary criterion determining which offers a consumer receives is the set of interests they explicitly declare in their account. In addition, purchase history originating from the Shopify stores of partner brands is used for two purposes: aggregate analytics that each brand sees exclusively about its own customers, and the aggregate-level refinement of offer selection in the network, so that the offers received are as well-suited as possible.
net21 operates as a trusted intermediary between two categories of users: brands (B2B clients) and consumers (end users). Brands do not have access to the personal data of consumers in the network. They only describe the type of audience they wish to reach, and net21 decides who receives each offer and delivers it directly, keeping consumer identities anonymous from brands.
3. What Data We Collect
3.1 Brand Data (B2B Clients)
When a brand registers on the platform, we collect: the brand's commercial name and company identification details; contact email address; website domain and Shopify store domain; the Shopify access token (OAuth); billing and payment data processed exclusively through Stripe (net21 never stores bank card data); wallet transaction history; campaign history; reputation score; authentication data managed through Clerk.
3.2 Consumer Data — Collected Automatically from Shopify Synchronization
When a connected brand synchronizes its Shopify store data, the platform automatically processes: the consumer's email address (used as a unique identifier for matching data across brands); order history, including purchased products, quantities, prices, order dates, and payment status. We do not collect card data, complete physical addresses, or phone numbers from Shopify synchronization.
3.3 Data Voluntarily Provided by the Consumer
Consumers who create an account on the dedicated portal may voluntarily indicate style, category, and color preferences, as well as the maximum number of offers they wish to receive per week. These preferences can be changed or deleted at any time.
3.4 Platform-Generated Data
Based on the collected data, the platform builds a preference profile for each consumer and records their interactions with received offers (views, clicks, and saved offers), the account creation date, and last activity.
4. How We Use Data
4.1 For Brands
- Providing and improving the service of analyzing the brand's own customer base
- Processing and displaying approved campaigns in the consumer portal
- Calculating estimated audience reach for network campaigns
- Calculating and updating the reputation score
- Processing payments through Stripe and managing the wallet
- Transactional communications: account approval confirmation, campaign status, low balance
- Preventing fraud and abuse of the platform
4.2 For Consumers
We use consumer data to build and update each consumer's preference profile, to select relevant offers — starting from the explicitly declared interests, refined with aggregate information from purchase history — and to deliver them in the For You section of the consumer portal. We respect the offer limit set by each consumer and ensure that no one receives the same offer twice. We use anonymous, aggregate statistics to improve the service.
5. Consumer Protection Rules
net21 applies technical and contractual rules to protect consumers against spam and abusive use of data:
- A consumer never receives the same offer twice.
- A consumer cannot receive more offers than the weekly limit they set themselves — 15 by default, adjustable at any time up to a maximum of 25 — regardless of how many brands launch campaigns.
- The promotion of an offer in the For You section is time-limited: it lasts for the duration of the campaign (at most 7 days from approval), after which the offer automatically disappears from the section.
- Offers that the consumer saves remain available in the Closet section for 12 months from saving, or until the consumer removes them, even if the campaign's promotion has ended in the meantime.
- Brands can never contact consumers directly: all communications are intermediated and controlled by net21, and every campaign is reviewed and approved by the net21 team before distribution.
- Brands with abusive behavior lose access to campaigns.
6. Legal Bases for Processing (GDPR)
| Type of Processing | GDPR Legal Basis |
|---|---|
| Brand data — performance of the service contract | Art. 6(1)(b) — contract performance |
| Synchronization of order data from Shopify | Art. 6(1)(f) — legitimate interest (personalization) |
| Building the preference profile | Art. 6(1)(f) — legitimate interest (personalization) |
| Consumer-declared preferences | Art. 6(1)(a) — explicit consent |
| Transactional communications to brands | Art. 6(1)(b) — contract performance |
| Technical data and security logs | Art. 6(1)(f) — legitimate interest (security) |
| Financial transactions | Art. 6(1)(c) — legal obligation |
7. With Whom We Share Data and International Transfers
We do not sell or rent personal data. We share data exclusively with the service providers below, strictly to the extent necessary for the platform to function:
| Provider | Purpose / Data Transferred |
|---|---|
| Supabase (USA) | Database storage — all platform data |
| Clerk (USA) | User authentication — sessions, cookies, 2FA |
| Stripe (USA) | Payment processing — brand billing data, wallet transactions |
| Resend (USA) | Transactional email — recipient email addresses |
| Vercel (USA) | Hosting and application delivery — technical data, IP addresses |
| Shopify (Canada) | Order synchronization — the brand's OAuth token, order data |
Our main providers (Supabase, Clerk, Stripe, Resend, Vercel) are US-headquartered companies. Data transfers from the EEA are covered by Standard Contractual Clauses (SCC) under Commission Implementing Decision (EU) 2021/914. Shopify is a Canadian company, and Canada benefits from a European Commission Adequacy Decision.
8. How Long We Retain Data
| Data Category | Retention Period |
|---|---|
| Active brand account data | Duration of the contract + 3 years after termination |
| Inactive brand account data | 2 years from the last recorded activity |
| Active consumer account data | Until voluntary account deletion |
| Consumer data without an account (from synchronization) | 3 years from the date of the last synchronized order |
| History of received offers | 2 years from campaign expiration |
| Offers saved in Closet | 12 months from saving, or until removed by the consumer |
| Consumer preference profile | Deleted upon account deletion |
| Financial transactions (wallet) | 10 years — fiscal obligation under Romanian law |
| Technical data and security logs | 90 days |
| Emails sent through Resend | 30 days in Resend systems |
9. Your Rights (GDPR)
- Right of access (Art. 15): you have the right to know whether we hold data about you, what categories of data we process, for what purposes, with whom we share it, and how long we retain it.
- Right to rectification (Art. 16): if the data we hold about you is incorrect or incomplete, you have the right to request its correction within 30 days.
- Right to erasure (Art. 17): you can request the deletion of all your personal data from the platform. Upon receiving the request, your preference profile and all received offers are deleted immediately, the account is deactivated within 24 hours and scheduled for permanent deletion within 30 days. Financial data is retained in anonymized form per legal fiscal obligations (10 years).
- Right to data portability (Art. 20): upon request, we provide your personal data in a structured, machine-readable format (JSON or CSV).
- Right to restriction of processing (Art. 18): you can request temporary restriction of processing in certain circumstances, including when you contest the accuracy of the data or when the processing is unlawful.
- Right to object (Art. 21): you can object to processing based on net21's legitimate interest. We will stop the processing unless we demonstrate compelling legitimate grounds.
- Right to withdraw consent: where processing is based on your consent, you can withdraw it at any time, without affecting the lawfulness of prior processing.
How to Exercise These Rights
Send an email to hello@net21.app with the subject "GDPR Request" and indicate which right you wish to exercise. We will respond within 30 calendar days at most.
10. Data Security
net21 applies appropriate technical and organizational measures to protect personal data: all communications are encrypted in transit, data is stored encrypted, authentication supports two-factor authentication (2FA), and the platform architecture guarantees that each brand accesses exclusively its own data. net21 never stores bank card data; all payments are processed exclusively through Stripe, PCI DSS Level 1 certified. The platform is continuously monitored to detect anomalies and unauthorized access attempts. In the event of a security incident, net21 will notify ANSPDCP within 72 hours and inform affected users without undue delay, per Art. 33–34 GDPR.
11. Cookies
net21 uses a minimal number of strictly necessary cookies: Clerk session cookies, required for user authentication, and the language preference cookie (next-intl). net21 does not use tracking, analytics, or third-party advertising cookies.
12. Changes to This Policy
net21 may update this Privacy Policy. For significant changes, users will be notified by email at least 14 days before the new provisions take effect. The updated version will be published at net21.app/privacy. Continued use of the platform after the changes take effect constitutes implicit acceptance.
13. Contact and Supervisory Authority
CANISMAJORIS21 SRL, Tudor Arghezi 15, Brașov, Romania, hello@net21.app, net21.app.
The Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP): anspdcp.ro, anspdcp@dataprotection.ro. You have the right to lodge a complaint with ANSPDCP or with the supervisory authority of the EU member state where you reside.