Privacy Policy

It matters to us that Mini-Store users' ("you") personal data is protected in accordance with Georgian law. This document explains the principles, grounds, and purposes under which we process your data, how we protect it, and what rights you have in relation to it. By using Mini-Store and/or registering on it, you agree that your personal data will be processed in accordance with this policy.

Who we are

Mini-Store (mini-store.org) is solely owned by sole proprietor Maiko Tkemaladze, ID No. 54001015703, address: 23 Mirian Mepe St., Tbilisi, Georgia. Contact email: [email protected].

Who this document is for

This document applies to:

  • Any Mini-Store user — a visitor, a seller (registered, former, or prospective), and a buyer placing an order on any store;
  • Anyone who contacts us out of interest in our product or service.

How we collect your data

Your data comes from:

  • Seller registration/login (email/password or Google/Facebook);
  • A buyer completing the checkout form on a store page;
  • Your direct communication with us (email, contact form);
  • Technical data collected automatically while using the Platform (see "Cookies" below).

What data we process

The data we process depends on whether you are a seller or a buyer, and is limited to what is proportionate to its purpose:

  • From a buyer — name, phone number, delivery address and/or email (during checkout, with your consent). We do not request or store a buyer's national ID number.
  • From a seller — email/phone, store name/logo/photos, bank IBAN, and (if card payment is connected) their own payment provider's API key, stored encrypted. We never receive or store card numbers or other payment card details — that stays entirely within the relevant payment provider's (Flitt or the seller's own provider's) PCI-compliant environment.
  • From both — technical logs (IP address, timestamp, browser/device information) for security and fraud prevention.

Cookies

We use two categories of cookies: (a) strictly necessary — an authentication refresh-token cookie (HttpOnly, not accessible to JavaScript) that keeps you signed in; and (b) analytics — Google Analytics/Tag Manager cookies, which help us measure and improve Platform usage (e.g. page views, adding to cart, purchase activity).

Data collected through analytics cookies (page views, browser/device type, approximate location, on-site behavior) is processed by Google under its own privacy policy. You can block analytics cookies through your browser settings or Google's Analytics Opt-out tool — we plan to add a dedicated cookie-preference control as well.

Why we process your data

We process data only for lawful purposes, including:

  • To process an order and pass it to the relevant seller;
  • To operate a seller's account and store (Dashboard, subscription package, payment integration);
  • To send order/booking status notifications (email, SMS, Telegram, or web push — via the channel the seller has chosen);
  • For statistical analysis and improvement of the Platform;
  • For data and system security, and fraud prevention;
  • To provide information to competent authorities where required by law;
  • To review requests or complaints you send us.

Legal grounds for processing

Depending on the specific case, the ground for processing is:

  • Your voluntary consent (the checkout checkbox, analytics cookies);
  • The conclusion/performance of a contract with you (registering and using a seller account);
  • A legal obligation;
  • Our or a third party's legitimate interest (e.g. security, fraud prevention, technical logging).

Who we share your data with

Your data may be shared with:

  • The specific seller with whom you placed an order — to the extent necessary to process it (name, phone, address/email);
  • The hosting/infrastructure provider where our database is stored — for technical storage purposes only, without independent access;
  • The payment provider (when paying by card) — the minimum data necessary for the transaction;
  • Technical service providers — email, SMS, and analytics service providers — only to the extent needed for that function;
  • Government bodies authorized by law, in cases provided by law;
  • Any other third party — only with your prior consent.

The Platform does not sell your data and does not share it with third parties for marketing purposes.

International data transfer

Our database is stored on a server located in the European Union (the Netherlands). An individual technical service provider (e.g. an analytics or email service) may be located in another country, including outside the EU.

In such cases, we make sure an adequate safeguard exists as required by the Georgian Law on Personal Data Protection (including an adequate level of data protection at the recipient country/service).

Your rights

You have the following rights — if they are violated, you may also contact personaldata.ge or a court:

  • Obtain information about the data processed about you, its purpose, and its legal ground;
  • Request a copy of your data;
  • Request correction/updating of inaccurate or incomplete data;
  • Request that processing stop, or that data be deleted or destroyed (if you withdraw the consent it relies on, it is no longer needed for its purpose, or processing has become unlawful);
  • Request that processing be restricted in certain cases (e.g. the accuracy of the data is disputed);
  • Withdraw any consent you have given for processing, at any time;
  • Request your data in a structured, electronic format (portability), where technically feasible and where consent is the ground for processing;

Limitations on your rights

The rights listed above may be limited in cases directly provided by law — for example, to protect state or public security, to prevent or investigate crime, or to protect the rights and freedoms of others — and only to the extent proportionate to that purpose.

Data security

We use appropriate technical and organizational measures to protect your data from unauthorized access, use, disclosure, or loss — including password hashing, encryption of payment-provider API keys (AES-256), and access controls.

While we take all reasonable measures, technological risk can never be fully eliminated — we do not offer an absolute guarantee against unauthorized access, but we operate in line with standard industry practice.

Data retention period

Order history is kept for statistical/accounting purposes. When a seller requests account deletion, their store disappears publicly immediately, while a buyer's contact details (name, phone, address) in historical orders are anonymized — the order record and amount remain for statistics, without personal data.

A buyer, or any other person whose data is processed on the Platform, may request that processing stop or that their data be deleted by writing to the email below — we respond within 10 calendar days at the latest.

Your obligations

To provide you with proper service, we need accurate and up-to-date information about you — please update your contact details in your account settings, or let us know, if they change.

Changes

This policy may need to change over time. If it changes, we will publish the updated version on this same page, noting the date of the change. Continuing to use the Platform after a change means you agree to the updated terms.

Contact us

The data controller is Mini-Store (sole proprietor Maiko Tkemaladze). For questions, requests, or complaints, contact: [email protected].

Last updated: 2026-08-27