Legal
Privacy policy
Last updated: 23 September 2026
holdmark checks facts about online stores using data from carriers and payment processors. It is designed to process as little data as possible: we do not store buyers' names, emails or addresses, and we use no tracking cookies on holdmark.org.
1. Who the controller is
- Operator
- Andrés Márquez Sánchez
- Tax ID (NIF)
- 80090833A
- Address
- Urbanización Cantera Blanca 13, 41900 Camas (Seville), Spain
- Contact
- equipo@holdmark.org
2. What data we process and what for
2.1 Stores that install the app
When a store installs holdmark on Shopify, we read the following from its account, with read-only permissions:
- From the store: its domain, its Shopify domain and the plan it is on.
- From each order: identifier, dates, payment status, whether it is a test order or cancelled, the payment processor, the shipments with their carrier and tracking number, and the destination country . We do not read the buyer's name, email, phone number or address. Of the order attributes we keep only
_hm, the one used by the A/B test (see 2.3); the rest is discarded as soon as it is read. - From refunds and bank disputes: dates, status and reason, in order to work out whether the store refunds money.
- From the theme: which templates the badge is placed in, so we can show the store in the app.
With the tracking numbers we ask the carrier for the status of the shipment (dates and statuses such as "delivered").
What for: to work out the store's facts under public rules, publish them in its record and show them to the store in the app. Legal basis: performance of the contract with the store (the terms of service).
2.2 The public record
Every registered store has a record on holdmark.org with aggregated facts: percentages rounded against the store, volume bands ("50,000+ orders") and delivery times only for the country of whoever is looking. Exact sales figures, countries sold to and any buyer data are never published.
Legal basis: performance of the contract with the store and the legitimate interest of buyers in checking a store before they buy.
2.3 Visitors to stores that display the badge
- Count of badge openings: only if the visitor accepted analytics in the store's own privacy notice. One number is stored per day and per store; no cookies, no identifiers.
- A/B test (only if the store turns it on and the visitor accepted analytics): the badge stores two of the store's own cookies in the visitor's browser,
_hm_g(test group) and_hm_v(a random identifier), for 90 days. That random identifier travels in the cart as the hidden attribute_hmso we know which orders come from each group, and we receive anonymous visit events (group, event type, page path without parameters, and date). If the visitor withdraws consent, the cookies are deleted.
For this data, holdmark acts as the store's data processor , since it is the store that decides to switch on the badge and the test and that collects its visitors' consent.
2.4 Visits to holdmark.org
We count how many people view each record and what kind of site they come from (search engine, AI assistant, the store itself, direct…). So as not to count the same person twice in one day, we compute a fingerprint from their browser and from the network portion of their IP (never the full address) using a random key that changes every day. The fingerprint and its key are kept only until the day rolls over, so that a restart of our service does not count again someone who had already visited; when the day changes, both are replaced entirely. A fingerprint cannot be turned back into an IP address, nor can it link visits from different days, because the key it was computed with no longer exists. Of the visit itself, only the daily total is stored.
Our server keeps no access logs containing IP addresses. holdmark.org uses no cookies and no third-party analytics tools, and the typeface is served from our own server.
Legal basis: legitimate interest in knowing how the registry is used, with data that identifies no one.
2.5 Emails you send us
If you write to us, we use your address and your message only to reply or, if you ask us to, to let you know when holdmark reaches your platform. Legal basis: your consent, which you may withdraw at any time.
2.6 App waiting list
While the app is not yet published on the Shopify App Store, the install button opens a form where you can leave us your store address and your email. That is all we keep, on our own server, and we use it for a single notification: the day the app can be installed. We ask for no payment details, we take no deposit, there is no newsletter and it is shared with nobody.
Legal basis: your consent, which you withdraw by writing to us: we delete your entry and we do not write to you. Retention: until we send that notification or you ask us to delete it, and in no case longer than 12 months from the day you sign up.
3. How long we keep it
- Store data: for as long as the app is installed. On uninstall, Shopify asks us to delete it (normally after 48 hours) and we delete the downloaded orders, the tracking data and the public record.
- A/B test events: 180 days. They delete themselves every day. That is the time needed to finish a test, publish its result and be able to redo the analysis if anyone disputes it. Since the cookies last 90 days, after that period there is no way to link anyone to their earlier events either.
- Visit counts: they are aggregated numbers with no personal data.
- Emails: until your query is resolved or you withdraw consent.
- App waiting list: until we send the notice that it can be installed, or until you ask us to delete it; at most 12 months.
4. Who we share it with
We do not sell or transfer data. We use these providers, which process data on our behalf:
- Amazon Web Services (servers in Ireland, European Union): hosting.
- Shopify: app installation and plan billing.
- Carriers: they receive the tracking number and return the shipment status to us.
- Domain and email provider: .
What is published in the record is public by design: anyone, and any AI assistant, can read it.
5. Your rights
You can request access, rectification, erasure, objection, restriction and portability by writing to equipo@holdmark.org. If you bought from a store that uses holdmark, go to the store first: we do not hold your name or your email. If you are not satisfied, you may lodge a complaint with the Spanish Data Protection Agency (aepd.es).
6. Changes and languages
If we change this policy, we will publish the new version here with its date and, if the change is significant, we will notify stores in the app.
This policy is published in Spanish, English, German, French, Italian and Portuguese. The translations are provided so that it can be understood; in the event of any discrepancy between versions, the Spanish one prevails, as it is the version drafted under the applicable law.