Private launch Special Founder price
12DAYS 01H 17MIN 19SEC
Claim my seat

Privacy Policy

FunnelCart privacy policy

TABLE OF CONTENTS

This policy explains what personal data we process, why, for how long, and what your rights are. It applies to the funnelcart.pro website, the shop and customer portal operated on sdravobiz.com, and the FunnelCart WordPress plugin.

It is drafted in accordance with Regulation (EU) 2016/679 (“GDPR”), Romanian Law no. 190/2018, and Romanian Law no. 506/2004.

1. Who is responsible

Sdravobiz S.R.L.
Strada Trandafirilor 51, 307220 Giroc, Romania
CUI: RO51472367 — Intra-EU VAT: RO51472369
Trade Register: J2025016522009
Email: contact@sdravobiz.com

Sdravobiz is not required to appoint a Data Protection Officer within the meaning of Article 37 of the GDPR: its activity relies neither on large-scale processing of sensitive data nor on large-scale systematic monitoring of individuals.

Any request may be sent to contact@sdravobiz.com, indicating “GDPR” in the subject line.

2. Two distinct situations

This is the most important point of this policy, and it is also the main difference between FunnelCart and an online service.

Your own data, as a customer or visitor to our site. We are the data controller for it: account, order, invoice, license, support, newsletter. This is the subject of Articles 3 to 9.

The data of the people who browse your sales funnels. It is stored in the database of your WordPress site, on your hosting. It does not pass through any of our servers, is never transmitted to us, and is not accessible to us. You are the sole data controller for it, and we are neither a controller nor a processor. This is the subject of Article 10.

3. What we process, and why

PurposeDataLegal BasisRetention
Orders, Licensing, and Invoicing — account creation, contract performance, invoices, accounting obligationsLast name, first name, company, address, email, VAT number, order and invoice history, license keyPerformance of a contract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c))Duration of the contract, then 10 years under Law no. 82/1991
Activation Management — license validity check, site count tracking, update distributionLicense key, address of activated sites, product identifier, installed version, activation and verification datesPerformance of a contract (Art. 6(1)(b)); legitimate interest for protection against unauthorized use (Art. 6(1)(f))Duration of the license, then 3 years
Payments — collection, fraud prevention, disputes, and refundsBilling details, transaction history, and transaction identifiersPerformance of a contract (Art. 6(1)(b)); legitimate interest in fraud prevention (Art. 6(1)(f))10 years (accounting obligations)
Service Emails — confirmation, invoice, license key, update availability, expiration, security incidentName, email, account identifierPerformance of a contract (Art. 6(1)(b))Duration of the contract, then statutory archiving
Support and Customer RelationsName, email, message content, screenshots, and environment reports you send to usPerformance of a contract (Art. 6(1)(b)); legitimate interest for prospective customers (Art. 6(1)(f))3 years after the last contact (customers); 13 months (prospective customers)
FunnelCart Community — access to the help community, posts, and repliesDisplay name, email, content of published messagesPerformance of a contract (Art. 6(1)(b)); consent for publication (Art. 6(1)(a))Duration of participation, then 12 months
Newsletter and Product InformationName, email, language, opens, and clicksLegitimate interest (Art. 6(1)(f)) for customers, regarding a similar product, and for professionals who write to us through the contact form, about their business; consent (Art. 6(1)(a)) in other casesUntil you unsubscribe, in one click from any email, and at most 3 years after the last interaction
Website AnalyticsAnonymized IP address, page views, duration, traffic source, device, and browserConsent (Art. 6(1)(a)) for non-essential cookies; legitimate interest for anonymized analytics14 months
Legal Obligations and LitigationInvoices, supporting documents, connection logsLegal obligation (Art. 6(1)(c)); legitimate interest for legal defenseApplicable statutory period

We do not make any fully automated decisions that have legal effects concerning you, and we do not practice advertising profiling.

4. We do not sell your data

Sdravobiz does not sell, rent, or transfer your personal data to third parties for commercial purposes.

Your data is only disclosed to the service providers listed in Article 5, to competent administrative or judicial authorities upon legal request, and to our advisers in the event of legal proceedings.

5. Our service providers

We use processors within the meaning of Article 28 of the GDPR, selected for their guarantees. This list is subject to change.

Service ProviderRoleLocationTransfer Safeguards
Stripe Payments Europe, LtdOnline payment, anti-fraudIreland (EU), group servers in the United StatesStandard Contractual Clauses + EU-US Data Privacy Framework
o2switchHosting of the website, shop, customer portal, and license serverFrance (EU)No transfers outside the EU
Shop, licenses, and customer portal (self-hosted)Orders, subscriptions, license keys, activations, invoicesFrance (EU)Not applicable — self-hosted
Contact and email management (self-hosted)Service emails, newsletterFrance (EU)Not applicable — self-hosted
Support and community (self-hosted)Support tickets, user peer-support forumFrance (EU)Not applicable — self-hosted
Google Ireland Ltd (Analytics, Search Console)Audience measurement and SEO trackingIreland (EU), servers in the United StatesStandard Contractual Clauses + EU-US Data Privacy Framework
Chartered accountant and legal counselAccounting and legal obligationsRomaniaService agreement, confidentiality clause

None of these service providers has access to the data that you collect with the extension on your own site.

6. What the extension sends to our servers

The extension installed on your site communicates with our license server in three situations: when you activate a key, when you deactivate it, and during periodic checks or update searches.

On each of these occasions, and on these occasions only, your site transmits exactly the following items:

  • the product identifier;
  • your license key;
  • your site address;
  • the version number of the installed extension;
  • a single-use nonce, intended to prevent response replay.

And nothing else. In particular, the following are never transmitted: data from your visitors, leads, and customers, their email addresses, their orders, their IP addresses, your statistics, your funnels, your settings, your site content, your administrator email address, your PHP or WordPress version, the list of your extensions.

The extension contains no telemetry, no usage statistics tracking, and no installation reporting. The diagnostic screen displays a description of your technical environment: this description remains on your site and is only transmitted if you copy it yourself into a support message.

Communications with FluentCRM, your webhooks, your advertising platforms, and your other tools go directly from your server to the destinations you have specified yourself. They do not pass through any of the publisher’s servers.

7. Transfers outside the European Union

Our customer data is hosted within the European Union. The only transfers likely to occur outside the European Economic Area concern our payment provider and our audience measurement tools, whose groups maintain infrastructure in the United States.

These transfers are governed by the safeguards of Chapter V of the GDPR: adequacy decisions where available (in particular the EU-US Data Privacy Framework) and standard contractual clauses adopted by the European Commission. A copy of these safeguards can be obtained upon request at contact@sdravobiz.com.

The data you collect with the extension is not subject to any transfer on our part, as it is never sent to us.

8. Your rights

You have the following rights (Articles 15 to 22 of the GDPR):

  • access: know whether we process data concerning you and obtain a copy of it;
  • rectification: have inaccurate or incomplete data corrected;
  • erasure: obtain its deletion, within the limits of our legal retention obligations;
  • restriction: temporarily restrict processing;
  • portability: receive your data in a structured, machine-readable format;
  • objection: object to processing based on legitimate interest, and unconditionally to commercial prospecting;
  • withdrawal of consent at any time, without affecting the lawfulness of prior processing;
  • post-mortem directives on the fate of your data;
  • complaint with a supervisory authority (Article 13).

How to exercise them. By email to contact@sdravobiz.com (subject line “GDPR”) or by mail to our registered office. To prevent any fraudulent communications, we may request proof of identity. We respond within a period of one (1) month, extendable by two months in case of complexity or volume of requests (Article 12.3 of the GDPR).

If you have gone through a sales funnel on the website of a company using FunnelCart and wish to exercise your rights regarding this information, please contact that company directly: they alone are the data controller, and they alone hold this data. We have no access to it and therefore cannot provide it to you or delete it.

9. Security

We implement the appropriate technical and organizational measures provided for in Article 32 of the GDPR, including: connection encryption (HTTPS/TLS), payments processed by a PCI-DSS Level 1 certified provider, strict access control and strong authentication for administrator accounts, access logging, regular backups, continuous security updates, and contractual confidentiality commitments with our subcontractors.

The update archives served by our server are sealed and cryptographically signed, and their signature is verified by your site prior to installation.

No system can guarantee absolute security. In the event of a data breach likely to result in a risk to your rights and freedoms, we notify the ANSPDCP within seventy-two (72) hours and inform you directly when the risk is high (Articles 33 and 34 of the GDPR).

10. Your visitors’ data remains with you

This article is addressed to you, the client, regarding the individuals who browse the sales funnels installed on your site.

10.1 You are the sole data controller

This data is stored in tables of your own WordPress database, on your hosting. We do not receive it, host it, consult it, and cannot restore it.

You alone determine the purposes and means of the processing. It is your responsibility to inform your visitors, define your legal bases and retention periods, publish your own privacy policy, collect the necessary consents, and respond to requests to exercise individual rights. Regarding this data, we are neither a data controller nor a data processor: we provide you with software, not a data processing service.

10.2 What the extension records on your end

So that you can include it verbatim in your own policy, here is what is recorded when a visitor goes through a funnel:

  • their journey: the funnel pages they view, the offers presented, accepted, or declined, and the date and time of each event;
  • the information they enter on a capture page: first name, email address, responses to the fields you have placed;
  • their orders, as recorded by FluentCart: items, amounts, payment method retained by your payment provider for a potential one-click offer;
  • proof of their consent to the one-click offer: the text displayed at checkout and the date;
  • their acquisition source: campaign parameters, ad click IDs, landing page, and referring site;
  • their device and, depending on your settings, their IP address — retained by default, can be disabled in the settings;
  • the notes and tags you subsequently add to their record.

The extension also maintains aggregated daily counters — page views, offers displayed, sales — which contain no data that can identify an individual.

10.3 What the extension makes available to you

  • An exporter and an eraser registered with native WordPress tools: export and erasure requests that you process from your site’s “Tools” screen automatically include data recorded by the extension.
  • A configurable retention period for visitor journeys — thirty days by default, after which they are automatically purged daily — and a separate period for buyers, kept indefinitely by default because they constitute a sales history.
  • A suggested privacy policy text, added to the WordPress privacy policy screen, which you can use and adapt.
  • A complete erasure upon uninstallation, if you choose this option.

Warning: buyers are kept indefinitely by default, and visitors’ IP addresses are stored by default. Configure these two settings upon installation.

10.4 What you are responsible for

  • Describe in your privacy policy the data listed in section 10.2, their purposes, their legal bases, and their retention periods.
  • Display a clear consent text before submission, and keep it as is: it is archived as proof.
  • Declare in your cookie policy the attribution cookie described in section 11.3, and subject it to consent if it is used for advertising purposes.
  • Do not ask questions that elicit sensitive data within the meaning of Article 9 of the GDPR, banking data, or government identifiers.
  • Verify that the messages you send from your funnels comply with the rules applicable to electronic marketing.
  • Check what the contact management system to which you copy this data does with it: this copying constitutes a processing operation for which you are responsible.

10.5 The only case where we see your data

If you provide us, as part of support, with a screenshot, an export, or access to your site, we may be exposed to your visitors’ data. We then act as a processor, on your specific and documented instruction, solely for the duration necessary to process your request. These items are deleted upon closing the ticket, and at the latest within the three (3) years of retention for support exchanges.

We recommend that you anonymize your screenshots before sending them to us.

11. Cookies

11.1 On our site

CategoryToolPurposeDurationLegal basis
Strictly necessaryWordPress Session (wordpress_*)Authentication to the customer area, securitySession / 30 daysLegitimate interest — without consent
Strictly necessaryCart and orderKeep the current orderSessionLegitimate interest — without consent
Strictly necessaryLanguage preference (pll_language)Display language12 monthsLegitimate interest — without consent
Audience measurementGoogle Analytics (_ga, _ga_*)Anonymized statistics13 monthsConsent
Functional / marketingEmail tracking (fcrm_*)Opens and clicks on our emails12 monthsConsent

During your first visit, a banner allows you to accept, decline, or configure non-strictly necessary cookies. You can modify your preferences at any time via the “Manage my cookies” link at the bottom of each page. Refusing non-essential cookies does not prevent access to the site or viewing its content.

11.2 What the extension stores on your visitors’ devices

On our customers’ websites, the extension places the following item in visitors’ browsers. It is set by your website, under your domain name, and it is your responsibility to declare it.

NameTypePurposeDuration
fcf_sidSigned cookie, inaccessible to JavaScriptRecognize the visitor from one funnel page to the next, link their order to their journey, and present them with the intended offersConfigurable, 30 days by default

11.3 The case of advertising platforms

The extension always measures your funnels on your end: statistics, user journeys, and step rankings do not depend on any cookie banner. What depends on it is solely what is sent to an advertising platform (Meta, Google, TikTok): these transmissions are only made if the visitor has given their consent through your website’s consent tool. In the absence of any signal, nothing is sent.

As the publisher of your website, it is up to you to qualify this use and connect your consent tool.

12. Minors

Our website and our product are not intended for minors under sixteen (16) years of age. We do not knowingly collect their data without the consent of the holder of parental authority (Article 8 of the GDPR). If we discover such data, we delete it without delay.

If your funnels are aimed at a minor audience, it is your responsibility, as the data controller, to implement the required verification and parental consent collection measures.

13. Complaints

If you believe that the processing of your data is not compliant, you may contact the Romanian supervisory authority:

Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
B-dul G-ral. Gheorghe Magheru nr. 28-30, sector 1, București, 010336, Romania
https://www.dataprotection.ro — anspdcp@dataprotection.ro — +40 318 059 211

If you reside in another Member State, you can also contact your national authority (CNIL in France, AEPD in Spain, Garante in Italy, CNPD in Portugal, BfDI in Germany, etc.).

14. Changes

We may modify this policy to reflect legal, regulatory, technical, or contractual developments. The applicable version is the one published on the date of your visit. In the event of a substantial change, we will inform you via a banner on the site or by email if you are a customer.

15. Contact

Sdravobiz S.R.L.
Strada Trandafirilor 51
307220 Giroc, Romania
contact@sdravobiz.com (legal and GDPR) — contact@sdravobiz.com (service and support)
https://funnelcart.pro/en/accueil/

Last updated: September 28, 2026