Moely — Privacy Policy
Last updated: July 6, 2026 Effective date: July 6, 2026
This Privacy Policy explains what personal data Moely collects, why we collect it, how we use it, who we share it with, and the rights you have over it. It applies to the Moely service at moely.store and any related subdomains (the "Service").
It covers three kinds of people: Creators (our customers, who build a page and sell products on it), Visitors (people who view a Creator's page), and Buyers (Visitors who purchase or claim a Creator's product).
We keep this short and honest. If anything is unclear, email us at hi@moely.store.
1. Who is responsible for your data
The company behind the Service is:
Codeto Prague s.r.o. ID (IČO): 11863226 Chudenická 1059/30, Hostivař, 102 00 Praha Czech Republic Contact: hi@moely.store
Our role depends on whose data it is:
- For Creators and Visitors, we are the data controller.
- For Buyers, there are two layers. We are the controller for the data we need to run the platform itself (security, abuse prevention, legal compliance). But the order itself — your name, email, and what you bought — is collected on behalf of the Creator you bought from: the Creator is the controller of that data, and Moely acts as their processor under Article 28 GDPR, handling it only to keep order records, deliver your purchase, and send order emails. This section, together with our Terms of Service, forms the data-processing terms between us and each Creator.
2. What data we collect
Data Creators give us directly
- Account data — your name, email address, and Google account identifier (you sign in with Google).
- Profile data — your chosen username, display name, bio, avatar image, accent color, social links, and the layout/theme settings you publish on your page.
- Content — the link titles and URLs you add to your page, and your product listings (names, descriptions, prices, images, and the digital files you upload for delivery).
- Billing data — your Subscription status and billing history. The payment card itself is handled by our payments provider; we never see or store card numbers.
- Payout account data — if you sell paid products, the identifier of the Stripe account you connect. Your relationship with Stripe (including the identity and bank details you give them) is governed by Stripe's own privacy policy.
- Support data — anything you send us by email or through a support form.
Data we collect about Buyers
When you purchase or claim a product on a Creator's page, we collect:
- Order data — your email address, the name you enter (for free-product claims) or share via checkout, the product you bought, the amount and currency paid, and order status (paid, refunded, delivered).
- Delivery data — the order confirmation/delivery emails we send you and your access to the order page and file downloads.
Payment card details go to Stripe, not to us. Paid checkout happens on Stripe's hosted checkout page, processed on the Creator's own Stripe account under Stripe's privacy policy. We never see or store card numbers.
We share your order details with the Creator you bought from — they are the seller, and they see your orders in their dashboard. What they do with your data beyond fulfilling the order (for example, marketing) is their responsibility as controller; our Terms require them to have a lawful basis for it.
Data we collect automatically
- Technical data — IP address, browser type, device type, operating system, referrer URL, and language preference.
- Usage data — pages visited within the Service, actions taken (link clicks, product views, page views), and timestamps.
- Cookies and similar technologies — see Section 8.
Data we collect about Visitors to creator pages
When someone visits a public page at moely.store/username, we record basic technical data (IP address, user agent, referrer, page accessed, timestamp) and aggregate interaction events (page views, link clicks, product views and clicks) for security, abuse prevention, and analytics. Our analytics run cookieless and we do not build profiles of Visitors across pages or for advertising.
What we don't collect
- We do not collect sensitive personal data (health, religion, political opinions, biometrics) unless you publish it voluntarily as part of your page content.
- We do not sell personal data to third parties.
- We do not use Buyer data for our own marketing.
- We do not use your data to train machine learning or AI models.
3. Why we process your data and on what legal basis
Under the GDPR, every use of your personal data needs a legal basis. Here's ours:
| What we do | Why | Legal basis (GDPR Art. 6) |
|---|---|---|
| Create and maintain a Creator account | To provide the Service you signed up for | Performance of a contract, Art. 6(1)(b) |
| Display a Creator's public page and products to Visitors | Same | Performance of a contract, Art. 6(1)(b) |
| Bill Creators and process their Subscription | Same | Performance of a contract, Art. 6(1)(b); legal obligation (tax/accounting), Art. 6(1)(c) |
| Record orders, deliver purchased or claimed products, and send order emails to Buyers | To fulfil the Creator's sale | Processed as the Creator's processor (Art. 28); the Creator's basis is performance of their contract with the Buyer, Art. 6(1)(b) |
| Send service notifications (billing, security, account emails) | To keep you informed about the Service | Performance of a contract, Art. 6(1)(b) |
| Prevent fraud, abuse, and security incidents (including rate-limiting by IP address and monitoring order abuse) | To keep the Service safe for everyone | Legitimate interest, Art. 6(1)(f) |
| Measure how the Service is used (aggregate analytics) | To improve the product | Legitimate interest, Art. 6(1)(f) |
| Send product updates or marketing emails to Creators | To tell you about relevant features | Consent, Art. 6(1)(a) — you can opt out anytime |
| Comply with legal obligations (tax records, responding to lawful requests) | Required by law | Legal obligation, Art. 6(1)(c) |
Where we rely on legitimate interests, we have balanced our interest against your rights and freedoms. You have the right to object — see Section 7.
4. Who we share data with
We share data only with the service providers we need to operate Moely, each under a data processing agreement. Rather than name every vendor, we group them by category of recipient:
| Category of recipient | What they do |
|---|---|
| Cloud hosting and infrastructure | Run the Service and serve pages to Visitors |
| Database and file storage | Store accounts, page content, product files, and orders |
| Authentication | Verify your identity and keep you signed in |
| Subscription billing | Process Creator Subscriptions and handle card details |
| Payment processing for Creator sales | Stripe — processes Buyer payments on the Creator's own Stripe account |
| Transactional email | Send order delivery and service emails |
| Product analytics | Measure page views, link clicks, and product interactions (cookieless) |
| Security and abuse prevention | Rate-limiting and fraud/abuse protection |
If you'd like to know the specific provider behind any of these categories, email us and we'll tell you.
In addition, Buyers' order details are shared with the Creator they bought from — the Creator is the seller and the controller of that data (see Section 1).
We may also disclose data where required by law — for example, in response to a valid court order or regulatory request — and when necessary to protect our rights or the safety of our users.
If Moely is ever acquired or merges with another company, your data may be transferred as part of that transaction. We will notify you before your data becomes subject to a different privacy policy.
5. International data transfers
Several of our providers are based in the United States and may process data there (our product analytics, for example, is hosted in the US). When data is transferred outside the European Economic Area, we rely on one or more of the following safeguards under Chapter V of the GDPR:
- Standard Contractual Clauses approved by the European Commission;
- Adequacy decisions, where the European Commission has recognized the destination country as providing adequate protection (including, currently, the EU–US Data Privacy Framework for certified US recipients);
- Your explicit consent, where applicable.
You can request a copy of the relevant safeguard by emailing us.
6. How long we keep data
We keep personal data only as long as we need it:
| Data | Retention |
|---|---|
| Active account data | While your account is active |
| Account data after deletion | Up to 30 days in live systems, then deleted; up to 90 days in backups |
| Order records (Buyer data) | While the Creator's account is active, so Buyers keep access to purchases and Creators keep their sales records; deleted or anonymized on the Creator's instruction or account deletion, subject to our own legal obligations |
| Billing and tax records | 10 years (Czech accounting and tax law requirements) |
| Support emails | 3 years after the ticket closes |
| Server logs (IP, request metadata) | 30–90 days |
| Aggregate analytics (no identifiers) | Indefinitely |
When retention ends, we delete or anonymize the data.
7. Your rights under GDPR
You have the following rights with respect to your personal data:
- Access — ask for a copy of the personal data we hold about you (Art. 15).
- Rectification — ask us to correct data that's wrong or incomplete (Art. 16).
- Erasure — ask us to delete your data, subject to our legal retention obligations (Art. 17).
- Restriction — ask us to stop processing your data in certain circumstances (Art. 18).
- Portability — get a copy of the data you gave us in a structured, machine-readable format, or have us send it to another controller (Art. 20).
- Objection — object to processing based on legitimate interests or for direct marketing (Art. 21).
- Withdraw consent — where we rely on consent, you can withdraw it at any time; this doesn't affect processing before withdrawal (Art. 7(3)).
- Not to be subject to automated decision-making — we don't make decisions about you by purely automated means that have legal or similarly significant effects (Art. 22).
To exercise any of these rights, email hi@moely.store. We will respond within 30 days (extendable to 90 days for complex requests, with notice).
If you are a Buyer: for your order data, the Creator you bought from is the controller, so you can direct your request to them — but you can always email us too, and we will handle it or pass it to the Creator and make sure it gets acted on.
Lodging a complaint
If you believe we are handling your data unlawfully, you have the right to lodge a complaint with a supervisory authority. The authority for the Czech Republic is:
Úřad pro ochranu osobních údajů (ÚOOÚ) Pplk. Sochora 27, 170 00 Prague 7, Czech Republic uoou.gov.cz
You can also complain to the supervisory authority in the EU Member State where you live or work.
8. Cookies and similar technologies
We use a minimal set of cookies:
- Strictly necessary cookies — for authentication, session management, and security (set when you sign in). These are required to use the Service and don't require consent under the ePrivacy Directive.
- Analytics — our product analytics run in a cookieless mode and do not set identifying cookies, so no consent banner is required.
We do not use advertising cookies, cross-site trackers, or third-party tracking pixels.
Paid checkout happens on Stripe's hosted checkout page (a stripe.com address), where Stripe sets its own cookies under its own cookie policy.
You can clear or block cookies in your browser settings. If you block strictly necessary cookies, parts of the Service will stop working.
9. Security
We take reasonable technical and organizational measures to protect your data, including:
- encryption in transit (TLS) and at rest;
- access controls and audit logs on our infrastructure;
- private storage for product files, with downloads gated by per-order access links;
- regular backups;
- vendor due diligence on every processor we use.
No system is perfectly secure. If we ever experience a data breach that is likely to result in a risk to your rights and freedoms, we will notify you (and, where we act as a Creator's processor, the affected Creator) and the supervisory authority as required by Art. 33–34 GDPR.
10. Children
Moely is not intended for children under 18, and we do not knowingly collect personal data from them. If you are a parent or guardian and believe your child has created an account or placed an order, contact us and we will delete the data.
11. Changes to this Policy
We may update this Privacy Policy from time to time. If a change is material, we will notify you by email or in-product notice at least 30 days before it takes effect. Non-material changes take effect on the date shown at the top of this document.
We will keep an archive of previous versions and link to them below when we publish an update:
- June 3, 2026 — the pre-store version (covered Creators and Visitors only). Available on request.
12. Contact
For any privacy question, request, or complaint:
Codeto Prague s.r.o. Chudenická 1059/30, Hostivař, 102 00 Praha hi@moely.store
We aim to reply within 7 business days, and always within the 30-day GDPR deadline.