<Legal>

Privacy
Policy

Last updated: July 1, 2026

We at SOFTCRAFTER (together with our affiliates and partners) respect your privacy and are strongly committed to keeping secure any information we obtain from you or about you. This Privacy Policy describes our practices concerning Personal Data that we collect from or about you when you use our website, mobile applications, or any related services (the "Services").

This Privacy Policy details how we collect, use, share, and protect your personal data in compliance with the highest data protection standards and applicable laws, including the GDPR and, where applicable, other relevant international data transfer mechanisms such as Standard Contractual Clauses and adequacy decisions.

By using our Services and platform, you agree to the terms outlined in this Privacy Policy. If you do not agree to this policy, please do not use the Company's website(s) or App.

Definitions

  • "Personal Data" refers to any information that identifies or can reasonably be used to identify an individual, either directly or indirectly, such as a name, identification number, location data, or factors specific to one's physical, physiological, genetic, mental, economic, cultural, or social identity.
  • "Sensitive Data" includes financial records, identity documents, and other information used for authentication and compliance.
  • "Processing" means any operation performed on personal data, whether by automated means or not, including collection, recording, organization, storage, use, disclosure, alignment, restriction, erasure, or destruction.
  • "Profiling" refers to any automated processing of personal data aimed at evaluating or predicting aspects related to an individual's behaviour, preferences, economic status, location, or other personal attributes.
  • "Platform" includes the SOFTCRAFTER website, mobile apps, and other platforms created by and for SOFTCRAFTER.

1. What Type of Data Do We Collect?

When you use our services you accept that our company collects some of your personal data. This page is intended to tell you what data we collect, why and how we use it.

We collect and process the following types of data:

  • Data provided by the users
  • Data we collect automatically
  • Anonymous data

1.1 Data provided by the user

We collect and store personal data that you voluntarily provide when using our Services, creating an account, or interacting with the platform. This information is necessary to deliver, maintain, and improve our services and to fulfill our contractual and legal obligations.

Here are some examples of personal information we collect: Name, surname, birthday, gender, city or address of contact, phone number, ID personal number only for some categories of users, company information, email, and password.

The personal data we may collect includes, but is not limited to:

  • Full name, date of birth, gender, contact address, phone number, email address, and password;
  • Identification number (for certain categories of users);
  • Company information (for certain categories of users);
  • Profile details and preferences;
  • Customer service interactions and communication records (platform, email, phone communications);
  • Uploaded contacts, listings, or other user-generated content;
  • Authentication data, such as login credentials, IP addresses, and device identifiers, are collected to secure your account;
  • Transactional data related to the payment history done through our approved channels.

You may also provide data when you:

  • Browse, search, shop, or interact with features (e.g. saved searches, reviews, etc.);
  • Use platform functionalities such as creating watchlists, managing your cart, or using personalized services;
  • Participate in questionnaires, contests, or community features;
  • Contact us via email, phone, or messaging tools;
  • Interact with content or complete any forms provided through the platform;
  • Provide feedback, ratings, and reviews on the platform or other services if available.

We may further collect technical and analytical information associated with your activity, such as:

  • IP address, login data, device/browser type, operating system, time zone, and browser settings;
  • Session information, URL clickstreams, interaction and error logs, download times, and content usage metrics;
  • Information from third-party sources, such as affiliated partners, subcontractors, analytics providers, payment processors, and delivery providers;
  • Behavioural and engagement data (e.g., interaction with emails, viewed content, click behaviour), which may be analysed to improve services or provide tailored offers, subject to your marketing preferences;
  • Data collected via cookies and similar tracking technologies for personalized content and promotional communications.

1.2 Data we collect automatically

We automatically collect and store certain types of information about your use of SOFTCRAFTER, including information about your interaction with content and services available through SOFTCRAFTER. Like many websites, we use "cookies" and other unique identifiers, and we obtain certain types of information when your web browser or device accesses content served by or on behalf of SOFTCRAFTER on other websites.

Examples of the information we collect and analyze include:

  • Technical data: for example, IP address, browser type, information on your computer, data relating to the current (approximate) position of the instrument you are using;
  • Data collected using cookies or similar technologies;
  • Login, email address, and password;
  • Purchase and content use history;
  • Phone numbers used to call our customer service number;
  • We may also use device identifiers, cookies, and other technologies on devices, applications, and our web pages to collect browsing, usage, or other technical information.

1.3 Anonymous data

We also process anonymous data, aggregated or not, to analyze and produce statistics related to the habits, usage patterns, and demographics of customers as a group or as individuals. This includes data regarding your interaction with content, services, and features, as well as information collected via cookies and similar technologies. Some of these technologies operate only with your consent, which may be given or withdrawn through our Cookie Preferences Centre.

Where the underlying data collected via cookies or similar technologies constitutes personal data, its collection is based either on our legitimate interest in improving and securing our services or, where applicable, your explicit consent in accordance with the General Data Protection Regulation (GDPR). Once such data has been anonymized, it no longer constitutes personal data and therefore falls outside the scope of the GDPR. Such anonymous data does not allow the identification of the customers to which it relates. Anonymous data is irreversibly de-identified and cannot be used to reconstruct individual user identities. This ensures it does not qualify as personal data under applicable data protection laws. It may be used for:

  • Internal research and performance analysis;
  • Development of new services and features;
  • Fraud detection algorithms and business intelligence;
  • Marketing performance metrics and benchmarking reports;
  • Optional sharing with external partners, researchers, or affiliates, provided the data remains non-identifiable.

Where relevant, anonymized datasets may also be shared with research partners or business affiliates. Please be aware that the Company may choose to permit third parties to offer subscription and/or registration-based services through the Company's site.

Continued use of our website or application implies acceptance of this Privacy Policy. If you do not agree with any part of this policy, we kindly request that you refrain from using our services.

2. How and Why Do We Use the Collected Data?

We process your personal data to deliver, operate, improve, and secure our services, to fulfil our contractual obligations to you, and to comply with applicable laws. We may also use your data, where permitted, to provide personalized content, optimize your experience, and inform you of relevant commercial activities.

This processing is based on our legitimate interests in accordance with the GDPR and national laws, in operating and improving the platform, or where required, your explicit consent (e.g., for non-essential cookies or personalized ads).

2.1 To provide and manage access to our services

We use your data to enable core platform functionalities, such as:

  • Account registration and private profile management;
  • Access to features including wish lists, saved searches, cart management, and user-to-user messaging;
  • Communication with customer support or other users.

We also use your data to:

  • Respond to inquiries, support requests, and complaints;
  • Develop, test, and improve features, interfaces, or services;
  • Deliver notifications, service updates, and account-related messages;
  • Recover outstanding payments;
  • Participate in legal proceedings or comply with legal demands;
  • Prevent fraudulent activity and moderate platform content;
  • Perform accounting, billing, or payment-related administration;
  • Detect approximate location to enhance local relevance;
  • Measure user satisfaction and conduct voluntary surveys;
  • Send essential service-related notices, such as account, transaction, or platform updates (opt-out available at any time for non-essential notices);
  • Direct marketing — we require your consent specifically for this purpose and you may opt out at any time. You may withdraw your consent to receive marketing emails at any time by clicking 'unsubscribe' or contacting us directly at [email protected];
  • Purposes directly related or incidental to the above; or
  • Where you have given consent to it.

These treatments are based on the legitimate interest of the Data Controller in improving the service and its implementation, and you can object, in the cases provided by law, at any time.

Failure to provide certain essential data may limit or restrict access to some features of the platform.

2.2 To inform you about our business activities

Subject to your explicit consent (Article 6(1)(a) GDPR), we may use your contact information to send:

  • Marketing messages about platform features, offers, events, or campaigns (via email, SMS, and/or other means);
  • Analytics to assess campaign performance, such as open/click rates, unsubscribe metrics, device, and OS tracking.

You may withdraw your consent at any time by selecting "unsubscribe" in emails or contacting [email protected].

2.3 To offer you a personalized service

We process the collected data, if you have expressly given us your consent, to analyze your habits or consumption choices in order to offer you an increasingly personalized service in line with your interests and to improve our commercial offer (e.g. suggest listings or content tailored to your interests; enhance recommendations and search results; improve our commercial offer, etc.).

This processing does not involve automated decision-making with legal or similarly significant effects.

2.4 To comply with legal obligations

In certain cases, we collect and use your personal information to comply with laws. For instance, we collect from vendors and in some cases other users information regarding the proof of identity and address when required, place of establishment and bank account information for identity verification, due diligence, and other legal purposes (if changes occur). We process personal data to comply with AML/KYC laws, financial reporting obligations, regulatory authority requests, audits, court orders, and similar.

Users are expected to provide accurate and lawful data. Providing false information may result in account suspension and reporting to relevant authorities.

If you have any questions as to how we collect and use your personal information, please contact our Customer Service. You can choose not to provide certain information, but then you might not be able to take advantage of many of the SOFTCRAFTER services. You can add or update certain information on the space dedicated to you as a user or store owner. When you update information, we usually keep a copy of the prior version for our records as long as it is allowed by law. We only retain personal data for as long as necessary to fulfill the purposes set out above, or as required by law. Data is processed in accordance with the principle of data minimization.

Users are solely responsible for managing their own privacy, cookie, and communication preferences. SOFTCRAFTER is not liable for limitations in user experience resulting from settings adjusted by the user.

We do not reuse personal data for purposes incompatible with those stated herein, unless legally required or the user provides new consent.

2.5 User's choice, technical settings & limitation of features

If you do not want to receive interest-based ads, email, or other communications from us, please adjust your preferences. If you don't want to receive in-app notifications from us, please adjust your notification settings in the app or device.

The Help feature on most browsers and devices will tell you how to prevent your browser or device from accepting new cookies or other identifiers, how to have the browser notify you when you receive a new cookie, or how to block cookies altogether. Some platform features, such as the cart or checkout, may not operate correctly if essential cookies or identifiers are blocked. For more information about cookies and other identifiers, see our Cookies Notice.

If you want to browse our website without linking the browsing history to your account, you may do so by logging out of your account and blocking cookies on your browser.

In addition, to the extent required by applicable law, you may have the right to request access to or delete your personal data. If you wish to do any of these things, please contact our Customer Service. Depending on your data choices, certain services may be limited or unavailable.

Users who voluntarily publish content or share data through the platform (e.g., via public profiles, chat, feedbacks, reviews, or forums) do so at their own risk. SOFTCRAFTER is not liable for any unintended exposure or misuse of information disclosed in public or user-controlled spaces.

2.6 Data sharing and disclosure

We do not sell or rent personal data. However, we may share personal data in limited, carefully controlled circumstances, as described below. All such disclosures are governed by strict contractual obligations and confidentiality standards.

Sharing with trusted third parties: We may share your data with trusted service providers who process data on our behalf and under our instructions, solely for the purposes specified in this policy:

  • Payment Processors and Financial Institutions – To process transactions and perform fraud detection or identity verification, in accordance with applicable financial regulations;
  • Cloud Infrastructure Providers – To securely host and store platform data with adequate encryption and data centre safeguards;
  • Security and Compliance Auditors – For conducting periodic security assessments and ensuring legal or industry compliance;
  • Analytics and Technical Service Providers – To generate anonymized insights that help improve platform performance and user experience.

Compliance with legal obligations:

  • To comply with a lawful request, court order, or legal process;
  • To cooperate with regulatory investigations, audits, or law enforcement proceedings.

Business reorganization or acquisition: In the event of a merger, acquisition, bankruptcy, or sale of assets, your personal data may be lawfully transferred to a successor entity, provided that:

  • The recipient assumes data protection obligations under this Policy;
  • You are notified of any material changes in processing. This notification can be done through the official website or the platforms of SOFTCRAFTER.

Personal data is retained only for as long as necessary to fulfill the purposes outlined in this policy, or as legally required. We regularly review data retention practices and implement anonymization or deletion protocols for outdated or unnecessary records. We will ensure such transfers are carried out with appropriate contractual safeguards in accordance with relevant articles of GDPR and other legal mechanisms in force.

While SOFTCRAFTER performs due diligence when selecting third-party providers, we do not control their operations. Once data is shared in accordance with this policy, any processing conducted by third parties is governed by their respective privacy practices and applicable laws. SOFTCRAFTER shall not be held liable for third-party acts or omissions beyond our contractual and technical control.

Public and aggregated data disclosures: We may publish or share:

  • Anonymized and Aggregated Data for statistical, research, or performance reporting purposes. This data cannot be used to identify individuals.
  • User-Generated Content, such as listings or public reviews, which is published voluntarily and may appear in public search results. Sensitive personal data is never published without consent.

In such event, users are solely responsible for the content they submit or publish through public platform features.

3. Data Security Measures

We implement industry-standard physical, technical, and organizational security measures to protect personal data against unauthorized access, loss, misuse, or disclosure.

3.1 Technical measures

  • Advanced Encryption: Data is encrypted in transit (SSL/TLS) and at rest using robust cryptographic standards.
  • Firewalls and Intrusion Detection Systems: Continuous monitoring for unauthorized access or breaches.
  • Role-Based Access Controls: Strict access limitations to sensitive data based on personnel roles.

3.2 Organizational measures

  • Regular Staff Training: Ongoing data protection training for all personnel with data access responsibilities.
  • Internal Security Policies: Comprehensive procedures and protocols to ensure data security. Enforced internal policies governing data access, handling, and deletion.

3.3 Risk audits and continuous improvement

  • Routine Security Assessments: We perform internal and third-party audits, vulnerability scans, and penetration tests.
  • Continuous Monitoring: Real-time monitoring of platform performance, network activity, and potential security anomalies.

3.4 Incident management and breach notification

  • Incident Response Plan: In the event of a data breach, we act immediately to investigate, contain, and mitigate the risk.
  • Timely Notification: Informing affected users and competent data protection authorities as required by law.
  • Detailed Documentation: Investigating and documenting all incidents for continuous security improvement.

All employees and contractors with access to personal data are subject to binding confidentiality obligations and are granted access strictly on a need-to-know basis. Despite our efforts, no system can be completely secure. While we follow recognized best practices in cybersecurity and data protection, no system is immune to all threats. Accordingly, SOFTCRAFTER does not guarantee absolute security and shall not be liable for data breaches that occur despite implementation of reasonable technical and organizational measures, unless due to proven gross negligence.

4. Who Are the Controllers?

The responsible department in charge of the protection of personal data is the Department for Protection of Personal Data of SOFTCRAFTER, with DPO Kleant Novi, reachable at [email protected].

You may contact this department at any time with questions, requests, or concerns regarding your personal data and your rights under applicable data protection laws.

Your personal data may be transferred outside Albania or the European Economic Area (EEA) to be processed by some of our service providers. In this case, we make sure that this transfer takes place in compliance with current legislation and that an adequate level of protection of personal data is guaranteed based on an adequacy decision.

If you would like to obtain a copy of these safeguards, you may request this by contacting us at [email protected].

5. How Can You Have Access to Your Data?

By logging into your SOFTCRAFTER account, you can directly access or update your account and information.

5.1 Information you can access

  • Personally identifiable information (including name, email, password, and address);
  • Payment settings (including payment card information, promotional certificate and gift card balances);
  • Email notification settings;
  • Your content, services, and related settings, communications and personalized advertising preferences;
  • Your Profile (including your product Reviews, Recommendations, Reminders and personal profile), etc.

Access to this data may require login verification. In some cases, certain data may be temporarily unavailable due to system maintenance or legal holds.

5.2 Export and deletion of personal data

To export your personal data or request its deletion (right to be forgotten), you can send a request to the e-mail address [email protected] from the e-mail address with which you are registered in SOFTCRAFTER. Your personal data will be exported or deleted within the timeframe set in the law.

Please note that deletion of essential data may result in restricted access to services. Certain data may be retained if required by law (e.g., transaction records, fraud prevention logs).

5.3 Exercising your rights

Any individual user who uses our services can:

  • Obtain from the owner, at any time, information about the existence of their personal data, the purposes and methods of treatment and, if present, obtain access to personal data and information. Request confirmation of whether we process your personal data, and, where applicable, obtain access to the data and details regarding the purpose, categories, source, and recipients of the data;
  • Request the correction or completion of inaccurate or incomplete personal data we hold about you;
  • Request to receive your data in a structured, commonly used, machine-readable format, and where feasible, to have it transmitted to another controller;
  • Request the deletion (right to be forgotten) of your personal data, where there is no lawful reason for its continued processing (e.g. legal compliance, fraud prevention);
  • Oppose, in whole or in part, for legitimate reasons and in accordance with the law, the processing of personal data provided for the purposes of commercial information or sending advertising or sales material, or for carrying out market research or commercial communication. Each user also has the right to withdraw consent at any time without prejudice to the lawfulness of the processing based on the consent given prior to the withdrawal.

To protect your personal data, we may ask you to verify your identity before fulfilling any rights request. We may decline to comply with a request where permitted or required by law.

If you believe your rights have been violated, you also have the right to lodge a complaint with the Commissioner for the Right to Information and Protection of Personal Data (Albania) or the competent supervisory authority in your country of residence.

6. How and for How Long Will Your Data Be Stored?

We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required to comply with legal, regulatory, or contractual obligations, in accordance with Article 5(1)(e) GDPR and the corresponding provisions of Law No. 124/2024 "On Personal Data Protection".

The personal data will be stored in paper and/or electronic form and for the time necessary to fulfill the purposes for which they have been collected in compliance with current legal regulations. The retention period depends on the type of data and the purpose of processing. For marketing purposes, we process your data, according to the consent you have provided, for a maximum period equal to that required by the applicable legislation.

Personal data used for analytics, performance monitoring, and product development may be retained in an aggregated or anonymized form, which cannot be used to identify individuals. These records are used exclusively for internal purposes and are not subject to deletion or export rights as they do not qualify as personal data under GDPR provisions. These data are confidential and for internal use only.

We apply periodic review protocols to ensure personal data is not retained longer than necessary.

In the case of exercising the right to be forgotten through a request for express cancellation of the personal data processed by the controller, we remind you that such data can be kept, in a protected form and with limited access, in our archives according to the applicable provisions of Law No. 124/2024 "On Personal Data Protection", and can be reused only if the user gives their expressed consent.

Please note that:

  • You may delete or modify your data at any time by accessing your account settings or contacting us.
  • Deleted data may remain in backup storage for a limited period (no longer than 30–90 days) for security, continuity, and disaster recovery purposes.

Once the relevant retention period has expired, or upon validated deletion requests, your personal data will be securely erased, anonymized, or pseudonymized in compliance with applicable data protection regulations.

7. How Do We Ensure the Protection of Your Data?

SOFTCRAFTER implements appropriate technical and organizational measures to safeguard personal data against unauthorized access, disclosure, alteration, loss, or destruction, in accordance with Article 32 of the General Data Protection Regulation (GDPR) and best industry practices. We design our systems with security and privacy in mind. We work to protect the security of your personal information during transmission by using encrypted protocols and software. We maintain physical, electronic, and procedural safeguards in connection with the collection, storage, and disclosure of personal customer information. Our security procedures mean that we may occasionally request proof of identity before we disclose personal information to you.

While we take every reasonable step to secure your data, you are also responsible for keeping your credentials safe. This includes:

  • Creating strong, unique passwords;
  • Avoid using the same password across multiple platforms;
  • Always sign out of your account, especially when using public or shared devices;
  • If available, activate 2FA to add an extra layer of security to your account;
  • Keeping your login details confidential;
  • Never share your password, and be cautious with emails or messages that request personal information. SOFTCRAFTER will never ask for your login details via email;
  • Regularly review your account settings and transaction history. If you notice suspicious activity, contact us immediately at [email protected];
  • Avoid saving login credentials on shared or public devices and disable auto-login features when possible.

SOFTCRAFTER is not liable for any unauthorized access resulting from user negligence or misuse of credentials.

We reserve the right to modify this section to reflect evolving technologies or regulatory changes. Any substantial updates that impact how your data is protected or processed will be:

  • Communicated through appropriate channels (e.g., email or platform alerts);
  • Published clearly on this page or related policy pages.

We encourage you to review this section periodically to stay informed about how we protect your personal information.

8. Cookies Notice

When you visit SOFTCRAFTER, we and our trusted partners may use cookies and similar technologies to collect and process certain information about your visit, in accordance with applicable privacy laws.

Cookies are small data files stored on your device that help us enhance your browsing experience, analyze site usage, deliver personalized content and ads, and maintain essential site functions.

Types of cookies we use:

  • Strictly Necessary Cookies — essential for the operation of our platform (e.g., to enable login, session management, or secure checkout). These cookies do not require your consent.
  • Functional Cookies — used to remember user preferences (e.g., language or region selection).
  • Performance and Analytics Cookies — help us understand how visitors use our website, so we can improve layout, performance, and user experience.
  • Advertising and Targeting Cookies — enable us and our partners to deliver ads relevant to your interests and measure campaign performance.
  • Geolocation and Device Data — we may request permission to collect approximate or precise location data and identify devices to tailor content and security features.

We rely on:

  • Your consent for all non-essential cookies and similar technologies (e.g., analytics, personalized ads);
  • Legitimate interest for the use of strictly necessary cookies (essential for platform functionality).

No non-essential cookies are activated unless you have explicitly provided your consent through our Cookie Banner or Preferences Panel.

You may manage or withdraw your consent at any time by:

  • Clicking "Cookie Settings" on our website footer;
  • Adjusting your preferences via the Privacy Settings page;
  • Configuring your browser or device to block or alert you about cookie use.

Please note that disabling certain cookies may affect your ability to access some features of our site.

For more information, please review our full Cookies Policy or contact us at [email protected].

9. Compliance With Local and International Regulations

At SOFTCRAFTER, we are committed to upholding the highest standards of data protection, user privacy, and legal transparency. Our platform operates in strict adherence to local, regional, and international data protection laws to ensure the trust and safety of our users, clients, and partners.

SOFTCRAFTER is committed to protecting your personal data in accordance with applicable data protection regulations, both within Albania and internationally.

We comply with:

  • The General Data Protection Regulation (EU) 2016/679 (GDPR);
  • Law No. 124/2024, dated 19.12.2024, "On Personal Data Protection" in Albania;
  • Any other applicable regional or cross-border legislation relating to privacy and personal data.

SOFTCRAFTER actively monitors changes in privacy laws, enforcement guidelines, and supervisory authority recommendations to ensure our policies, technical infrastructure, and operational practices remain compliant.

We maintain a proactive legal strategy by:

  • Continuously reviewing regulatory developments across jurisdictions;
  • Conducting internal data protection impact assessments (DPIAs);
  • Periodically updating our Privacy Policy, Cookies Notice, and Terms of Use;
  • Training staff and partners on privacy, cybersecurity, and lawful data handling;
  • Engaging with external legal counsel and compliance consultants where required.

SOFTCRAFTER is committed to full transparency with users and cooperation with supervisory authorities in any country where we operate. Users may contact our Data Protection Officer or legal team at [email protected] for any questions, concerns, or data rights inquiries.

10. Updates to the Privacy Policy

We may update or amend this Privacy Policy from time to time in response to changes in applicable law, regulatory guidance, technological developments, or business operations. SOFTCRAFTER reserves the right to modify this Privacy Policy at its discretion and without prior notice, provided that such updates remain compliant with applicable data protection laws.

We update this Privacy Policy as required to reflect:

  • Legal developments;
  • Regulatory changes;
  • Industry best practices.

All updates will be published on this page, and where the changes are material or affect your rights, we will:

  • Notify you via email or in-app message (if you have a registered account), and/or
  • Display a prominent notice on our platform homepage.

Unless stated otherwise, changes will become effective upon publication. Continued use of our services after the revised Privacy Policy has been posted constitutes your acceptance of the updated terms.

We encourage you to periodically review this Privacy Policy to stay informed of how we protect your information.

Contact Us

If you have any questions about this Privacy Policy or wish to exercise your data rights, please contact our Data Protection Officer:

  • Data Protection Officer: Kleant Novi
  • Email: [email protected]
  • Phone: +355 69 606 6339
  • Company: SoftCrafter Sh.P.K
  • NIPT: M41819018B
  • Address: Rr. Ndreko Rino, Nd. 1, NJ 1/3, Tiranë, Albania