VariantaVariantaBack to Home

Privacy Policy

Varianta.io — Product Customization Platform

Operated by Tedy Development s.r.o.

Last updated: February 16, 2026


1. Introduction

Tedy Development s.r.o. (“Company,” “we,” “us,” or “our”) operates the Varianta.io platform (“Service,” “Platform”). This Privacy Policy explains how we collect, use, store, share, and protect personal data when you use our Service.

We are committed to protecting your privacy and handling your data in accordance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”), the ePrivacy Directive, and other applicable data protection laws.

By using our Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices, please discontinue use of the Service.

2. Who We Are

For the purposes of data protection law, the data controller is:

Tedy Development s.r.o.
Email: info@varianta.io
Website: https://varianta.io

If you have questions or concerns about how we handle your data, you may contact us at the details above.

3. Roles and Responsibilities

Our Service involves multiple parties, each with distinct data protection roles:

Varianta.io as Data Controller: We act as the data controller for personal data we collect directly from Subscribers (our customers), such as account registration data, billing information, and usage analytics.

Varianta.io as Data Processor: When Subscribers use our Platform to offer product customization to their End-Customers, we process personal data on behalf of the Subscriber. In this context, the Subscriber is the data controller and we act as the data processor. This processing is governed by a Data Processing Agreement, available upon request.

Subscribers as Data Controllers:Subscribers are responsible for the lawful collection and processing of their End-Customers’ personal data and must ensure compliance with applicable data protection laws, including providing appropriate privacy notices and obtaining necessary consents.

4. What Data We Collect

4.1 Data Collected from Subscribers

When you register for and use the Service, we may collect:

  • Account Information: Name, email address, company name, and login credentials.
  • Billing Information: Payment method details, billing address, and transaction history. Payment card data is processed by our third-party payment processor and is not stored on our servers.
  • Communication Data: Records of correspondence with our support team, feedback, and survey responses.
  • Usage Data: Information about how you interact with the Platform, including features used, configuration settings, login times, and session duration.
  • Technical Data: IP address, browser type and version, device information, operating system, and referral URLs.

4.2 Data Collected from End-Customers

When End-Customers use the customization tools embedded in a Subscriber’s Store, the following data may be processed through our Platform:

  • Customization Content: Images, text, designs, and other materials uploaded by End-Customers to personalize products.
  • Session Data: Browser type, device information, IP address, and interaction data within the customization interface.
  • Order-Related Data: Information passed from the Subscriber’s Store related to the customized product order, which may include names, shipping details, or email addresses depending on the Subscriber’s integration setup.

We process End-Customer data solely on behalf of the Subscriber and in accordance with the Subscriber’s instructions.

4.3 Data Collected Automatically

When you visit our website or use the Platform, we automatically collect certain information through cookies and similar technologies:

  • Google Analytics Data: We use Google Analytics to collect anonymized usage statistics, including pages visited, time spent on pages, traffic sources, and general geographic location. Google Analytics may use cookies to distinguish unique users. For more information, see Google’s privacy policy at https://policies.google.com/privacy.
  • Essential Cookies: We use strictly necessary cookies to enable core functionality such as authentication, session management, and security. These cookies do not require consent as they are essential for the Service to operate.

5. How We Use Your Data

We process personal data for the following purposes and on the following legal bases:

PurposeLegal Basis (GDPR Art. 6)
Providing and maintaining the ServicePerformance of a contract (Art. 6(1)(b))
Processing payments and managing subscriptionsPerformance of a contract (Art. 6(1)(b))
Communicating with you about your account and support requestsPerformance of a contract (Art. 6(1)(b))
Sending service-related notifications (downtime, updates, security alerts)Legitimate interest (Art. 6(1)(f))
Analyzing usage patterns to improve the ServiceLegitimate interest (Art. 6(1)(f))
Ensuring security and preventing fraudLegitimate interest (Art. 6(1)(f))
Complying with legal obligationsLegal obligation (Art. 6(1)(c))
Processing End-Customer data on behalf of SubscribersPerformance of a contract with the Subscriber (Art. 6(1)(b))

We do not use personal data for automated decision-making or profiling that produces legal effects.

6. Cookies

6.1 Essential Cookies Only

We use only strictly necessary cookies that are required for the Platform to function properly. These include:

  • Session Cookies: To maintain your authenticated session while using the Platform.
  • Security Cookies: To support security features and detect malicious activity.
  • Preference Cookies: To remember your settings and configuration choices within the Platform.

These cookies do not track your activity across other websites and do not collect data for advertising purposes.

6.2 Google Analytics

We use Google Analytics, which sets its own cookies to collect aggregated, anonymized usage data. We have configured Google Analytics with IP anonymization enabled. You may opt out of Google Analytics tracking by installing the Google Analytics Opt-Out Browser Add-on.

6.3 Third-Party Cookies via Subscriber Stores

When our customization tools are embedded in a Subscriber’s Store, the Subscriber’s own cookies and third-party trackers may operate independently of our Service. We are not responsible for cookies set by the Subscriber’s Store or its other third-party integrations.

7. Data Sharing and Third Parties

We do not sell your personal data. We may share personal data with the following categories of recipients, only to the extent necessary:

7.1 Service Providers

We engage trusted third-party service providers to assist in operating the Service, including:

  • Payment Processors: To process subscription payments securely.
  • Hosting and Infrastructure Providers: To host and deliver the Service.
  • Analytics Providers: Google Analytics, for aggregated usage analysis.
  • Customer Support Tools: To manage support communications.

All service providers are contractually obligated to process data only on our instructions and to maintain appropriate security measures.

7.2 E-Commerce Platform Providers

When you integrate the Service with Shopify or another e-commerce platform, certain data is exchanged between our Platform and the e-commerce platform as necessary to deliver the customization functionality. This data exchange is governed by the respective platform’s terms and privacy policies.

7.3 Legal and Regulatory Disclosures

We may disclose personal data if required to do so by law, regulation, or legal process, or if we believe in good faith that disclosure is necessary to protect our rights, your safety, or the safety of others, investigate fraud, or respond to a lawful government request.

7.4 Business Transfers

In the event of a merger, acquisition, reorganization, or sale of assets, your personal data may be transferred to the acquiring entity. We will notify you of any such change and any choices you may have regarding your data.

8. International Data Transfers

Our infrastructure may involve the processing of data in multiple locations, which may include countries outside the European Economic Area (EEA). When personal data is transferred outside the EEA, we ensure appropriate safeguards are in place, including:

  • Standard Contractual Clauses (SCCs) approved by the European Commission.
  • Transfers to countries recognized by the European Commission as providing an adequate level of data protection.
  • Other legally recognized transfer mechanisms as applicable.

You may request a copy of the safeguards we use for international transfers by contacting us.

9. Data Retention

We retain personal data only for as long as necessary to fulfill the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law.

  • Subscriber Account Data: Retained for the duration of your subscription and for up to 12 months after account termination, unless a longer period is required for legal or accounting purposes.
  • Billing and Transaction Data: Retained for the period required by applicable tax and commercial laws (typically 5–10 years under Czech law).
  • End-Customer Customization Content: Retained for the duration of the Subscriber’s subscription. Upon termination, Customization Content is deleted within 90 days unless the Subscriber exports it beforehand.
  • Usage and Analytics Data: Retained in anonymized or aggregated form and may be kept indefinitely for analytical purposes.
  • Support Communications: Retained for up to 24 months after the resolution of a support request.

10. Data Security

We implement appropriate technical and organizational measures to protect personal data against unauthorized access, alteration, disclosure, or destruction. These measures include:

  • Encryption of data in transit (TLS/SSL) and at rest where applicable.
  • Access controls and authentication mechanisms.
  • Regular security assessments and vulnerability monitoring.
  • Employee training on data protection practices.

While we strive to protect your data, no method of transmission over the internet or electronic storage is completely secure. We cannot guarantee absolute security but are committed to promptly addressing any security incident in accordance with applicable law.

11. Your Rights

Under the GDPR and other applicable data protection laws, you have the following rights regarding your personal data:

Right of Access: You may request a copy of the personal data we hold about you.

Right to Rectification: You may request correction of inaccurate or incomplete personal data.

Right to Erasure (“Right to Be Forgotten”): You may request deletion of your personal data, subject to certain legal exceptions.

Right to Restriction of Processing: You may request that we limit the processing of your personal data under certain circumstances.

Right to Data Portability: You may request to receive your personal data in a structured, commonly used, and machine-readable format, and to have it transmitted to another controller where technically feasible.

Right to Object: You may object to the processing of your personal data based on legitimate interests, including processing for analytics purposes.

Right to Withdraw Consent: Where processing is based on consent, you may withdraw your consent at any time without affecting the lawfulness of processing carried out before withdrawal.

Right to Lodge a Complaint: You have the right to lodge a complaint with a supervisory authority. In the Czech Republic, the relevant authority is the Office for Personal Data Protection (Urad pro ochranu osobnich udaju, UOOU) — https://www.uoou.cz.

To exercise any of these rights, please contact us at the details provided in Section 2. We will respond to your request within 30 days, as required by law.

12. End-Customer Rights

If you are an End-Customer who has used the customization tools on a Subscriber’s Store, please note that the Subscriber is the data controller for your personal data. To exercise your data protection rights, you should contact the Subscriber (the store owner) directly. We will cooperate with the Subscriber in fulfilling any data subject requests as needed.

13. Children’s Privacy

Our Service is not directed at individuals under the age of 16. We do not knowingly collect personal data from children under 16. If we become aware that we have collected personal data from a child under 16 without appropriate parental consent, we will take steps to delete such data promptly. If you believe that a child has provided us with personal data, please contact us.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make material changes, we will notify you by posting the updated policy on our website with a revised “Last updated” date and, where practicable, by email.

We encourage you to review this Privacy Policy periodically to stay informed about how we protect your data.

15. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:

Tedy Development s.r.o.
Email: info@varianta.io
Website: https://varianta.io

For data protection inquiries, you may also reach our designated data protection contact at: dpo@varianta.io


By using Varianta.io, you acknowledge that you have read and understood this Privacy Policy.