Skip to main content
Jaapi
GDPR Compliant

GDPR Compliance

Jaapi AB is a Swedish company. Stores are hosted in the EU by default, we collect only what a store needs to run, and every data subject right is honoured. The policies, the sub-processor register and the audit evidence behind that are on the trust center.

View Trust Center

GDPR FAQs

Is Jaapi GDPR compliant? +

Yes. Jaapi AB is a Swedish company under the GDPR. For the data in a customer's store the customer is the controller and Jaapi the processor, acting on its instructions under a data processing agreement. Jaapi is certified to ISO 27001:2022, audited in January 2026. The full privacy policy is at jaapi.com/privacy.

Where is my data stored? +

Each store has one home region. Stores are hosted in the EU (Nuremberg, Germany) unless the customer chooses US hosting (Ashburn, Virginia); backups for every store stay in the EU, and store data is hosted in its home region; only a supplier's shipment notices and support reads may briefly be processed in the other. A customer that requires EU-only hosting gets it as a contractual commitment. Where data leaves the EEA, because a store is US-hosted or a sub-processor is in the US, the transfer is covered by the European Commission's standard contractual clauses or an adequacy decision.

What personal data does Jaapi collect? +

A store holds account data (name, email address, role), the shipping addresses you enter, order history, credit balance and support correspondence, plus request logs kept for 30 days. Card details go to Stripe and never reach our systems. We hold no government identifiers, health data or biometric data.

What are my data rights under GDPR? +

You can access your data, have it corrected or erased, restrict or object to its processing, and receive it in a portable format. Your organization is the controller and its administrators can act on a request with the store's own tools, so start with them; a request sent to lynn@jaapi.store is passed on and helped along. We answer within one month, as GDPR Article 12 requires. You can also complain to Integritetsskyddsmyndigheten (IMY), the Swedish supervisory authority.

Who are Jaapi's sub-processors? +

Hetzner (hosting and backups, Germany, with a US data centre for US-hosted stores), Stripe (payments, Ireland), MailerSend (email delivery, Belgium), Google Workspace (our email, EU), Slack (team communication and operational alerts, US), Cloudflare (product image delivery, US), Juni (banking, Sweden) and Vercel (US), which carries traffic in transit for stores on a customer-owned domain that still points at our previous edge network. Each is under a data processing agreement. The current register, with what each holds, is at trust.jaapi.com/vendors. Orders are produced by a curated network of approved on-demand manufacturing suppliers, which receive only the name, address, contact details, any customs tax identifier and product details an order needs; their identities are disclosed to customers on request.

How long does Jaapi retain my data? +

Store data is kept until the customer's store is deleted, and within 30 days of the end of the service Jaapi deletes it and confirms the deletion. The order records behind an invoice, with the recipient's name and address, are kept for seven years after the end of the financial year, as the Swedish Bookkeeping Act requires. Request logs and expired sessions are deleted after 30 days; daily backups expire after 30 days and monthly backups after 24 months.

Who is Jaapi's Data Protection contact? +

Lynn Smeria, Jaapi's Security Officer, at lynn@jaapi.store. Jaapi has not appointed a data protection officer, as the conditions of Article 37 GDPR do not apply. Policies, the sub-processor register and audit evidence are at trust.jaapi.com.

Custom branded tumblers

Ready to send your global team swag they actually want?

Book a demo and we'll show you a store your team will actually be excited about. Quality branded items, made on demand, delivered locally. No warehouse, no customs drama.

Get a demo