Privacy Policy
Anmelda verifies wholesale applicants for Shopify merchants. Applicant data is the most sensitive thing we hold, and this page describes exactly what happens to it — in plain terms, matching what the software actually does.
Last updated: 17 July 2026
1. Who we are
Anmelda is operated as a sole trader by:
Santo Gigliotti, trading as Anmelda
Via Vergiò 27
6932 Lugano
Switzerland
Privacy contact: hello@anmelda.com
We have not appointed a Data Protection Officer. Our processing does not meet the Art. 37 GDPR criteria that would require one; if that changes, this page changes with it.
Anmelda is operated from Switzerland and serves merchants in the EU, so two laws apply at once: the GDPR, and the Swiss Federal Act on Data Protection (FADP). We comply with both, and where they differ we apply whichever is stricter. This page is written to the GDPR because that is the higher standard on most points. Our own supervisory authority is the Federal Data Protection and Information Commissioner (FDPIC).
2. Two different roles
Which rules apply depends on whose data it is. We hold two distinct kinds:
a) Applicant data — we are the processor
When someone applies for a wholesale account in a merchant's store, that merchant is the controller. They decide who may apply, what is asked, and who is approved. We process that data only on the merchant's documented instructions, under the Data Processing Agreement. If you applied to a shop and want your data accessed or erased, contact that shop first — they control it. You may also contact us and we will help them act.
b) This website and merchant accounts — we are the controller
For anmelda.com and for the merchant's own account details, we decide the purposes, so we are the controller.
3. What we process
Applicant data
Only what the merchant's form collects, which is:
- Contact — first name, last name, email address
- Business — company name, country, business address (street, city, postcode)
- Identifiers — VAT number and/or commercial register number, where given
- Optional — phone, website, expected monthly volume, free-text message
- Verification results — what each registry answered, when it was checked, and the registry's consultation ID, kept as proof the check was performed
We never ask for payment details, government ID numbers, or any special-category data under Art. 9 GDPR.
Website visitors
This site runs no analytics, no advertising or tracking pixels, and no third-party scripts. We set no tracking cookies and there is no consent banner because there is nothing to consent to. A single value (an_lang_dismiss) may be stored in your browser to remember that you dismissed the language suggestion; it never leaves your device.
4. Why, and on what legal basis
For applicant data we act on the merchant's instructions; the legal basis is the merchant's to establish, and is normally the performance of a contract or their legitimate interest in trading only with verified businesses. The purposes are strictly: receiving the application, verifying the business against public registries, letting the merchant decide, notifying the applicant of that decision, and creating the B2B account on approval.
We do not use applicant data for our own purposes. We do not profile, we do not sell data, and we do not use it to train machine-learning models.
5. Automated decisions
A merchant may enable rules that approve an application automatically when the registry checks pass. That decision is about a business, is based on public register facts, and produces no legal effect concerning a person within the meaning of Art. 22 GDPR. A rejection is never automated: applications that fail a check are always routed to a human.
6. Where data is processed
All application data is hosted in the European Union, in AWS's eu-central-1 region (Frankfurt, Germany). The database and its encrypted backups stay in that region. Backups are encrypted at rest and expire automatically after 30 days.
Decision emails are sent with Amazon SES in that same region, so an applicant's email address does not leave Frankfurt in order to reach them.
Anmelda is operated from Switzerland, so administering the service means the data is available to us there. Under the GDPR that counts as a transfer to a third country, whatever region the servers are in — we would rather say so plainly than claim a Frankfurt address settles the question. Switzerland holds a European Commission adequacy decision, which is the transfer's legal basis, so no Standard Contractual Clauses or transfer impact assessment are needed. No applicant personal data reaches any country without an adequacy decision.
Registry lookups reach EU, Swiss and UK public authorities. Switzerland and the United Kingdom both hold adequacy decisions. We send registries only a company identifier — never an applicant's name, address, phone or email. See Subprocessors for the full picture.
7. Who else sees it
Only the subprocessors listed on the Subprocessors page, each for a single stated purpose. We do not sell personal data or share it for advertising. We disclose data to authorities only where the law compels it, and we tell the merchant unless legally forbidden.
8. How long we keep it
Each merchant sets a retention window for their shop. Where they have not chosen one, applications are deleted after 365 days. A merchant may set anything from 1 day to 10 years, or choose to keep applications indefinitely — that choice is theirs as controller, and it is a deliberate opt-out rather than the default.
A sweep runs daily at 03:00 UTC and deletes applications past their window. This matters most for people who never became customers: a rejected or undecided applicant triggers no Shopify webhook, ever, so this sweep is the only thing that erases their data. Encrypted backups roll off after 30 days.
Erasure means deletion, not anonymisation. An "anonymised" application still carries a company name and VAT number, which together re-identify a sole trader. So we delete the record.
9. Your rights
Under the GDPR you may request access, rectification, erasure, restriction, portability, and object to processing. For applicant data, address these to the merchant you applied to — they are the controller, and we act on their instruction. We support them with:
- Access — a complete export of everything held about an applicant, every field rather than a summary
- Erasure — deletion of the application and its verification records
- Uninstall — when a merchant removes Anmelda, all of that shop's data is deleted 48 hours later
You can always contact us directly at hello@anmelda.com. The FADP grants equivalent rights, so the same requests reach us whichever law covers you.
You also have the right to complain to a supervisory authority: in the EU, one in your country of residence, place of work, or where you believe an infringement occurred; in Switzerland, the FDPIC. You do not need to come to us first, though it is usually faster if you do.
10. Security
Data is encrypted in transit (TLS) and at rest. Access to production is restricted to the operator, over audited sessions, without a public administrative interface. We never log applicant fields or webhook payloads — logs record counts and identifiers only, so personal data cannot leak into them. Our handling of security incidents, including notification timelines, is described in the Data Processing Agreement.
11. Changes
If we change this policy we update the date above. For changes that materially affect how applicant data is processed, we notify merchants before the change takes effect.