GDPR
GDPR Notice
Smarlist GDPR notice explaining data controller roles, lawful bases, data subject rights, transfers, retention, and contact details.
Last updated: July 19, 2026
Scope and roles
This GDPR Notice explains how Smarlist approaches personal data for people in the European Economic Area, the United Kingdom, and Switzerland.
For account, waitlist, website, marketing, and direct business contact data, Smarlist generally acts as a controller. For merchant store data processed on behalf of a customer, Smarlist may act as a processor under a separate data processing agreement.
Categories of personal data
We may process account information, contact details, authentication information, device and usage data, support communications, product preferences, billing-related records when applicable, and information you provide in prompts or store briefs.
Users should avoid submitting sensitive personal data unless it is necessary for the requested service and permitted by applicable law.
Lawful bases
Depending on the context, we rely on contract performance, legitimate interests, consent, legal obligations, and protection of rights and security as lawful bases for processing.
Where processing depends on consent, you may withdraw that consent at any time, without affecting processing that occurred before withdrawal.
Your rights
Subject to applicable limitations, you may request access, correction, deletion, restriction, portability, objection, or withdrawal of consent.
You may also have the right to lodge a complaint with a supervisory authority. Contact privacy@smarlist.com to exercise rights.
Transfers, retention, and subprocessors
Smarlist may use infrastructure, analytics, authentication, communication, and AI service providers located in different countries. Where required, we use appropriate transfer safeguards.
We retain personal data only as long as reasonably necessary for the purposes described, legal obligations, dispute resolution, security, and product operation.