Skip to content

Legal

Privacy Policy

Last updated: September 24, 2026

This Privacy Policy explains how ForkPoint Ltd. collects, uses, shares and protects personal data when you visit retailpace.com, contact us, subscribe to our updates or use the RetailPace e-commerce monitoring platform. We have written it to be read, not skimmed past, so if anything is unclear, ask us.

Who we are

RetailPace is a product of ForkPoint Ltd. ("ForkPoint", "we", "us", "our"), a company registered in Bulgaria with its registered address at 14 Slivnitza Str., Ruse, Ruse 7000, Bulgaria.

For the personal data described in this policy, ForkPoint is the data controller under the EU General Data Protection Regulation (GDPR) and the Bulgarian Personal Data Protection Act. You can reach us about any privacy matter at hello@forkpoint.com.

Scope of this policy

This policy covers personal data about:

  • Website visitors who browse retailpace.com.
  • Prospects and business contacts who fill in a form, book a meeting, subscribe to our updates or otherwise get in touch.
  • Platform users: people our customers authorise to use RetailPace, such as e-commerce managers, developers and operations staff.

It does not cover the store data our customers connect to RetailPace, which may include information about their own shoppers. For that data we act as a processor on the customer's behalf; see Store data we process for customers.

Personal data we collect

Data you give us

  • Contact and demo requests: first and last name, work email, phone number, company, commerce platform and the content of your message.
  • Newsletter sign-up: your email address.
  • Meeting bookings: your name, email, chosen time slot and anything you add to the booking.
  • Platform accounts: name, work email, job role, login credentials and your notification settings, such as the email addresses, phone numbers or chat channels where you want to receive alerts.
  • Support and correspondence: the content of emails, tickets and calls with our team.
  • Billing contacts: name, email and company billing details. We do not store payment card details.

Data collected automatically

  • Technical logs: when you visit the website or use the platform, our servers record your IP address, browser type, pages requested, referring page and timestamps.
  • Platform activity: sign-ins, settings changes, alert configuration and similar events, kept for security, troubleshooting and audit purposes.

Data from others

If your employer is a RetailPace customer, it may give us your name and work email so that we can create your account.

How we use data and why

We only use personal data where we have a legal basis under Article 6 GDPR:

  • Answering enquiries, running demos and preparing proposals. Basis: steps taken at your request before entering into a contract, and our legitimate interest in responding to business enquiries.
  • Providing the RetailPace platform: creating accounts, delivering dashboards and alerts, and giving support. Basis: performance of our contract with the customer, and our legitimate interest in providing the service to the people the customer authorises.
  • Sending our newsletter and product updates. Basis: your consent. You can withdraw it at any time using the unsubscribe link in every email or by writing to us.
  • Service messages, such as security notices, maintenance windows and changes to these terms. Basis: performance of contract and legitimate interest.
  • Keeping the website and platform secure, preventing abuse and investigating incidents. Basis: our legitimate interest in protecting our systems and our customers.
  • Improving RetailPace based on how features are used, in aggregated form wherever possible. Basis: our legitimate interest in developing our products.
  • Invoicing, accounting and complying with the law. Basis: legal obligation.

Where we rely on legitimate interests, we have weighed them against your rights and you can object at any time (see Your rights). We do not sell personal data, and we do not make decisions about you based solely on automated processing that have legal or similarly significant effects.

Store data we process for customers

RetailPace connects to commerce platforms such as Shopify, Salesforce Commerce Cloud, BigCommerce, Adobe Commerce, commercetools to monitor orders, payments, inventory, site performance and other operational signals. This store data can include personal data about the customer's shoppers, for example the details attached to an order.

For this data, the retailer is the controller and ForkPoint is a processor under Article 28 GDPR. We process it only to provide the service the customer has configured and on the customer's documented instructions, under a data processing agreement. We do not use it for our own marketing, we do not sell it and we do not combine it with data from other customers.

If you are a shopper and want to exercise your rights over this data, please contact the retailer you bought from. If you contact us instead, we will pass your request on to them.

Cookies and similar technologies

The RetailPace website does not use advertising or analytics cookies. We only use technology that is strictly necessary to deliver the pages you ask for.

  • Fonts: the website loads fonts from Google Fonts. To do this, your browser connects to Google's servers, which receive your IP address. See Google's Privacy Policy.
  • Platform sign-in: the RetailPace platform uses essential cookies to keep you signed in and to protect your session. These cannot be switched off without breaking sign-in.
  • Social and share links are plain links. Nothing is sent to LinkedIn, Facebook, X or other networks unless you click one, at which point that network's own privacy policy applies.

If we introduce analytics or any other non-essential cookies, we will update this policy first and ask for your consent where the law requires it.

Who we share data with

We share personal data only as far as needed for the purposes above:

  • Service providers who help us run RetailPace, such as hosting and cloud infrastructure, email delivery, form handling, meeting scheduling, customer support and invoicing tools. They act under contract, on our instructions and with appropriate confidentiality and security obligations. Customers can request our current list of sub-processors.
  • Commerce platforms and tools you connect, where data flows between them and RetailPace because you have authorised it.
  • Professional advisers such as lawyers, accountants and auditors, under a duty of confidentiality.
  • Authorities where the law requires it, or where needed to establish, exercise or defend legal claims.
  • A buyer or successor if ForkPoint or RetailPace is involved in a merger, acquisition or sale of assets. This policy will continue to protect your data.

International transfers

We are based in the European Union and aim to keep personal data within the European Economic Area (EEA). Where a service provider processes data outside the EEA, we make sure the transfer is protected by an adequacy decision of the European Commission (including the EU–US Data Privacy Framework for certified US companies) or by the European Commission's Standard Contractual Clauses together with any additional safeguards that are needed. You can ask us for a copy of the relevant safeguards.

How long we keep data

We keep personal data only as long as we need it:

  • Enquiries and prospect records: up to 24 months after our last interaction, unless you become a customer.
  • Newsletter subscribers: until you unsubscribe. We then keep your email address on a suppression list so that we do not contact you again.
  • Platform accounts: for as long as the customer's subscription runs, and deleted within 90 days after it ends.
  • Technical and security logs: up to 12 months, unless we need them longer to investigate an incident.
  • Contracts, invoices and accounting records: for the periods required by Bulgarian accounting and tax law.
  • Customer store data: as set out in the customer's agreement, and deleted or returned when that agreement ends.

Security

We use technical and organisational measures appropriate to the risk, including encryption of data in transit, role-based access controls, restricted access to production systems on a need-to-know basis, and confidentiality obligations for everyone who works with personal data. No system is perfectly secure. If a personal data breach occurs that is likely to put your rights at risk, we will notify the competent supervisory authority within 72 hours and inform affected people and customers without undue delay, as the GDPR requires.

Your rights

Under the GDPR you have the right to:

  • Access the personal data we hold about you and receive a copy.
  • Rectify data that is inaccurate or incomplete.
  • Erase your data where there is no longer a valid reason for us to keep it.
  • Restrict how we use your data in certain circumstances.
  • Data portability: receive data you gave us in a structured, machine-readable format.
  • Object to processing based on legitimate interests, and at any time to direct marketing.
  • Withdraw consent at any time, without affecting processing that took place before.

To exercise any of these rights, email hello@forkpoint.com. We will reply within one month, and may ask you to confirm your identity first. There is no charge for a reasonable request.

You also have the right to lodge a complaint with a data protection authority. In Bulgaria this is the Commission for Personal Data Protection, 2 Prof. Tsvetan Lazarov Blvd., 1592 Sofia (cpdp.bg). You can also complain to the authority in the EU country where you live or work. We would appreciate the chance to address your concern first.

If you live outside the EU, for example in the UK or a US state with a consumer privacy law, we will honour the same requests wherever we reasonably can. We do not sell personal information or share it for cross-context behavioural advertising.

Children

RetailPace is a business service. It is not directed at anyone under 18, and we do not knowingly collect their personal data. If you believe a child has given us personal data, contact us and we will delete it.

Changes to this policy

We may update this policy as our service or the law changes. The date at the top of the page shows when it was last revised. If we make material changes, we will tell platform users by email or in the product before they take effect.

Contact us

For questions about this policy or how we handle personal data, contact:

ForkPoint Ltd., 14 Slivnitza Str., Ruse, Ruse 7000, Bulgaria
Email: hello@forkpoint.com
Telephone: +359878466722