Documents
Personal data processing policy
Edition No. 3 dated 02.09.2026
This Policy describes how SHD-ECOM LLC (the SHODROP brand) processes personal data when operating the website shodrop.io and providing the Services.
Personal data controller:
ООО «ШД-ЭКОМ»
УНП 193823192
220101, Республика Беларусь, г. Минск, ул. Якубова, д. 10, пом. 13
Email для обращений: support@shodrop.io
Hereinafter — the “Controller”, the “Provider”.
The Policy applies to personal data processing under the Law of the Republic of Belarus of 7 May 2021 No. 99-Z “On Personal Data Protection” and other legislation of the Republic of Belarus.
2.1. The Controller processes personal data to the extent necessary for the stated purposes. The composition of the data depends on the selected Service, the Order and the requirements of the relevant organization. Not all of the data listed below is collected for every request or Order.
2.2. In this Policy the terms Client, Services, and Order have the meanings set out in the Public Offer; data subject means the individual to whom the personal data relate.
3.1. Depending on the purpose, the Controller can process:
- first name, last name and patronymic;
- telephone number;
- email;
- accounts and usernames in instant messengers;
- information about the selected service;
- information about the business and project;
- Client details;
- history of orders, payments and correspondence;
- IP address;
- cookie;
- information about the browser, device, time of visit and actions on the site.
3.2. To register a company and connect third-party services, the following can be additionally processed:
- passport details and document image;
- date and place of birth;
- citizenship;
- registration and residence address;
- tax residency;
- sample signature;
- information about owners, directors and beneficiaries;
- information about the nature of the activity;
- documents and identification results;
- other information required by a foreign registrar, bank, payment system or government agency.
Below, for each purpose, the categories of subjects, data, legal basis, duration and recipients (or categories thereof) are indicated.
- Subjects: site visitors who sent a request or message.
- Data: name; contact (phone, email or messenger account); text of the appeal; information about the selected service; technical data of the form.
- Ground: actions preceding the conclusion of the contract; consent - if specifically requested.
- Term: 12 months from the last request, if the contract is not concluded; when concluding an agreement - according to the rules for the purpose of execution of the agreement.
- Recipients: Controller’s employees; application processing and CRM services; email services; messengers chosen by the subject.
- Subjects: potential Clients.
- Data: contact details; information about the business and project; correspondence.
- Ground: actions preceding the conclusion of the contract.
- Term: 12 months from the last application or until the conclusion of the contract.
- Recipients: Controller’s employees; contractors involved in consultation; messengers and mail.
- Subjects: Clients and their representatives.
- Data: identification and contact details; details; information about the Order; correspondence; access and project materials to the required extent.
- Ground: conclusion and execution of the contract.
- Term: the period of execution of the Order and 3 years after its completion (taking into account the statute of limitations), unless a longer period is required by law.
- Recipients: Controller’s employees; contractors; document management and mail services.
- Subjects: payers and Clients.
- Data: Full name or name; details; amount and date of payment; operation identifiers; email for check.
- Ground: execution of the contract; fulfillment of duties established by law.
- Term: at least 5 years after the year of the transaction (accounting and tax accounting), unless a different period is established by law.
- Recipients: Alfa-Bank JSC; Provider's bank; other payment details agreed upon for payment of the Order; accounting and authorized contractors.
- Subjects: Clients and their representatives.
- Data: contacts; information about the project; access to sites; brand materials; correspondence.
- Ground: execution of the contract.
- Term: Order period and 3 years after its completion.
- Recipients: contractors of the Provider; platforms chosen by the Client (including Shopify, Yandex KIT and others according to the Order); hosting providers.
- Subjects: founders, directors, beneficiaries and other persons whose data is needed for registration.
- Data: categories from clause 3.2 to the extent required by the registrar or authority.
- Ground: execution of the contract; consent – when it is required for the processing of third party data or cross-border transfers.
- Term: Order period and additionally deadlines established by law, registrar or authority.
- Recipients: foreign registrars and agents; government and registration authorities of the chosen jurisdiction; the Provider’s contractors.
- Subjects: Clients, owners and authorized persons of the company.
- Data: contact and identification data; KYC/AML documents; information about activities; data from clause 3.2 if necessary.
- Ground: execution of the contract; consent - when required.
- Term: Order period and terms required by the bank, payment system or platform.
- Recipients: banks and payment systems; Shopify, TikTok Shop and other Order platforms; foreign agents and contractors.
- Subjects: Clients and applicants.
- Data: contacts; content of the appeal; information about the Order.
- Ground: execution of the contract; actions to address the subject.
- Term: 3 years after consideration of the application, unless a longer period is required by agreement or law.
- Recipients: Controller’s employees; support contractors; messengers and mail.
- Subjects: persons whose data is processed by the Controller.
- Data: data necessary to fulfill the obligation.
- Ground: fulfillment of duties established by legislative acts.
- Term: terms established by relevant legislation.
- Recipients: government bodies in cases and to the extent provided by law.
- Subjects: applicants.
- Data: Full name; contacts; content of the application; payment and order information.
- Ground: fulfillment of duties under the law; protection of the rights and legitimate interests of the Controller or third parties.
- Term: 3 years after consideration of the application.
- Recipients: Controller’s employees; banks when returning a payment; government agencies if necessary.
- Subjects: site visitors who have consented to analytical cookies.
- Data: IP address; cookie; information about the browser, device, pages and actions on the site.
- Base: consent of the subject (the “Accept” button in the cookie box).
- Term: before the expiration of the cookie consent period (12 months) and according to the rules of the analytical service, no longer than necessary for the purpose.
- Recipients: Yandex Metrica; Google Analytics.
5.1. Data can be transferred in the required volume:
- CAlfa-Bank JSC;
- hosting providers;
- CRM and application processing services;
- email services;
- messengers chosen by the Client (including Telegram, WhatsApp, MAX);
- the Provider’s contractors;
- foreign registrars and agents;
- banks and payment systems;
- Shopify, TikTok Shop and other platforms by Order;
- government and registration authorities;
- analytical systems (if you agree to cookies);
- other persons necessary to fulfill the Order.
5.2. The Controller does not sell personal data.
6.1. When registering a foreign company, connecting a foreign bank, payment system or platform, personal data may be transferred outside the Republic of Belarus, including to the USA, Great Britain and other jurisdictions chosen by the Client.
6.2. The transfer is carried out only to the extent necessary for the execution of the Order, on the basis provided for in Article 9 of Law No. 99-Z (including execution of an agreement with the subject; consent when informing about risks; other legal grounds).
6.3. If a cross-border transfer requires separate consent, the subject is provided with information about the purpose, data, duration, recipients and possible risks of such transfer.
7.1. Shelf life:
- applications without a contract - 12 months from the last application;
- documents and correspondence on Orders - execution period and 3 years after completion;
- payment and accounting documents - at least 5 years after the year of operation;
- registration and identification documents – the Order period plus the terms required by law, bank, registrar or platform;
- appeals and claims - 3 years after consideration;
- cookie-consent – 12 months;
- analytics - according to the rules of the corresponding service and no longer than the purpose of processing.
7.2. After the expiration of the period, the data is deleted or anonymized, unless otherwise required by law.
8.1. The subject of personal data has the right:
- obtain information about the processing of your personal data;
- request changes to incomplete, outdated or inaccurate data;
- revoke consent to processing;
- demand termination of processing and deletion of data in the absence of other legal grounds;
- appeal the actions (inaction) of the Controller.
8.2. To receive information about processing, send a request to the Controller. The response is provided within 5 working days, unless a different period is established by legislative acts.
8.3. To correct the data, send an application with documents (or copies) confirming the need for changes. The Controller makes changes or reports a refusal within 15 days.
8.4. To stop processing or delete data if there are grounds, please submit a request. The Controller reviews it within 15 days.
8.5. Consent can be revoked at any time without giving reasons. If consent was received electronically (site form, email, cookie), it can be revoked in the same way or by email to support@shodrop.io. Withdrawal of consent does not affect the lawfulness of the processing prior to the withdrawal and does not invalidate the processing on other lawful grounds.
8.6. The application is submitted in writing or in the form of an electronic document in accordance with Article 14 of Law No. 99-Z. Additionally, the Controller accepts requests by email support@shodrop.io and at the address: 220101, Republic of Belarus, Minsk, st. Yakubova, 10, room. 13.
8.7. The Controller’s actions can be appealed to the National Center for Personal Data Protection of the Republic of Belarus and (or) to court.
9.1. Sending an application is not formalized as a separate consent to processing if processing is necessary to respond to an appeal and prepare a contract. Next to the button it is indicated: “By clicking the button, you confirm that you have read the Personal data processing policy.”
9.2. The words “I consent” are only used when the processing is actually based on separate consent (for example, consent to analytical cookies).
10.1. The site uses cookies - small files that are stored in the browser.
10.2. Necessary cookies ensure the operation of the site: session, application forms, saving the selected consent. They do not require separate permission and are not used for advertising.
10.3. Analytical and marketing cookies are only launched after you click "Accept". These include Yandex Metrica (including web viewer and click map) and Google Analytics. Advertising pixels (Meta Pixel and similar) are not connected at the time of this revision; if they appear, they will also be included only after consent.
10.4. If you select Required Only, optional analytics and advertising scripts will not be downloaded.
10.5. The choice is retained for 12 months. To change your decision sooner, clear the site's cookies in your browser settings and refresh the page.
11.1. The Controller takes legal, organizational and technical measures to protect personal data from unauthorized access, loss, modification and disclosure.
12.1. The Controller may publish a new version of the Policy on this page. The date and revision number are indicated at the beginning of the document.
12.2. Using the site does not in itself mean consent to the processing of personal data. Consent is requested separately when it is the basis for processing.
