Privacy Policy

Privacy isn't a setting. It's how Qusto is built — no cookies, no cross-site tracking, EU-hosted data, and open-source code you can check.

Last updated: 9 August 2026 · Privacy Notice v1.1

1. Data Controller

The data controller for personal data collected through qusto.io and the Qusto platform is:

Qusto
Email: compliance@qusto.io

We have not appointed a Data Protection Officer, as we are not required to under Article 37 GDPR. This notice is governed by the GDPR and Spain’s LOPDGDD.

2. Data We Collect

We collect the minimum data necessary to provide our service:

3. Legal Basis for Processing (GDPR)

4. Cookies and Tracking

Qusto does not use tracking cookies. We do not place any third-party cookies, advertising pixels, or cross-site tracking scripts on our website or within the analytics platform. A single session cookie is used solely for authentication (keeping you logged in); it contains no tracking data and expires when you close your browser.

Because we do not use tracking cookies, no consent banner is required on your store when using Qusto for analytics.

5. Data Storage and Transfers

Account data, analytics event data, and backups are stored on servers located within the European Union. Our primary hosting provider processes data only on our instructions within the EU. Where a limited edge or form processor may process technical or form data outside the EEA (see the sub-processor list), transfers rely on an adequacy decision, the EU–US Data Privacy Framework, and/or EU Standard Contractual Clauses (Commission Decision 2021/914), as applicable. Store analytics event payloads are not processed by US advertising or analytics trackers.

6. Data Retention

7. Your Rights Under GDPR

If you are located in the European Economic Area, you have the following rights:

To exercise any of these rights, contact us at compliance@qusto.io. We will respond within 30 days.

8. Data processors and third-party services

We use the following categories of processor to operate Qusto. Each acts under a written contract meeting Article 28 GDPR. Named providers are listed on our sub-processor page.

We do not use Google Analytics, Meta Pixel, LinkedIn Insight, or any other third-party advertising trackers.

9. Security

We protect personal data with encryption in transit, access controls limiting who can reach production systems, network firewalls, monitoring, and regular encrypted backups. If a breach ever affects your rights we will notify the competent supervisory authority without undue delay and tell you where the law requires it.

10. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated to registered users by email. The "Last updated" date at the top of this page reflects the most recent revision.

11. Contact

For any privacy-related questions or to exercise your rights:
compliance@qusto.io