Legal
Privacy Policy
Last updated: 20 July 2026
This Privacy Policy explains how HATCHED105 LEADERSHIP LIMITED, trading as Presterly (“Presterly”, “we”, “us”), collects, uses, and protects personal data. It covers our website at presterly.com, the Presterly application for Shopify (“the App”), and the retention services we operate for merchants. You can reach us about anything in this policy at fergus@presterly.com.
1. Who we are
Presterly is operated by HATCHED105 LEADERSHIP LIMITED, a company registered in the Republic of Ireland under company number 816748, with its registered office at 105 Baggot Street Lower, Dublin 2, D02 DX60, Ireland. We are the data controller for personal data we collect about visitors to our website and about the merchants who use our services. Where we process the personal data of a merchant’s own customers, we act as a data processor on that merchant’s behalf, under our standing Data Processing Addendum (see section 3).
2. Information we collect
When you contact us or join the waitlist
Our website contact and waitlist forms collect your name and email address, and optionally your store URL and any message you send us. We use this to respond to you and to keep you informed about Presterly.
Technical data
When you submit a form we briefly process your IP address and basic request metadata to prevent abuse and rate-limit submissions. We do not use advertising trackers. To understand whether the website works, we use Vercel Web Analytics, a privacy-friendly measurement that counts page views and visits without cookies, without storing anything on your device, and without identifying you. More detailed, optional analytics are described in section 6 and run only after you choose to allow them.
When a merchant uses Presterly
When a merchant installs the App or takes a Presterly service, we receive store and account details from Shopify (store name and domain, contact email, and billing status) and contact details for the merchant’s team. Where a merchant connects other platforms (for example Klaviyo, a WhatsApp Business account, or a booking platform), we receive the account identifiers and access tokens needed to operate them on the merchant’s behalf; we store those credentials encrypted. Shopify handles App billing; we do not receive or store card details.
Customer data we process for merchants
To do its job, Presterly processes personal data belonging to a merchant’s customers, including:
- identity and contact data: name, email address, and phone number;
- order and purchase history: orders, products, quantities, values, dates, discount codes, and order attributes (including Presterly attribution tokens), received through the Shopify API and through order-history exports the merchant provides;
- appointment and purchase records from booking or point-of-sale platforms the merchant connects (for example, Phorest);
- marketing consent and opt-out status for each channel, as recorded in the merchant’s store and connected platforms;
- opt-in submissions a customer makes on the merchant’s storefront through surfaces Presterly operates for the merchant (for example a checkout SMS consent box, a post-purchase offer, or a welcome pop-up), including the phone number submitted, which we store encrypted together with a record of the consent given;
- message and engagement events: deliveries, opens, clicks, and replies for messages sent on the merchant’s behalf; and
- reorder-link click data: when a customer taps a Presterly reorder link, we record the click with technical data (IP address, device and browser information, and timestamp) to take them to checkout, attribute the resulting order, and prevent abuse.
From this data we generate predictions (such as the date a customer is likely to run out of a product). We use customer data only to provide the services the merchant has taken: predicting reorder timing, sending reorder, win-back, and retention messages on the merchant’s behalf, growing the merchant’s consented marketing lists, attributing orders, and reporting to the merchant. We process it solely on the merchant’s documented instructions.
3. Our roles: controller and processor
For our website visitors, leads, and merchant accounts, we are the data controller. For the personal data of a merchant’s customers, the merchant is the controller and we are the processor: the merchant is responsible for having a lawful basis to contact its customers, and we act under the merchant’s instructions and our Data Processing Addendum, which applies to every merchant automatically. If you are a merchant’s customer and want to exercise your rights over data we process for that merchant, the quickest route is to contact the merchant; we will assist them (see section 10).
4. How we use data and our legal bases
- Responding to enquiries and waitlist sign-ups: our legitimate interests in operating and growing Presterly, and taking steps at your request before any contract (GDPR Art. 6(1)(a)/(f)).
- Providing the Service to merchants: performance of our contract with the merchant (Art. 6(1)(b)).
- Processing customer data for merchants: on the merchant’s instructions; the lawful basis is the merchant’s, as controller. For marketing messages, that basis is the customer’s consent, which the merchant collects and which we always check before a send.
- Security, fraud prevention, and legal compliance: our legitimate interests and our legal obligations (Art. 6(1)(f)/(c)), including keeping consent and opt-out records as evidence of compliance.
- Improving the service: we use aggregated and anonymised data that no longer identifies anyone to improve our predictions and benchmark performance.
- Anonymous website measurement: our legitimate interest in understanding whether the website works (GDPR Art. 6(1)(f)). We use Vercel Web Analytics, which counts page views and visits without cookies and does not identify you (see section 6).
- Optional website analytics: with your consent, we measure the limited actions listed in section 6 to understand whether the website works. You can withdraw that consent at any time through the Cookie settings control in the footer.
Automated processing
Presterly’s predictions (for example, when a customer may run out of a product) are generated automatically from order history, and message copy may be drafted with the assistance of AI tools under merchant review. These are marketing aids; we make no automated decisions about individuals that produce legal or similarly significant effects (GDPR Art. 22).
5. WhatsApp Business messaging, SMS reminders, and Facebook Login
Where a merchant enables it, Presterly sends reorder, win-back, and reminder messages by WhatsApp and/or SMS / text message to that merchant’s customers, on the merchant’s behalf. We send these only to customers who have opted in to receive marketing or messaging from that merchant on that channel; the merchant collects that consent and is the controller for it (see section 3). The full terms of our SMS and WhatsApp programme are set out in our SMS & WhatsApp Terms.
The Presterly SMS programme. Presterly also runs its own SMS programme, where you opt in directly with us: on our public opt-in page at presterly.com/sms-optin (a mobile-number field and a consent checkbox that is unticked by default), or by texting START to our programme number. For those numbers, we are the data controller: we hold your number and consent record solely to run the programme, and the disclosures and opt-out rights in this section apply in full. Consent is never a condition of any purchase.
Opting out. Every promotional text identifies the merchant and tells the recipient how to stop. Recipients can reply STOP at any time to opt out, or HELP for help; we honour opt-outs promptly and record them so the customer is not messaged again. Message frequency varies, and message and data rates may apply. Carriers are not liable for delayed or undelivered messages.
To provide this, we process the customer’s phone number and opt-out status. We process those data on the merchant’s documented instructions. We do not sell this data or use it for our own marketing. No mobile information will be shared with third parties or affiliates for marketing or promotional purposes, and opt-in data is not shared with third parties for their own purposes. Messages are delivered through the merchant’s connected messaging platform (for example, Klaviyo), Meta’s WhatsApp Business Platform, and/or our SMS delivery provider (see section 7).
Connecting a WhatsApp Business Account (Facebook Login)
To send messages over WhatsApp, a merchant connects their own WhatsApp Business Account to the App using Facebook Login for Business. When a merchant authorises this connection, Meta provides us with information about that WhatsApp Business Account, including the WhatsApp Business Account and phone-number identifiers, the display name and business profile, and an access token that lets the App send messages from the account. We use this solely to connect the merchant’s account and send the reorder and reminder messages the merchant has configured. We do not use Facebook Login to access a merchant’s personal Facebook profile, friends, or posts, and we request only the whatsapp_business_management and whatsapp_business_messaging permissions needed to provide the service.
Information we receive through the WhatsApp Business Platform
When the App sends WhatsApp messages on a merchant’s behalf, Meta’s WhatsApp Business Platform returns message delivery and read receipts and any replies the customer sends back within the conversation. We process these to show the merchant the status of their messages and to manage the conversation. Message content is limited to the reorder and reminder messages the merchant configures and the customer’s replies; we do not use it for any other purpose.
Meta Platform compliance
Our access to and use of any data obtained through Meta APIs (Facebook Login and the WhatsApp Business Platform) complies with the Meta Platform Terms, the Meta Developer Policies, and the WhatsApp Business Messaging Policy. We use data received from Meta only to provide the features described in this policy; we never use it for advertising or profiling, and we never sell it.
6. Cookies
Our website uses only strictly-necessary, first-party cookies needed for the site to function and to keep form submissions secure before you make a choice. If you select Allow analytics, we also use PostHog through an EU analytics endpoint to understand how the site is used: the pages you visit and the buttons and links you interact with, such as opening a walkthrough or starting the demo video.
PostHog stores a pseudonymous analytics identifier in your browser’s local storage. Session recording is disabled, and the values you type into forms are never captured. We do not send your form answers, name, email address, phone number, or message to PostHog. Analytics are optional: you may reject them without affecting the site, and change your choice at any time through Cookie settings in the footer.
Separately, we use Vercel Web Analytics to count page views and visits and see which pages are used. It is cookieless — it sets no cookies and stores nothing on your device — and it does not identify you or track you across other sites, so it runs for every visitor and is not covered by the analytics choice above. It never receives your form answers, name, email address, phone number, or message.
7. Sharing and sub-processors
We do not sell personal data, and we never share it for anyone else’s marketing. We share data with the service providers that run Presterly, each under contract and only as needed:
- Shopify: the commerce platform the App runs on and which handles billing.
- Supabase: database hosting and storage.
- Railway: hosting for the App’s backend (EU region).
- Vercel: hosting and content delivery for this website, and privacy-friendly, cookieless website analytics (aggregate page-view and visit counts, with no cookies and no identification of individual visitors).
- Resend: sending transactional and reminder emails.
- PostHog: optional website analytics, used only after a visitor has allowed analytics. We send it pseudonymous website-usage data, not form content or direct contact details.
- Meta Platforms: where a merchant connects a WhatsApp Business Account, messages are sent and delivery, read, and reply events are received through Meta’s WhatsApp Business Platform (Meta Platforms Ireland Limited / Meta Platforms, Inc.).
- Twilio: SMS and WhatsApp delivery, where messages are sent through Presterly’s own channel.
- The merchant’s own connected platforms: where a merchant delivers messages through its own accounts (for example, Klaviyo), data flows to those platforms under the merchant’s own agreements with them.
The current sub-processor list for merchant customer data, and how we announce changes to it, is maintained in our Data Processing Addendum. We may also disclose data where required by law or to protect our legal rights, and in a business transfer (such as a merger or acquisition), in which case this policy continues to apply.
8. International transfers
Our primary application infrastructure is hosted in the European Economic Area. Some of our service providers process data outside the EEA (for example, in the United States). Where they do, we rely on appropriate safeguards: an adequacy decision (including the EU-US Data Privacy Framework where the provider is certified) or the European Commission’s Standard Contractual Clauses.
9. How long we keep data
We keep contact and waitlist data for as long as we are in touch with you and for a reasonable period afterwards, then delete it. Merchant account data and customer data processed only on a merchant’s instructions are retained for the life of the merchant’s service and deleted or returned within 30 days of it ending (including uninstalling the App), unless the merchant instructs us sooner or the law requires otherwise. We may retain consent, opt-out, suppression and minimal audit records for longer as evidence of compliance, to prevent further sends and to resolve disputes or enforce agreements. Data in encrypted backups is removed on the backup-rotation cycle.
10. Your rights
Under the GDPR you have the right to access, correct, delete, restrict, or object to our processing of your personal data, to data portability, and to withdraw consent at any time. To exercise these rights, email fergus@presterly.com. We respond within the timelines the law requires and do not discriminate against you for exercising your rights.
Deleting your data. To request deletion of the personal data we hold about you, email fergus@presterly.com; we will action the request and confirm once it is complete. We also honour the deletion and data requests relayed by Shopify automatically. If your request concerns SMS, replying STOP to any message also removes you from further texts immediately.
If your request concerns customer data that we process on behalf of a merchant, please contact that merchant (the controller) directly; we will assist them in responding.
United States residents. Depending on your state, you may have rights to know, access, correct, delete, and obtain a copy of your personal information, and to opt out of its sale or sharing. We do not sell personal information, and we do not share it for cross-context behavioural advertising. You may exercise these rights, or appeal a decision, by emailing fergus@presterly.com.
11. Security
We protect personal data with encryption in transit, encryption at rest for sensitive fields such as platform credentials and captured phone numbers, access controls, and tenant isolation so that one merchant’s data cannot be accessed by another. Consent is checked in the send pipeline before any message goes out. No method of transmission or storage is perfectly secure, but we work to protect your data and to address issues promptly.
12. Children
Presterly is a business tool and is not directed to children. We do not knowingly collect personal data from anyone under 16.
13. Changes to this policy
We may update this policy from time to time. When we do, we will revise the “Last updated” date at the top of this page, and for material changes we will take reasonable steps to notify merchants.
14. Contact and complaints
Questions or concerns? Email fergus@presterly.com. You also have the right to lodge a complaint with the Irish Data Protection Commission (www.dataprotection.ie).