SMB Shield EU

Combined audit checks for EU small businesses.

Privacy notice

How SMB Shield EU handles audit request data

This privacy notice explains the practical data handling model for SMB Shield EU, a website digital risk audit service for European small businesses, e-commerce owners and agencies.

Operator and contact

SMB Shield EU

Contact: hello@smbshield.eu

This page is informational and is not legal advice. It may be updated as the MVP service evolves.

Data collected

Information used to provide the audit service

The service collects only the data needed to receive a request, run observable website checks, prepare a report and maintain the application.

  • Business name
  • Email address
  • Website URL submitted for review
  • Optional country, e-commerce platform and message details
  • Website scan results from observable technical and content signals
  • Generated reports and report recommendations
  • Technical logs needed to operate, secure and debug the service

Why this data is used

Data is used for service delivery, support and security. It is not used to claim certification or legal compliance.

  • Process website audit requests
  • Run website digital risk checks
  • Generate practical reports and findings
  • Contact the requester about the audit or report
  • Maintain service security, reliability and abuse prevention

Data minimization

Request forms and reports are designed to avoid unnecessary sensitive information.

  • SMB Shield EU does not ask for website login credentials.
  • SMB Shield EU does not store payment card data.
  • SMB Shield EU does not request sensitive personal documents.
  • Free-text fields should only include information needed to understand the audit request.
Service providers

Third-party services used at a high level

SMB Shield EU relies on infrastructure and technical check providers to operate the service. These services may process data needed for hosting, storage, authentication, scanning or payment handling.

Supabase

Database and authentication services used to store requests, scans and admin access data.

Vercel

Hosting and application infrastructure for the public site and application routes.

Google PageSpeed Insights

Technical checks for performance, accessibility, SEO and best-practice signals.

Future or manual payment provider

Payment handling may use manual invoices, payment links or a payment provider during MVP testing.

Retention and deletion

During MVP testing, audit requests, scan results and reports are kept only as long as needed for service delivery, support, security and reasonable business records. You can request deletion by contacting hello@smbshield.eu.

Limitations

This notice may be updated as SMB Shield EU evolves, including when payment processing, public report sharing or monitoring features are added. This page is informational and is not legal advice.