IntelliJ SFCC

Privacy Policy

How Divetek Inc., the operator of Intellij SFCC, collects, uses, shares, and protects personal data across the website, customer dashboard, plugin, checkout, analytics, and support.

Your privacy at a glance

  • Divetek Inc., the operator of Intellij SFCC, is the controller of your personal data.
  • We collect account, billing, License, usage, support, and, with consent, analytics and advertising data, to run and protect the Products.
  • We use trusted providers, including Kinde for sign-in and Paddle for billing, and we do not sell your personal data.
  • You can download or delete Account data from Dashboard Security settings, or contact [email protected] for broader access, correction, and other privacy requests.

This summary is provided for convenience only and does not replace the full policy below.

Who we are and what this covers

This Privacy Policy explains how Divetek Inc., the developer and operator of Intellij SFCC (“Divetek”, “we”, “us”, or “our”), collects, uses, shares, and protects personal data when you use the IntelliJ SFCC website, customer dashboard, plugin, APIs, and related services (together, the “Products”), or otherwise interact with us. For the purposes of the EU and UK General Data Protection Regulation, Divetek Inc. is the data controller of the personal data described here.

This policy works together with our Cookie Policy and our Terms of Use. If you do not agree with this policy, please do not use the Products.

Information we collect

We collect the following categories of personal data:

Account and profile data.
Name, email address, and authentication identifiers, managed through our identity provider, Kinde, when you register and sign in.
Subscription and billing data.
Plan, transaction references, subscription status, and billing details processed by Paddle, our merchant of record. Full payment card numbers are handled by Paddle and its processors, not stored by us.
License and device data.
License Keys, activation status, Seat and Authorized User counts, and limited device and installation signals used to provision and verify Licenses and to detect sharing, tampering, or piracy.
Product usage data.
Logs and signals about how the website, dashboard, and plugin are used, needed to operate, secure, support, and improve the Products.
Support communications.
The content of messages, support requests, and chat conversations you send us, including through live chat.
Website analytics and advertising data.
With your consent where required, device, browser, page, referral, and interaction data, and advertising and conversion identifiers, collected through the tools described below.

Where the data comes from

We collect personal data directly from you when you register, subscribe, install the Plugin, or contact us; automatically from your use of the Products, including through cookies and similar technologies; and from our service providers, such as Kinde for authentication and Paddle for billing, who pass us the data needed to provide and manage the Products.

How we use data and our legal bases

We use personal data for the purposes below. For users protected by the GDPR, the relevant legal basis under Article 6 is shown for each purpose.

Provide the Products.
To create and manage your Account, deliver the plugin and Services, and provide support. Legal basis: performance of a contract.
Billing and subscriptions.
To process purchases, renewals, taxes, and refunds through Paddle. Legal basis: performance of a contract and compliance with legal obligations such as tax and accounting.
License verification and anti-piracy.
To validate Licenses, enforce Seat and Authorized User limits, and detect sharing, circumvention, fraud, and abuse. Legal basis: our legitimate interest in protecting our intellectual property and our paying customers, and performance of a contract.
Security and reliability.
To keep the Products secure, prevent abuse, and diagnose problems. Legal basis: our legitimate interest in a secure service, and compliance with legal obligations.
Analytics and improvement.
To understand usage and improve the Products and website. Legal basis: consent where required for non-essential analytics, otherwise our legitimate interest.
Marketing and advertising.
To measure campaigns, attribute conversions, and show relevant ads. Legal basis: your consent.

Cookies, analytics, and advertising

We separate required product cookies from optional analytics and advertising cookies. Required cookies keep authentication, dashboard state, preferences, and checkout security working and are not controlled by optional consent. With your consent, we use the following tools:

  • Google Tag Manager, Google Analytics 4, and Google Ads for page and ecommerce measurement, purchase-journey analysis, and conversion attribution, operating under Google consent mode;
  • Meta and LinkedIn for conversion measurement and retargeting using click identifiers and first-party cookies;
  • Crisp to operate live support chat and remember your chat session when you use it.

Server-side conversion events may be sent to Google, Meta, and LinkedIn after checkout so that browser and server events can be deduplicated. Where matching data is used, it is normalized and hashed before transmission, and sensitive data is not sent in plain text. You can grant or withdraw consent at any time. For details and controls, see our Cookie Policy.

How we share data

We do not sell your personal data. We share it only as needed to run the Products and to comply with the law, with the following categories of recipients:

  • Service providers and processors that operate the Products on our behalf, including Kinde (authentication), Paddle (merchant of record and billing), Google, Meta, and LinkedIn (analytics and advertising, with consent), Crisp (support chat), and our hosting and infrastructure providers;
  • Professional advisers and authorities, where required to comply with the law, respond to lawful requests, enforce our Terms, or protect our rights, property, and safety, or those of others;
  • Parties to a business transfer, if we are involved in a merger, acquisition, financing, or sale of assets, in which case data may be transferred subject to this policy.

Where a provider processes personal data on our behalf, it does so under a data processing agreement that limits use to our instructions and requires appropriate safeguards.

International data transfers

We operate internationally and may process personal data in the United States and other countries whose data protection laws may differ from those in your country. Where we transfer personal data out of the European Economic Area or the United Kingdom, we rely on an appropriate transfer mechanism, such as the European Commission Standard Contractual Clauses and the UK addendum, or another lawful safeguard, to protect your data.

Data retention

We keep personal data only for as long as needed for the purposes described in this policy. Account, License, and billing records are retained while your relationship with us is active and afterward as needed for security, accounting, tax, audit, dispute-resolution, and other legal obligations. Marketing attribution data is time-limited and can be revoked. When data is no longer needed, we delete or anonymize it.

If you delete your Account from the dashboard, we delete the related Kinde identity, revoke dashboard and plugin credentials, remove organization memberships where allowed, delete or unlink operational plugin/device records, and anonymize the local Account profile. Paddle billing, subscription, transaction, tax, security, and audit records may be retained or archived where deletion is not available or where retention is required for legal, accounting, fraud-prevention, dispute, or enforcement purposes.

Your privacy rights

Depending on where you live, you may have some or all of the following rights regarding your personal data:

  • access to, and a copy of, the personal data we hold about you;
  • correction of inaccurate or incomplete data;
  • deletion of your data in certain circumstances;
  • restriction of, or objection to, certain processing, including direct marketing;
  • portability of data you provided to us, in a structured, machine-readable format;
  • withdrawal of consent at any time, without affecting prior processing.

Access and data portability

From Dashboard Security settings, you can download a structured, commonly used, machine-readable JSON copy of personal data associated with your Account in our application database. The export includes information about the purposes, sources, recipients, retention, and rights relevant to that data. It excludes authentication secrets, payment credentials, full License Keys, and data whose disclosure could adversely affect another person's rights and freedoms.

The self-service file does not necessarily contain data held only by a processor or every item that may be considered personal data in a broader access request. Contact [email protected] for processor-held data, a broader Article 15 access request, correction, or a portable transfer where technically feasible. We may need to verify your identity before responding.

Account deletion and erasure

You can start self-service Account deletion from Dashboard Security settings. Before the final action is available, we send a time-limited link to the email address on your Account. The link confirms the email request but does not delete anything. You must then remain signed in and type that email address again in the final confirmation window to approve permanent deletion.

Some blockers, such as active subscriptions, sole-owned organizations, or pending orders, must be resolved first. The right to erasure is not absolute: we may retain or restrict records where processing remains necessary to comply with a legal obligation, maintain tax and accounting records, protect security and prevent fraud, or establish, exercise, or defend legal claims. Where full deletion is not required or possible, we limit, archive, or anonymize the data as appropriate.

To exercise broader rights or ask for manual review, contact us at [email protected]. We will respond within the time required by applicable law. If you are in the EEA or the UK, you also have the right to lodge a complaint with your local data protection supervisory authority.

California privacy rights

If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act, gives you specific rights. Over the preceding 12 months, we have collected the categories of personal data described in the “Information we collect” section, from the sources and for the purposes described in this policy, and have disclosed them to the categories of recipients listed above.

Your California rights

  • to know and access the personal data we have collected about you;
  • to request correction or deletion of your personal data;
  • to opt out of the sale or sharing of your personal data;
  • to limit the use and disclosure of sensitive personal data;
  • to not be discriminated against for exercising your rights.

We do not sell personal data and we do not knowingly share it for cross-context behavioral advertising in a way that requires an opt-out beyond the consent controls described in our Cookie Policy. To exercise your California rights, contact us at [email protected].

How we protect data

We use appropriate technical and organizational measures to protect personal data against unauthorized access, loss, misuse, and alteration, including access controls, encryption in transit, and the use of reputable infrastructure and payment providers. No method of transmission or storage is completely secure, so we cannot guarantee absolute security, but we work to protect your data and to notify you and the relevant authorities of a breach where required by law.

Children

The Products are intended for professional and business use and are not directed to children. We do not knowingly collect personal data from anyone under the age of 16. If you believe a child has provided us with personal data, please contact us so that we can delete it.

Changes to this policy

We may update this Privacy Policy as the Products, our practices, and the law evolve. When we make material changes, we will revise the “Updated” date at the top of this page and, where appropriate, provide additional notice. Your continued use of the Products after the changes take effect means you accept the updated policy.

Contact us

The data controller is Divetek Inc., the operator of Intellij SFCC. If you have any questions about this Privacy Policy or how we handle your personal data, or if you wish to exercise your rights, contact us at [email protected].

This Privacy Policy was last updated on July 13, 2026. For any privacy request, contact [email protected].