Legal

Privacy Policy

This policy explains what personal data GNShift collects, how we use it, and the choices you have. We keep it plain and specific - the same standard we apply to client work.

Last updated July 2026

Last updated July 2026

Who we are

GNShift is a senior B2B product and commerce studio based in Skopje, North Macedonia. We design, build, and maintain Webflow marketing sites and Medusa JS storefronts for scaling SaaS and D2C brands in Europe and the United States, typically on fixed monthly retainers.

For privacy questions, contact us at hello@gnshift.com.

What this policy covers

This policy explains how we collect, use, store, and protect personal data when you visit gnshift.com, subscribe to our updates, submit a contact or brief form, book a call, or otherwise interact with us as a prospective client, partner, or site visitor.

It does not cover client projects we deliver under separate agreements. Where we process data on a client’s behalf, that work is governed by the relevant contract and data processing terms.

Data we collect

We collect only what we need to respond, deliver services, and improve the site. Depending on how you interact with us, this may include:

Information you provide: name, work email, company, role, phone number, project details, budget range, and any files or messages you send through forms or email.

Automatic technical data: IP address, browser type, device information, pages viewed, referring URL, and approximate location derived from IP.

Communications: records of emails, call notes, and support messages when you contact us.

We do not intentionally collect special categories of personal data. Please do not send sensitive information unless we explicitly ask for it in a client engagement.

How we use your data

We use personal data to:

Respond to inquiries and evaluate fit for a retainer or project.
Schedule and conduct discovery calls.
Prepare proposals, statements of work, and contracts.
Deliver and support services for clients.
Send operational messages such as scheduling updates or policy changes.
Send marketing or insight emails where you have opted in or where permitted by law.
Maintain site security, diagnose issues, and understand aggregate usage.
Meet legal, tax, and accounting obligations.

We do not sell personal data.

Legal bases for processing (GDPR)

If you are in the European Economic Area, UK, or Switzerland, we process personal data on one or more of the following bases:

Consent - for optional cookies, analytics where required, and marketing emails you subscribe to.
Contract - to take steps at your request before entering a contract, and to perform client agreements.
Legitimate interests - to operate and secure our website, understand demand for our services, and communicate with business contacts in a proportionate way. You may object to processing based on legitimate interests.
Legal obligation - where we must retain or disclose information to comply with applicable law.

How we share data

We share personal data only with trusted processors that help us run the business, such as hosting, email, form handling, scheduling, analytics, and accounting tools. These providers may process data in the EU, UK, US, or other countries with appropriate safeguards where required.

We may also disclose information if required by law, to protect our rights, or in connection with a merger, acquisition, or sale of assets - always subject to appropriate confidentiality measures.

International transfers

GNShift is based in North Macedonia. Some of our tools and subprocessors are located outside your country. Where GDPR applies, we rely on appropriate transfer mechanisms such as Standard Contractual Clauses or equivalent safeguards when data is transferred internationally.

Retention

We keep personal data only as long as needed for the purposes above. Inquiry and sales records are typically retained for up to three years unless a longer period is required for an active client relationship, dispute, or legal obligation. Analytics and server logs are retained for shorter periods consistent with security and troubleshooting needs.

Your rights

Depending on where you live, you may have the right to access, correct, delete, restrict, or object to certain processing, and to receive a portable copy of data you provided. Where processing is based on consent, you may withdraw consent at any time without affecting prior lawful processing.

You also have the right to lodge a complaint with your local supervisory authority. In North Macedonia, the relevant authority is the Agency for Personal Data Protection.

To exercise your rights, email hello@gnshift.com. We may need to verify your identity before responding.

Cookies and analytics

Our site may use essential cookies required for security and basic functionality. We may also use analytics tools to understand traffic in aggregate. Where required, we will ask for consent before setting non-essential cookies.

You can control cookies through your browser settings. Blocking some cookies may affect site functionality.

Security

We apply reasonable technical and organizational measures to protect personal data, including access controls, encrypted connections, and vendor review. No online service can guarantee absolute security, but we treat client and visitor data with the same care we apply to production systems.

Changes to this policy

We may update this policy from time to time. When we make material changes, we will post the revised version on this page and update the “Last updated” date above.

Contact

GNShift
Skopje, North Macedonia
hello@gnshift.com