Legal
Privacy Policy
What we collect, why we process it, who we share it with, and the rights you have.
Last updated: 2 October 2026
1. Who controls your data
The company operates from the United States and also serves clients in the European Union, so the GDPR applies to that work as well.
Maxano Solutions is a brand of Stella eCommerce LLC, a limited liability company formed in Wyoming, United States (EIN 30-1276173), with its registered address at 30 N Gould St, STE 4000, Sheridan, WY 82801, United States. Stella eCommerce LLC is the data controller. In this policy, “we” and “Maxano” mean that company.
For anything about privacy, write to [email protected].
2. What we collect
This site has no database. When you send the contact form, our server passes your name, email address, the service you chose and your message to Resend, our email delivery provider, which delivers it to our mailbox. Nothing is stored on the site itself. To stop abuse, the server briefly remembers the IP address a form was sent from — in memory only, for at most one hour.
The data we may hold about you:
| Type of data | Where it comes from |
|---|---|
| Name, email address and the content of your message | An enquiry you send through the form or straight to our address |
| Contract and invoicing details: company name, address, tax number, contact person, phone number | You give them to us when you become a client |
| Payment details: amount, currency, date, transaction status, last four digits of the card | Stripe, our payment processor. We never see or store the full card number. |
| Server logs: IP address, time of request, browser type | Our hosting provider, automatically, to run and protect the site |
| IP address of a contact-form submission | Our server, to limit repeated submissions; kept in memory for at most one hour |
| Language cookie | Your browser, so we remember whether you want the Montenegrin or the English version |
| Data inside the projects we build for clients | The client entrusts it to us; there we are a processor, not a controller (see section 10) |
We have no analytics, no advertising tools and we do not track visitors around the site. The details are in the Cookie Policy.
3. Why we process data, and on what legal basis
The GDPR requires a legal basis for each purpose. Here they are:
| Purpose | Data | Legal basis |
|---|---|---|
| Answering your enquiry and preparing a quote | Name, email, message | Steps before entering a contract, at your request — Article 6(1)(b) GDPR |
| Performing the contract and delivering the work | Contract details, contact details, correspondence | Performance of a contract — Article 6(1)(b) |
| Invoicing and accounting | Invoice data and payment records | Legal obligation — Article 6(1)(c) |
| Keeping the site working and secure | Server logs | Our legitimate interest in a site that runs and is not abused — Article 6(1)(f) |
| Protecting the contact form from spam | IP address of a submission | Our legitimate interest in a form that is not abused — Article 6(1)(f) |
| Remembering your language | Language cookie | Necessary for a service you asked for yourself — Article 6(1)(f); the cookie is strictly necessary |
| Bringing or defending legal claims | Contracts, correspondence, invoices | Legitimate interest — Article 6(1)(f) |
We do not send marketing without your consent. If we ever start a newsletter, we will ask separately and you will be able to withdraw at any time.
4. Payments
Payments are processed by Stripe. When you pay by card, you enter your card details directly with Stripe, on their payment form or page. We never see, transmit or store the full card number, the expiry date or the security code.
From Stripe we receive only what accounting and support require: the amount, currency, date, payment status, the payer's name and the last four digits of the card. Stripe acts as an independent controller for the part of the processing it carries out to prevent fraud and meet its own legal obligations. Their privacy policy is at stripe.com/privacy.
5. Who we share data with
We do not sell data and we do not give it to anyone for advertising. We share it only with the suppliers we need in order to work, each under a contract that binds them to confidentiality:
| Recipient | Why | Where they process it |
|---|---|---|
| Stripe | Processing payments and issuing invoices | United States and EU |
| GoDaddy Operating Company, LLC | Hosting the site, server logs | Europe (our hosting region); GoDaddy is a US company |
| Resend (Plus Five Five, Inc.) | Delivering contact-form messages to our mailbox | United States |
| Our email hosting provider | Our business mailbox, where your enquiries arrive | United States or EU |
| Our accountant | Invoices and statutory obligations | United States |
| Public authorities | Only where the law requires it | United States and other competent jurisdictions |
This site carries no analytics, no ad networks, no social media buttons and no content embedded from other services. Fonts are served from our own server, so your browser makes no request to Google or any third party while you read this page. The moving metal at the top of the home page is drawn in your browser by our own code and sends nothing anywhere.
6. Transfers from the EU to the United States
We are a US company, so the data we process sits in the United States. If you are in the European Union, that means your data leaves the EU.
When you send us data yourself — writing to us, or becoming a client — we receive it directly from you. When an EU client entrusts us with data, that transfer relies on the European Commission's Standard Contractual Clauses.
You can ask us for a copy of the safeguards we apply at [email protected].
7. How long we keep data
| Data | Retention |
|---|---|
| Enquiries that led nowhere | 12 months after the last message, then deleted |
| Project correspondence and documentation | For the engagement and 5 years afterwards, for possible contractual claims |
| Invoices and accounting records | 7 years |
| Payment records held by Stripe | According to Stripe's own retention periods, which we do not control |
| Server logs | According to GoDaddy's own retention periods, which we do not control |
| IP address of a form submission | At most one hour, in memory only |
| Contact-form messages held by Resend | 30 days |
| Language cookie | 12 months, or until you delete it |
8. Your rights
If the GDPR applies to you, because you are in the European Union or the European Economic Area, you have the right to:
- get a copy of the data we hold about you
- have inaccurate data corrected
- have data deleted when there is no longer a basis for keeping it
- have processing restricted while something is being sorted out
- receive your data in a format you can take to another provider
- object to processing based on our legitimate interest
- withdraw consent where processing rests on consent, without affecting what came before
Send your request to our privacy address. We answer within 30 days. There is no charge, unless requests are clearly unfounded or repetitive.
If our answer does not satisfy you, you can complain to the data protection authority where you live or work. US residents can also contact their state Attorney General's office.
9. If you live in the United States
Several US state laws — California (CCPA and CPRA), Virginia, Colorado and others — give residents specific rights. If you are one of them, you have the right to know what data we hold, to ask for a copy or for deletion, and not to be treated worse for asking.
We do not sell personal information and we do not share it for cross-context behavioural advertising, in the sense those laws use. The site carries no advertising cookies, pixels or trackers, so there is no such data to share. We do not process sensitive categories of data to draw inferences about you.
10. When we are a processor rather than a controller
When we build automation, a SaaS product or a billing system for a client, we often process the personal data of that client's own customers. In that relationship the client decides why the data is processed and is the controller; we act on their instructions as a processor.
For that work we sign a Data Processing Agreement, which we send on request.
11. Children
Our services are for businesses and adults. The site is not directed at children under 16 and we do not knowingly collect their data. If we learn that we have, we delete it.
12. Security
The site is served over HTTPS. Our mailbox and tools are protected with passwords and two-factor sign-in, and client data reaches only the people who need it for the work.
No system is perfectly secure. If a breach puts you at risk, we notify the supervisory authority within 72 hours and tell you without undue delay where the risk is high.
13. Changes to this policy
When we change this policy we change the date at the top. If a change is significant, we email active clients.
14. Contact
[email protected]. Postal address: Stella eCommerce LLC, 30 N Gould St, STE 4000, Sheridan, WY 82801, United States.