Cooloff is a Wix app that adds the withdrawal function required by Article 11a of Directive 2011/83/EU to an online shop, and keeps a record of every withdrawal declaration the shop receives. This policy explains what personal data the app handles, where that data lives, and who is responsible for it.
Cooloff is installed by a merchant onto their own website. The merchant is the data controller for everything a consumer submits through the withdrawal form: it is their contract, their customer, and their legal duty to acknowledge the withdrawal and keep the record.
Eitan Plaks, Rosh HaAyin, Israel, develops and maintains the app and acts as a processor on the merchant's behalf. Contact: eitanp214@gmail.com.
Only what the withdrawal function needs, and only when a consumer chooses to submit the form:
| Data | Why |
|---|---|
| Name | Identifies who is withdrawing, as the declaration requires. |
| Email address | The address the acknowledgement of receipt is sent to. |
| Order or contract reference, as typed | Identifies the contract being withdrawn from. |
| Optional message | Free text the consumer chooses to add. |
| Date and time of receipt | Article 11a(4) requires the exact moment to be confirmed. |
| Page address and language | Shows where the declaration was made and in which language. |
| Matched order details, when found | Order number, date, totals and payment or fulfilment status, so the merchant can act on the withdrawal. |
The app does not ask for, and has no use for, payment details, identity documents, or any special category of data.
Records are written to a data collection inside the merchant's own Wix site, on Wix infrastructure. The developer does not run a separate database, does not copy records out of the merchant's site, and does not build a profile of consumers across shops. Uninstalling the app leaves the records with the merchant, which is deliberate: they are the trader's evidence that the withdrawal was received and acknowledged.
No other third party receives this data. It is not sold, rented, or used for advertising.
Cooloff sets no cookies. It does not use local storage, session storage, analytics, advertising tags, fingerprinting, or any cross-site tracking. The button and form on the site run without storing anything in the visitor's browser.
Retention is the merchant's decision, and it is bound by their own record-keeping duties. In Germany, for example, commercial records are commonly retained for ten years under §257 HGB and §147 AO. The merchant can delete an individual record from their site at any time.
Consumers in the EU and the UK have the right to access, correct, delete, restrict and port their data, and to object to its processing. Because the merchant is the controller, these requests should be addressed to the shop the withdrawal was sent to. If you contact the developer instead, the request will be passed to that merchant and supported without delay. You may also complain to your national supervisory authority.
The developer is based in Israel, which the European Commission recognises as providing an adequate level of data protection. Wix and Resend operate their own infrastructure and publish their own transfer safeguards.
All traffic runs over HTTPS. The app's backend endpoints check the caller's identity before returning any record, and withdrawal records are readable only through the merchant's own dashboard. The mail provider key is stored as a server-side secret and is never exposed to the browser.
If this policy changes materially, the date at the top of the page changes with it, and the change is described in the app's App Market listing.