1. Name and Contact Data of the Controller

This privacy policy applies to the data processing by the Hyvä Pocket iOS app:
Controller: Hyvä Themes B.V.
Dutch CoC: 80794343
VAT id: NL861802329B01
Directors: Willem Wigman
Address: Kloosterweg 1, 6412CN, Heerlen, The Netherlands
Email: info@hyva.io.

2. The Short Version

Hyvä Pocket is built on a simple principle: your data is yours, full stop.

  • We never see your store data.
  • Nothing is sent to Hyvä Themes B.V. or any third party from your normal use of the app.
  • Everything stays on your device.
  • The app only reads data — it can never change anything in your store.

3. How the App Connects to Your Store

Hyvä Pocket connects directly from your device to your Magento store. For Magento traffic there is no server in between — no relay, no analytics backend. Every Magento API call goes straight from your iPhone or iPad to your store URL over HTTPS. Think of it as a private window into your store that only you can see.

4. Optional Mollie Integration

If you connect a Mollie account, the app talks to Mollie's API at api.mollie.com directly from your device to fetch your payments, refunds and chargebacks. Hyvä Themes B.V. never sees that data.

Two authentication options are supported:

  • API keys — you paste your Mollie live and/or test key into the app. Keys are stored in the iOS Keychain on your device and are sent only to api.mollie.com.
  • Connect with Mollie (OAuth) — you sign in to Mollie in a secure system browser. Mollie sends an authorization code back to the app. Access and refresh tokens are stored in the iOS Keychain on your device.

All Mollie API requests use read-only scopes (payments.read, refunds.read, profiles.read, balances.read, balance-reports.read, settlements.read). The app cannot create, capture or refund payments through Mollie.

a) About the Mollie OAuth Proxy

Mollie's OAuth design requires a client_secret at the token-exchange step. Apple's guidance — and Mollie's own — is not to ship that secret inside a mobile app, because anyone could extract it from the binary.

When you tap Connect with Mollie, the authorization code is sent through a small proxy at www.hyva.io/pocket-oauth-token. The proxy adds the client_secret server-side and forwards the request to Mollie's token endpoint. The fresh tokens are returned to your device and stored in the iOS Keychain.

What the proxy does and doesn't do:

  • It is only used for the initial token exchange and for refreshing expired tokens — not for ongoing payment data, which goes from your device straight to api.mollie.com.
  • It adds the client_secret Mollie requires, nothing more — it doesn't read your Mollie data or your tokens after forwarding.
  • No request bodies, tokens or authorization codes are logged or stored.
  • No tracking, analytics or third-party SDKs run on the proxy.

5. What Is Stored on Your Device

  • Your Magento API token (used to authenticate with your store).
  • Your admin username, if you use the Admin Login method. Your password is never stored.
  • Your Mollie credentials when configured — either API keys or OAuth access and refresh tokens. These live in the iOS Keychain.
  • Your store URL and display name.
  • App preferences (currency, time zone, lock settings).
  • A small cache of the recent rows in your list views — orders, customers, products, dashboard totals and your Mollie balance — so the app stays snappy and works briefly offline. The cache is wiped when you disconnect a store or delete the app.

All of this lives in your device's local storage and is never transmitted anywhere except to your own Magento store and (if configured) Mollie's API.

6. What We Do Not Store

  • Your admin password — it is used once to obtain a token, then immediately discarded.
  • Individual payment details, card numbers or customer bank details — these are fetched live when you open a transaction and are never kept around.
  • Order, invoice or credit-memo line items — fetched fresh each time you open a detail view.
  • Analytics, usage data or crash reports — we don't track anything.

7. Network, Cookies and Third Parties

The app uses an ephemeral (private) networking session. This means:

  • No cookies are stored between sessions.
  • No cross-site tracking is possible.
  • No background network calls are made except optional new-order checks, which you control from the app settings.

The external services the app contacts besides your own store are:

  • Mollie (api.mollie.com) — only when you have configured the Mollie integration, to fetch your own payments, refunds and chargebacks.
  • Hyvä OAuth proxy (www.hyva.io/pocket-oauth-token) — only during the Mollie “Connect” flow and on token refresh, to keep Mollie's client_secret off your device.
  • YouTube — video embeds in the in-app news feed use the privacy-enhanced youtube-nocookie.com domain, which prevents YouTube from storing cookies or tracking your browsing. If you choose to open a video on YouTube directly, it uses the regular youtube.com domain.
  • ipinfo.io — when you tap an IP address in order details, it opens ipinfo.io in an in-app browser to show the location and ISP. No data is sent automatically; it only loads when you explicitly tap.

8. Read-Only by Design

The app uses Magento's REST API and Mollie's API with read-only access. It physically cannot create, modify or delete any data — no orders, no products, no customer records, no configuration changes, no Mollie payments or refunds. This isn't just a promise; it is how the API permissions are set up.

You can safely hand this app to anyone on your team without worrying about accidental changes.

9. Removing Your Data

Delete the app and everything goes with it. There are no accounts to close, no servers to contact and no data to request. Uninstalling the app removes every credential, token and cache it ever held on your device.

10. Rights of the Individuals Affected

You have the right to obtain from us:

  • access to your personal data (GDPR Art 15),
  • the rectification of your personal data (GDPR Art 16),
  • the erasure of your personal data (GDPR Art 17),
  • the restriction of the processing of your personal data (GDPR Art 18) and
  • the portability of your personal data (GDPR Art 20).

You also have the right to revoke any consent you have given at any time in accordance with GDPR Art 7(3). This means we are no longer allowed to continue the processing of the data which was based on said consent.

You also have the right to lodge a complaint with a supervisory authority in accordance with GDPR Art 77 if you believe that the processing of your data was unlawful. Usually you can direct your complaint to the supervisory authority of your usual residence or workplace or our location.

To exercise any of these rights, send us an email at info@hyva.io.

11. Data Security

All connections to your Magento store and to Mollie's API are made over HTTPS using the highest encryption level supported by iOS. Credentials and OAuth tokens are stored in the iOS Keychain — the system-level secure storage that protects them with the device's hardware security and the user's passcode or biometric lock.

We use appropriate technical and organizational security measures to secure your data from accidental or intentional manipulation, partial or complete loss, destruction or unauthorized access by third parties. Our security measures are continuously adjusted to keep pace with technological advancements.

12. Actuality and Change of This Privacy Policy

This privacy policy is currently valid and was last updated in May 2026.

As Hyvä Pocket evolves, or due to changed legal or official requirements, it may be necessary to update this policy. The current version is always available at this URL for you to view and print.

Get Hyvä for your store

Build your ideal setup in just a few clicks, on your terms.

Step of 2 Your store Your setup

This domain will be linked to your Hyvä licenses.

Please enter a valid domain (e.g. mystore.com)

Recommended
Hyvä Commerce

Everything you need to build your store, your way.

Hyvä Commerce €3,000/year
Hyvä Theme, Checkout and UI in one complete setup
Fast and flexible content management with Hyvä CMS
Improved admin experience, built for speed and ease
Tools for performance, scalability and control
Upgrade to Hyvä Enterprise for full Adobe Commerce support (includes Hyvä Commerce) /year
Learn more
Hyvä Commerce Recommended
Build your own
Build your own
Hyvä Theme
Hyvä Theme Included with all Hyvä products.
Free
Hyvä UI
Hyvä UI

Copy. Paste. Done. Enhance your design and coding workflow with a library of modern, reusable components that make building beautiful, consistent pages effortless.

€250
Hyvä Checkout
Hyvä Checkout

Faster checkout. Happier customers. Reduce friction and boost conversions with a lightning-fast, fully customisable checkout that's easy to integrate.

€1,000
Choose your Update & Support plan
Hyvä Enterprise
Hyvä Enterprise

Full Adobe Commerce support, including Hyvä Commerce. Unlock Adobe Sensei capabilities, content staging, B2B functionality, loyalty features and more.

€7,500/year
Choose your Update & Support plan
Total: