GDPR compliance built in, not bolted on.
Overvio treats GDPR as part of the product, not paperwork you handle on the side. It records provable consent the moment a shopper gives it, refuses to send when consent is not clean, and carries out a single request to be forgotten across every place that shopper's data lives. The compliance work an EU store dreads is done as the marketing runs, not bolted on afterward.
Built for the European market Overvio serves: WooCommerce, custom-built, and Shopify stores alike.
See how consent is captured on-siteOne shopper
Consent given, and on record.
- What she agreed to
- Recorded the moment she gave it
Now you can email her knowing you are allowed to, and prove it if you are ever asked.
And if she changes her mind
One request, and she is forgotten everywhere.
Erased across every place her data lived. Opt-outs stay opted out.
Consent, kept honest from collection to erasure.
Good privacy is not a policy page nobody reads. It is what the tool actually does with a shopper's data. From the moment consent is given to the moment it is withdrawn, here is how Overvio keeps you on the right side of the line, piece by piece.
Consent is captured the moment it is given.
When a shopper subscribes through a popup, at checkout, wherever, Overvio records exactly what she agreed to and keeps it. Not a vague box ticked somewhere, but provable consent tied to the moment she gave it. If you are ever asked to show it, it is there.
Capture consent you can proveConsent record
She agreed, and it is on file.
- What she agreed to receive
- Recorded at the moment she gave it
- Ready to show on request
If consent is not clean, the send does not go.
Overvio checks every send against who is actually allowed to receive it, and holds back anyone whose consent is missing or unclear. It would rather not send at all than send where it should not. You do not have to police the list yourself; the tool refuses on your behalf.
A send, checked first
Consent unclear, so this one did not go.
Refused rather than risked
One request to be forgotten, carried out everywhere.
When a shopper asks to be erased, you do not go hunting through tools and spreadsheets. One request in Overvio clears her, on its own, from every place her data lived: the list, the history, the reporting. What used to be an afternoon of dread is a single action.
One erasure request
- The mailing list
- The order history
- The reporting
cleared everywhere, on its own
Opt out once, and it sticks.
Anyone who unsubscribes or asks to be left alone is removed from every list, for good, everywhere Overvio sends. There is one place that remembers a no, not five lists that disagree, so a person who said no never hears from you again by accident.
Opted out
Removed for good
Off every list · never emailed again by accident
Asked what you hold? It is all in one place.
A shopper's data does not sit scattered across four tools. In Overvio it lives in one place. So when someone asks what you have about them, you can find it and answer without a scramble or an afternoon of exporting by hand. The job is easier because the data was never split up to begin with.
A data request
All in one place, easy to find and hand over.
One place · no hunting across tools
Overvio only sends where you are allowed to.
The most honest thing a marketing tool can do is refuse to send. Overvio draws a hard line between the shoppers you may write to and the ones you may not, and it will not cross it.
Asked and allowed
She gave clean consent, and it is on record. Overvio may email her.
Provable consent, kept with the moment it was given. These are the only people your campaigns can reach.
Not asked, or opted out
No clean consent, or she asked to be left alone.
Overvio will not email her. The message is refused rather than risked. Quietly set aside, never crossed.
Every send is checked against that line first. If consent is not clean, the message does not go: no exceptions, no overrides.
See how consent is captured on-siteEverything GDPR asks of your marketing, handled.
| What you get | What it does |
|---|---|
| Provable consent | Records exactly what each shopper agreed to, the moment they agreed, and keeps it ready to show. |
| Sending that checks first | Checks every send against who is allowed to receive it and holds back anyone whose consent is not clean. |
| One-request erasure | From a single request, clears a shopper from every place their data lived: list, history, reporting. |
| One do-not-email list | Anyone who opts out is removed everywhere Overvio sends, for good, so a no is never overridden by accident. |
| Data kept in one place | Keeps each shopper's data in one place, so when you are asked what you hold, you can find it and answer without a scramble. |
| Consent at capture | Every popup and signup asks for consent the proper way, so the list you grow is one you are allowed to email. |
| Built for the EU | Made for the European market Overvio serves, where consent and erasure are the law, not a nice-to-have. |
Compliance is one part of a connected system, not a plugin bolted on the side.
The questions EU owners actually ask.
Straight answers about consent, erasure, and where Overvio's job ends and yours begins. Anything else, ask us directly, no demo required.
It handles the parts a marketing tool is responsible for: provable consent, sends that stop themselves when consent is not clean, erasure, and clean opt-outs. So those are done properly and on their own. Your own duties as a business still stand, but the marketing side, the part most stores get wrong, is looked after.
Yes. Overvio records what each shopper agreed to at the moment they gave consent and keeps it, so if you are ever asked to show consent, it is there, not reconstructed after the fact.
One request in Overvio clears that shopper, on its own, from everywhere their data lived: the list, the history, the reporting. You do not have to hunt through separate tools to be sure it is really gone.
Overvio is built so that is hard to do. Every send is checked against who is actually allowed to receive it, and anyone without clean consent is held back. It refuses to send rather than risk it.
In Europe, and we will name every place. The application, its main database and its cache run on Hetzner servers in Germany. The database holding cart, contact and analytics records runs on DigitalOcean in Frankfurt. Outbound email and stored files go through Amazon Web Services, also in Frankfurt. Nothing leaves the EU.
Three companies process it on our behalf, and we would rather name them than be asked: Hetzner, a German company in a German data centre; DigitalOcean, a US company serving from Frankfurt; and Amazon Web Services, a US company in its Frankfurt region. Amazon sends the mail, so it receives the address and the message itself. We also use Bouncer, a European vendor, to check whether an address can be delivered to, and it receives the address alone.
As long as each kind of record needs, and not a day longer. Popup visitor records last 30 days. Cart events, email opens and clicks last 90 days. Bounces, unsubscribes and contact history last a year. Proof that a shopper agreed to be emailed is kept for ten years, because we have to be able to show it. None of that is policy wording: it is one list every part of Overvio must obey, and our own build fails if any part of it drifts.
No. Overvio gives you the tools to handle consent, erasure, and clean opt-outs properly, but it does not replace your own legal responsibilities or advice from someone who knows your business. What it does is make the mechanical side something you no longer manage by hand.
Compliance handled, not left to chance.
Connect your store and let Overvio record consent, refuse the sends it should refuse, and carry out erasure on its own: the compliance work an EU store dreads, done as your marketing runs.
Prefer to ask something first? Ask a question

