Privacy Policy
1. Introduction
This Privacy Policy explains how Shoptimio ("Shoptimio", "we", "us") processes personal data when you visit our website, sign up for an account, or use the Shoptimio platform and its integrations. We process personal data in accordance with the EU General Data Protection Regulation (GDPR, Regulation 2016/679), the Spanish LOPDGDD 3/2018, and applicable local law.
2. Data Controller
The data controller for the processing described in this policy is Shoptimio. For any data-protection enquiry you can reach us at [email protected].
3. Categories of Personal Data We Process
- Account data: name, email address, password hash, preferred language, role within the store.
- Store and integration data: Shopify store domain, store identifier, connection tokens, the merchant's catalogue and analytics drawn from connected APIs:
- Shopify
- Amazon
- Billing data: the subscription plan, billing status, and invoice records returned by Shopify Billing. We do not store full payment card numbers.
- Usage data: log records, IP address, device and browser metadata, pages visited, features used, error reports.
- Communications: messages you send us by email, in-app support requests, and feedback.
4. Purposes and Legal Basis
- Providing the service (account creation, store connection, dashboards, AI suggestions) — Art. 6(1)(b) GDPR, performance of a contract.
- Billing and accounting — Art. 6(1)(b) and 6(1)(c) GDPR, contract performance and legal obligation.
- Security, fraud prevention, abuse monitoring — Art. 6(1)(f) GDPR, legitimate interest in keeping the platform safe.
- Product analytics and improvement — Art. 6(1)(a) GDPR, your consent given via the cookie banner.
- Service communications (transactional emails, policy updates) — Art. 6(1)(b) and 6(1)(f) GDPR.
- Marketing communications, where applicable — Art. 6(1)(a) GDPR, consent that can be withdrawn at any time.
5. Sources of Data
Most data is collected directly from you when you sign up or use the platform. When you connect a Shopify store or another integration, additional data is received from that provider on your instruction, within the permissions granted by the connected account.
6. Recipients and Processors
We share personal data only with processors that act on our documented instructions and offer appropriate safeguards:
- Shopify — store authentication, billing, app distribution.
- Cloud hosting and infrastructure providers — running the platform and the database.
- Email delivery providers — sending transactional and verification emails.
- Analytics providers — only where you have given consent (see our Cookie Policy).
- AI providers — when you use AI features, prompts and the data needed to answer them are sent to the model provider under a data-processing agreement; we do not allow them to use your data to train their models.
We do not sell personal data and do not share it for third-party advertising.
7. International Transfers
Where a processor is located outside the European Economic Area, transfers are made under the European Commission's Standard Contractual Clauses (2021/914) and, where relevant, supplementary technical and organisational measures. A copy of the safeguards is available on request.
8. Retention
- Account and store data: for as long as the account is active, then deleted within 90 days of closure unless a longer period is required by law.
- Billing records: 10 years (statutory accounting obligation).
- Security logs: up to 12 months.
- Support correspondence: up to 24 months after the case is closed.
9. Your Rights
Under the GDPR you have the right to access your personal data, request rectification or erasure, restrict or object to processing, and request portability. Where processing is based on consent, you can withdraw that consent at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, email [email protected]. You also have the right to lodge a complaint with a supervisory authority — in Spain, the Agencia Española de Protección de Datos (www.aepd.es).
10. Security
We apply industry-standard technical and organisational measures: TLS in transit, encryption at rest for sensitive fields, role-based access control, audit logging, and regular review of supplier security. No system is perfectly secure; if a breach affects your data and is likely to result in a high risk to your rights, we will notify you and the competent authority in line with Art. 33–34 GDPR.
11. Children
Shoptimio is a B2B platform and is not directed at children under 16. We do not knowingly collect personal data from children.
12. Cookies
How we use cookies and similar technologies is described in our Cookie Policy.
13. Updates
We may update this policy from time to time. We will notify you at your registered email of any material change. The current version is always available at shoptimio.com/privacy-policy.
14. Google API Services — Limited Use
Shoptimio's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. The use of raw or derived user data received from Google Workspace APIs adheres to the Google User Data Policy, including the Limited Use requirements.
Where Shoptimio uses artificial-intelligence or machine-learning models, or integrates with third-party AI/ML services, we do not use, transfer, or sell Google user data — whether raw, aggregated, or derived — to develop, train, or improve foundational or generalised AI/ML models. Google user data is used solely to provide and improve the user-facing features you request, and is never shared with AI/ML providers for model-training purposes.
15. Contact
For questions about this privacy policy or to exercise your rights: [email protected]