Política de Privacidad

Tu privacidad, nuestra responsabilidad

Shopimize atiende a comerciantes de todo el mundo. Nos tomamos la privacidad de los datos muy en serio y estamos comprometidos con la transparencia total sobre cómo recopilamos, usamos y protegemos tus datos.

Nunca vendemos tus datos
Conforme con GDPR y CCPA
Almacenamiento seguro de datos
Transparencia total

Última actualización: 19 de febrero de 2026

Resumen

Shopimize ("we", "our", or "us") is an e-commerce analytics platform that helps merchants understand their true profitability. We are committed to protecting your personal data and operating in full compliance with applicable data protection laws worldwide, including the General Data Protection Regulation (GDPR) for EEA users, the UK GDPR, and the California Consumer Privacy Act (CCPA) for California residents.

This Privacy Policy explains what data we collect when you use Shopimize, why we collect it, how we use it, and your rights with respect to that data. It applies to our marketing website at shopimize.com and our SaaS application at app.shopimize.com.

Shopimize is operated by a company registered in France. We serve merchants globally and apply strong data privacy standards to all users regardless of location. We are not in the business of selling data — your information is used solely to operate and improve the Shopimize platform.

Datos que recopilamos

We collect two types of information: data you provide to us directly, and data collected automatically as you use the Service.

Account data (provided by you)

  • Email address — used for login, billing notifications, and support communications
  • Name — displayed in your account profile and on team invitations
  • Password — stored as a bcrypt hash; we never store or transmit passwords in plain text
  • Billing information — payment details are handled entirely by Stripe; we never receive or store your card number
  • Company name and preferred language (EN/FR) — optional, used to personalise your experience

Technical & usage data (collected automatically)

  • IP address and approximate geolocation (country and city)
  • Browser type, version, and operating system
  • Pages visited, features used, and time spent in the application
  • Error logs and crash reports to help us debug issues
  • Authentication tokens and session identifiers

Datos de tienda y pedidos

To provide its core analytics features, Shopimize connects to your e-commerce store (Shopify, WooCommerce, PrestaShop, or Wix) via OAuth or API key. Through this connection we import and process the following data from your store:

  • Orders — order ID, date, status, line items, quantities, prices, discounts, and shipping cost
  • Products — product names, SKUs, variants, and sale prices
  • Customer identifiers — anonymised IDs for cohort and LTV analysis (we do not import customer names or addresses unless you explicitly configure this)
  • Ad spend — campaign names, impressions, clicks, and spend from Google Ads, Meta Ads, TikTok Ads, and Pinterest Ads
  • Payment fees — transaction fees from Stripe, PayPal, and Shopify Payments
  • Shipping costs — cost data from ShipStation, ShipBob, Easyship, Sendcloud, and other connected carriers

This business data belongs to you. We process it solely to provide the analytics and reporting features you have subscribed to. We do not sell, rent, or share this data with any third party for marketing or advertising purposes.

Your end-customers' personal data (names, home addresses, phone numbers) is not required by Shopimize. If such data is incidentally present in a synced order payload, it is stored encrypted and is never used for any purpose other than displaying your own order history back to you.

Cómo usamos tus datos

We process your data for the following purposes. Where GDPR applies (EEA/UK users), the corresponding legal basis under Article 6 is noted:

PurposeLegal Basis
Providing the analytics platform and all its featuresPerformance of contract (Art. 6(1)(b))
Processing subscription payments via StripePerformance of contract (Art. 6(1)(b))
Sending transactional emails — magic links, invoices, weekly digests, alertsPerformance of contract (Art. 6(1)(b))
AI-generated insight summaries from your aggregated store metricsPerformance of contract (Art. 6(1)(b))
Sending product announcements and feature updatesLegitimate interest (Art. 6(1)(f)) — you may opt out at any time
Improving the platform through anonymised, aggregated usage analysisLegitimate interest (Art. 6(1)(f))
Complying with legal obligations — accounting records, fraud preventionLegal obligation (Art. 6(1)(c))

Compartición de datos

We do not sell your data to anyone. We share data only with the following trusted sub-processors under contractual data processing agreements (DPAs), and only to the extent necessary to provide the Service:

  • Stripe — payment processing and subscription management (US; EU Standard Contractual Clauses apply)
  • Vercel — application hosting and serverless compute (US; EU Standard Contractual Clauses apply)
  • Neon (PostgreSQL) — primary database hosting (EU region)
  • Resend — transactional email delivery
  • Anthropic Claude API — generates AI insight text from your aggregated metrics; no raw order data or customer PII is transmitted
  • Google Analytics — anonymised, aggregated marketing website usage statistics only

We may disclose your data to law enforcement or regulatory authorities if required by applicable law, a valid court order, or to protect the safety and rights of Shopimize, its employees, or its users.

Retención de datos

We retain your personal data for as long as your account is active or as needed to provide the Service. Specific retention periods are:

  • Account data (email, name, preferences) — retained until account deletion or 90 days after subscription cancellation
  • Store and order data — retained for as long as your account is active, and erased when you disconnect the store or close your account
  • Billing records — 7 years minimum, as required by applicable accounting and tax regulations
  • Application logs and error data — 30 to 90 days on a rolling basis
  • Database backups — purged within 30 days of account deletion

You may request deletion of your data before these periods expire at any time by emailing hello@shopimize.com. Legally required retention (billing records) cannot be waived.

Seguridad

We implement appropriate technical and organisational security measures to protect your data against unauthorised access, alteration, disclosure, or destruction:

  • All data in transit is encrypted using TLS 1.2 or higher (HTTPS enforced everywhere)
  • Passwords are hashed with bcrypt — never stored or logged in plain text
  • Database servers are accessible only via private VPC networking; no public exposure
  • Sensitive credentials (OAuth tokens, API keys) are encrypted at rest using AES-256
  • Two-factor authentication (TOTP) is available on all accounts
  • Payment processing is fully handled by Stripe under PCI-DSS compliance — we never touch raw card data
  • Regular security reviews, dependency audits, and penetration testing

If you discover a security vulnerability, please report it responsibly to hello@shopimize.com. We appreciate responsible disclosure and will respond promptly.

Derechos de privacidad

Depending on where you are located, you may have the following rights regarding your personal data. These apply to all users; EEA/UK users are additionally protected by the GDPR, and California residents by the CCPA:

  • Right of access (Art. 15) — request a complete copy of all personal data we hold about you
  • Right to rectification (Art. 16) — request correction of inaccurate or incomplete data
  • Right to erasure / "right to be forgotten" (Art. 17) — request deletion, subject to legal retention obligations
  • Right to restriction of processing (Art. 18) — request we limit how we use your data in certain circumstances
  • Right to data portability (Art. 20) — receive your data in a machine-readable format (JSON or CSV)
  • Right to object (Art. 21) — object to processing based on legitimate interest, including direct marketing
  • Rights related to automated decision-making (Art. 22) — we do not make legally significant automated decisions about you
  • California residents (CCPA) — right to know what data we collect, right to delete, right to opt-out of sale (we do not sell data), and right to non-discrimination

To exercise any of these rights, email hello@shopimize.com. We will acknowledge your request within 5 business days and respond fully within 30 days.

If you are unsatisfied with our response, you have the right to lodge a complaint with your local data protection authority. For EU users, this is typically the DPA of your country of residence. In France, this is the CNIL. For UK users, it is the ICO. For California residents, complaints may be directed to the California Privacy Protection Agency (CPPA).

Cookies

Shopimize uses a minimal set of cookies. We do not use advertising cookies, retargeting cookies, or cross-site tracking:

  • Session token (next-auth.session-token) — strictly necessary; authenticates your login session
  • CSRF token — strictly necessary; protects against cross-site request forgery attacks
  • Language preference — functional; remembers your chosen language
  • Google Analytics (_ga, _gid) — analytical; anonymised, aggregated website usage on shopimize.com only; you may opt out via your browser or our cookie banner

Strictly necessary cookies cannot be disabled without breaking the application (login will not work). All other cookies can be controlled via your browser settings or by declining in our cookie banner. Disabling analytical cookies does not affect your use of the Service.

Privacidad infantil

Shopimize is a business-to-business (B2B) analytics platform designed for e-commerce merchants and their teams. We do not knowingly collect or solicit personal data from anyone under the age of 16. If you believe that a minor has provided personal data to us, please contact us at hello@shopimize.com and we will delete that information promptly.

Cambios en la política

We may update this Privacy Policy from time to time to reflect changes in our practices, the features of the Service, or applicable law. We will notify you of any material changes by email and/or by displaying a prominent notice in the application at least 14 days before the changes come into effect.

Continued use of Shopimize after the effective date of an updated Privacy Policy constitutes your acceptance of the new terms. If you do not agree to a material change, you must stop using the Service before the effective date and may request deletion of your data.

The "Last updated" date at the top of this page will always reflect the most recent revision.

Contacto

For any questions, requests, or concerns about your privacy or this policy:

Shopimize — Privacidad de datos

Email: hello@shopimize.com

Sitio web: shopimize.com/contact

Nuestro objetivo es responder a todas las solicitudes de privacidad en un plazo de 5 días hábiles y no más de 30 días, según lo exigido por el GDPR.