Privacy Policy
What we do with personal data, in both directions: yours as our customer, and your customers' as your processor.
The distinction that matters in B2B. For your account, billing and use of the platform, we are the controller. For the personal data of the people who buy from you through your touchpoints, you are the controller and we are your processor — we act on your instructions and never use that data for our own purposes.
01Who is responsible
The controller is the Shoppi entity you contract with — Shoppi Inc. (USA), Shoppi UG (Germany) or Shoppi Ltd (United Kingdom). Their registered addresses are listed in the Terms of Service. For data protection matters you can reach us through the contact page; requests are routed to the entity responsible for your account.
02Data we process as controller
- Account data — business name, VAT or tax identifier, contact name, email, phone, country, credentials.
- Billing data — plan, touchpoints, invoices, payment status. Card details are handled by Stripe; we never see the full number.
- Usage and telemetry — logins, dashboard actions, API calls, error and performance logs. Used to run, secure and improve the Service.
- Support data — the content of your tickets, calls and emails with us.
- Marketing data — only where you asked for it, or where legitimate interest applies to existing customers. Every message carries an unsubscribe link.
03Legal bases
- Performance of a contract — providing the Service, billing you, supporting you.
- Legal obligation — accounting, tax, anti-fraud and anti-money-laundering duties.
- Legitimate interest — platform security, abuse prevention, service improvement, and business-to-business communications about the product you use.
- Consent — non-essential cookies and any marketing you actively opted into. Withdrawable at any time.
04Data we process on your behalf
When your End Customers order, book or pay through a touchpoint, we process their data as your processor: name, contact details, delivery address, order history, and any custom fields you configure. We process it only to operate the touchpoint for you, and we do not sell it, rent it, or use it to train models for anyone else.
You decide what to collect and why, you provide the notices your customers are entitled to, and you determine retention. A Data Processing Agreement reflecting Article 28 GDPR is available on request and forms part of your contract.
One exception, stated plainly: for orders originated through the Shoppi Marketplace, we are an independent controller for the marketplace relationship with that buyer, because we operate the marketplace and provide the buyer guarantee on those orders.
05Sub-processors
We use a small, deliberate set of providers. We remain responsible for them.
| Provider | Purpose | Region |
|---|---|---|
| Oracle Cloud Infrastructure | Hosting, storage, backups | EU / US |
| Stripe | Payment processing and payouts | EU / US |
| Cloudflare | CDN, DNS, edge security | Global |
| Email delivery provider | Transactional and notification email | EU |
We give at least 30 days' notice before adding a sub-processor that handles data we process for you, so you can object.
06International transfers
Because the group spans the USA, Germany and the United Kingdom, some data crosses borders. Transfers outside the EEA or the UK rely on Standard Contractual Clauses and the UK Addendum, supplemented by technical measures — encryption in transit and at rest, access controls and logging.
07Retention
- Account and usage data — for the life of the account, then up to 12 months.
- Invoices and accounting records — as long as tax law requires, typically 7 to 10 years depending on the entity.
- Data we hold for you — available for export for 30 days after termination, then deleted.
- Security logs — up to 12 months.
08Security
Encryption in transit and at rest, isolated databases on dedicated plans, least-privilege access for our engineers, logged administrative actions, managed patching, and regular backups. Access to production data is limited to the people who need it to operate or support the Service.
If a breach affects your data, we notify you without undue delay and give you what you need to meet your own notification duties.
09Your rights
Where you are the data subject, you can request access, rectification, erasure, restriction, portability, and object to processing based on legitimate interest. Write to us through the contact page; we answer within one month.
If your End Customer sends a request to us instead of you, we will not act on it directly — we will forward it to you, because you are the controller.
You may also complain to a supervisory authority: your local EU authority, the ICO in the United Kingdom, or the competent state authority in the United States.
10Cookies
On this website we use technically necessary cookies for sessions, language and security, plus analytics cookies only with consent. On your own touchpoints, the cookies are the ones you configure — that banner and that choice belong to you.
11Automated processing
We use automation to translate catalogs, generate keywords, categorize products and detect fraud or abuse. None of it produces legal effects for you or your End Customers without human involvement, and we do not use your commercial data to train models offered to other merchants.
12Changes
We will announce material changes to this policy at least 30 days in advance by email and in the dashboard, so you can review them and, if needed, update your own notices.