Skip to content
Shopyai Logo

Privacy Policy

Controller

Controller within the meaning of the General Data Protection Regulation (GDPR) and the Austrian Data Protection Act (DSG):

Shopyai e.U.

Wehlistraße 131-143/14/10 1020 Vienna, Austria

Email: [email protected]

What data we process

  • Account data: e-mail address (required for login)
  • If you sign in via an identity provider (e.g. Google, Facebook or Telegram), we may receive your name and profile image
  • Technical login data for secure authentication and session management
  • Preferences: selected language (cookie “preferred_language”)
  • Location preference: country/region (derived from the IP address by our CDN provider)
  • Payment data: For paid plans, payment information (credit card data, bank account data) is processed by our payment service provider. We do not store complete payment data.
  • Order data: Orders, delivery addresses and transaction data of shop customers are stored as part of data processing.
  • Support/communication data you actively send us
  • Content you create (e.g. shop name, images, products). Avoid personal data in content unless necessary.
  • For security, servers may temporarily process technical metadata (e.g. IP address, user agent, error logs)
  • Waitlist data: When you join the waitlist for a region we haven't launched in yet, we store your e-mail, the selected country and the short business description from the chat — solely to notify you at launch.
  • Project enquiries: if you send us a project enquiry through the contact page, we store what you tell us about the project (business type, answers to our questions, note and, where given, your city and website address), your name, your e-mail address and/or phone number, and your preferred callback time and timeframe.

Purposes

  • Provide account, login, and session management
  • Protect service, prevent abuse, and troubleshoot
  • Processing of payments and subscriptions
  • AI-powered features for shop creation and product management
  • Optional: send newsletter when you opt in
  • Fulfil legal obligations (e.g. retention duties)
  • Analysis of website usage to improve our service (with consent)
  • Waitlist management and one-time notification when we launch in your region.
  • Answering project enquiries sent through the contact page and preparing an offer

Legal Bases (GDPR/DSG)

The processing of personal data is based on the EU General Data Protection Regulation (GDPR) and the Austrian Data Protection Act (DSG 2018):

  • Art. 6(1)(b) GDPR – performance of a contract (account/onboarding)
  • Art. 6(1)(f) GDPR – legitimate interests (operation/security)
  • Art. 6(1)(a) GDPR – consent (e.g. newsletter)
  • Art. 6(1)(c) GDPR – legal obligation (e.g. tax retention obligations under § 132 BAO)

Obligation to provide the data

Providing your e-mail address is contractually required for registration and for using an account — without it we cannot provide an account. Payment data is required in order to conclude a paid plan. We are required by law to collect tax-relevant data. All other information (e.g. profile image, telephone number, newsletter subscription) is voluntary; not providing it has no effect on your use of the platform.

Recipients / processors

To provide our services, we use the following service providers, with whom data processing agreements (DPA) pursuant to Art. 28 GDPR may exist:

  • Hosting: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany (processor pursuant to Art. 28 GDPR). Server location: Germany (EU).
  • Cloudflare, Inc. (USA): content delivery network, security/DDoS protection for the entire platform as well as storage and delivery of media (product images, logos).
  • Our authentication service stores your e-mail and essential login data to manage your account.
  • If you sign in via Google, your e-mail and basic profile information are provided for authentication.
  • If you sign in via Telegram, the login widget of Telegram Messenger Inc. is embedded; in doing so we receive your Telegram ID, your name, your username and, where applicable, your profile image.
  • Meta Platforms Ireland Ltd. (Facebook, Instagram): when signing in via Facebook and when connecting a Facebook Page or an Instagram account for automatic posts (see section “Facebook login, Facebook Pages and Instagram”).
  • A certified payment service provider for processing payments and subscriptions for shop operators.
  • An AI service provider for processing texts and images as part of the AI-powered features (product descriptions, image analysis, assistant).
  • An AI image generation service for creating and editing product images.
  • An e-mail delivery service for e-mails sent by the platform (e.g. notifying our team of a project enquiry) and for optional newsletters sent by shop operators.
  • An e-mail provider that hosts our mailbox; e-mails to us and the notifications about project enquiries arrive there.

Hosting

This website is hosted by Hetzner Online GmbH (Germany). The server location is Germany; the hosting itself does not involve any transfer to third countries. When you visit the website, the server automatically collects technical access data (IP address, time, page requested, browser type). This data is processed exclusively to ensure operation and is deleted after no more than 90 days. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in secure operation).

Content delivery network, attack protection & media storage

For the entire platform we use the content delivery network and the DDoS/security protection of Cloudflare, Inc. (101 Townsend St, San Francisco, CA, USA) as a processor. All requests to our website are technically routed via Cloudflare's servers; in doing so, Cloudflare processes connection data (in particular IP address, the URL requested, header information and the country of origin derived from it) in order to deliver and cache content and to defend against attacks. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in fast, secure and available provision).

The same provider is also used to store and deliver media (product images, shop logos, banners). The provider is certified under the EU-US Data Privacy Framework; in addition, EU Standard Contractual Clauses are in place.

Unused media files (orphaned files) are automatically and regularly deleted.

Payment Processing

For processing payments and subscriptions we use a certified payment service provider. Payment data you enter (e.g. credit card number, bank details) is processed directly by the payment service provider. We do not store complete payment data on our servers.

The payment service provider processes this data as an independent controller for payment processing, fraud prevention and compliance with legal obligations. The payment service provider is certified under the EU-US Data Privacy Framework.

Shop operators can receive payments from their customers via the payment service provider. In this case, the payment service provider acts as a data processor for the respective shop operator. Legal basis is Art. 6(1)(b) GDPR (performance of contract).

Sign-in via Telegram

We optionally offer sign-in via Telegram. In doing so, the official login widget of Telegram Messenger Inc. is embedded and a connection to Telegram servers is established, whereby your IP address is transmitted. If you sign in, we receive your Telegram ID, your name, your username and, where applicable, your profile image. Telegram is established outside the EEA; for this provider there is neither an adequacy decision nor a certification under the EU-US Data Privacy Framework. The use of the Telegram login is voluntary and takes place on the basis of your consent (Art. 6(1)(a), Art. 49(1)(a) GDPR); alternative sign-in methods are available to you.

Facebook login, Facebook Pages and Instagram (Meta)

We optionally offer sign-in via Facebook (Facebook Login by Meta Platforms Ireland Ltd., Merrion Road, Dublin 4, Ireland). If you sign in this way, we receive from Meta your name, your e-mail address and your Facebook user ID (your profile picture where applicable) in order to create your account. The legal basis is the performance of the contract (Art. 6(1)(b) GDPR); use is voluntary and alternative sign-in methods are available to you.

Shop and website operators can connect a Facebook Page in the dashboard so that Shopyai publishes posts (e.g. about new products, pages or topics you create) on that Facebook Page. For this we receive from Meta the name, ID and one Page access token for each Page you grant access to when connecting; we store the tokens encrypted, your personal profile is not stored. We transmit to Meta only the post text and, where applicable, the address of an image. The legal basis is the performance of the contract (Art. 6(1)(b) GDPR). The connection can be disconnected in the dashboard; the token and post history are then deleted from the database (backup copies within 7 days).

Likewise, an Instagram Business or Creator account can be connected in the dashboard — either via your Facebook Page or by signing in directly with the Instagram account (Instagram Login). For this we receive from Meta the ID and username of the Instagram account and an access token (for the connection via Facebook the token of your Facebook Page, for the direct sign-in a token of your Instagram account that is valid for 60 days and which we renew before it expires); we store the tokens encrypted. The purpose is publishing posts on your behalf; we transmit to Meta only the post text and the address of an image. The recipient is Meta Platforms Ireland Ltd. The legal basis is the performance of the contract (Art. 6(1)(b) GDPR). How to disconnect and have the data deleted is described on the deletion page (link below).

Meta Platforms, Inc. (USA) is certified under the EU-US Data Privacy Framework. Meta’s own processing is governed by Meta’s privacy policy.

Instructions for deleting the data received from Facebook and Instagram

Email Marketing

Shop operators can optionally use an email marketing service to send newsletters to their customers. Processing of email addresses only takes place with the explicit consent of the recipients (Art. 6(1)(a) GDPR). Consent can be withdrawn at any time with effect for the future (e.g. via the unsubscribe link in the newsletter). The email service provider processes the data as a processor within the EEA.

Project enquiries through the contact page

On the contact page you can send us an enquiry about a website project. To do so, you answer a few questions about your project and give your name and an e-mail address or phone number. Without a name and a way to reach you we cannot reply, so the enquiry cannot be sent; everything else is optional. The enquiry is stored only when you send it — together with the language of the page and a random identifier that prevents duplicate enquiries. We use the details only to answer your enquiry and to prepare an offer. The legal basis is Art. 6(1)(b) GDPR (steps prior to entering into a contract, taken at your request); if you enquire on behalf of a company, our legitimate interest in answering enquiries (Art. 6(1)(f) GDPR).

So that we only ask questions that fit, your note is evaluated automatically: first we look for keywords in it (business type, city, website address, languages). Only if no business type is recognised may the text of the note be sent to our AI service provider (see “AI-powered features”), which merely suggests a business type from our fixed list and the same details. We store nothing during this evaluation, and you decide on every suggestion yourself before you send the enquiry.

Once sent, the enquiry lands in our internal inbox and our team receives an e-mail notification with your details. To send it we use an e-mail delivery service as a processor (see “Recipients / processors”). To prevent abuse we limit the number of enquiries per connection: for this, your IP address is counted in memory for at most 26 hours and is not stored with the enquiry (Art. 6(1)(f) GDPR).

A note typed into the field on the home page is kept by your browser in local storage so that it reaches the contact page; it is deleted there once the enquiry has been sent successfully. For the duration of your visit the browser also keeps the random identifier of the enquiry (session storage). Both are technically necessary for the enquiry you asked for (§ 165 Abs. 3 TKG 2021).

Analytics & Statistics

We use our own analytics tools to understand and improve the use of the platform. No personal data is transmitted to third parties in this process. Additional analytics services may be added in the future — this will only happen with prior consent (consent banner). No analytics cookies are set without your approval.

AI-powered features

Shopyai offers AI-powered features to assist with shop creation and product management. The following services are used:

  • Processing of texts and images for product descriptions, image analysis, categorization and assistant features. Only the data necessary for the respective function (entered texts, uploaded images) is transmitted.
  • AI-based image generation and editing (text-to-image, image-to-image, background removal). Only image data and description texts are transmitted.

Personal data is not permanently stored by the AI provider. Legal basis is Art. 6(1)(b) GDPR (performance of contract) or Art. 6(1)(a) GDPR (consent). The AI providers used are certified under the EU-US Data Privacy Framework.

Automated decision-making and profiling

Automated decision-making within the meaning of Art. 22 GDPR that produces legal effects concerning you or similarly significantly affects you does not take place. The AI-powered features generate suggestions only (e.g. texts, images, categories), and you decide yourself whether to use them. We do not carry out profiling for advertising purposes.

Search Engine Indexing

To improve the discoverability of shops, we notify search engines about new or changed shop pages. Only URLs of publicly accessible pages are transmitted — no personal data. Legal basis is Art. 6(1)(f) GDPR (legitimate interest in discoverability).

Map Services

To display location information (e.g. delivery addresses in order management), an external map service may be used. Data (including IP address) is then transmitted to the map service provider. This only occurs after active user interaction (click). Legal basis is Art. 6(1)(f) GDPR (legitimate interest). The provider is certified under the EU-US Data Privacy Framework.

Data processing (SaaS)

As a SaaS platform, we process data on behalf of our shop operators (processing pursuant to Art. 28 GDPR). Shop operators are themselves controllers for the personal data of their customers. We provide a data processing agreement (DPA) and process this data exclusively on the instructions of the shop operators.

Retention

Account data is stored for the lifetime of your account and deleted after deletion requests unless legal retention periods apply. Login credentials are short-lived and regularly renewed. Technical logs are kept for a limited time for security (e.g. up to 90 days).

Data relevant under tax and commercial law (e.g. invoices, payment receipts) is retained in accordance with the Austrian retention obligations (§ 212 UGB (Commercial Code), § 132 Bundesabgabenordnung – BAO (Federal Fiscal Code)) for at least seven years.

After account cancellation, personal data will be deleted within 30 days, unless statutory retention obligations apply. You may request an export of your data before the deadline expires.

Waitlist data is deleted at the latest 30 days after launch notification in your region, or after 24 months without launch, unless you have registered as a customer in the meantime.

We keep project enquiries until they have been dealt with. If a collaboration results, we keep them for its duration; otherwise we delete them as soon as we no longer need them, unless statutory retention obligations apply. At your request we delete an enquiry at any time.

Transfers outside the EEA

Some of our service providers are based outside the European Economic Area (EEA), particularly in the USA. Data transfers to third countries are based on the following safeguards:

  • EU-US Data Privacy Framework (DPF): For providers with a valid DPF certification, the EU Commission's adequacy decision of 10 July 2023 applies.
  • EU Standard Contractual Clauses (SCC): Where no DPF certification exists, EU Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR are used.
  • Consent (Art. 49(1)(a) GDPR): For services without an adequacy decision and without appropriate safeguards — in particular the voluntary sign-in via Telegram — the transfer takes place exclusively on the basis of your explicit consent.

Cookies & local storage

The storage of information on your terminal equipment and access to it are governed by § 165 Abs. 3 TKG 2021 (Telecommunications Act). We use technically necessary cookies, which are indispensable for the operation of the website, without consent. All other cookies — in particular analytics and marketing cookies — are only set with your consent, which you give in the cookie banner and can withdraw at any time.

Technically necessary cookies

  • Essential session cookies for secure authentication
  • Preference cookie for the selected language (1 year)
  • Preference cookie for detected country/region (1 year)
  • Cookie to store the currently active shop for shop operators (1 year)
  • Local storage entry to store your cookie selection

Cookies requiring consent

In the cookie banner you can allow analytics and marketing cookies separately. Marketing cookies can be activated by shop operators for their own shops (e.g. advertising pixels); on the platform itself we currently do not set any marketing cookies. Without your consent, neither analytics nor marketing cookies are set.

Local Storage (Browser)

  • Authentication data is cached in the browser to maintain the login session. This data is deleted upon logout.

Your rights

Under the GDPR and DSG, you have the following rights regarding your personal data:

  • Access, rectification, erasure
  • Restriction and objection to processing
  • Data portability
  • Withdraw consent at any time (with effect for the future)
  • Right to lodge a complaint with a supervisory authority

RIGHT TO OBJECT (Art. 21 GDPR): Insofar as we process your data on the basis of legitimate interests (Art. 6(1)(f) GDPR), you have the right to object at any time, on grounds relating to your particular situation, to such processing. We will then no longer process your data unless we can demonstrate compelling legitimate grounds which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims. You may object to processing for the purpose of direct marketing at any time without giving reasons.

The competent supervisory authority in Austria is the Austrian Data Protection Authority (DSB), Barichgasse 40–42, 1030 Vienna, dsb.gv.at.

To exercise your rights, please contact us by e-mail at the address stated above. We will process your request without undue delay, and at the latest within one month (Art. 12(3) GDPR).

Last updated: 2026-10-02