Privacy Policy
Controller
Controller within the meaning of the General Data Protection Regulation (GDPR) and the Austrian Data Protection Act (DSG):
What data we process
- Account data: e-mail address (required for login)
- If you sign in via an identity provider (e.g. Google or Telegram), we may receive your name and profile image
- Technical login data for secure authentication and session management
- Preferences: selected language (cookie “preferred_language”)
- Location preference: country/region (derived from the IP address by our CDN provider)
- Payment data: For paid plans, payment information (credit card data, bank account data) is processed by our payment service provider. We do not store complete payment data.
- Order data: Orders, delivery addresses and transaction data of shop customers are stored as part of data processing.
- Support/communication data you actively send us
- Content you create (e.g. shop name, images, products). Avoid personal data in content unless necessary.
- For security, servers may temporarily process technical metadata (e.g. IP address, user agent, error logs)
- Waitlist data: When you join the waitlist for a region we haven't launched in yet, we store your e-mail, the selected country and the short business description from the chat — solely to notify you at launch.
Purposes
- Provide account, login, and session management
- Protect service, prevent abuse, and troubleshoot
- Processing of payments and subscriptions
- AI-powered features for shop creation and product management
- Optional: send newsletter when you opt in
- Fulfil legal obligations (e.g. retention duties)
- Analysis of website usage to improve our service (with consent)
- Waitlist management and one-time notification when we launch in your region.
Legal Bases (GDPR/DSG)
The processing of personal data is based on the EU General Data Protection Regulation (GDPR) and the Austrian Data Protection Act (DSG 2018):
- Art. 6(1)(b) GDPR – performance of a contract (account/onboarding)
- Art. 6(1)(f) GDPR – legitimate interests (operation/security)
- Art. 6(1)(a) GDPR – consent (e.g. newsletter)
- Art. 6(1)(c) GDPR – legal obligation (e.g. tax retention obligations under § 132 BAO)
Obligation to provide the data
Providing your e-mail address is contractually required for registration and for using an account — without it we cannot provide an account. Payment data is required in order to conclude a paid plan. We are required by law to collect tax-relevant data. All other information (e.g. profile image, telephone number, newsletter subscription) is voluntary; not providing it has no effect on your use of the platform.
Recipients / processors
To provide our services, we use the following service providers, with whom data processing agreements (DPA) pursuant to Art. 28 GDPR may exist:
- Hosting: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany (processor pursuant to Art. 28 GDPR). Server location: Germany (EU).
- Cloudflare, Inc. (USA): content delivery network, security/DDoS protection for the entire platform as well as storage and delivery of media (product images, logos).
- Our authentication service stores your e-mail and essential login data to manage your account.
- If you sign in via Google, your e-mail and basic profile information are provided for authentication.
- If you sign in via Telegram, the login widget of Telegram Messenger Inc. is embedded; in doing so we receive your Telegram ID, your name, your username and, where applicable, your profile image.
- A certified payment service provider for processing payments and subscriptions for shop operators.
- An AI service provider for processing texts and images as part of the AI-powered features (product descriptions, image analysis, assistant).
- An AI image generation service for creating and editing product images.
- An e-mail marketing platform for optional newsletter dispatch by shop operators.
Hosting
This website is hosted by Hetzner Online GmbH (Germany). The server location is Germany; the hosting itself does not involve any transfer to third countries. When you visit the website, the server automatically collects technical access data (IP address, time, page requested, browser type). This data is processed exclusively to ensure operation and is deleted after no more than 90 days. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in secure operation).
Content delivery network, attack protection & media storage
For the entire platform we use the content delivery network and the DDoS/security protection of Cloudflare, Inc. (101 Townsend St, San Francisco, CA, USA) as a processor. All requests to our website are technically routed via Cloudflare's servers; in doing so, Cloudflare processes connection data (in particular IP address, the URL requested, header information and the country of origin derived from it) in order to deliver and cache content and to defend against attacks. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in fast, secure and available provision).
The same provider is also used to store and deliver media (product images, shop logos, banners). The provider is certified under the EU-US Data Privacy Framework; in addition, EU Standard Contractual Clauses are in place.
Unused media files (orphaned files) are automatically and regularly deleted.
Payment Processing
For processing payments and subscriptions we use a certified payment service provider. Payment data you enter (e.g. credit card number, bank details) is processed directly by the payment service provider. We do not store complete payment data on our servers.
The payment service provider processes this data as an independent controller for payment processing, fraud prevention and compliance with legal obligations. The payment service provider is certified under the EU-US Data Privacy Framework.
Shop operators can receive payments from their customers via the payment service provider. In this case, the payment service provider acts as a data processor for the respective shop operator. Legal basis is Art. 6(1)(b) GDPR (performance of contract).
Sign-in via Telegram
We optionally offer sign-in via Telegram. In doing so, the official login widget of Telegram Messenger Inc. is embedded and a connection to Telegram servers is established, whereby your IP address is transmitted. If you sign in, we receive your Telegram ID, your name, your username and, where applicable, your profile image. Telegram is established outside the EEA; for this provider there is neither an adequacy decision nor a certification under the EU-US Data Privacy Framework. The use of the Telegram login is voluntary and takes place on the basis of your consent (Art. 6(1)(a), Art. 49(1)(a) GDPR); alternative sign-in methods are available to you.
Email Marketing
Shop operators can optionally use an email marketing service to send newsletters to their customers. Processing of email addresses only takes place with the explicit consent of the recipients (Art. 6(1)(a) GDPR). Consent can be withdrawn at any time with effect for the future (e.g. via the unsubscribe link in the newsletter). The email service provider processes the data as a processor within the EEA.
Analytics & Statistics
We use our own analytics tools to understand and improve the use of the platform. No personal data is transmitted to third parties in this process. Additional analytics services may be added in the future — this will only happen with prior consent (consent banner). No analytics cookies are set without your approval.
AI-powered features
Shopyai offers AI-powered features to assist with shop creation and product management. The following services are used:
- Processing of texts and images for product descriptions, image analysis, categorization and assistant features. Only the data necessary for the respective function (entered texts, uploaded images) is transmitted.
- AI-based image generation and editing (text-to-image, image-to-image, background removal). Only image data and description texts are transmitted.
- Background removal: Performed on our own servers (no third-party provider).
Personal data is not permanently stored by the AI provider. Legal basis is Art. 6(1)(b) GDPR (performance of contract) or Art. 6(1)(a) GDPR (consent). The AI providers used are certified under the EU-US Data Privacy Framework.
Automated decision-making and profiling
Automated decision-making within the meaning of Art. 22 GDPR that produces legal effects concerning you or similarly significantly affects you does not take place. The AI-powered features generate suggestions only (e.g. texts, images, categories), and you decide yourself whether to use them. We do not carry out profiling for advertising purposes.
Search Engine Indexing
To improve the discoverability of shops, we notify search engines about new or changed shop pages. Only URLs of publicly accessible pages are transmitted — no personal data. Legal basis is Art. 6(1)(f) GDPR (legitimate interest in discoverability).
Map Services
To display location information (e.g. delivery addresses in order management), an external map service may be used. Data (including IP address) is then transmitted to the map service provider. This only occurs after active user interaction (click). Legal basis is Art. 6(1)(f) GDPR (legitimate interest). The provider is certified under the EU-US Data Privacy Framework.
Data processing (SaaS)
As a SaaS platform, we process data on behalf of our shop operators (processing pursuant to Art. 28 GDPR). Shop operators are themselves controllers for the personal data of their customers. We provide a data processing agreement (DPA) and process this data exclusively on the instructions of the shop operators.
Retention
Account data is stored for the lifetime of your account and deleted after deletion requests unless legal retention periods apply. Login credentials are short-lived and regularly renewed. Technical logs are kept for a limited time for security (e.g. up to 90 days).
Data relevant under tax and commercial law (e.g. invoices, payment receipts) is retained in accordance with the Austrian retention obligations (§ 212 UGB (Commercial Code), § 132 Bundesabgabenordnung – BAO (Federal Fiscal Code)) for at least seven years.
After account cancellation, personal data will be deleted within 30 days, unless statutory retention obligations apply. You may request an export of your data before the deadline expires.
Waitlist data is deleted at the latest 30 days after launch notification in your region, or after 24 months without launch, unless you have registered as a customer in the meantime.
Transfers outside the EEA
Some of our service providers are based outside the European Economic Area (EEA), particularly in the USA. Data transfers to third countries are based on the following safeguards:
- EU-US Data Privacy Framework (DPF): For providers with a valid DPF certification, the EU Commission's adequacy decision of 10 July 2023 applies.
- EU Standard Contractual Clauses (SCC): Where no DPF certification exists, EU Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR are used.
- Consent (Art. 49(1)(a) GDPR): For services without an adequacy decision and without appropriate safeguards — in particular the voluntary sign-in via Telegram — the transfer takes place exclusively on the basis of your explicit consent.
Cookies & local storage
The storage of information on your terminal equipment and access to it are governed by § 165 Abs. 3 TKG 2021 (Telecommunications Act). We use technically necessary cookies, which are indispensable for the operation of the website, without consent. All other cookies — in particular analytics and marketing cookies — are only set with your consent, which you give in the cookie banner and can withdraw at any time.
Technically necessary cookies
- Essential session cookies for secure authentication
- Preference cookie for the selected language (1 year)
- Preference cookie for detected country/region (1 year)
- Cookie to store the currently active shop for shop operators (1 year)
- Local storage entry to store your cookie selection
Cookies requiring consent
In the cookie banner you can allow analytics and marketing cookies separately. Marketing cookies can be activated by shop operators for their own shops (e.g. advertising pixels); on the platform itself we currently do not set any marketing cookies. Without your consent, neither analytics nor marketing cookies are set.
Local Storage (Browser)
- Authentication data is cached in the browser to maintain the login session. This data is deleted upon logout.
Your rights
Under the GDPR and DSG, you have the following rights regarding your personal data:
- Access, rectification, erasure
- Restriction and objection to processing
- Data portability
- Withdraw consent at any time (with effect for the future)
- Right to lodge a complaint with a supervisory authority
RIGHT TO OBJECT (Art. 21 GDPR): Insofar as we process your data on the basis of legitimate interests (Art. 6(1)(f) GDPR), you have the right to object at any time, on grounds relating to your particular situation, to such processing. We will then no longer process your data unless we can demonstrate compelling legitimate grounds which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims. You may object to processing for the purpose of direct marketing at any time without giving reasons.
The competent supervisory authority in Austria is the Austrian Data Protection Authority (DSB), Barichgasse 40–42, 1030 Vienna, dsb.gv.at.
To exercise your rights, please contact us by e-mail at the address stated above. We will process your request without undue delay, and at the latest within one month (Art. 12(3) GDPR).
Last updated: 2026-07-17
