Privacy Policy
Last updated: 5 August 2026
1. Who is responsible
SEOforEshop (“we”, “us”) is operated from the United States, and is the controller of personal data processed through this Service. Contact us any time via the contact page — that is the channel for all privacy requests (access, correction, deletion, marketing opt-out).
2. What we collect
Account data: name, email, whether you are a company or freelancer, company/brand name, industry, and a hashed password (we never store passwords in plain text). Shop settings: shop name, website, target audience, tone, language and target market. Product content: the product information you submit and the SEO content generated from it. Billing data: handled by Stripe — we store your plan, credit balance and Stripe customer reference, never your card number. Technical data: server logs and error logs needed to run the Service securely.
3. What we use it for
To provide the Service (generating and storing your SEO content), to process payments and manage subscriptions, to respond to messages you send us, to protect the Service against abuse, and to comply with legal obligations. We do not sell personal data and we do not run third-party advertising or tracking on this site.
Marketing: when you sign up we may also contact you by email with marketing about the Service and related products offered by our company and its affiliated brands, as described in the Terms. You can opt out of marketing at any time via the unsubscribe link in any marketing email or via the contact page; opting out does not affect service emails.
4. AI processing
Product information you submit is sent to Anthropic (our AI provider) to generate your SEO content. Under our API terms, Anthropic does not use this data to train its models. Your shop settings are included with each request so the output matches your store.
5. Processors we rely on
Vercel (hosting, USA/EU), Supabase (database, EU — Frankfurt), Stripe (payments), and Anthropic (AI generation, USA). Each processes data only as needed to provide their service to us. Data may be processed outside the EEA under appropriate safeguards (standard contractual clauses).
6. Retention
Generated content (single products and bulk imports) is deleted automatically 30 days after creation. Account data is kept while your account is active. Contact and support-chat messages are kept for up to 12 months. When you delete your account, your data is deleted within 30 days except where law requires longer (e.g. invoicing records).
7. Cookies
We use one essential cookie: your login session. No analytics cookies, no advertising cookies, no cross-site tracking — which is why there is no cookie banner.
8. Your rights
Depending on where you live (including under GDPR if you are in the EEA/UK), you have the right to access, correct, export, restrict or delete your personal data, and to object to processing. Use the contact page and we will respond within 30 days. EEA/UK residents may also lodge a complaint with their local supervisory authority.
9. Security
Data is encrypted in transit (HTTPS everywhere), passwords are hashed with bcrypt, database access is restricted to a dedicated role, and payment data never touches our servers.
10. Changes
We will post any changes to this policy on this page and update the date above; material changes will be notified in the app.