Privacy Policy
Effective date: 2026-07-20
This Privacy Policy explains how YAStuning OÜ ("we", "us", "our") collects and processes personal data when you use our website at shoptoai.com and the ShopToAI service (the "Service"), in accordance with Articles 13 and 14 of the General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR").
NOTEThis policy covers personal data for which we are the controller - mainly data about our customers and their users. Where we process the catalog/store data our customers connect on their behalf, we act as a processor and that processing is governed by our Data Processing Agreement.
1. Who is the controller
YAStuning OÜ (private limited company / OÜ), Pae tn 25-47, 11414 Tallinn, Estonia. Registration number: 14016370. VAT: EE102354272. Email: [email protected].
Data protection contact: our Privacy team (no dedicated DPO is required) - [email protected].
2. What data we collect, why, and on what legal basis
2.1 Account and authentication data
- Data: email address, first and last name (optional), password (stored only as an Argon2 hash - we never store or see your plaintext password), preferred language, email-verification status and timestamps.
- Purpose: to create and secure your account, authenticate you, and operate the Service.
- Legal basis: performance of a contract - Art. 6(1)(b) GDPR.
2.2 Workspace and billing data
- Data: workspace name, account type, billing name, country, address, city, postal code, VAT number.
- Purpose: to provide the Service, manage subscriptions, and issue invoices.
- Legal basis: performance of a contract - Art. 6(1)(b); and compliance with accounting/tax obligations - Art. 6(1)(c).
2.3 Payment data
- Data: subscription plan, Stripe customer and subscription identifiers, subscription status. We do not store full card numbers; card data is processed directly by Stripe.
- Purpose: to take payment and manage your subscription.
- Legal basis: performance of a contract - Art. 6(1)(b).
2.4 Connected-store credentials
- Data: API credentials for the e-commerce platform you connect (e.g. WooCommerce consumer key/secret). These are encrypted at rest and are never logged or shown back to you.
- Purpose: to read (and, where you grant write access on a platform that supports it, update) your store's catalog.
- Legal basis: performance of a contract - Art. 6(1)(b).
2.5 Security, access and error logs
- Data: IP address, user agent, request method/path, response status and timing, and diagnostic error events (a stack trace when something fails). Sensitive values, including store credentials, are automatically redacted before storage.
- Purpose: to secure the Service, prevent abuse, diagnose faults, and keep an audit trail.
- Legal basis: our legitimate interest in securing and operating the Service - Art. 6(1)(f).
- How: error diagnostics are handled by self-hosted error tracking on our own infrastructure in the EEA - no third-party provider receives them.
- Retention: access logs 90 days; error events up to 30 days.
2.6 Communications and notifications
- Data: the email address we send transactional emails to (verification, password reset, audit/enrichment results, invitations) and in-app notifications.
- Purpose: to operate the Service and inform you about account activity.
- Legal basis: performance of a contract - Art. 6(1)(b). Promotional email is sent only with your consent - Art. 6(1)(a) - which you can withdraw at any time.
2.7 Cookies and similar technologies
We use strictly-necessary and functional cookies to keep you logged in, protect forms against bots, and remember your preferences; these do not require consent. We also use Google Analytics to measure how the site is used - but only if you accept analytics cookies on our consent banner.
- Legal basis: your consent - Art. 6(1)(a) GDPR - which you can withdraw at any time via "Cookie settings" in the footer. No analytics data is collected if you reject.
See the Cookie Policy for the full list.
2.8 Data from workspace invitations
- Data: email address of a person invited to a workspace.
- Source: if a colleague invites you, we receive your email address from the person who invited you, not from you directly (Art. 14 GDPR).
- Purpose: to send the invitation and set up your access.
- Legal basis: our legitimate interest, and that of the inviting organisation, in enabling team collaboration - Art. 6(1)(f). Where Art. 14 applies, we provide this notice within a reasonable period, at the latest within one month.
2.9 Do you have to provide this data?
Providing account, workspace, billing and store-connection data is necessary to enter into and perform your contract with us; without it we cannot create your account or run audits. Analytics and promotional email are optional and based on your consent.
3. Catalog data (our role as processor)
When you connect a store, we create a local snapshot of its catalog (product names, SKUs, GTINs, brands, categories, descriptions, prices, availability, images and attributes) to run audits and propose improvements. If that catalog contains personal data, you (or your client merchant) are the controller and we process it under the DPA, only on your instructions.
To generate enrichment suggestions we send a limited subset of product text (product name, SKU, current brand/category, and up to the first 300 characters of the description) to our AI sub-processor (Google's Gemini API / AI Studio, on the paid tier, where your data is not used to train Google's models). We do not send account holders' personal data, pricing, images, or raw store records to the AI model.
If you enable the optional AI-visibility monitoring add-on, we additionally send your brand name and the category search queries you configure to third-party answer-engine APIs (Google, OpenAI and Perplexity AI) to measure whether those assistants mention your brand. This add-on is off by default; we send this data only after you explicitly enable it and give consent, and you can withdraw consent at any time. Because OpenAI and Perplexity process this data in the United States, enabling the add-on involves an international transfer (see Section 5).
4. Who we share data with
We share personal data only with service providers that process it on our behalf under an Art. 28 GDPR contract. The current list is in Sub-processors and includes our cloud hosting provider (Hetzner Online GmbH, Germany), Stripe (payments), Google (Gemini API / AI Studio - AI enrichment, and AI-visibility monitoring queries when you enable that add-on), Cloudflare (bot protection), our email provider, Google Analytics (website analytics - only with your cookie consent), and - only if you enable the AI-visibility monitoring add-on - OpenAI and Perplexity AI. We do not sell your data and we do not use third-party advertising trackers.
5. International transfers
Some sub-processors may process data outside the European Economic Area. Where that happens, transfers are protected by appropriate safeguards under Chapter V GDPR - typically the European Commission's Standard Contractual Clauses and, where applicable, the EU-U.S. Data Privacy Framework. You can request a copy at [email protected].
6. How long we keep data
| Data | Retention |
|---|---|
| Account & workspace data | For the life of your account, then deleted within 30 days of closure |
| Store credentials & catalog snapshot | Until you disconnect the store or close the account |
| Billing records (incl. Stripe IDs, invoices) | As required by tax/accounting law (7 years) |
| Security / access logs | 90 days |
| Error diagnostics / stack traces | up to 30 days (self-hosted, EEA) |
| Google Analytics data (only if you consent) | up to 26 months |
| In-app notifications | Most recent 100 per workspace |
7. Your rights
Under the GDPR you have the right to access (Art. 15), rectify (Art. 16), erase (Art. 17), restrict (Art. 18), receive a portable copy (Art. 20) of your data, and object to processing based on legitimate interests (Art. 21). Where processing is based on consent, you can withdraw it at any time.
To exercise any right, contact [email protected]. We respond within one month (Art. 12(3)) and may need to verify your identity first.
You may also lodge a complaint with a supervisory authority: the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon).
8. Automated decision-making
The Service uses AI to *suggest* catalog improvements, but these are proposals only and a human reviews and approves changes. We do not carry out automated decision-making within the meaning of Art. 22 GDPR with respect to your personal data.
9. Data security
We use encryption of store credentials at rest, password hashing (Argon2), TLS in transit, scoped multi-tenant access, short-lived rotating tokens with instant revocation, redaction of secrets in logs, and abuse protection. We will notify you and the supervisory authority of a personal data breach where required (Art. 33-34 GDPR).
10. Children
The Service is a business tool for professional use, not directed to individuals under 18. We do not knowingly collect children's data.
11. Changes
We may update this policy. Material changes will be announced via the Service or by email.
12. Contact
Questions about this policy or your data: [email protected].