Skip to main content

Privacy Policy

How we collect, use, and protect your personal information.

Last updated:

Introduction

Welcome to our Privacy Policy. The data controller for your personal data is KARA, a French limited liability company (SARL) with share capital of €7,624 (SIREN 439 639 618, Montpellier Trade and Companies Register), registered office: Route de Palavas, Chemin Saint-Hubert, 34970 Lattes, France, represented by its manager Mr Rachid ZENASNI, contact: support@ecomptimize.com. No data protection officer has been appointed, as the activity does not involve large-scale processing within the meaning of the GDPR; any question relating to your data may be sent to support@ecomptimize.com. This document explains how we collect, use, disclose and protect your information when you visit our website or use our services.

Data Collection

We collect information that you voluntarily provide to us when you register on the site, express an interest in obtaining information about us or our products and services, or otherwise when you contact us. When you choose to connect a WooCommerce or eBay store, we also collect the published product listings of that store (titles, descriptions and related information), as well as the access credentials you provide to us for that connection. This reading is limited to product listings: it covers neither your orders nor your customers.

Personal Information

The personal information that we collect depends on the context of your interactions with us and the site, the choices you make, and the products and features you use. This may include names, email addresses, phone numbers, and billing information.

Usage Data

We automatically collect certain information when you visit, use, or navigate the site. This information does not reveal your specific identity but may include device and usage information, such as your IP address, browser and device characteristics, operating system, language preferences, referring URLs, device name, country, location, and information about how and when you use our site.

Data Usage

We process your personal data on the following legal bases: performance of the contract (account, runs, payment); legal obligation (invoicing, accounting); legitimate interest (service security, fraud prevention, product usage measurement); consent (non-essential cookies, marketing communications). You may withdraw your consent at any time from your preferences or by writing to us.

Providing Services

To facilitate account creation and logon process, to manage user accounts, and to deliver and facilitate delivery of services to the user.

Communication

To send administrative information to you, such as product, service, and new feature information and/or information about changes to our terms, conditions, and policies.

Analytics & Improvements

To identify usage trends, determine the effectiveness of our promotional campaigns, and to evaluate and improve our site, products, marketing, and your experience.

Data Protection

We aim to protect your personal information through a system of organizational and technical security measures.

Security Measures

We have implemented appropriate technical and organizational security measures designed to protect the security of any personal information we process. However, despite our safeguards and efforts to secure your information, no electronic transmission over the Internet or information storage technology can be guaranteed to be 100% secure.

Data Retention

Your data is kept for the following periods: active account for as long as the account exists, plus three years after account deletion for security logs; uploaded catalog files, or product listings imported from a connected store, for 30 days after the run completes, then automatic purge; access credentials for a connected store, kept in encrypted form for as long as the connection is active and deleted as soon as it is disconnected; billing data for 10 years (accounting obligation, French Commercial Code article L.123-22); technical logs for 12 months at most.

Cookies & Tracking

We may use cookies and similar tracking technologies (like web beacons and pixels) to access or store information. Specific information about how we use such technologies and how you can refuse certain cookies is set out in our Cookie Policy.

Third-party Services

We may share your data with third-party vendors, service providers, contractors, or agents who perform services for us or on our behalf and require access to such information to do that work.

Service Providers

Our processors within the meaning of the GDPR are listed below, with their role: Stripe Payments Europe Ltd (Ireland, payment processing); Hostinger International Ltd (Lithuania, hosting); OpenAI Ireland Ltd (Ireland, processing in the United States, AI models); Google Ireland Ltd (Ireland, audience measurement through Google Analytics, with transfers to the United States under the European Commission's Standard Contractual Clauses; no request is sent to Google before analytics consent, which can be withdrawn at any time); PostHog Inc. (United States, product analytics, consent only); Functional Software Inc. dba Sentry (United States, error monitoring); Hostinger SMTP (Lithuania, transactional emails); Backblaze, Inc. (United States, client-side encrypted backup storage in EU Central/Amsterdam; any US access or transfer is covered by Standard Contractual Clauses and the EU-U.S. Data Privacy Framework).

External Links

Some processors are established outside the European Union. These transfers are governed by the Standard Contractual Clauses adopted by the European Commission, ensuring an equivalent level of protection. Our site may also contain links to third-party sites; we are not responsible for their privacy practices or content.

eBay connection (optional)

If you connect your eBay account (an optional feature), we receive from eBay, with your authorization (OAuth): your seller identifier, your public username, and the content of your active listings (titles, subtitles, descriptions, and references). This content is sent to our AI provider (OpenAI, listed above) solely to generate your optimization proposals. On output, Ecomptimize writes to eBay only the title, subtitle, and description of the listings you have reviewed and explicitly confirmed — never prices, stock, images, or any other field, and never without your action. The original version of each listing is kept so it can be restored. eBay access tokens are encrypted at rest and deleted when you disconnect. This data is erased when you disconnect your eBay account, when you delete your Ecomptimize account, or when eBay notifies us that your seller account has been deleted. eBay acts as an independent data controller for the data in your eBay account.

WooCommerce connection (optional)

If you connect your WooCommerce store (an optional feature), we store your store address and a pair of API credentials (key and secret) that WooCommerce generates at your request, after you authorize them in your site's administration area. These credentials are encrypted at rest with a dedicated key and are never shown to you again, including in your data export. WooCommerce does not allow these credentials to be restricted to a single type of data: they are necessarily issued with read and write permissions. Ecomptimize, however, only calls the "products" endpoints of the WooCommerce API — never your orders, your customers, or your settings — and this restriction is locked in our code. We read the content of your published products: identifier, type, name, description, short description, SKU, public product address, and variations. This content is sent to our AI provider (OpenAI, listed above) solely to generate your optimization proposals. On output, Ecomptimize writes to your store only the name, description, and short description of the products you have reviewed and explicitly confirmed — never prices, stock, images, categories, tags, variations, or any other field, and never without your action. The original version of each product is kept so it can be restored, and imported content is deleted together with the optimization it belongs to. When you disconnect your store, the credentials are immediately erased from our servers; the store address is kept so that you can reconnect and restore an earlier optimization, until you delete your Ecomptimize account. Disconnecting does not revoke the key on your store's side: you can delete it yourself in WooCommerce, under Settings > Advanced > REST API. Because WooCommerce is software you host yourself, no additional recipient is involved: your hosting provider remains your own service provider.

User Rights

Under Articles 15 to 22 of the GDPR, you have the following rights: access, rectification, erasure, restriction of processing, objection, portability, as well as the right to set directives for the fate of your data after your death. To exercise your rights, write to support@ecomptimize.com; we will respond within the one-month period provided by the regulation.

Access & Control

You can review, change, or terminate your account at any time. If you would like to request access to or correction of your personal data, please contact us.

Data Portability

You have the right to receive the data you have provided in a structured, commonly used and machine-readable format, and to transmit it to another controller. If you consider that the processing of your data does not comply with the regulation, you also have the right to lodge a complaint with the French data protection authority (CNIL), 3 place de Fontenoy, 75007 Paris, www.cnil.fr.

Contact Us

If you have questions or comments about this notice, you may email us at privacy@ecomptimize.com.