Privacy Policy
Data controller: Liljestrand Consulting AB, org. no. 559464-4378, Sweden. Contact: [email protected]. We process personal data under the GDPR; our lawful bases are contract performance (delivering reports and the app) and legitimate interest (improving the service, security).
What we collect
- Free check & audits: your email address, store URL, brand name, category and competitor names you provide.
- Payments: handled by Stripe (or Shopify Billing for the app). We never see or store full card details.
- Shopify app: on install we access your shop's name, domain, and product/collection metadata via Shopify's API to configure and run visibility checks. We do not access your customers' personal data, orders, or payment information.
- Website basics: server logs (IP, user agent) for security, kept briefly. No advertising trackers.
How reports are produced
To run a check we send shopping-related questions containing your brand, category and competitor names to AI providers' APIs (OpenAI, Anthropic, Google, Perplexity). These prompts contain business information, not personal data. Providers process them under their own API terms.
Who we share with
Processors that help us operate: Cloudflare (hosting), Stripe (payments), Shopify (app platform), the AI API providers above, and our email provider. We don't sell data, and we don't share it beyond what operating the service requires. Some processors are outside the EU; transfers rely on standard contractual clauses or adequacy decisions.
Retention
Reports and account data: kept while you're a customer and up to 24 months after, then deleted. Bookkeeping records are kept as Swedish law requires. Uninstalling the Shopify app triggers deletion of shop data per the timelines below.
Your rights
You can request access, correction, deletion, restriction, or a copy of your data at any time via [email protected]. You may also complain to IMY (the Swedish data protection authority).
Shopify GDPR webhooks
We implement Shopify's mandatory privacy webhooks: customers/data_request (we hold no customer personal data, and respond accordingly), customers/redact, and shop/redact (shop data deleted within 30 days of the request).