Privacy Policy
1. Who we are
Commerce365 is operated by Flatline Agency B.V., a company registered in the Netherlands. For everything described in section 5, Flatline Agency is the data controller.
Privacy questions, data-subject requests and California privacy requests all go to privacy@flatlineagency.com. We answer at the address below.
2. Controller or processor — which are we?
This distinction decides whose legal basis applies, so it comes before everything else.
- Your account data — we are the controller. Your name, email, organization, billing details and how you use the platform. Section 5 sets out our legal basis for each purpose.
- Your store data — we are a processor. The product, order, customer, advertising and marketing data we read from your connected platforms is yours. Where it contains personal data about your customers, you are the controller and we process it only on your documented instructions, under Article 28 GDPR. The legal basis for that processing is yours to determine, not ours, and your own privacy notice is what governs it. A data processing agreement is available on request.
Under the CCPA the same split makes us a service provider for your store data. We do not retain, use or disclose it for any purpose other than performing the service for you.
3. What data we collect
- Account information: your name, email address and organization name when you sign up, and your login credentials, which are handled by our authentication provider and never stored by us in readable form.
- Connected platform data: product, order, inventory, customer, advertising and marketing data from the platforms you connect — Shopify, Klaviyo, Meta Ads, Google Ads, Google Analytics, Search Console and others. We only ever access the scopes you explicitly authorise, and you can revoke them from the platform at any time.
- Usage data: your chat messages, agent instructions, generated reports and agent run history.
- Technical data: IP address, browser and device information, request logs and error diagnostics.
- Billing data: billing contact details and transaction records. Card details go directly to our payment processor and never reach our servers.
We do not ask for, and do not want, special categories of data under Article 9 GDPR — health, biometrics, political opinions and the like. Please do not put them into chat.
4. How we use your data
To run the service you signed up for: analysing your commerce data, running agents, building dashboards and reports, and executing the changes you approve. To bill you. To keep the platform secure and working. To answer you when you get in touch. And, if you opted in, to send you product news.
We do not sell your data, and we do not use your store data to train AI models — ours or anyone else's.
5. Our legal bases under the GDPR
Article 6(1) GDPR requires a lawful basis for every purpose. These are ours, for the data we control (see section 2).
| Purpose | Data | Legal basis |
|---|---|---|
| Creating and running your account, authenticating you, and giving you access to the platform | Name, email address, organization name, login credentials | Article 6(1)(b) — performance of the contract with you |
| Connecting your platforms over OAuth and reading the data you authorise, so the service can analyse it | Access tokens, account identifiers, and the store, advertising and marketing data in the scopes you grant | Article 6(1)(b) — performance of the contract with you |
| Running AI analysis, agents, dashboards and reports — the service you signed up for | Connected platform data, your chat messages, agent instructions and run history | Article 6(1)(b) — performance of the contract with you |
| Executing an action you approve in a connected platform | The specific change you approve, and the access token needed to apply it | Article 6(1)(b) — performance of the contract with you |
| Taking payment, issuing invoices, and keeping the records tax law requires | Billing contact details, subscription and transaction records | Article 6(1)(b) for the payment itself; Article 6(1)(c) — legal obligation — for retaining the accounting records |
| Service and transactional email: alerts, approval requests, digests, security notices | Email address, the content of the notification | Article 6(1)(b) — performance of the contract with you |
| Keeping the platform secure: authentication logs, abuse and fraud prevention, error monitoring | IP address, user and organization identifiers, request metadata, error diagnostics | Article 6(1)(f) — our legitimate interest in keeping the service secure and available, balanced against your rights |
| Understanding how the product is used so we can fix and improve it | Aggregated and pseudonymised feature-usage data, support conversations | Article 6(1)(f) — our legitimate interest in improving a service you use |
| Marketing email — product announcements and newsletters | Email address, name | Article 6(1)(a) — your consent, which you can withdraw at any time using the unsubscribe link in every message |
| Responding to a lawful request from a court, regulator or law-enforcement authority | Whatever the request lawfully compels | Article 6(1)(c) — compliance with a legal obligation |
Where we rely on legitimate interests, we have weighed those interests against your rights and freedoms. You can object to that processing at any time under Article 21 — see section 10. Where we rely on consent, you can withdraw it at any time, and doing so does not affect processing carried out before you withdrew it.
6. Who we share data with
We do not sell your data. We share it only with the providers below, each under a contract that binds them to process it solely on our instructions.
| Provider | What it does | Where |
|---|---|---|
| Supabase | Database, authentication and encrypted secret storage. Your platform access tokens live here, encrypted in Supabase Vault. | European Union |
| Vercel | Application hosting and delivery. | European Union (primary region), United States (company) |
| OpenRouter | Routes every AI request to the underlying model provider. All model calls go through OpenRouter, including calls served by Anthropic and MiniMax models. | United States |
| Anthropic | Provides the Claude models used for analysis, chat and agents, reached via OpenRouter. Your data is not used to train their models. | United States |
| MiniMax | Provides models used for parts of report generation, reached via OpenRouter. | Outside the EEA |
| Inngest | Runs scheduled and background agent work. | United States |
| Stripe | Payment processing. We never see or store your full card details. | United States / European Union |
| Resend | Sends transactional and notification email. | United States |
| Sentry | Error monitoring. Events carry the user and organization identifier so a fault can be traced to the account that hit it. | United States |
| Gleap | In-app support and feedback widget, when you choose to contact us through it. | European Union |
We may also disclose data where the law compels us to, and to a successor entity if the business is sold — in which case this policy continues to apply until you are told otherwise.
7. International transfers
Your account and store data is stored in the European Union. Some of the providers in section 6 are established in the United States, so processing there does happen — most notably when an AI request is routed to a model provider.
Those transfers are covered by the European Commission's Standard Contractual Clauses, together with the supplementary technical measures described in section 8. Where a provider is certified under the EU–US Data Privacy Framework, we rely on that instead. You can ask us for a copy of the safeguards that apply to a specific transfer.
8. Security
Data is encrypted in transit and at rest. Access tokens for your connected platforms are held in Supabase Vault, encrypted separately from the rest of the database. Every table carries row-level security keyed to your organization, so one organization cannot read another's data. Access to production is restricted and logged.
No system is immune. If a breach affects your personal data we will notify the Dutch Data Protection Authority within 72 hours as Article 33 requires, and notify you directly where Article 34 requires it.
9. How long we keep it
- Account and store data: for as long as your account is active. When you delete your account or uninstall the app, we delete it within 30 days — which also satisfies the Shopify and Klaviyo data deletion requirements.
- Billing records: seven years, as Dutch tax law requires.
- Security and error logs: up to 90 days.
- Marketing contact details: until you unsubscribe, plus a suppression record so we do not email you again.
10. Your rights under the GDPR and UK GDPR
If you are in the EEA, the UK or Switzerland, you have the right to:
- Access a copy of the data we hold about you (Art. 15).
- Rectify data that is wrong or incomplete (Art. 16).
- Erase your data (Art. 17).
- Restrict processing while a dispute is resolved (Art. 18).
- Port your data to another provider in a machine-readable format (Art. 20).
- Object to processing based on legitimate interests, and to direct marketing at any time (Art. 21).
- Withdraw consent where consent is the basis (Art. 7(3)).
Email privacy@flatlineagency.com to exercise any of these. We respond within one month, and will tell you if we need to extend that by up to two further months as Article 12(3) allows.
You can also complain to a supervisory authority. In the Netherlands that is the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl); elsewhere, the authority where you live or work.
If your request concerns data a merchant holds about you as their customer, send it to that merchant — they are the controller and we act on their instructions. Tell us anyway and we will pass it on.
11. California privacy rights (CCPA / CPRA)
This section applies if you are a California resident. It also sets out the disclosures the California Consumer Privacy Act, as amended by the CPRA, requires. Commerce365 is available worldwide, so we make these disclosures rather than assuming our users are only in Europe.
Personal information we collect
| Category | Examples | Source | Business purpose | Disclosed to |
|---|---|---|---|---|
| A. Identifiers | Name, email address, organization name, account ID, IP address | Directly from you at sign-up; automatically from your browser | Providing and securing the service, billing, support | Hosting, database, email and payment service providers |
| B. Customer records (Cal. Civ. Code §1798.80(e)) | Billing contact details, company address | Directly from you; from our payment processor | Taking payment and issuing invoices | Payment processor; our accountants |
| D. Commercial information | Subscription tier, transaction and credit-usage records | Generated by your use of the service | Billing, plan enforcement, support | Payment processor, database provider |
| F. Internet or other electronic network activity | Pages viewed, features used, chat and agent activity, error diagnostics | Automatically as you use the platform | Providing the service, security, product improvement | Hosting, database, error-monitoring and AI service providers |
We do not collect the other statutory categories — biometric information, precise geolocation, education records, or professional information beyond your job title and employer.
Sensitive personal information
The only sensitive personal information involved is your account log-in credential. We use it solely to authenticate you — a use the CPRA exempts from the right to limit — and never to infer anything about you.
We do not sell or share your personal information
We have not sold personal information, and have not shared it for cross-context behavioural advertising, in the preceding twelve months — using the definitions of “sell” and “share” in the CCPA. We also do not sell or share the personal information of anyone we know to be under 16.
Your California rights
- Know: what we collect, where it came from, why we collect it, and who we disclose it to.
- Access: a copy of the specific pieces we hold.
- Delete: your personal information, subject to the exceptions the statute allows.
- Correct: inaccurate personal information.
- Opt out of sale or sharing: we do neither, so there is nothing to opt out of. If that ever changes we will add a “Do Not Sell or Share My Personal Information” link before it does.
- Limit the use of sensitive personal information: we use it only to authenticate you, which the statute exempts.
- Non-discrimination: we will not deny you service, change your price, or give you a lesser experience for exercising any of these rights.
How to exercise them
Email privacy@flatlineagency.com with “California privacy request” in the subject line and tell us which right you want to exercise. We verify your identity by matching the details in your request against the account — for a request to delete or to access specific pieces we may ask you to confirm from your registered email address. An authorised agent may act for you with written permission that we can verify.
We confirm receipt within 10 business days and respond within 45 calendar days. If we need longer we will tell you within that first 45 days and take no more than 45 further days. There is no charge.
If your request is about data a merchant holds about you as their customer, we act as that merchant's service provider. Send the request to the merchant; if you send it to us we will forward it.
12. Cookies
We use only what the service needs to work: a session cookie to keep you signed in, and your interface preferences. We do not run advertising or cross-site tracking cookies, so there is nothing here to consent to or refuse. Our marketing site is covered by its own notice.
13. Children
Commerce365 is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us data, tell us and we will delete it.
14. Changes to this policy
We may update this policy. The date at the top always reflects the current version, and we will email you about any change that materially affects your rights before it takes effect.
Contact
Flatline Agency B.V., the Netherlands.
Privacy, data-subject and California requests: privacy@flatlineagency.com