Privacy Policy

Last updated: 30 August 2026

1. Who we are

Commerce365 is operated by Flatline Agency B.V., a company registered in the Netherlands. For everything described in section 5, Flatline Agency is the data controller.

Privacy questions, data-subject requests and California privacy requests all go to privacy@flatlineagency.com. We answer at the address below.

2. Controller or processor — which are we?

This distinction decides whose legal basis applies, so it comes before everything else.

Under the CCPA the same split makes us a service provider for your store data. We do not retain, use or disclose it for any purpose other than performing the service for you.

3. What data we collect

We do not ask for, and do not want, special categories of data under Article 9 GDPR — health, biometrics, political opinions and the like. Please do not put them into chat.

4. How we use your data

To run the service you signed up for: analysing your commerce data, running agents, building dashboards and reports, and executing the changes you approve. To bill you. To keep the platform secure and working. To answer you when you get in touch. And, if you opted in, to send you product news.

We do not sell your data, and we do not use your store data to train AI models — ours or anyone else's.

5. Our legal bases under the GDPR

Article 6(1) GDPR requires a lawful basis for every purpose. These are ours, for the data we control (see section 2).

PurposeDataLegal basis
Creating and running your account, authenticating you, and giving you access to the platformName, email address, organization name, login credentialsArticle 6(1)(b) — performance of the contract with you
Connecting your platforms over OAuth and reading the data you authorise, so the service can analyse itAccess tokens, account identifiers, and the store, advertising and marketing data in the scopes you grantArticle 6(1)(b) — performance of the contract with you
Running AI analysis, agents, dashboards and reports — the service you signed up forConnected platform data, your chat messages, agent instructions and run historyArticle 6(1)(b) — performance of the contract with you
Executing an action you approve in a connected platformThe specific change you approve, and the access token needed to apply itArticle 6(1)(b) — performance of the contract with you
Taking payment, issuing invoices, and keeping the records tax law requiresBilling contact details, subscription and transaction recordsArticle 6(1)(b) for the payment itself; Article 6(1)(c) — legal obligation — for retaining the accounting records
Service and transactional email: alerts, approval requests, digests, security noticesEmail address, the content of the notificationArticle 6(1)(b) — performance of the contract with you
Keeping the platform secure: authentication logs, abuse and fraud prevention, error monitoringIP address, user and organization identifiers, request metadata, error diagnosticsArticle 6(1)(f) — our legitimate interest in keeping the service secure and available, balanced against your rights
Understanding how the product is used so we can fix and improve itAggregated and pseudonymised feature-usage data, support conversationsArticle 6(1)(f) — our legitimate interest in improving a service you use
Marketing email — product announcements and newslettersEmail address, nameArticle 6(1)(a) — your consent, which you can withdraw at any time using the unsubscribe link in every message
Responding to a lawful request from a court, regulator or law-enforcement authorityWhatever the request lawfully compelsArticle 6(1)(c) — compliance with a legal obligation

Where we rely on legitimate interests, we have weighed those interests against your rights and freedoms. You can object to that processing at any time under Article 21 — see section 10. Where we rely on consent, you can withdraw it at any time, and doing so does not affect processing carried out before you withdrew it.

6. Who we share data with

We do not sell your data. We share it only with the providers below, each under a contract that binds them to process it solely on our instructions.

ProviderWhat it doesWhere
SupabaseDatabase, authentication and encrypted secret storage. Your platform access tokens live here, encrypted in Supabase Vault.European Union
VercelApplication hosting and delivery.European Union (primary region), United States (company)
OpenRouterRoutes every AI request to the underlying model provider. All model calls go through OpenRouter, including calls served by Anthropic and MiniMax models.United States
AnthropicProvides the Claude models used for analysis, chat and agents, reached via OpenRouter. Your data is not used to train their models.United States
MiniMaxProvides models used for parts of report generation, reached via OpenRouter.Outside the EEA
InngestRuns scheduled and background agent work.United States
StripePayment processing. We never see or store your full card details.United States / European Union
ResendSends transactional and notification email.United States
SentryError monitoring. Events carry the user and organization identifier so a fault can be traced to the account that hit it.United States
GleapIn-app support and feedback widget, when you choose to contact us through it.European Union

We may also disclose data where the law compels us to, and to a successor entity if the business is sold — in which case this policy continues to apply until you are told otherwise.

7. International transfers

Your account and store data is stored in the European Union. Some of the providers in section 6 are established in the United States, so processing there does happen — most notably when an AI request is routed to a model provider.

Those transfers are covered by the European Commission's Standard Contractual Clauses, together with the supplementary technical measures described in section 8. Where a provider is certified under the EU–US Data Privacy Framework, we rely on that instead. You can ask us for a copy of the safeguards that apply to a specific transfer.

8. Security

Data is encrypted in transit and at rest. Access tokens for your connected platforms are held in Supabase Vault, encrypted separately from the rest of the database. Every table carries row-level security keyed to your organization, so one organization cannot read another's data. Access to production is restricted and logged.

No system is immune. If a breach affects your personal data we will notify the Dutch Data Protection Authority within 72 hours as Article 33 requires, and notify you directly where Article 34 requires it.

9. How long we keep it

10. Your rights under the GDPR and UK GDPR

If you are in the EEA, the UK or Switzerland, you have the right to:

Email privacy@flatlineagency.com to exercise any of these. We respond within one month, and will tell you if we need to extend that by up to two further months as Article 12(3) allows.

You can also complain to a supervisory authority. In the Netherlands that is the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl); elsewhere, the authority where you live or work.

If your request concerns data a merchant holds about you as their customer, send it to that merchant — they are the controller and we act on their instructions. Tell us anyway and we will pass it on.

11. California privacy rights (CCPA / CPRA)

This section applies if you are a California resident. It also sets out the disclosures the California Consumer Privacy Act, as amended by the CPRA, requires. Commerce365 is available worldwide, so we make these disclosures rather than assuming our users are only in Europe.

Personal information we collect

CategoryExamplesSourceBusiness purposeDisclosed to
A. IdentifiersName, email address, organization name, account ID, IP addressDirectly from you at sign-up; automatically from your browserProviding and securing the service, billing, supportHosting, database, email and payment service providers
B. Customer records (Cal. Civ. Code §1798.80(e))Billing contact details, company addressDirectly from you; from our payment processorTaking payment and issuing invoicesPayment processor; our accountants
D. Commercial informationSubscription tier, transaction and credit-usage recordsGenerated by your use of the serviceBilling, plan enforcement, supportPayment processor, database provider
F. Internet or other electronic network activityPages viewed, features used, chat and agent activity, error diagnosticsAutomatically as you use the platformProviding the service, security, product improvementHosting, database, error-monitoring and AI service providers

We do not collect the other statutory categories — biometric information, precise geolocation, education records, or professional information beyond your job title and employer.

Sensitive personal information

The only sensitive personal information involved is your account log-in credential. We use it solely to authenticate you — a use the CPRA exempts from the right to limit — and never to infer anything about you.

We do not sell or share your personal information

We have not sold personal information, and have not shared it for cross-context behavioural advertising, in the preceding twelve months — using the definitions of “sell” and “share” in the CCPA. We also do not sell or share the personal information of anyone we know to be under 16.

Your California rights

How to exercise them

Email privacy@flatlineagency.com with “California privacy request” in the subject line and tell us which right you want to exercise. We verify your identity by matching the details in your request against the account — for a request to delete or to access specific pieces we may ask you to confirm from your registered email address. An authorised agent may act for you with written permission that we can verify.

We confirm receipt within 10 business days and respond within 45 calendar days. If we need longer we will tell you within that first 45 days and take no more than 45 further days. There is no charge.

If your request is about data a merchant holds about you as their customer, we act as that merchant's service provider. Send the request to the merchant; if you send it to us we will forward it.

12. Cookies

We use only what the service needs to work: a session cookie to keep you signed in, and your interface preferences. We do not run advertising or cross-site tracking cookies, so there is nothing here to consent to or refuse. Our marketing site is covered by its own notice.

13. Children

Commerce365 is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us data, tell us and we will delete it.

14. Changes to this policy

We may update this policy. The date at the top always reflects the current version, and we will email you about any change that materially affects your rights before it takes effect.

Contact

Flatline Agency B.V., the Netherlands.
Privacy, data-subject and California requests: privacy@flatlineagency.com