Privacy Policy
Draft v1 — Last updated 2026-05-28. Pending counsel review.
StoreWiz is operated by its parent company, currently in formation. The operating entity, jurisdiction of incorporation, and governing-law clauses will be finalized prior to general availability. For current corporate status, contact
legal@storewiz.ai.
This Privacy Policy describes how StoreWiz ("StoreWiz", "we", "us") collects, uses, discloses, and protects Personal Data when you visit our websites, sign up for an account, or use the StoreWiz platform.
StoreWiz is an autonomous AI platform that runs e-commerce stores on behalf of merchants. The platform reads merchants' connected store data, makes automated proposals (and, where the merchant grants autonomy, executes them), and is supervised by the merchant. This Privacy Policy reflects the end-state of the platform; sections marked "available from [Module N+]" disclose features that will be live at the noted milestone.
We aim to write this policy in plain English. Where legal terms are required for accuracy, we define them on first use.
1. Who we are and how to contact us
| Topic | Contact |
|---|---|
| Privacy questions, complaints, exercising your rights | privacy@storewiz.ai |
| Data Protection Officer (see §13) | dpo@storewiz.ai 1 |
| Legal / corporate matters | legal@storewiz.ai |
| General support | support@storewiz.ai |
| Postal address | [TODO[entity-pending]: registered office address] |
1 Our DPO contact will be staffed by a named individual (or external DPO firm) prior to general availability. Until then, requests to dpo@storewiz.ai are answered by the same team that handles privacy@storewiz.ai.
If you are in the European Economic Area, the United Kingdom, or Switzerland and would prefer to use a local representative, see §16 (Regional Supplements) for jurisdiction-specific contacts. These contacts will be staffed prior to general availability.
2. The two roles StoreWiz plays
StoreWiz handles two distinct categories of data, and our role differs for each:
a) Account data — StoreWiz is the Data Controller. When you create a StoreWiz account, give us your name and work email, configure your Pillars and OKRs, or use our marketing website, StoreWiz decides why and how that data is processed. For account data, you have the rights described in §11.
b) Tenant Store Data — StoreWiz is the Data Processor. When you connect Shopify, Klaviyo, Meta Ads, Google Ads, Plaid, Zendesk/Intercom, or other systems to StoreWiz, you authorize us to read (and sometimes write) data from those systems on your behalf. That data may include your own customers' Personal Data. For Tenant Store Data, you are the Controller and StoreWiz is the Processor. The terms governing that relationship are in our Data Processing Addendum (the "DPA"), which is incorporated by reference into your subscription agreement.
If a conflict exists between this Privacy Policy and the DPA in respect of Tenant Store Data, the DPA prevails.
3. Personal Data we collect
We collect different categories of Personal Data depending on whether you are a (i) prospective or signed-up merchant ("Account Data"), (ii) a person who interacts with our marketing site, or (iii) a customer of a merchant whose store is run by StoreWiz ("Merchant-Customer Data", which we process as a Processor on behalf of our merchant tenant).
3.a — Account Data (we are the Controller)
| Category | Examples | Source |
|---|---|---|
| Identifiers | Name, email address, login credentials (managed via our authentication sub-processor — see §10), phone number (optional, for 2FA) | Directly from you |
| Business profile | Business name, store URL, country, industry, currency, team size | Directly from you and your Shopify connection |
| Pillars and OKRs | Brand voice, business objectives, KPI targets you set, transcripts of your onboarding voice/text interview with Wizzy | Directly from you (voice onboarding available from Module M2) |
| Billing data | Plan tier, billing cycle, tax-resident country, VAT/GST number where applicable. We do not store full card details — these are tokenized and held by Lemon Squeezy, our Merchant of Record | Lemon Squeezy (via webhook) (available from Module M2) |
| Usage data | Pages viewed, features used, agent proposals approved/rejected, click and scroll events on the in-product interface, session duration, error logs (with PII scrubbing) | Generated automatically by your use of the platform |
| Communications | Support emails, in-product chat with Wizzy, feedback you provide | Directly from you |
| Device and connection | IP address, user-agent, device type, approximate geolocation derived from IP, browser fingerprint signals (collected by hCaptcha on public forms only) | Generated automatically |
3.b — Marketing-site visitor data (we are the Controller)
| Category | Examples | Source |
|---|---|---|
| Site-visit data | Pages visited, referring URL, session duration, IP address, user-agent | Cookies and server logs |
| Form submissions | Free Audit input (your store URL), email address, optional questions you answer | Directly from you |
| Anti-bot signals | Behavioral signals collected by hCaptcha on the Free Audit form, sign-up form, and login form | Collected by hCaptcha |
See the Cookies Policy for the full list of cookies we use and how to control them.
3.c — Merchant-Customer Data (we are the Processor; merchant is the Controller)
When you connect your store(s) and ad/email/support systems to StoreWiz, we ingest the following on your behalf:
| Category | Typical fields | Source |
|---|---|---|
| Customers | Name, email, postal address, phone, purchase history, lifetime value, segmentation tags | Shopify, Klaviyo, Zendesk/Intercom, Plaid (limited) |
| Orders & transactions | Order ID, line items, prices, discounts, refunds, fulfillment status | Shopify |
| Products & inventory | SKU, description, price, cost, stock levels, supplier data | Shopify (+ tenant uploads) |
| Marketing | Campaign content, recipient lists, opens/clicks, ad creatives and performance, social posts | Klaviyo, Meta, Google, social platforms |
| Communications with end-customers | Support tickets, review content, social DMs | Zendesk/Intercom, review platforms, social platforms (M8+) |
| Financial signals | Bank reconciliation data, cash position (Plaid-derived) | Plaid (M6+) |
We process Merchant-Customer Data only on the documented instructions of the merchant tenant (see DPA §3). The merchant — not StoreWiz — chooses what data to share, what autonomy to grant agents, and how long to retain it (subject to the limits in §8).
4. Why we collect Personal Data (purposes and lawful basis)
| Purpose | What it looks like in practice | Lawful basis (GDPR Art. 6) |
|---|---|---|
| Providing the platform | Running Wizzy + 17 specialist agents on your data; generating proposals; executing approved actions; rendering dashboards; sending you notifications | Contract (Art. 6(1)(b)) |
| Account creation and authentication | Verifying your identity at login, 2FA, session management | Contract (Art. 6(1)(b)) |
| Billing and tax compliance | Issuing invoices, collecting payment via Lemon Squeezy, complying with tax law | Legal obligation (Art. 6(1)(c)) and Contract (Art. 6(1)(b)) |
| Safety and abuse prevention | Detecting prompt-injection attempts, fraud signals, rate-limit violations; investigating misuse | Legitimate interest (Art. 6(1)(f)) in protecting the platform and other tenants |
| Service improvement | Identifying common failure modes, calibrating agent decisions using anonymized cross-tenant patterns (see §6), capacity planning | Legitimate interest (Art. 6(1)(f)) |
| Customer support | Responding to your support requests; troubleshooting | Contract (Art. 6(1)(b)) |
| Marketing to existing customers | Product updates, feature announcements, transactional emails. You can unsubscribe from marketing emails at any time | Legitimate interest (Art. 6(1)(f)) for product updates; Consent (Art. 6(1)(a)) for non-transactional marketing |
| Marketing to prospects | Newsletters, demo requests, gated content | Consent (Art. 6(1)(a)) |
| Compliance with law | Responding to lawful demands, audit, regulatory reporting | Legal obligation (Art. 6(1)(c)) |
| Aggregated and de-identified analytics | Producing statistics and benchmarks that cannot be linked back to any individual or tenant | Legitimate interest (Art. 6(1)(f)) |
We do not process Special Category Data (Article 9) as part of normal operations and do not knowingly process Personal Data of children (see §12).
5. How automated decisions are made (Article 22 GDPR — important)
This section is load-bearing. Please read it carefully.
5.1 What StoreWiz does autonomously
StoreWiz includes Wizzy (an orchestrator running on a strategic-tier large language model) and 17 specialist agents (running on analytical and routine model tiers). These agents:
- Read data from your connected systems;
- Generate Proposals — typed payloads recommending specific actions on your store (e.g., "reorder 240 units of SKU X by Friday", "send this email sequence to this segment", "reduce CPC bid on this campaign by 12%");
- And — only where you have explicitly granted that level of autonomy per skill per tenant — execute approved Proposals against the relevant third-party systems.
These are automated decisions within the meaning of Article 22 GDPR, Quebec Law 25 Article 12.1, and similar provisions.
5.2 Your control over autonomy (the three tiers)
For every skill (e.g., Inventory, Ad Operations, Campaign), you choose one of three autonomy tiers:
| Tier | What happens | Default |
|---|---|---|
| Proposal-only | The agent prepares a Proposal and queues it for your review. Nothing is executed without your explicit approval. | DEFAULT for every skill at sign-up |
| Review-required | The agent prepares a Proposal and waits for your approval, but with a clearly-displayed countdown (e.g., 4 hours). If you neither approve nor reject, the action does not execute (it expires). | Opt-in per skill |
| Auto-approve | The agent executes the Proposal automatically, subject to the safety guardrails described in §5.4. You see a record of every action and can configure exclusions (e.g., "never auto-approve over $X spend per day"). | Opt-in per skill, with attestation |
You can change a skill's autonomy tier at any time from the StoreWiz Admin Console (available from Module M3). Changing a skill from Auto-approve to a lower tier takes effect immediately for new Proposals.
5.3 Your right to opt out of automated decisions
You have the right at any time to:
- Require human review for any individual Proposal, even on an Auto-approve skill — simply reject and rework.
- Set a skill back to Proposal-only — degraded UX, full agency preserved.
- Disable automated decision-making entirely for your tenant — agents will continue to read data and prepare Proposals, but nothing will be queued for execution. Your platform usefulness will be substantially reduced; you remain fully in control.
- Express your view, contest a decision, and request human re-review of any executed Auto-approve action. We will provide written reasoning and reverse or compensate where the action is determined to have been wrong.
To exercise any of these rights, write to privacy@storewiz.ai or use the Admin Console.
5.4 Safety guardrails that always apply
Regardless of your autonomy tier, certain categories of action always require human approval:
- Spending above a per-tenant configurable daily cap (default: per channel);
- Outbound communications to more than a per-tenant configurable number of customers in a single send;
- Deletion of any data (we soft-delete only — see §8);
- Modification of brand-voice baseline;
- Cancelling subscriptions or issuing refunds;
- Publishing to platforms where you have explicitly opted out;
- Any action our confidence-threshold engine scores below 0.85 on sensitive actions (financial, billing, customer PII, external publishing).
5.5 The data sources that feed automated decisions
Automated decisions draw from: (a) data the merchant has connected to StoreWiz; (b) the merchant's stated OKRs and brand pillars; (c) anonymized cross-tenant learning patterns (statistical patterns derived from aggregated outcomes across many tenants, with k-anonymity ≥ 10 — no individual tenant or person can be identified from these patterns, no PII is included).
5.6 The logic involved and likely consequences
We do not provide proprietary model weights, but we will explain in plain English on request:
- The category of data inputs used;
- The chain of agent reasoning that produced a given Proposal (the platform stores reasoning traces and you can request them via the Admin Console or
privacy@storewiz.ai); - The expected impact (e.g., projected change in a KPI);
- The actual outcome after execution (we record actuals and compare against expectations).
5.7 Data Protection Impact Assessment (DPIA)
Because automated decision-making on tenant store data constitutes high-risk processing under GDPR Article 35, StoreWiz will conduct a Data Protection Impact Assessment prior to general availability. The DPIA is renewed annually and on every material change to the platform's autonomous capabilities. A summary is available to enterprise tenants on request.
6. AI: training, retention, and cross-tenant patterns
This section is also load-bearing. Read this carefully.
6.1 We do not train any AI model on your data
StoreWiz does not use any tenant data (Account Data or Merchant-Customer Data) to train, fine-tune, or otherwise adapt the weights of any foundation model. We do not sell tenant data to AI model providers for training purposes.
6.2 How AI providers receive your data
All AI model calls are routed through Vercel AI Gateway — a single proxy that forwards prompts to the actual model provider (currently Anthropic for our LLM workloads; image / video / voice generation may route to additional providers in the future and will be disclosed in this Privacy Policy when added). We use BYOK (bring-your-own-key) configuration with Anthropic.
Anthropic's terms (incorporated by reference into our commercial relationship) state that Anthropic does not train its models on Customer Content delivered via the API.
6.3 The honest disclosure on retention
We are required to be precise about retention because it varies by configuration:
- Anthropic standard API retention (our current configuration): Anthropic retains the content of API calls for approximately 30 days for the purpose of abuse and safety review, then deletes it. This is the default retention behavior for the Anthropic paid API tier.
- Zero Data Retention (ZDR): ZDR is an Anthropic Enterprise-tier configuration that disables the 30-day retention window entirely. StoreWiz has NOT yet provisioned ZDR. We are evaluating it for Module M2 / M3 (when real tenant data starts flowing) and will update this section when our configuration changes.
- Vercel AI Gateway: Vercel commits in its AI Product Terms that AI Gateway content is not used to train AI Products and Services for Enterprise subscribers; for Pro plans, additional terms apply. Our subscription places us in this scope; we will publish the precise current Vercel tier in
legal/sub-processorsat GA.
If the 30-day Anthropic abuse-review retention is unacceptable for your data, please write to privacy@storewiz.ai before sending sensitive content. We will assess whether your use case requires us to prioritize ZDR provisioning.
6.4 Cross-tenant learning patterns
To improve agent decisions over time, StoreWiz derives statistical patterns from outcomes across many tenants. We do this under the following constraints:
- No raw PII. Cross-tenant aggregates contain no names, emails, addresses, or other direct identifiers.
- No tenant-attributable signals. Aggregates are derived only when at least 10 distinct tenants contribute to a pattern (k-anonymity ≥ 10).
- Tenant opt-out available. You can opt your tenant out of contributing to cross-tenant pattern learning from the Admin Console (available from Module M3). Opting out has no effect on your platform usage.
- No reverse-engineering. Patterns cannot be reverse-engineered to disclose individual tenant data, and we contractually prohibit any attempt to do so.
6.5 Prompt-injection and content safety
We treat content provided by your end-customers (emails, reviews, support tickets, social posts) as untrusted input. We sanitize it before any AI model sees it (see our Safety & Guardrails section in Terms). We log suspected prompt-injection attempts in our internal safety audit log.
7. Who receives your data (sub-processors and other recipients)
We share Personal Data only with the parties listed in this section.
7.1 Sub-processors
The canonical list of sub-processors is set out below and reproduced in our DPA Annex III. The current sub-processors are:
| # | Sub-processor | Role | Region | Status |
|---|---|---|---|---|
| 1 | Vercel Inc. | Application hosting, CDN, edge runtime, server-side logs | US / EU | Active |
| 2 | Vercel Inc. (AI Gateway) | Routing of AI model calls | US / global | Active |
| 3 | Anthropic, PBC (via Gateway BYOK) | LLM provider for Wizzy and specialist agents | US | Active |
| 4 | Neon Inc. | Primary Postgres database with point-in-time recovery | US / EU configurable | Active |
| 5 | Upstash Inc. | Redis cache and rate-limiting | Global edge | Active |
| 6 | Inngest Inc. | Durable background jobs and event bus | US + GCP | Active |
| 7 | Functional Software Inc. (Sentry) | Error and performance monitoring, uptime checks | US (EU optional) | Active |
| 8 | Atlassian Pty Ltd. (Statuspage) | Public status page | US | Active |
| 9 | Clerk Inc. | Authentication and session management | US (EU on Enterprise) | Available from Module M2 |
| 10 | Resend Inc. | Transactional email delivery | US | Available from Module M2 |
| 11 | Sold through Link, LLC (Lemon Squeezy) | Merchant of Record for billing and tax | US (processes globally) | Available from Module M2 |
| 12 | Shopify Inc. | The merchant's own e-commerce platform (data flows merchant → StoreWiz) | Shopify-hosted | Available from Module M6 (read-only Free Audit from M1) |
| 13 | Intuition Machines, Inc. (hCaptcha) | Anti-bot challenges on public forms | US (EU edge) | Active on public forms |
Sub-processors marked "Available from Module MN" are not currently in production. We will not engage them until that module launches. Adding a new sub-processor requires written change order in our internal records and 30 days' advance notice to you (see §7.4).
7.2 Tenant-OAuth connectors
When you connect Klaviyo, Meta Ads, Google Ads, Plaid, Zendesk/Intercom, or similar to StoreWiz, the tenant — not StoreWiz — has the primary contract with that vendor. StoreWiz acts as a Processor of the data flowing through that OAuth connection. The vendor's own DPA continues to govern the relationship; StoreWiz's DPA covers our handling of the data once it reaches us.
7.3 Other recipients
We may also disclose Personal Data to:
- Professional advisers (lawyers, accountants, auditors) under confidentiality obligations.
- Law enforcement and regulators, where required by law. We will challenge overbroad or improperly-served requests and, where legally permitted, notify you of any compelled disclosure relating to your data.
- A successor entity in connection with a merger, acquisition, financing, or sale of all or substantially all of StoreWiz's assets. Your data continues to be protected under terms no less protective than this Privacy Policy.
- With your direction — e.g., when you ask us to send your data to a third party you nominate.
7.4 Sub-processor change notification
We give 30 days' advance notice of any new or replacement sub-processor (or of any material change to an existing sub-processor's role) by email to your primary contact and by updating storewiz.ai/legal/sub-processors. You may object in writing within 14 days. If we cannot accommodate your objection, you may terminate the affected service for cause. Emergency changes (e.g., security incident at a vendor) may be made with shorter notice and documented post-hoc.
7.5 We do not sell your data
We do not "sell" Personal Data within the meaning of CCPA/CPRA, and we do not "share" Personal Data for cross-context behavioral advertising. We honor the Global Privacy Control (GPC) signal as a valid opt-out request where applicable. We do not use Personal Data for retargeting on our marketing site.
8. How long we keep data (retention)
We keep Personal Data for as long as is necessary for the purposes set out in §4 and as required by law. Specifically:
| Data category | Retention period | Notes |
|---|---|---|
| Account Data | Duration of subscription + 90 days, then deletion or de-identification | The 90-day window allows you to reactivate or export |
| Tenant Store Data (Merchant-Customer Data) | Per merchant's instructions, default 365 days rolling for hot tables; archived for the duration of the tenant's subscription | The tenant Controller decides; we provide tooling |
| Wizzy onboarding transcripts | Duration of subscription + 90 days | You may request earlier deletion |
| Billing records | 7 years from issuance | Required by tax law in most jurisdictions |
| Server-side error logs (Sentry) | 90 days (with PII scrubbing applied at capture) | Standard Sentry retention |
| Anti-bot signals (hCaptcha) | Per hCaptcha policy | Typically short (days) |
| Safety audit log (internal) | 1 year hot retention, then archived | Includes guardrail trips, prompt-injection flags |
| Anonymized cross-tenant patterns | Indefinite | No PII; k-anonymity ≥ 10 |
| Marketing-site logs | 90 days for IP-resolved logs; longer for aggregated analytics | Configurable |
Soft-delete model. Deletions from StoreWiz are first applied as soft-deletes (the row is marked inactive and excluded from queries). Hard deletion follows within 30 days, subject to backups (see below).
Backups. Neon database backups are retained for 14 days (point-in-time recovery window). If a deletion request is honored during a period when backups still contain the data, the data continues to exist in backup until the backup ages out; we will not restore it. If a database restore is genuinely necessary within the backup window, we re-run the deletion as soon as the restore completes.
Shopify-mandated retention. If you uninstall the StoreWiz Shopify app (Module M6+), we honor Shopify's mandatory privacy webhooks: data is deleted within 30 days of the relevant webhook (customers/redact, shop/redact, customers/data_request).
9. International data transfers
StoreWiz is built primarily on US-based infrastructure (Vercel, Neon, Upstash, Inngest, Sentry, Anthropic via Gateway). When you are in the EEA, the United Kingdom, or Switzerland, your Personal Data is transferred to the United States and, in some cases, to other jurisdictions where our sub-processors operate.
We rely on the following transfer mechanisms:
- EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module 2 (controller-to-processor) and Module 3 (processor-to-sub-processor) as applicable;
- UK International Data Transfer Addendum (IDTA) and / or the UK Addendum to the EU SCCs, as applicable;
- Swiss FADP supplement to the SCCs, where Swiss data is in scope;
- Transfer Impact Assessments (TIAs) that we conduct before engaging US-based sub-processors and update annually or on material change.
We do not currently certify under the EU-US Data Privacy Framework (DPF). [TODO[founder-decide]: DPF certification]
If you wish to receive a copy of the SCCs or the TIA summary in respect of a specific sub-processor, write to privacy@storewiz.ai.
Data residency choice. From Module M2 onward, paid tenants may elect EU-region data residency for their Neon-hosted Tenant Store Data. Application traffic and AI-gateway calls remain US-routed (see §6); we will update this clause as additional residency regions go live.
10. Security
We protect Personal Data using a defense-in-depth model that includes:
- Encryption in transit with TLS 1.2 or higher for all external traffic.
- Encryption at rest for the Neon database (AES-256 per Neon's documentation) and for sensitive secrets (OAuth tokens, credentials) in our application layer.
- Row-Level Security (RLS) at the database layer, ensuring that every query against a tenant-scoped table is filtered by the verified tenant identity.
- Application-layer tenant scoping through a typed query wrapper that prevents tenant-id leakage in code.
- Per-request tenant context that is set from your verified session and that throws if missing.
- A cross-tenant attack test suite that runs in CI on every code change.
- Prompt-injection defenses including input sanitization, structural prompt boundaries, output schema validation, and per-agent tool whitelists.
- Confidence-threshold gating on sensitive actions; below-threshold actions escalate to human review.
- Internal safety audit log capturing guardrail trips, prompt-injection signals, scope violations, and confidence-threshold escalations.
- Error monitoring via Sentry with PII-scrubbing rules applied at capture.
- Public status page at
status.storewiz.ai(powered by Statuspage).
Honest limits. StoreWiz has NOT yet completed SOC 2 Type I or Type II certification, ISO 27001 certification, or PCI-DSS attestation. Our roadmap targets SOC 2 Type I post-MVP (currently planned within ~6 months of GA) and SOC 2 Type II to follow. We do not claim compliance with frameworks we have not yet attested to. We will update this section when audit reports are available.
Pen-testing. We will commission third-party penetration tests as we approach SOC 2 Type I readiness and at least annually thereafter.
11. Your rights
Subject to applicable law, you have the following rights in respect of Personal Data we hold about you as a Controller (and, in respect of Merchant-Customer Data, where law gives you a direct right against a Processor):
- Right of access — receive a copy of the Personal Data we hold about you.
- Right to rectification — correct inaccurate or incomplete data.
- Right to erasure ("right to be forgotten") — request deletion, subject to legal-retention obligations (see §8).
- Right to restriction — pause our processing of your data.
- Right to data portability — receive your data in a structured, commonly-used, machine-readable format and (where technically feasible) have it transmitted to another controller.
- Right to object — object to processing based on legitimate interests, including direct marketing.
- Rights in respect of automated decision-making — see §5.3 for the full set of controls.
- Right to withdraw consent — where processing is based on consent, you may withdraw it at any time without affecting prior lawful processing.
- Right to lodge a complaint with a supervisory authority in your country of residence.
How to exercise. Email privacy@storewiz.ai from the email address associated with your account, or contact us at the postal address in §1. We will verify your identity (typically via email confirmation; for higher-risk requests, additional verification may apply). We will respond within 30 days for most requests, extendable by up to two further months for complex requests with reasoned notice (GDPR Art. 12(3)). We do not charge for the first DSAR per year; manifestly unfounded or excessive repeat requests may attract a reasonable fee or be refused.
For Tenant Store Data, contact the merchant first. If you are an end-customer of a merchant who uses StoreWiz, please contact the merchant directly to exercise your rights. We will assist the merchant in responding to your request as required by the DPA.
12. Children's data
StoreWiz is a business-to-business platform. The Services are not directed to and we do not knowingly collect Personal Data from any person under the age of 16 (or under the higher local age of digital consent where it applies, such as under 13 in the United States under COPPA). If you believe we hold data about a minor, contact privacy@storewiz.ai and we will delete it promptly.
Merchants using StoreWiz to run stores aimed at minors must ensure their own compliance with applicable youth-data law. The DPA addresses Controller-side responsibility.
13. Data Protection Officer
[TODO[entity-pending]: Named DPO or external DPO firm — to be staffed prior to general availability.]
Until the DPO is named, the same team that handles privacy@storewiz.ai handles DPO-routed requests at dpo@storewiz.ai. EEA tenants may also nominate a EU Representative under Article 27 GDPR; we will name our own EU Representative prior to general availability ([TODO[entity-pending]: EU representative]).
14. Data breaches
If we become aware of a Personal Data breach affecting your data, we will:
- For data where we are the Controller: notify the competent supervisory authority within 72 hours of becoming aware where required by Article 33 GDPR, and notify you without undue delay where the breach is likely to result in a high risk to your rights and freedoms.
- For Tenant Store Data where you are the Controller and we are the Processor: notify you without undue delay after becoming aware so you can meet your own 72-hour obligation. The DPA contains more specific commitments.
The notification will include, to the extent known: nature of the breach, categories and approximate number of data subjects affected, likely consequences, and measures taken or proposed to address and mitigate.
15. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top of this page reflects the most recent change. For material changes, we will:
- Post a clear notice on our marketing site and in the Admin Console at least 30 days before the change takes effect (or 14 days for changes required by law), and
- Email tenants' primary contacts.
Your continued use of the Services after a material change takes effect constitutes acceptance, unless applicable law requires affirmative consent in which case we will obtain it.
Previous versions are archived at storewiz.ai/legal/archive.
16. Regional supplements
16.a — California (United States) — CCPA and CPRA
If you are a California resident, the California Consumer Privacy Act (as amended by the California Privacy Rights Act) gives you the following rights:
- Right to know what categories of Personal Information we have collected, sold (we don't), shared (we don't for cross-context behavioral advertising), and disclosed for business purposes — see §3 and §7.
- Right to delete Personal Information we hold about you (subject to legal-retention obligations).
- Right to correct inaccurate Personal Information.
- Right to opt out of sale or sharing — we do not sell or share Personal Information; we honor the Global Privacy Control (GPC) signal as a valid opt-out request.
- Right to limit use of Sensitive Personal Information — we do not collect or use Sensitive Personal Information except as strictly necessary to provide the Services.
- Right to opt out of automated decision-making technology — see §5.3 and §5.6. The right to receive meaningful information about the logic is built into the platform via reasoning traces; the right to opt out is exercisable per skill or platform-wide.
- Right to non-retaliation — we will not discriminate against you for exercising any of these rights.
- Authorized agents — you may designate an authorized agent to make a request on your behalf; we will verify the agent's authority.
Categories of personal information collected per the CCPA taxonomy: Identifiers; Customer Records (Cal. Civ. Code § 1798.80(e)); Commercial Information; Internet/Network Activity Information; Geolocation Data (approximate, IP-derived); Professional/Employment-Related Information; Inferences drawn from the foregoing.
Sensitive Personal Information categories collected: account credentials (used only to authenticate). We do not use this category beyond service-provision per Cal. Civ. Code § 1798.121.
Number of requests received in the preceding 12 months: [TODO[founder-decide]: annual CCPA metrics — first metrics due 1 July 2027].
16.b — Other US states (Virginia, Colorado, Connecticut, Utah, Texas, and others with comprehensive privacy laws)
Residents of US states with comprehensive privacy laws have analogous rights to those described above, including the right to access, correct, delete, opt out of sale/sharing, opt out of profiling for decisions producing legal or similarly significant effects, and appeal denied requests. Where the relevant law applies to us, we honor those rights on the same channels as the CCPA rights above.
16.c — European Economic Area and United Kingdom
The Controller for Account Data is StoreWiz (with the entity to be confirmed prior to general availability — see banner). Our EU Representative under Article 27 GDPR is [TODO[entity-pending]: EU representative]; our UK Representative is [TODO[entity-pending]: UK representative]. You may lodge a complaint with the supervisory authority in your country of residence. A list of EU supervisory authorities is maintained by the EDPB at https://edpb.europa.eu/about-edpb/about-edpb/members_en.
16.d — Switzerland
The Swiss Federal Act on Data Protection (FADP, revised 2023) applies in addition to the references above for Swiss residents. Our Swiss representative is [TODO[entity-pending]: Swiss representative or "to be appointed if processing meets FADP threshold"].
16.e — Canada (PIPEDA and Quebec Law 25)
Canadian residents have rights under the Personal Information Protection and Electronic Documents Act (PIPEDA) and, where applicable, provincial laws (most notably Quebec's Law 25). These include the right to access, correct, withdraw consent, and — under Law 25 — receive information about automated decision-making and request human review. We treat the Article 22 GDPR right and Law 25 Article 12.1 right as equivalent in practice (see §5).
16.f — Brazil (LGPD)
[TODO[founder-decide]: Brazil LGPD coverage — recommend confirm yes/no for launch; if yes, name DPO (encarregado) and add LGPD-specific rights paragraph here]
16.g — Australia (Privacy Act 1988)
[TODO[founder-decide]: Australia coverage — recommend confirm yes/no for launch; if yes, add Australian Privacy Principles applicability paragraph here]
16.h — Other jurisdictions
If you are in a jurisdiction not listed above, we still aim to give you the substance of the rights set out in this Privacy Policy. Contact privacy@storewiz.ai and we will work with you in good faith.
17. Governing law
[TODO[entity-pending]: This Privacy Policy is governed by the laws of [JURISDICTION TBD]; disputes resolved in [VENUE TBD], subject to mandatory consumer-protection and data-protection law of your country of residence.]
Contact. Questions about this Privacy Policy: privacy@storewiz.ai. DPO matters: dpo@storewiz.ai. Legal: legal@storewiz.ai. General support: support@storewiz.ai.