Privacy policy
This policy explains what data Atlios collects, why we collect it, who processes it on our behalf, and the choices you have. We try to keep the language plain. Where legal terms are unavoidable, we say what they mean.
Last updated: 4 August 2026
1. What we collect
- Account data: your name, email address, password (hashed), and team or store role.
- Shopify catalog data: products, variants, metafields, images, collections, and inventory levels we read from your Shopify store after you connect it.
- Shopify order data: if you grant order access, we read recent orders to work out how much of each product sold and what it earned. That means order dates, line quantities and prices, the product each line refers to, and refund amounts. We do not read your customers' names, email addresses, phone numbers, or addresses. We do not store individual orders or order lines, only per-product totals, which cannot be traced back to any individual customer. Order access is optional.
- Google Merchant Center data: when you connect Google Merchant Center, we read your product feeds and attributes and the diagnostic and policy issues Google reports for them, through Google APIs. See section 6 for how we handle this Google user data.
- Google Search Console and Google Analytics data: when you connect them, we read aggregate performance figures for your store's pages to show which catalog problems are costing you traffic. These are aggregate figures, not individual visitor records.
- Usage data: pages viewed, features used, sync and fix activity, timestamps, browser type, device type, and IP address (used for security, rate limiting, and product analytics).
- Payment data: handled by Stripe. Card numbers never touch our servers. We retain billing metadata (plan, amount, invoice references) needed for accounting.
- Support data: messages and attachments you send when contacting us.
- Cookies: a session cookie for authentication and preference cookies for your saved settings. Analytics is collected by our hosting provider in aggregate.
2. Why we collect it
- Provide the service: check your catalog, surface issues, generate draft fixes, and publish what you approve.
- Estimate what a problem is worth: use per-product sales totals to estimate the revenue affected by the issues we find, so you can work in order of money rather than issue count.
- Operate billing: charge paid plans, apply credits, prevent fraud.
- Improve the product: understand what works, fix what breaks, prioritize roadmap.
- Communicate: transactional emails (Quality reports, billing receipts, security notices) and, only with your opt-in, product updates.
- Protect the service and our users: detect abuse, enforce limits, comply with law.
3. Legal bases (EU, UK, and similar regimes)
4. AI processing
5. Sub-processors
- Vercel, Inc. (hosting, file storage, analytics, performance monitoring, and AI request routing)
- Google Cloud (cloud infrastructure)
- Neon (Postgres database)
- Trigger.dev (background job processing)
- Stripe, Inc. (payment processing)
- Loops and Resend (transactional and product email)
- Google Gemini, OpenAI, Anthropic, and MiniMax (AI model APIs for text, image, and video generation)
- PhotoRoom (product image processing)
- DataForSEO (search-volume and keyword data; we send search terms and your storefront domain, never customer data)
- Barcode Lookup (product reference data)
- Dropbox and Google Drive (only if you choose to import files from them, and only the files you select)
6. Google user data
Who we share, transfer, or disclose it to. We share Google user data only with the sub-processors listed in section 5 that are needed to provide these features: Vercel and Google Cloud (hosting and infrastructure), Neon (database), and Trigger.dev (background processing). When you run a generative task on a Merchant Center field, the specific fields needed are sent to the AI model providers named in section 4 (Google Gemini, OpenAI, and Anthropic). We do not transfer or disclose Google user data to anyone else, except: to you and other members of your team or store account; where you direct us to; where required by law or to a regulator; or as part of a merger, acquisition, or sale of assets, in which case we will notify you first.
Atlios's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell Google user data, do not use it for advertising, and do not use it to train AI models.
7. Where data is stored
8. Retention
- Account data: retained while your account is active and for up to 90 days after deletion to recover from accidental deletion.
- Shopify catalog snapshots: retained while you keep your store connected so Quality trends remain meaningful. Removed within 30 days of disconnection.
- Per-product sales totals: retained while your store is connected, so revenue comparisons over time stay possible. They hold no customer-identifying data. Deleted with your store record when you remove the store or close your account.
- Usage data: retained in identifiable form for 12 months, then aggregated and anonymized.
- Billing records: retained for the period required by tax and accounting law (typically 5 to 7 years).
- Support data: retained for 24 months after the conversation closes.
9. Your rights
- EU / UK (GDPR): rights above, plus the right to lodge a complaint with your supervisory authority.
- California (CCPA / CPRA): right to know, delete, correct, and opt out of sale. We do not sell personal information.
- United Arab Emirates (Federal Decree-Law No. 45 of 2021 on Personal Data Protection): rights above, exercised via the contact below.
10. Security
11. Children
12. Changes to this policy
13. Contact
- Email: privacy@atlios.io
- Postal: SDFP Software Solutions, Dubai, United Arab Emirates