1. Scope and responsibilities
This Privacy Policy explains how ComplyCat (“ComplyCat”, “we”, “us” or “our”) handles information when you browse complycat.cc, contact us, request updates, create an account, connect a store or use Price Transparency, Dark Pattern Audit, Grievance Desk or related services.
For account administration, business contacts and operation of our own website and services, we determine the relevant processing purposes where the law treats us as a controller or data fiduciary. For merchant-provided buyer or complaint data handled on a merchant’s behalf, our role and instructions depend on the applicable service, agreement and law. Merchants remain responsible for their own customer notices and lawful instructions.
This policy is supplemented by Data Controls and any applicable written data-processing terms. It does not itself grant access to a store or authorize a data use that otherwise requires permission.
2. Account, business and technical information
We may process your name, email address, role, organization, store or account identifiers, authorized-user details, billing contact information, plan or charge references and support communications.
Technical information can include IP address, browser and device details, service interactions, logs, diagnostics, security signals and approximate location inferred from technical information. The categories collected depend on the website or app configuration and features in use.
An early-access request asks for your store URL, email address and phone number, and identifies the app you selected. When you submit, the request also includes its timestamp, the submitting page URL and path, referring page, and any UTM campaign parameters or advertising click identifiers present on that page.
Please avoid sending passwords, complete payment-card details or unnecessary sensitive information in a support enquiry, prompt or complaint attachment.
3. Information relevant to each app
Price Transparency: store metadata, product and variant identifiers, catalog and offer context, prices and comparison values, market or currency context, timestamps, historical imports, campaign references, disclosure settings and related records.
Dark Pattern Audit: authorized storefront URLs and content, screenshots, shopping-journey observations, relevant theme or app configuration signals, review findings, reviewer notes, remediation records, audit reports and certificate-related records. Scope can differ for public pages and authorized restricted journeys.
Grievance Desk: customer contact details included in a grievance, complaint text, attachments, order, shipping, payment-status or refund context, recorded complaint copies, correspondence, assignments, deadlines, resolution history and NCH case references where provided or lawfully connected.
Not every app needs every category. Processing is limited by enabled features, available integrations, permissions and lawful instructions. A screenshot or attachment may contain personal information even when its primary purpose is an audit or operational record; provide only the context needed for the task.
4. Where information comes from
Information may come directly from you, your organization and authorized users, Shopify or other integrations you connect, customer records you lawfully provide, service providers, and technical interactions with our website and apps.
An NCH case reference or record may be supplied through an authorized merchant workflow. This policy does not establish a public NCH API connection or bypass official registration and access requirements.
5. How information is used
We use information to administer accounts, authenticate users, connect authorized systems, provide pricing records and disclosures, organize storefront review evidence, support grievance handling, generate enabled outputs, maintain records, provide support, manage billing and send necessary service notices.
We also use appropriate information to diagnose faults, understand feature usage, improve reliability and quality, prevent abuse, protect security, investigate disputes, enforce agreements and comply with legal obligations. Marketing communications are sent only where permitted and can be opted out of.
Where a legal basis is required, we rely on the applicable basis for the activity, such as performance of an agreement, your or the merchant’s valid instructions, consent where required, legal obligations or a permitted legitimate interest. A processing basis used in one jurisdiction is not assumed to apply identically everywhere.
6. AI-assisted processing and improvement
When you use an AI-enabled feature, relevant prompts, selected store context, screenshots, findings, complaint material, correspondence or feedback may be processed to generate a summary, explanation, classification, recommendation or response draft. Third-party AI or cloud providers may process that context on our behalf as service providers or processors under the applicable arrangements.
Provide only relevant context and limit unnecessary personal information. Review output before operational use. Contact us about the controls available for a particular app, agreement or data category rather than assuming that all providers or features use identical retention or processing settings.
We may use aggregated, de-identified or otherwise privacy-preserving information to evaluate and improve the services. We do not sell personal data. This policy does not grant an unrestricted right to use merchant customer information for unrelated model training or other purposes outside the applicable permissions and processing terms.
9. International processing
Information may be stored or processed in countries other than where you or your business are located, including where service providers operate. Data-protection rules may differ between countries.
Where required, appropriate contractual, organizational or other lawful transfer safeguards are used. We do not promise a particular hosting region or data-localization arrangement unless it is expressly agreed for the relevant service.
10. Retention, deletion and account closure
We retain information for the purposes for which it is needed, including providing the service, maintaining relevant pricing, audit or complaint records, supporting the account, complying with law, resolving disputes and protecting security. Retention depends on data type, authorized configuration, contractual or legal requirements, account status and operational or backup needs.
When information is no longer needed, it is deleted, anonymized or de-identified as appropriate. Verified deletion requests and valid Shopify data requests are handled subject to applicable law and platform requirements. Uninstalling or disconnecting an app stops the corresponding authorized connection as supported by the platform, but does not necessarily erase every already-retained billing, security, backup or other lawful record instantly.
Any retention exception is limited to a legitimate and legally permitted purpose; it does not override a mandatory erasure obligation. See Data Controls for requesting deletion or export and for the distinction between source-system data and retained app records.
11. Security and access
We use reasonable technical and organizational measures designed to protect information, which may include access controls, encryption, logging, monitoring and provider review appropriate to the service. No internet-based system can promise absolute security.
Protect your credentials and devices, assign appropriate Shopify and app permissions, and keep customer information out of unnecessary prompts or support channels. Contact us if you believe access or information has been compromised.
12. Privacy rights and requests
Depending on your location, role and applicable law, you may have rights to access, correct, delete, obtain a copy of, restrict or object to processing of personal information, withdraw consent, or exercise other applicable privacy choices. The scope of these rights can depend on whether the request concerns your account, a business-managed workspace or a merchant’s buyer.
Send requests to [email protected]. We may verify identity and authority and coordinate with the relevant merchant or administrator. A Shopify buyer should normally direct an order or customer-data request to the merchant, with ComplyCat assisting where it processes the relevant information on that merchant’s behalf.
We respond within the time required by applicable law and explain any lawful limitation where required. You may also have a right to complain to an appropriate supervisory or regulatory authority. A service contact process does not remove that right.
13. Children and communications
The services are intended for business use and are not directed to children. Do not intentionally provide children’s information unless it is necessary for an authorized feature and you have the authority and safeguards required by applicable law. Contact us if you believe children’s information has been handled improperly.
You can opt out of marketing communications using an available unsubscribe mechanism or by contacting us. Necessary service, security, billing and transactional messages may continue where appropriate.
14. Updates and contact
We may update this policy to reflect changes in the services, practices or legal requirements. The revised date will appear on this page; material changes will be communicated as required through an appropriate notice. An update does not remove existing mandatory privacy rights.
Operator: ComplyCat. Privacy, support and legal enquiries: [email protected]. Also see our Terms of Service and Data Controls.
Questions?
Contact [email protected] for support, billing and privacy enquiries.