Privacy Policy
Your privacy matters to us
Last updated: March 18, 2026
Data Controller
Heartly Apps UG (haftungsbeschränkt)
Tschaikowskistraße 5
04105 Leipzig
Germany
Email: support@heartly.io
VAT ID: DE459972977
Heartly ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Shopify and WooCommerce application for creating flash sales and marketing campaigns.
1. Information We Collect
a) Information You Provide
- Account Information: Email address, shop URL, business name
- Shop Data: Product information, pricing, inventory levels
- Campaign Data: Flash sale configurations, promotional settings
- Communications: Support requests, feedback, survey responses
b) Information We Collect Automatically
- Usage Data: Pages viewed, features used, time spent in the app
- Device Information: Browser type, operating system, IP address
- Analytics Data: Campaign performance metrics, conversion rates, visitor behavior (anonymized)
- Log Data: Access times, error logs, performance data
c) Information from Third Parties
- Shopify/WooCommerce: Shop information, order data, customer data (processed on your behalf)
- Order Analytics Data: Anonymized transaction data including order timestamps, product IDs, quantities, and prices. We do NOT collect or store customer personal information (names, emails, addresses, phone numbers) from orders.
- Payment Processors: Transaction status, payment information (we do not store full payment details)
2. How We Use Your Information
We use the collected information for the following purposes:
- Service Delivery: To provide and maintain our flash sale and marketing campaign services
- Campaign Management: To create, manage, and optimize your promotional campaigns
- Analytics: To provide you with performance insights and recommendations
- Communication: To send service updates, security alerts, and support messages
- Improvement: To enhance our features, develop new functionality, and improve user experience
- Security: To detect, prevent, and address fraud, abuse, and security issues
- Market Intelligence: To analyze anonymized sales data (products, prices, order timing) and provide merchants with insights on sales velocity, product performance, and revenue patterns. This analysis uses only aggregate transaction data - no customer personal information is processed.
- Legal Compliance: To comply with applicable laws, regulations, and legal processes
3. Legal Bases for Processing (GDPR)
Under the General Data Protection Regulation (GDPR), we process your personal data based on the following legal grounds:
Contract Performance (Art. 6(1)(b) GDPR)
Processing necessary to fulfill our contractual obligations to you:
- Account creation and administration
- Shop data synchronization (products, pricing, inventory)
- Flash sale and campaign management
- Order synchronization for analytics features
- Responding to your support requests
- Market Intelligence features (Pro Plan subscribers)
Consent (Art. 6(1)(a) GDPR)
Processing based on your explicit consent, which you can withdraw at any time:
- Google Analytics (website usage statistics)
- Meta Pixel / Facebook (advertising and conversion tracking)
- Microsoft Clarity (behavioral analytics and session replays)
Legitimate Interest (Art. 6(1)(f) GDPR)
Processing based on our legitimate business interests, balanced against your rights:
- Sentry error tracking (maintaining service quality and debugging)
- Security measures and fraud prevention
- Log data (access times, error logs) for technical operations
- Service improvements based on anonymized usage patterns
Legal Obligation (Art. 6(1)(c) GDPR)
Processing required to comply with legal requirements:
- Billing and invoice data (10-year retention under German tax law)
- Cooperation with authorities when legally required
4. Data Sharing and Disclosure
We Do Not Sell Customer Data
Heartly does not sell, rent, or trade any personal data - including merchant data or their customers' data - to third parties. We do not share data for advertising or marketing purposes with external parties.
We may share your information in the following limited circumstances:
- Service Providers: With trusted third-party vendors who help us operate our service (hosting, analytics, customer support)
- Platform Partners: With Shopify/WooCommerce as necessary to integrate with your store
- Legal Requirements: When required by law, court order, or government request
- Business Transfers: In connection with a merger, acquisition, or sale of assets (you will be notified)
- With Your Consent: When you explicitly authorize us to share specific information
5. Data Storage and Security
We implement industry-standard security measures to protect your data:
- Encryption: Data is encrypted in transit (TLS/SSL) and at rest (AES-256)
- Access Controls: Strict role-based access controls and authentication requirements
- Infrastructure: Data is hosted on secure, compliant cloud infrastructure (Supabase, Vercel)
- Monitoring: Continuous security monitoring and regular security audits
- Backups: Regular automated backups with secure storage
- Incident Response: We maintain a security incident response policy with defined procedures for detecting, responding to, and notifying affected parties of any data breaches within 72 hours as required by GDPR.
While we strive to protect your information, no method of transmission or storage is 100% secure. We cannot guarantee absolute security but continuously work to improve our security practices.
6. Data Retention
We retain your personal data only as long as necessary for the purposes outlined in this policy:
- Active Account Data: Retained while your account is active
- Campaign Data: Retained for 24 months after campaign ends (for analytics and reporting)
- Order Analytics Data: Anonymized transaction data is retained for up to 24 months for Market Intelligence analytics, then automatically deleted or further anonymized.
- Legal Requirements: Some data may be retained longer to comply with legal obligations
- Account Deletion: Upon request, we will delete or anonymize your personal data within 30 days (except where legal retention is required)
7. Your Rights (GDPR)
Under the General Data Protection Regulation (GDPR), you have the following rights:
Right to Access
Request a copy of all personal data we hold about you
Right to Rectification
Request correction of inaccurate or incomplete data
Right to Erasure
Request deletion of your personal data ("right to be forgotten")
Right to Restrict Processing
Request limitation of how we process your data
Right to Data Portability
Receive your data in a structured, machine-readable format
Right to Object
Object to processing based on legitimate interests or direct marketing
Right to Withdraw Consent
Withdraw consent for data processing at any time
Right to Lodge a Complaint
File a complaint with a supervisory authority
Supervisory Authority
You have the right to lodge a complaint with a data protection supervisory authority. For Heartly, the competent authority is:
Sächsischer Datenschutz- und Transparenzbeauftragter
Devrientstraße 5
01067 Dresden, Germany
Email: post@sdtb.sachsen.de
Website: www.datenschutz.sachsen.de
To exercise any of these rights, please contact us at support@heartly.io. We will respond to your request within 30 days.
9. Third-Party Services
We use the following third-party services that may collect your data:
- Supabase: Database and authentication services (GDPR-compliant, EU hosting available)
- Vercel: Application hosting and CDN (GDPR-compliant)
- Shopify/WooCommerce: E-commerce platform integration (subject to their privacy policies)
- Google Analytics: Website analytics and usage statistics. Google Analytics uses cookies to collect anonymized data about how visitors interact with our website, including pages visited, time spent, and general geographic location. This data helps us improve our service. Google Analytics is only activated after you consent to analytics cookies. For more information, see Google's Privacy Policy.
- Meta Pixel (Facebook): Advertising and conversion tracking. The Meta Pixel helps us measure the effectiveness of our advertising campaigns and enables us to show relevant ads to visitors who have interacted with our website. It collects data such as pages visited and actions taken. The Meta Pixel is only activated after you consent to marketing cookies. For more information, see Meta's Privacy Policy.
- Microsoft Clarity: We use Microsoft Clarity to understand how you use and interact with our website through behavioral metrics, heatmaps, and session replays. Usage data is captured to improve our products/services and for marketing purposes. Microsoft Clarity uses cookies and other tracking technologies to collect this data. For more information about how Microsoft collects and uses your data, visit the Microsoft Privacy Statement.
- Sentry: Error tracking and monitoring (data anonymization enabled)
Each third-party service has its own privacy policy. We recommend reviewing their policies to understand how they handle your data.
10. International Data Transfers
Your data may be transferred to and processed in countries outside your country of residence. We ensure adequate protection through:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Data Processing Agreements with all third-party processors
- Compliance with EU-U.S. Data Privacy Framework (where applicable)
11. Automated Decision-Making
We do not use automated decision-making, including profiling, that produces legal effects or similarly significantly affects you (as defined in Art. 22 GDPR).
Our AI-powered features (such as carousel suggestions and market intelligence) are used as recommendations only and do not make binding decisions without your explicit action. You always retain full control over whether to act on any suggestions.
12. Children's Privacy
Heartly is not intended for individuals under the age of 18. We do not knowingly collect personal data from children. If we discover that we have collected data from a child, we will delete it immediately. If you believe a child has provided us with personal data, please contact us at support@heartly.io.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by:
- Posting the new policy on this page
- Updating the "Last Updated" date
- Sending you an email notification (for significant changes)
Your continued use of our service after any changes indicates your acceptance of the updated policy.
14. Contact Us
If you have questions or concerns about this Privacy Policy or our data practices, please contact us:
Heartly Apps UG (haftungsbeschränkt)
Tschaikowskistraße 5
04105 Leipzig, Germany
Email: support@heartly.io
Contact Form: www.heartly.io/contact
We will respond to all requests within 30 days as required by GDPR.