Legal

Privacy Policy

How Knotly handles personal data. We are the data controller for our own merchant accounts and the data processor (Art. 28 GDPR) for the customer records that flow through the Shopify app on behalf of the installing merchant.

Last updated: 17 May 2026

1. Controller

Knotly GmbH, TODO_FILL_IN address, Germany. Contact: support@getknotly.com. See our Impressum for full company details.

2. Data we process

  • Merchant account data: name, email, role on a Shopify store, login activity. Lawful basis: contract (Art. 6(1)(b) GDPR).
  • Shop data we mirror from Shopify Admin (orders, products, customers, inventory) for analytics. We are the processor — the merchant is the controller. Lawful basis: the merchant's instructions, executed under our DPA.
  • Customer data embedded in the above (names, email, shipping addresses, order line items). Same processor relationship.
  • EU Widerrufsformular submissions: customer name, email, order number, withdrawal reason. Stored for the statutory retention period the merchant configures (default 10 years per German commercial law).
  • Operational telemetry: error logs, request traces — pseudonymised, retained 30 days.

3. How long we keep it

Account + shop data: for the duration of your subscription + 90 days after uninstall (Shopify mandates that we wipe everything within 30 days of receiving the shop/redact webhook, which fires 48 hours after the merchant uninstalls — see Shopify's compliance guide).

Withdrawal requests: per the retention period the merchant sets in Knotly's withdrawal settings (default 10 years; documents auto-deleted via Firestore TTL once expired).

4. Sub-processors

  • Google Cloud Platform (EU region europe-west1): all compute, BigQuery, Firestore.
  • Shopify Inc.: data source. We access via the Admin GraphQL API with an offline access token granted by the merchant during OAuth.
  • Resend: transactional email delivery (withdrawal confirmations, password resets). EU-region routing.
  • Google Vertex AI (region global): the daily digest + copilot chat use Google's Gemini models. Prompts contain anonymised, aggregated business metrics — no individual customer PII is included.

We sign a DPA with every sub-processor and add new ones to this list before they go live.

5. Your rights

  • Access (Art. 15), rectification (Art. 16), erasure (Art. 17), portability (Art. 20), restriction (Art. 18), objection (Art. 21).
  • The right to complain to a supervisory authority — for German residents that's the BfDI or your state-level commissioner.
  • Where you're a customer of a merchant using Knotly, please direct your request to the merchant first; we'll handle it on their behalf if they instruct us to.

To exercise your rights, email support@getknotly.com. We acknowledge within 72 hours and respond substantively within 30 days.

6. Security

Data in transit is encrypted with TLS 1.2+. Data at rest is encrypted with Google Cloud's default AES-256. Access tokens to merchant Shopify stores are stored on Google Cloud KMS-wrapped keys (TODO: roll this out — currently relying on GCP's default-at-rest encryption). We follow Google Cloud's SOC 2 / ISO 27001 baseline.

7. International transfers

All processing happens in the EU (Google Cloud europe-west1). The single exception is Vertex AI's global region which may route prompts through US data centres. Prompts contain aggregated, anonymised data only and are covered by Google Cloud's Standard Contractual Clauses.

8. Cookies

Knotly does not set marketing cookies. The app sets two strictly-necessary cookies after login: __Host-authjs.csrf-token and __Secure-authjs.session-token. Embedded inside Shopify admin we additionally set knotly_shopify_session (SameSite=None, Secure) to avoid re-handshaking session tokens on every page view.

9. Changes

We post material changes here at least 30 days before they take effect, and email affected merchants. Non-material edits (typos, clarifications) are made silently with the date at the top of the page updated.

Impressum · Zurück zur Startseite