Privacy
This explains what we do with personal data at WhizzyCommerce, operated by [LEGAL ENTITY NAME], [ADDRESS], Portugal.
There are two different relationships here and they matter, so we will be precise about them:
- You, the merchant. We decide how your data is handled. We are the controller.
- Your shoppers. You decide how their data is handled. We hold it on your instructions. You are the controller; we are your processor. Section 6 covers what that means for both of us.
Part one: your data as a merchant
1. What we hold about you
Account. Name, email, password hash, the shops you belong to and your role in each.
Billing. Your plan, subscription status, invoices, VAT number and billing address. Card details are held by Stripe, not by us. We never see or store a full card number.
Shop configuration. Shop name, domain, business identity, tax settings and the like.
Support. Messages you send us, and our replies.
Technical. IP address, browser and device information, and timestamps, from your use of the dashboard.
Assistant use. Your instructions to the assistant, its replies, and a record of what it changed. Section 5 covers this specifically.
2. Why, and on what legal basis
| What for | Basis |
|---|---|
| Running your shop and your account | Performance of our contract with you |
| Billing, invoicing and collecting fees | Contract, and legal obligation for tax records |
| Support | Contract |
| Security, fraud prevention, abuse investigation | Legitimate interests |
| Service emails (billing, limits, incidents) | Contract |
| Marketing emails | Consent, withdrawable at any time |
| Keeping accounting records | Legal obligation |
We do not sell your data. We do not use your shop's data to train AI models.
3. How long we keep it
Account and shop data for as long as your account is open. After you cancel, 30 days, then deletion. If you delete a shop yourself, deletion is immediate.
Invoices and accounting records for 10 years, as Portuguese tax law requires. This survives account deletion: we cannot delete records we are legally required to keep.
Support conversations for 2 years. Security and access logs for 12 months.
4. Who we share it with
We use these processors to run the service. Each is bound by contract to handle data only on our instructions.
| Who | For | Where |
|---|---|---|
| Hetzner | Hosting and databases | [EU / CONFIRM] |
| DigitalOcean | Infrastructure | [CONFIRM REGION] |
| Cloudflare | CDN, DNS, media storage (R2) | Global edge |
| Stripe | Our subscription billing | EU/US |
| Anthropic | Assistant processing | US |
| [EMAIL PROVIDER] | Transactional email | [CONFIRM] |
We also disclose data where the law requires it, and to professional advisers under confidentiality. If we are ever acquired, data transfers with the business, and we will tell you before it happens.
Transfers outside the EEA rely on the European Commission's Standard Contractual Clauses.
5. The assistant and AI
This is the part most people want to understand, so here it is plainly.
What is sent. When you instruct the assistant, your message and the shop data needed to answer it are sent to Anthropic to be processed. What that includes depends on what you asked: a question about orders sends order data, a question about products sends product data.
Shopper data. Some asks involve shopper data: looking up an order, checking a customer. Only what is needed for that request is sent, and only when you ask for it.
Training. Your data is not used to train models. Anthropic's API terms do not permit training on API inputs.
What we keep. Your conversations with the assistant, and a record of what it changed in your shop, so you can see and undo them.
Your own key. If you add your own Anthropic API key, requests go to Anthropic under your account and your agreement with them. We do not see the content and take no cut.
Outside clients. If you connect an agent to a third-party client such as Claude, your conversation happens on their systems under their privacy policy, and the shop data that agent reads passes through them. That is your choice to make and your relationship with them.
6. Part two: your shoppers' data
When someone buys from your shop, their data is in our systems because you put it there. You are the controller. We are your processor. This section is our data processing agreement with you, and it forms part of our terms.
What we process on your behalf. Shopper names, emails, phone numbers, shipping and billing addresses, order history, and any account they create on your storefront. Card data goes directly to your payment provider and does not reach us.
On your instructions only. We process it to run your shop and for nothing else. We do not use it for our own purposes, do not sell it, and do not use it to train AI models.
Our commitments to you. We keep it secure (section 7). We bind our sub-processors to the same obligations. We help you respond when a shopper exercises their rights. We tell you without undue delay if there is a breach. We delete or return the data when you leave.
Your obligations. You need your own privacy policy for your shop, a lawful basis for what you collect, and consent where you rely on it, marketing above all. You must handle shopper requests to access, correct or delete their data. The tools to do that are in your dashboard.
Sub-processors. The list in section 4 applies to shopper data too. We will tell you before adding a new one and you may object.
When the assistant touches shopper data. If you or an agent you configured asks something that involves a shopper's record, that data is sent to Anthropic as described in section 5. You should say so in your own privacy policy. If that is not acceptable for your business, do not grant agents the customer permissions.
7. Security
Passwords are hashed. Payment provider keys and API keys are encrypted at rest, each under its own purpose, and only opened at the moment they are used. Traffic is encrypted in transit.
Each shop's data lives in its own database schema, isolated from every other shop. Access tokens name exactly one shop and cannot reach another.
Every change made through the assistant or an agent is recorded with who did it.
Staff access to shop data is limited to support purposes and logged.
If a breach affects you, we will tell you without undue delay, and notify the CNPD where the law requires it.
8. Your rights
Under the GDPR you can ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, or send it elsewhere in a portable form. You can withdraw consent where we rely on it.
Email [PRIVACY EMAIL]. We answer within 30 days.
If you are unhappy with how we handle it, you can complain to the Comissão Nacional de Proteção de Dados (cnpd.pt) or your own country's supervisory authority.
Shoppers: if you bought from a shop built on WhizzyCommerce and want to exercise your rights, contact that shop. They control your data. We will help them respond, but we cannot act on their data without their instruction.
9. Cookies
On whizzycommerce.com and the dashboard
Necessary. These keep you signed in and the service secure. They cannot be switched off and do not require your consent.
| Cookie | Purpose | Lasts |
|---|---|---|
| whizzy_session | Keeps you signed in | 30 days |
| whizzy_impersonator | Holds a staff member's own session while they are helping in your shop. Staff only. | 30 days |
| wz_consent | Remembers your answer to the cookie notice | 6 months |
Analytics. We do not currently use analytics cookies. If we add them, they will be loaded only if you accept them in the cookie notice, and you can change your mind at any time from the Cookies link in the footer. A browser that sends the Global Privacy Control signal is treated as having declined.
We do not use advertising cookies and we do not allow third parties to track you across other sites from our dashboard.
Cloudflare, which serves our traffic, may set cookies for security and performance. These are necessary to how the service is delivered.
On your storefront
Cookies on your own shop are your responsibility as its controller. We set only what the shop needs to work:
| Cookie | Purpose | Lasts |
|---|---|---|
| whizzy_cart | Remembers what a shopper put in their basket | 30 days |
| whizzy_customer | Keeps a shopper signed in to their account | 30 days |
| whizzy_currency | Remembers the currency a shopper chose | 1 year |
| whizzy_order | Shows the shopper their receipt after checkout | 30 minutes |
| wz_access | The entry pass for a demo or password-protected shop | 12 hours |
| wz_consent | The shopper's answer to your consent banner, if you switch it on | 6 months |
These are necessary for the shop to function and do not require consent under EU rules.
Anything beyond that is yours. If you add analytics, a Google Tag Manager container, a Meta pixel, a chat widget or any other third-party script, those cookies are yours to disclose and yours to gather consent for. Your shop needs its own privacy policy and, where you use non-necessary cookies, its own consent banner. Your dashboard includes one: switch it on in your shop's settings and your tags stay off until the shopper accepts.
Controlling cookies
Your browser can block or delete cookies. Blocking necessary cookies will stop the dashboard from working, and you will not be able to stay signed in.
10. Children
WhizzyCommerce is for businesses. We do not knowingly collect data from anyone under 16. If you believe we have, tell us and we will delete it.
11. Changes
We will update this page when things change, and email you about anything material at least 30 days before it takes effect.
Contact
[PRIVACY EMAIL]
[LEGAL ENTITY NAME], [ADDRESS], Portugal