In short

→ We hold store data — products, collections, customer tags, order totals — to price carts and attribute revenue.

→ Everything is stored in Toronto, Canada. Nothing at rest leaves Canada.

→ We don't train models on your data and don't sell it, aggregated or otherwise.

→ Attribution 24 months, assistant conversations 12 months, logs 30 days.

→ Uninstall and everything is deleted after a 30-day grace period.

What we collect

Two categories, kept separate.

Merchant account data

Your store domain, store name, plan, billing status, the email address associated with the Shopify account, and your settings in Sconta. This is the information we need to run and bill the service, and to answer your support email.

Store operational data

Read from Shopify under the scopes you approve at install: product and variant identifiers and prices, collections, product tags, customer tags and segment membership, and order line items with totals and discounts applied.

We do not read or store customer names, email addresses, phone numbers, shipping addresses or payment details. Where a campaign qualifies on customer attributes, we hold the identifier and the tag — not the person's contact information.

Website visitors

This marketing site sets no advertising or analytics cookies and does not embed third-party trackers. Server request logs, including IP addresses, are kept for 30 days for abuse prevention.

Why, and on what basis

Pricing carts at checkoutPerformance of our contract with you
Campaign attribution reportingPerformance of our contract with you
Billing through ShopifyPerformance of our contract, and legal obligation
Support and debuggingLegitimate interest in operating the service
Assistant draftingPerformance of our contract, at your initiation
Abuse and fraud preventionLegitimate interest in service integrity

Where your customers' personal data is involved, you are the controller and we are your processor. The DPA governs that relationship and applies automatically.

The assistant

When you use the assistant, your prompt is sent to our AI provider along with structural metadata about your store — collection names, product tags, customer tag names, currency and timezone. Product prices are included where the prompt concerns them. No customer personal data is ever included in a prompt.

Our contract with the provider excludes training on our inputs or outputs. The provider retains request data only as long as needed to return a response and for its own limited abuse monitoring.

Conversations are stored in Canada for 12 months so you can revisit how a campaign was drafted. You can delete any conversation immediately, and deletion is permanent.

Retention

Campaign configurationWhile your account is active
Order attribution records24 months, then deleted
Assistant conversations12 months, or until you delete them
Application and request logs30 days
Encrypted backups35 days, rolling
Billing records7 years, as Canadian tax law requires

Uninstalling starts a 30-day grace period, in case the uninstall was accidental. After that everything but billing records is deleted, including backups as they age out.

Where data lives

All application data and backups are stored in Toronto, Canada. Nothing at rest is held outside Canada.

Canada holds an adequacy decision from the European Commission, so EU and UK merchants transfer personal data to us without needing Standard Contractual Clauses. Our AI provider processes prompts in the United States; that transfer is covered by SCCs, and is the only transfer of data outside Canada we make.

Who else sees it

Only the sub-processors needed to run the service: hosting, error monitoring, transactional email, and the AI provider. Each is listed by name, location and purpose on the sub-processors page, which we update at least 30 days before adding a new one.

We don't sell data, don't share it for advertising, and don't provide it to data brokers. If we were ever compelled to disclose data by legal process, we would notify you unless the law forbids it.

Your rights

You can ask for a copy of the data we hold about your store, ask us to correct it, or ask us to delete it. Depending on where you are, you may also have the right to restrict or object to certain processing, and to lodge a complaint with a supervisory authority — in Canada, the Office of the Privacy Commissioner.

Email [email protected]. We respond within five business days and complete requests within 30 days. There's no charge, and we don't require a specific form.

If one of your own customers contacts us directly with a request about their data, we'll forward it to you rather than acting on it — under the DPA you are the controller of that data, not us.

Security

Data is encrypted in transit with TLS 1.3 and at rest with AES-256. Access to production is limited to the two of us, requires hardware-key two-factor authentication, and is logged. Backups are encrypted and restore-tested quarterly.

We request the narrowest Shopify scopes the product needs, and never request write access to products or customers. The one write scope we hold is for discounts.

If we discover a breach affecting your data, we'll notify you within 48 hours of confirming it, with what we know at that point rather than waiting for a complete picture. To report a vulnerability, email [email protected] — we won't pursue good-faith research.

Changes & contact

Material changes are emailed to the address on your account at least 30 days before they take effect, and the version number at the top of this page increments. Older versions are available on request.

BioAnalix Inc., 100 King Street West, Toronto, ON M5X 1A9, Canada · [email protected]