Ecomify Privacy Policy
This policy explains what Ecomify collects, how we use connected platform data, how we secure it, and how users can request access or deletion.
Controller / responsible party
Responsible for data processing on this website and in the Ecomify service is:
Luca Bastisch
Ecomify
Neuss, NRW, Germany
Postal code: 41462
Email: info@ecomify.tech
What Ecomify is
Ecomify is an ecommerce operating system for merchants, operators, agencies, and teams. It combines campaign management, Shopify data, ad intelligence, analytics, and business monitoring into one software platform available at https://ecomify.tech.
When you create an Ecomify account or connect external providers such as Meta or Shopify, we process information required to operate the service and present your business data inside the product.
Information we collect
Depending on how you use Ecomify, we may collect and process:
- account and profile data such as email address, workspace membership, authentication state, and login activity
- session, cookie, and device data needed to keep users signed in and secure the service
- business and integration identifiers such as Shopify shop domains, Meta ad account IDs, page IDs, business IDs, and provider account labels
- campaign, advertising, analytics, store, product, customer, order, inventory, and commerce metrics pulled from connected providers
- OAuth tokens and integration credentials stored securely on the server side only
- technical logs, request metadata, diagnostics, abuse-prevention signals, and performance records needed to operate and secure the service
Meta and Shopify connected data
If you connect Meta, Shopify, or another provider, Ecomify receives the data and permissions you authorize through that provider. This may include ad account identifiers, campaign metrics, store domain details, products, orders, customers, inventory counts, and related business metadata.
Ecomify does not expose raw provider credentials in the browser. Access tokens are stored server-side and used only to provide authorized features, sync data, and maintain your connected workspace.
Meta/Facebook and Instagram-related data may include business, page, pixel, campaign, ad account, ad, spend, performance, and account selection data. Shopify-related data may include shop domain, shop profile information, products, collections, orders, customers, discounts, and inventory data depending on permissions granted.
Purposes of processing
We process personal and business-related data in order to:
- provide the contracted Ecomify service and maintain user accounts
- authenticate users, protect sessions, and secure connected workspaces
- connect external providers such as Meta, Shopify, and Apify and retrieve authorized business data
- display dashboards, analytics, reports, ad intelligence, and operational recommendations
- monitor reliability, detect abuse, debug incidents, and improve performance
- comply with legal obligations, enforce our terms, and respond to legitimate requests
GDPR legal bases
Where the GDPR applies, Ecomify processes data on the following legal bases, depending on the context:
- Art. 6(1)(b) GDPR — performance of a contract or steps prior to entering into a contract
- Art. 6(1)(f) GDPR — legitimate interests, including service security, fraud prevention, reliability, and product operations
- Art. 6(1)(a) GDPR — consent where optional technologies or communications rely on consent
- Art. 6(1)(c) GDPR — compliance with legal obligations where applicable
How we use information
We use the information we collect to:
- authenticate users and secure accounts
- connect and maintain Shopify, Meta, and other integrations
- display dashboards, analytics, ad intelligence, and store performance insights
- generate reports, summaries, alerts, and operational recommendations
- monitor service reliability, prevent abuse, and troubleshoot issues
Storage, protection, and sharing
Ecomify stores application data, integration metadata, and tokens using server-side infrastructure and service providers that help operate the platform. We apply technical and organizational safeguards designed to limit unauthorized access, disclosure, or misuse.
We share data only as needed with infrastructure, database, hosting, analytics, authentication, and automation providers that help us run Ecomify. This may include providers such as Vercel, Supabase or other database infrastructure, Meta, Shopify, Apify, and supporting technical processors used in the service. We do not sell personal data. We do not intentionally send raw OAuth tokens or provider credentials to the browser.
International transfers
Some processors or integrated services may process data outside the European Union or European Economic Area. Where this occurs, transfers are made only where a lawful transfer mechanism is available, such as adequacy decisions, contractual protections, or other safeguards used by the relevant provider.
Cookies, sessions, and authentication data
Ecomify uses cookies and session mechanisms to keep users signed in, complete OAuth flows, remember workspace state, and secure authenticated requests. These technologies are used for service operation, fraud prevention, and user experience.
Retention and user rights
We retain information for as long as needed to provide Ecomify, maintain records, protect the service, and comply with legal obligations. If you disconnect an integration or close your account, we will delete or anonymize information unless we must retain certain records for legal, security, fraud-prevention, or accounting reasons.
You may request access, correction, export, or deletion of your data by emailing info@ecomify.tech. Please include the account email used in Ecomify and any relevant workspace or integration details.
Security measures
Ecomify uses reasonable technical and organizational security measures designed to protect accounts, sessions, integration credentials, and stored service data. These measures may include access controls, server-side token storage, transport encryption, logging, and operational safeguards appropriate to the nature of the service.
Your GDPR rights
Where applicable, you may have rights to:
- request access to your data
- request correction of inaccurate data
- request deletion or restriction of processing
- object to certain processing based on legitimate interests
- receive a copy of certain data in portable form
- withdraw consent where processing is based on consent
- lodge a complaint with a supervisory authority
Right to withdraw consent and supervisory authority
If processing is based on consent, you may withdraw that consent at any time with effect for the future. You may also lodge a complaint with a competent data protection supervisory authority, in particular in the EU member state of your residence, place of work, or place of the alleged infringement.
Meta and Facebook data deletion
Users can disconnect Meta from within Ecomify where available, or remove Ecomify from Facebook settings. If you want server-side deletion confirmed, email info@ecomify.tech with the subject line Ecomify Data Deletion Request.
Shopify data deletion and disconnect
Users may disconnect Shopify within Ecomify where available. After disconnection, Ecomify will stop using the shop connection for future syncs. If you want stored server-side data deleted or anonymized, email info@ecomify.tech with the shop domain and account email so the request can be processed correctly.
Contact
For privacy questions or requests, contact info@ecomify.tech.