Skip to main content
Privacy Policy

Ecomify Privacy Policy

This policy explains what Ecomify collects, how we use connected platform data, how we secure it, and how users can request access or deletion.

Effective date: July 13, 2026

Controller / responsible party

Responsible for data processing on this website and in the Ecomify service is:

Luca Bastisch
Ecomify
Neuss, NRW, Germany
Postal code: 41462
Email: info@ecomify.tech

What Ecomify is

Ecomify is an ecommerce operating system for merchants, operators, agencies, and teams. It combines campaign management, Shopify data, ad intelligence, analytics, and business monitoring into one software platform available at https://ecomify.tech.

When you create an Ecomify account or connect external providers such as Meta or Shopify, we process information required to operate the service and present your business data inside the product.

Information we collect

Depending on how you use Ecomify, we may collect and process:

  • account and profile data such as email address, workspace membership, authentication state, and login activity
  • session, cookie, and device data needed to keep users signed in and secure the service
  • business and integration identifiers such as Shopify shop domains, Meta ad account IDs, page IDs, business IDs, and provider account labels
  • campaign, advertising, analytics, store, product, customer, order, inventory, and commerce metrics pulled from connected providers
  • OAuth tokens and integration credentials stored securely on the server side only
  • technical logs, request metadata, diagnostics, abuse-prevention signals, and performance records needed to operate and secure the service

Meta and Shopify connected data

If you connect Meta, Shopify, or another provider, Ecomify receives the data and permissions you authorize through that provider. This may include ad account identifiers, campaign metrics, store domain details, products, orders, customers, inventory counts, and related business metadata.

Ecomify does not expose raw provider credentials in the browser. Access tokens are stored server-side and used only to provide authorized features, sync data, and maintain your connected workspace.

Meta/Facebook and Instagram-related data may include business, page, pixel, campaign, ad account, ad, spend, performance, and account selection data. Shopify-related data may include shop domain, shop profile information, products, collections, orders, customers, discounts, and inventory data depending on permissions granted.

Purposes of processing

We process personal and business-related data in order to:

  • provide the contracted Ecomify service and maintain user accounts
  • authenticate users, protect sessions, and secure connected workspaces
  • connect external providers such as Meta, Shopify, and Apify and retrieve authorized business data
  • display dashboards, analytics, reports, ad intelligence, and operational recommendations
  • monitor reliability, detect abuse, debug incidents, and improve performance
  • comply with legal obligations, enforce our terms, and respond to legitimate requests

GDPR legal bases

Where the GDPR applies, Ecomify processes data on the following legal bases, depending on the context:

  • Art. 6(1)(b) GDPR — performance of a contract or steps prior to entering into a contract
  • Art. 6(1)(f) GDPR — legitimate interests, including service security, fraud prevention, reliability, and product operations
  • Art. 6(1)(a) GDPR — consent where optional technologies or communications rely on consent
  • Art. 6(1)(c) GDPR — compliance with legal obligations where applicable

How we use information

We use the information we collect to:

  • authenticate users and secure accounts
  • connect and maintain Shopify, Meta, and other integrations
  • display dashboards, analytics, ad intelligence, and store performance insights
  • generate reports, summaries, alerts, and operational recommendations
  • monitor service reliability, prevent abuse, and troubleshoot issues

Storage, protection, and sharing

Ecomify stores application data, integration metadata, and tokens using server-side infrastructure and service providers that help operate the platform. We apply technical and organizational safeguards designed to limit unauthorized access, disclosure, or misuse.

We share data only as needed with infrastructure, database, hosting, analytics, authentication, and automation providers that help us run Ecomify. This may include providers such as Vercel, Supabase or other database infrastructure, Meta, Shopify, Apify, and supporting technical processors used in the service. We do not sell personal data. We do not intentionally send raw OAuth tokens or provider credentials to the browser.

International transfers

Some processors or integrated services may process data outside the European Union or European Economic Area. Where this occurs, transfers are made only where a lawful transfer mechanism is available, such as adequacy decisions, contractual protections, or other safeguards used by the relevant provider.

Cookies, sessions, and authentication data

Ecomify uses cookies and session mechanisms to keep users signed in, complete OAuth flows, remember workspace state, and secure authenticated requests. These technologies are used for service operation, fraud prevention, and user experience.

Retention and user rights

We retain information for as long as needed to provide Ecomify, maintain records, protect the service, and comply with legal obligations. If you disconnect an integration or close your account, we will delete or anonymize information unless we must retain certain records for legal, security, fraud-prevention, or accounting reasons.

You may request access, correction, export, or deletion of your data by emailing info@ecomify.tech. Please include the account email used in Ecomify and any relevant workspace or integration details.

Security measures

Ecomify uses reasonable technical and organizational security measures designed to protect accounts, sessions, integration credentials, and stored service data. These measures may include access controls, server-side token storage, transport encryption, logging, and operational safeguards appropriate to the nature of the service.

Your GDPR rights

Where applicable, you may have rights to:

  • request access to your data
  • request correction of inaccurate data
  • request deletion or restriction of processing
  • object to certain processing based on legitimate interests
  • receive a copy of certain data in portable form
  • withdraw consent where processing is based on consent
  • lodge a complaint with a supervisory authority

Right to withdraw consent and supervisory authority

If processing is based on consent, you may withdraw that consent at any time with effect for the future. You may also lodge a complaint with a competent data protection supervisory authority, in particular in the EU member state of your residence, place of work, or place of the alleged infringement.

Meta and Facebook data deletion

Users can disconnect Meta from within Ecomify where available, or remove Ecomify from Facebook settings. If you want server-side deletion confirmed, email info@ecomify.tech with the subject line Ecomify Data Deletion Request.

Shopify data deletion and disconnect

Users may disconnect Shopify within Ecomify where available. After disconnection, Ecomify will stop using the shop connection for future syncs. If you want stored server-side data deleted or anonymized, email info@ecomify.tech with the shop domain and account email so the request can be processed correctly.

Contact

For privacy questions or requests, contact info@ecomify.tech.

Questions about these policies can be sent to info@ecomify.tech.