ShopSnapAI
Features Pricing FAQ Support Open app
Privacy

Privacy Policy

How ShopSnapAI handles website, merchant, product, image-generation, billing, and support data.

Effective date

18 July 2026

Privacy questions:
info@shopsnapai.com

No ad trackingWe do not load advertising or behavioral analytics cookies on this website.
Purpose limitationShop and product data is used to provide the workflow selected by the merchant.
Merchant controlGenerated media is published only through actions initiated by the merchant.

1. Controller and service provider

Banida Shops UG, Sophie-Schoop-Weg 72, 21035 Hamburg, Germany, represented by Niklas Alexander Kather.

Email: info@shopsnapai.com. For public-site and account administration data, we act as controller. When we process Shopify data on a merchant’s instructions to provide the app, the merchant generally remains controller and we act as processor where applicable.

2. Data we process

  • Shop and installation data: shop domain and name, Shopify access token, granted scopes, installation state, locale, plan, subscription and usage status.
  • Product workflow data: Shopify product identifiers, titles, handles, product descriptions used for image context, source media URLs, media counts, selected products, generation settings, prompts, status and error messages.
  • Generated media: generated image files and related technical metadata required to upload and associate them with Shopify products.
  • Public image lab: uploaded source image, optional style note, a pseudonymous IP hash for rate limiting, processing status, and generated result. Temporary source files are deleted after processing; generated demo files and their rate-limit record are deleted automatically after approximately 24 hours.
  • Support and technical data: name, email, shop URL, request content, IP address, user agent, timestamps, operational logs and security events.

3. Purposes and legal bases

  • Providing installation, authentication, image generation, Shopify publishing, plan and support functions (Art. 6(1)(b) GDPR).
  • Protecting the service, preventing misuse, rate limiting, troubleshooting and maintaining reliable operations (Art. 6(1)(f) GDPR).
  • Accounting, tax, compliance and legal-defense obligations (Art. 6(1)(c) and (f) GDPR).
  • Optional processing based on consent, where we expressly request it (Art. 6(1)(a) GDPR); consent can be withdrawn prospectively.

For product and store data processed on a merchant’s instructions, the merchant determines the applicable legal basis and is responsible for its notices to affected individuals.

4. AI processing and recipients

To generate and analyze images, relevant source media, product context, and merchant instructions are transmitted to the configured AI service provider. Shopify receives generated media and app-related data when the app reads from or writes to the merchant’s store. Hosting, email, logging, and infrastructure providers may process data only as needed to operate the service.

We do not sell personal data. Providers are selected under contractual data-protection obligations. Where a recipient processes data outside the EEA, we rely on an applicable adequacy decision, approved safeguards such as Standard Contractual Clauses, or another lawful transfer mechanism.

5. Cookies and local storage

The public website does not use advertising or behavioral analytics trackers. Technically necessary storage may be used to secure forms, maintain a session, and remember that the cookie notice was acknowledged.

StoragePurposeTypical durationCategory
Laravel session cookieSession continuity, form validation and security.Session or configured session lifetime.Strictly necessary
XSRF security token, when setProtects form submissions against cross-site request forgery.Session-related.Strictly necessary
shopsnapai_cookie_notice_v1Remembers that the information banner was acknowledged.Until browser storage is cleared.Strictly necessary preference

You can remove browser storage in your browser settings. Blocking necessary storage may prevent forms or authenticated areas from working correctly.

6. Retention and deletion

We keep data only while needed for the app, security, support, legal obligations, or claims. Shopify access is revoked on uninstall. Store data is deleted or anonymized when no longer required and in response to valid Shopify compliance webhooks; statutory business records may be retained for the legally required period. Backup copies expire through the applicable backup cycle.

7. Security

We use measures appropriate to the risk, including encrypted transport, access controls, encrypted storage for secrets, signed webhook validation, logging, data minimization, and separation of merchant data. No internet service can guarantee absolute security.

8. Your rights

Subject to the GDPR, individuals may request access, rectification, erasure, restriction, portability, or object to certain processing. They may also lodge a complaint with a competent supervisory authority. Requests concerning customer data held for a merchant should first be directed to that merchant; we assist merchants with verified requests.

We do not use personal data for solely automated decisions that produce legal or similarly significant effects.

9. Changes

We may update this policy when the service, providers, or law changes. The current version and effective date are published on this page. Material changes affecting existing merchants will be communicated through an appropriate channel.

ShopSnapAI

AI-assisted product imagery built for focused Shopify workflows. © 2026 Banida Shops UG.

Terms Privacy Imprint Support
Privacy by default

We use only technically necessary session and security storage. No advertising or analytics cookies are set. Details