Back to home

Legal

Privacy Policy

What nouz reads from your store, what it stores, who processes it and how to get it back or have it deleted.

Information provided under Articles 12 to 14 of the EU General Data Protection Regulation (GDPR / DSGVO), §§24 and 25 of the Austrian Data Protection Act (DSG), and §165 Telekommunikationsgesetz (TKG 2021).

Last updated 27 Aug 2026

ImprintTerms of Service
01

Who is responsible for your data

The controller under Article 4(7) GDPR is:

Controller
Ibrahim Ölmez (nouz, Einzelunternehmen)support@nouz.co

We have not appointed a Data Protection Officer, because the size and nature of the processing does not require one under Article 37 GDPR. For anything privacy related, write to support@nouz.co and a person reads it.

02

What we collect and why

2.1 Account data

When you sign up we collect and store:

  • Email address, for signing in, for the verification code and for transactional messages such as receipts.
  • Password, stored only as a salted hash by our authentication provider, Supabase. We never see it in plain text.
  • Store settings you configure, such as the store name and the time your nightly sync runs. Your currency and time zone are read from Shopify rather than typed.

Legal basis: Art. 6(1)(b) GDPR, necessary to perform the contract.

2.2 Your store data

Once you connect your shop, nouz reads the figures it needs to build your profit and loss statement. Access is read only: nouz never writes anything back to your Shopify store.

  • From Shopify: orders and their line items, prices, discounts, taxes and shipping charges; refunds and returns; payment transactions and the gateway that processed them; products, variants, SKUs, prices, weights and inventory levels; and shop settings such as currency and time zone.
  • From your ad accounts, if you connect them: daily spend per account and campaign from Meta, Google and TikTok. We read spend figures, not audiences and not creatives.
  • From you: the cost rules that turn revenue into profit. Unit costs, shipping rate cards, pick and pack rates, packaging, return processing, packaging levies, payment gateway fees, and your overhead.

This data is stored under your account. It is never sold, never shared with another customer, and never used to train machine learning models.

Legal basis: Art. 6(1)(b) GDPR, necessary to perform the contract.

2.3 What we do not collect about your customers

nouz stores no personal data about the people who buy from you

From each order we keep Shopify's internal customer id, which is a number and nothing else, so the app can tell a repeat order from a first order. We do not read or store names, email addresses, phone numbers, delivery addresses or payment details of your customers. The only piece of location we keep is the destination country of the parcel, because shipping rates and packaging levies are priced by country. That is a deliberate design decision, not an omission: it means a breach of nouz cannot expose your customer list.

2.4 Billing data

When you start a trial or a subscription we collect and store:

  • Your billing name, billing address, country and VAT ID where you give one.
  • Your Stripe customer id and subscription id.
  • Plan, status, trial end date and cancellation flag.
  • Invoice metadata: amounts, VAT rate, VAT country, reverse charge flag and the payment method fingerprint.

Card numbers, expiry dates and security codes are collected and stored by Stripe directly and never reach our servers. We only ever see the last four digits, for display.

Legal basis: Art. 6(1)(b) GDPR (contract performance) and Art. 6(1)(c) GDPR (legal obligation, invoice retention under §132 Bundesabgabenordnung).

2.5 Logs and technical data

  • Server access logs: IP address, user agent, timestamp and requested URL, kept for up to 30 days for security and abuse prevention.
  • Error reports sent to Sentry, scrubbed of user identifiers where technically possible.
  • Sync logs: which source was synced, when, how many records arrived and any error returned. These are about your store, not about a person.

Legal basis: Art. 6(1)(f) GDPR, our legitimate interest in keeping the service secure and diagnosable.

2.6 Cookies and analytics

Strictly necessary, set without asking because the service cannot work without them:

  • Supabase authentication cookies, which keep you signed in.
  • A cookie that records your analytics choice, so we do not ask again.

Legal basis: Art. 6(1)(b) GDPR and §165(3) TKG 2021, strictly necessary.

Product analytics, only with your consent: PostHog, for aggregate usage measurement such as which pages are opened and where a flow is abandoned. Data is stored in PostHog's EU region in Frankfurt. Until you consent, no analytics script captures anything and no analytics cookie is set. You can change your choice at any time.

We run no advertising pixels and no cross-site tracking on the product or on this website, and we send nothing about your business to an advertising network.

Legal basis: Art. 6(1)(a) GDPR and §165(3) TKG 2021, consent.

03

Who processes your data

We use the following sub-processors to run the service. All are bound by a data processing agreement under Article 28 GDPR, and none of them may use your data for their own purposes.

Sub-processorPurposeRegion
Supabase Inc.Database, authentication, encrypted credential storageEU (Frankfurt)
Vercel Inc.Web hosting and CDNEU (Frankfurt, fra1)
Stripe Payments Europe Ltd.Payment processing, invoicing, VAT determination via Stripe TaxIreland (EU)
Resend (Drip, Inc.)Transactional and notification emailEU (Frankfurt)
Sentry (Functional Software GmbH)Error monitoringEU region
PostHog Inc.Product analytics, only after your consentEU (Frankfurt); the contracting entity is US based

Separately, nouz reads data from the platforms you connect. You choose which of these to connect and you can disconnect any of them at any time. We hold an access credential for each connection and use it only to read the figures listed in section 2.2.

SourceWhat nouz readsAccess
ShopifyOrders, refunds, products, variants, inventory, payment transactions, shop settingsRead only
MetaDaily advertising spend per account and campaignRead only
GoogleDaily advertising spend per account and campaignRead only
TikTokDaily advertising spend per account and campaignRead only

We do not sell or rent your data to anyone, and we have no advertising business that could benefit from it.

04

Where your data is stored

Your account, your store data and your cost rules are stored in the European Union, in Frankfurt. The application is served from the same region.

Where a sub-processor's contracting entity sits outside the EU or the EEA, that transfer is covered by EU Standard Contractual Clauses under Article 46 GDPR, or by an adequacy decision under Article 45 GDPR where one applies. We will name the mechanism for any individual sub-processor on request.

05

How long we keep your data

  • Account, store and cost data: for as long as your account exists.
  • After you delete your account: the account is soft deleted for 30 days so you can change your mind, then permanently deleted along with all store data.
  • Invoices and billing events: 7 years, as required by §132 Bundesabgabenordnung. We cannot delete these earlier.
  • Server access logs: up to 30 days.
  • Support emails: up to 2 years after the last message in the thread.
06

Your rights

Under the GDPR you have the right to:

  • Access (Art. 15), a copy of the personal data we hold about you.
  • Rectification (Art. 16), correction of anything inaccurate.
  • Erasure (Art. 17), deletion of your data, subject to the retention obligations above.
  • Restriction (Art. 18), a pause on processing.
  • Portability (Art. 20), your data in a structured, machine-readable format.
  • Objection (Art. 21), to processing based on legitimate interest.
  • Withdrawal of consent at any time, where processing rests on consent.

You do not have to ask us to exercise the portability right: the app carries a full account export that gives you every dataset it holds, on every plan, at any time. Portability is a right, so it is never something we charge for.

For anything else, write to support@nouz.co. We answer within 30 days.

You may also complain to a supervisory authority. The Austrian one is:

Datenschutzbehörde
Barichgasse 40-421030 WienAustriadsb.gv.at
07

How your data is protected

Measures under Article 32 GDPR, in plain terms:

  • Every table carries row level security, scoped to your organisation, so one customer's query cannot reach another customer's rows.
  • The credentials for Shopify, Meta, Google and TikTok are encrypted at rest, decrypted only on the server at the moment of a call, never sent to the browser and never written to a log.
  • All traffic runs over TLS.
  • The Shopify connection requests read-only scopes, so even a compromised credential could not change your shop.
  • Payment card data never reaches our servers at all. Stripe holds it.
08

Children

nouz is a tool for people running a business. We do not knowingly collect data from anyone under 16. If you believe a minor has created an account, tell us and we will delete it.

09

Changes to this policy

When we make a material change we notify you by email and update the date at the top of this page. The current version is dated 27 Aug 2026. Continuing to use the service after a change means you accept the updated policy.

The rest of the paperwork

Three documents, and these are the other two.