Legal
Privacy Policy
What nouz reads from your store, what it stores, who processes it and how to get it back or have it deleted.
Information provided under Articles 12 to 14 of the EU General Data Protection Regulation (GDPR / DSGVO), §§24 and 25 of the Austrian Data Protection Act (DSG), and §165 Telekommunikationsgesetz (TKG 2021).
Who is responsible for your data
The controller under Article 4(7) GDPR is:
- Controller
- Ibrahim Ölmez (nouz, Einzelunternehmen)support@nouz.co
We have not appointed a Data Protection Officer, because the size and nature of the processing does not require one under Article 37 GDPR. For anything privacy related, write to support@nouz.co and a person reads it.
What we collect and why
2.1 Account data
When you sign up we collect and store:
- Email address, for signing in, for the verification code and for transactional messages such as receipts.
- Password, stored only as a salted hash by our authentication provider, Supabase. We never see it in plain text.
- Store settings you configure, such as the store name and the time your nightly sync runs. Your currency and time zone are read from Shopify rather than typed.
Legal basis: Art. 6(1)(b) GDPR, necessary to perform the contract.
2.2 Your store data
Once you connect your shop, nouz reads the figures it needs to build your profit and loss statement. Access is read only: nouz never writes anything back to your Shopify store.
- From Shopify: orders and their line items, prices, discounts, taxes and shipping charges; refunds and returns; payment transactions and the gateway that processed them; products, variants, SKUs, prices, weights and inventory levels; and shop settings such as currency and time zone.
- From your ad accounts, if you connect them: daily spend per account and campaign from Meta, Google and TikTok. We read spend figures, not audiences and not creatives.
- From you: the cost rules that turn revenue into profit. Unit costs, shipping rate cards, pick and pack rates, packaging, return processing, packaging levies, payment gateway fees, and your overhead.
This data is stored under your account. It is never sold, never shared with another customer, and never used to train machine learning models.
Legal basis: Art. 6(1)(b) GDPR, necessary to perform the contract.
2.3 What we do not collect about your customers
nouz stores no personal data about the people who buy from you
From each order we keep Shopify's internal customer id, which is a number and nothing else, so the app can tell a repeat order from a first order. We do not read or store names, email addresses, phone numbers, delivery addresses or payment details of your customers. The only piece of location we keep is the destination country of the parcel, because shipping rates and packaging levies are priced by country. That is a deliberate design decision, not an omission: it means a breach of nouz cannot expose your customer list.
2.4 Billing data
When you start a trial or a subscription we store your plan, its status, the trial end date and whether it has been cancelled. What else we hold depends on who bills you:
- Billed through Shopify, when you install nouz from the Shopify App Store: your shop's domain and Shopify's id for the subscription. Shopify is the billing processor here, for billing data only: it charges the plan on your Shopify invoice and collects the payment, so we receive no payment details and no billing address.
- Billed by us directly: your billing name, billing address, country and VAT ID where you give one; your Stripe customer id and subscription id; and invoice metadata: amounts, VAT rate, VAT country, reverse charge flag and the payment method fingerprint.
Card numbers, expiry dates and security codes are collected and stored by Stripe directly and never reach our servers. We only ever see the last four digits, for display.
Legal basis: Art. 6(1)(b) GDPR (contract performance) and Art. 6(1)(c) GDPR (legal obligation, invoice retention under §132 Bundesabgabenordnung).
2.5 Logs and technical data
- Server access logs: IP address, user agent, timestamp and requested URL, kept for up to 30 days for security and abuse prevention.
- Abuse limits: the forms that sign you in or send email, and a few other endpoints, count requests per IP address so they cannot be used to flood inboxes or the service. Each count covers at most a day and is deleted within two days.
- Error reports sent to Sentry, scrubbed of user identifiers where technically possible.
- Sync logs: which source was synced, when, how many records arrived and any error returned. These are about your store, not about a person.
Legal basis: Art. 6(1)(f) GDPR, our legitimate interest in keeping the service secure and diagnosable.
2.6 Cookies and analytics
Strictly necessary, set without asking because the service cannot work without them:
- Supabase authentication cookies, which keep you signed in.
- A cookie that records your analytics choice, so we do not ask again.
Legal basis: Art. 6(1)(b) GDPR and §165(3) TKG 2021, strictly necessary.
Page view statistics, without cookies: Vercel Web Analytics counts how often the pages of this website and of the product are opened, so we can see which pages are read and which are never found. It sets no cookie and stores nothing on your device. With each page view it records the time, the page's address with any query string or fragment removed, the referring website, your approximate location (country, region and city), and your browser, operating system and device type. It tells one visit from another only by a hash of the request that is discarded after 24 hours, and nothing it records is tied to your account or to your IP address. We see aggregated counts, never an individual visitor.
Legal basis: Art. 6(1)(f) GDPR, our legitimate interest in knowing which pages are used, so we can improve them.
Product analytics, only with your consent: PostHog, for measuring how the product is used: which pages are opened, what is clicked, where a flow is abandoned, and recordings of the screen (session recordings). In recordings every digit is replaced before it leaves your browser, so no amount, count or percentage is recorded, and nothing you type is recorded either. The data travels through nouz's own domain and is stored in PostHog's EU region in Frankfurt. Until you consent, no analytics script captures anything and no analytics cookie is set. You can change your choice at any time in Settings → Profile; withdrawing stops the recording at once and deletes PostHog's cookie and stored data on that device.
We run no advertising pixels and no cross-site tracking on the product or on this website, and we send nothing about your business to an advertising network.
Legal basis: Art. 6(1)(a) GDPR and §165(3) TKG 2021, consent.
2.7 Data from Google
If you connect Google Ads, nouz receives a credential for the Google Ads API and uses it to read two things: the Google Ads accounts your Google login can access, with each account's id, name and currency, and the daily cost of each campaign, with its name, in the accounts you choose to sync. We receive nothing else from your Google account: not its email address, not your contacts and nothing from any other Google service. nouz never creates, changes or deletes anything in your Google Ads account.
We use this data only to show your marketing costs wherever nouz shows them: your profit and loss statement, Insights, the emails and reports you set up, and your exports. The credential is encrypted at rest and never sent to the browser. The spend figures are stored with the rest of your store data in the EU, and are shared only with the sub-processors in section 3, which run the service, and with the recipients you add to your own reports.
We do not sell this data or transfer it to advertising platforms, data brokers or other resellers, and we do not use it to serve ads, to judge creditworthiness or for lending, or to train machine learning models. No person at nouz reads it unless you ask us to, for example in a support request, or unless that is necessary to investigate a bug or abuse, or to comply with the law.
nouz's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
You can disconnect Google Ads at any time in Settings → Integrations. When you disconnect the last account connected through a Google login, nouz deletes that login's credential. You can also revoke nouz's access from your Google account at myaccount.google.com/permissions. Spend already imported stays in your history and is kept as described in section 5.
Legal basis: Art. 6(1)(b) GDPR, necessary to perform the contract.
2.8 The waitlist
Until nouz is listed in the Shopify App Store, the sign-up page puts you on a waitlist instead of opening an account. When you join it we store:
- Your email address.
- Where you joined from: the sign-up page itself, or the plan you chose on the pricing page.
- When you joined.
We send nothing to that address when you join. The operator of nouz receives a short email notice that a new entry arrived. The list is used once, to tell you when nouz opens, and is then deleted. To be removed before then, write to support@nouz.co. The form is protected against abuse by Cloudflare Turnstile and by a limit on how often one IP address can submit it.
Legal basis: Art. 6(1)(b) GDPR, steps taken at your request before entering into a contract.
Who processes your data
We use the following sub-processors to run the service. All are bound by a data processing agreement under Article 28 GDPR, and none of them may use your data for their own purposes.
| Sub-processor | Purpose | Region |
|---|---|---|
| Supabase Inc. | Database, authentication, encrypted credential storage | EU (Frankfurt) |
| Vercel Inc. | Web hosting and CDN; page view statistics without cookies (Vercel Web Analytics) | EU (Frankfurt, fra1) for hosting; its global network for the statistics; the contracting entity is US based |
| Stripe Payments Europe Ltd. | Payment processing, invoicing, VAT determination via Stripe Tax | Ireland (EU) |
| Resend (Drip, Inc.) | Transactional and notification email | EU (Frankfurt) |
| Sentry (Functional Software GmbH) | Error monitoring | EU region |
| PostHog Inc. | Product analytics and session recordings, only after your consent | EU (Frankfurt); the contracting entity is US based |
| Cloudflare, Inc. | Bot protection (Turnstile) on the sign-up, waitlist, login and password reset forms | Global network; the contracting entity is US based |
| Calendly LLC | Booking calls with your account manager, only when you book one | United States |
Shopify, for App Store billing. If you install nouz from the Shopify App Store, Shopify is the billing processor: it charges your subscription on your Shopify invoice and collects the payment on our behalf. For this it handles billing data only, meaning the plan your store is on, its status and its charges, under the Shopify Partner Program Agreement and its own privacy policy. We send Shopify none of your store data.
Separately, nouz reads data from the platforms you connect. You choose which of these to connect and you can disconnect any of them at any time. We hold an access credential for each connection and use it only to read the figures listed in section 2.2.
| Source | What nouz reads | Access |
|---|---|---|
| Shopify | Orders, refunds, products, variants, inventory, payment transactions, shop settings | Read only |
| Meta | Daily advertising spend per account and campaign | Read only |
| Daily advertising spend per account and campaign | Read only | |
| TikTok | Daily advertising spend per account and campaign | Read only |
We do not sell or rent your data to anyone, and we have no advertising business that could benefit from it.
Where your data is stored
Your account, your store data and your cost rules are stored in the European Union, in Frankfurt. The application is served from the same region.
Where a sub-processor's contracting entity sits outside the EU or the EEA, that transfer is covered by EU Standard Contractual Clauses under Article 46 GDPR, or by an adequacy decision under Article 45 GDPR where one applies. We will name the mechanism for any individual sub-processor on request.
How long we keep your data
- Account, store and cost data: for as long as your account exists.
- After you delete your account: the account is soft deleted for 30 days so you can change your mind, then permanently deleted along with all store data.
- After you uninstall the nouz app in Shopify: Shopify tells us 48 hours later, and we then delete the orders, refunds, payments, daily figures and exports synced from that store. The cost rules you entered and your product catalogue with its costs stay in your account, so a reconnect does not start from nothing, until you delete the store or the account.
- Invoices and billing events: 7 years, as required by §132 Bundesabgabenordnung. We cannot delete these earlier.
- The waitlist: until we have sent the one email that says nouz is open, then deleted.
- Server access logs: up to 30 days.
- Page view statistics: the hash that tells one visit from another is discarded after 24 hours; the counts kept after that identify nobody.
- Support emails: up to 2 years after the last message in the thread.
Your rights
Under the GDPR you have the right to:
- Access (Art. 15), a copy of the personal data we hold about you.
- Rectification (Art. 16), correction of anything inaccurate.
- Erasure (Art. 17), deletion of your data, subject to the retention obligations above.
- Restriction (Art. 18), a pause on processing.
- Portability (Art. 20), your data in a structured, machine-readable format.
- Objection (Art. 21), to processing based on legitimate interest.
- Withdrawal of consent at any time, where processing rests on consent.
You do not have to ask us to exercise the portability right: the app carries a full account export that gives you every dataset it holds, on every plan, at any time. Portability is a right, so it is never something we charge for.
For anything else, write to support@nouz.co. We answer within 30 days.
You may also complain to a supervisory authority. The Austrian one is:
- Datenschutzbehörde
- Barichgasse 40-421030 WienAustriadsb.gv.at
How your data is protected
Measures under Article 32 GDPR, in plain terms:
- Every table carries row level security, scoped to your organisation, so one customer's query cannot reach another customer's rows.
- The credentials for Shopify, Meta, Google and TikTok are encrypted at rest, decrypted only on the server at the moment of a call, never sent to the browser and never written to a log.
- All traffic runs over TLS: between your browser and nouz, between nouz and the platforms you connect, and between our servers and the database.
- Data at rest is encrypted by our database provider, Supabase.
- The Shopify connection requests read-only scopes, so even a compromised credential could not change your shop.
- Payment details never reach our servers at all: Shopify holds them for App Store billing, and Stripe for direct billing.
Children
nouz is a tool for people running a business. We do not knowingly collect data from anyone under 16. If you believe a minor has created an account, tell us and we will delete it.
Changes to this policy
When we make a material change we notify you by email and update the date at the top of this page. The current version is dated 27 Sep 2026. Continuing to use the service after a change means you accept the updated policy.
The rest of the paperwork
Three documents, and these are the other two.