1. Introduction
EcomSpy ("we", "us", "our") operates the website at ecomspy.se. This Privacy Policy explains what information we collect, how we use it, who we share it with, and your rights regarding your data.
EcomSpy is the data controller for the personal data described here. You can reach us at support@ecomspy.se.
2. Information We Collect
Account information:
- Email address
- Password (stored securely using bcrypt hashing)
- Name and profile picture (if you sign in with Google)
- Optionally, how you plan to use EcomSpy, if you tell us at signup
Billing information:
- Subscription status and billing period
- Payment details are handled entirely by Stripe and never stored on our servers
Tracking and notification settings:
- Which stores you choose to track, and your per-store notification preferences
- Whether you have enabled the daily email digest
- A Slack or Discord webhook URL, if you choose to configure one to receive notifications
Usage data:
- Saved filter presets and favorited stores
- API keys you generate for programmatic access — only a sha256 hash and a short display prefix are stored; the full key is shown to you once and never retained
Security and anti-abuse data:
- Your IP address is used to enforce rate limiting on requests
- At the moment you create an account, we record and store your IP address, browser user agent, and referring URL. This signup record is retained to detect and prevent fraudulent or abusive account creation, and is visible only to EcomSpy admins
Feedback / bug reports:
When you submit a report via the in-app feedback form, we collect:
- The text description and category you provide
- An optional screenshot if you attach one
- The page URL where you submitted the report
- Your browser user agent and viewport size (to help reproduce bugs)
- Your account ID (so we can follow up if needed)
Feedback reports are visible only to EcomSpy admins and are retained until the issue is resolved.
3. How We Use Your Information
- To create and manage your account
- To process subscription payments via Stripe
- To send email verification when you sign up
- To send you a daily email digest of changes to the stores you track, if you have it enabled
- To deliver notifications to a Slack or Discord webhook URL you have configured
- To prevent abuse through rate limiting and to detect fraudulent or abusive account creation
- To gate premium features (full store profiles, ad data, change history, store tracking, API and AI-assistant access) to active, verified subscribers
- To review and act on feedback / bug reports you submit
- To provide and improve our services
4. Legal Bases for Processing
If you are in the EU/EEA, we process your personal data on the following bases:
- Performance of a contract — creating and running your account, providing the Service, and processing your subscription.
- Legitimate interests — preventing fraud and abuse (rate limiting and the signup record), securing the Service, and improving it.
- Consent — optional features you switch on yourself, such as the email digest or a webhook integration. You can withdraw consent at any time in your settings.
- Legal obligation — retaining billing and tax records where the law requires it.
5. Third-Party Services
We use the following third-party services. Only the first four ever receive personal data about you:
- Stripe (United States) — Payment processing and subscription management. Receives your email address and payment details. Stripe's privacy policy applies to payment data.
- Google (United States) — Optional sign-in via Google OAuth. We receive your email, name, and profile picture from Google.
- Resend (EU region) — Transactional email: account verification and the daily tracked-store digest. Receives your email address in order to deliver these messages.
- Slack / Discord — Only if you choose to configure a webhook. In that case, notification content is sent to the webhook URL you provide, and that platform's privacy policy applies.
The following services process only publicly available store data — never your personal data:
- OpenAI — Classifying store data (for example, product niche). No personal user data is sent.
- Anthropic (Claude) — Generating campaign-structure analysis of public advertising data. No personal user data is sent.
- EnsembleData — Public TikTok profile statistics. No personal user data is sent.
- DigitalOcean Spaces & CDN (Frankfurt, EU) — Object storage and delivery of advertising creative media (images and videos) collected from public sources. No personal user data is stored there.
Our servers and data-collection infrastructure are operated on hosting from Hostinger, Hetzner, and DigitalOcean.
6. Where Your Data Is Processed
Our application servers, database, and media storage are located in the EU. Some of the processors listed above (Stripe, Google) are based in the United States, and your personal data is transferred to them for the purposes described. These transfers rely on the safeguards those providers have in place, such as the EU Standard Contractual Clauses and/or the EU–US Data Privacy Framework.
OpenAI, Anthropic, and EnsembleData receive no personal data about you, so no personal-data transfer occurs with those services.
7. Data Storage and Security
- Your data is stored on secure servers located in the EU
- Passwords are hashed with bcrypt and never stored in plain text
- Authentication uses signed JWT tokens stored in your browser's local storage, which expire after 7 days
- We do not use tracking cookies or third-party analytics
8. Data Retention and Deletion
We retain your account data for as long as your account is active.
You can permanently delete your account yourself at any time, from Settings → Danger zone. Deletion is immediate and irreversible: your account and all associated data (favorites, saved filters, tracked stores, notification settings, webhook configuration, API keys, connected apps, feedback reports, and your signup record) are erased from our database, and any active subscription is cancelled at the same time. If you would rather we did it for you, contact us at the email below.
If you sign up with email and do not verify your email address within 7 days, your account is automatically deleted, along with any API keys associated with it.
9. Your Rights
You have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Delete your account and all associated data — you can do this yourself at any time from Settings → Danger zone, without contacting us
- Request a copy of your data in a portable format
- Object to, or request restriction of, certain processing
- Withdraw consent for optional features (such as the email digest or webhooks) at any time
- Manage your subscription and payment methods via the Stripe billing portal
If you are in the EU/EEA and believe we have handled your data improperly, you also have the right to lodge a complaint with your national data protection authority. In Sweden this is the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY).
10. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated revision date.
11. Contact
If you have questions about this Privacy Policy, contact us at support@ecomspy.se.