€35M online, run rate 2026, 6 FTE.Read how

    Security & privacy

    Your store data stays yours.

    Your data is stored in the EU. Nobody trains AI models on your store data. And nothing goes live in your store without your approval.

    • Stored in the EU
    • No training on your data
    • You approve

    Access to your store

    What we read, and what we write back.

    You install the Optivate app in your Shopify store. With it we read what's needed and, after your approval, make changes.

    • What we read

      Products, stock and orders from your Shopify store, every night. And where needed your other systems, such as your accounting or ad accounts.

    • What we write back

      Only what you approve: prices, product copy and translations.

    • In your name

      Your accounts stay in your name and under your control.

    • Revocable at any time

      You can revoke our access at any time. Optivate then stops working, fully or partly.

    Where your data lives

    In the EU, and not in a training set.

    • Stored in the EU

      We store the data Optivate uses with hosting providers in the EU.

    • AI through Anthropic and OpenAI

      We enable their zero-retention settings where available, so prompts and outputs don't linger with them.

    • No training on your data

      We don't train AI models on your store data, not even anonymised or aggregated. And we only use AI suppliers on terms under which they don't either.

    • Outside the EU with safeguards

      For AI processing, data sometimes goes outside the EU. Only with appropriate safeguards, such as the EU-US Data Privacy Framework or the standard contractual clauses.

    Who sees what

    Only the people working on your store.

    Everyone at our end who has access to your data is bound by confidentiality.

    • Only your team at our end

      Inside Optivate, access is limited to the team members working on your engagement.

    • Confidentiality

      Your store data, prices, margins, numbers, customer and supplier data and brand voice stay confidential. We never share them with other clients or third parties, not even after the agreement ends.

    • Encrypted and logged

      Encryption of connections and storage, access only for those who need it, and logging. We store keys and passwords securely.

    • A data breach? You hear it

      If a data breach affects your data, we tell you without undue delay. We aim for within 48 hours.

    Your rights

    Set down in writing.

    Everything here is also in our terms.

    • Data processing agreement

      Part C of our terms is the data processing agreement (article 28 GDPR). It forms part of every agreement. Rather use your own? We can discuss it.

      Read the data processing agreement
    • Sub-processors

      You get a current list on request. We notify you of a new sub-processor at least 30 days in advance.

    • Deleted within 30 days

      When the agreement ends or you remove the app, we delete your store data within 30 days, including from our backups. Except what we're legally required to keep, such as invoices.

    • Take your data with you

      Request an export before the end, for example of your settings or the ‘Activity’ overview. You receive it within the same 30 days in a common format.

    • Audits

      Once a year, you may have an independent expert check that we comply with the data processing agreement.

    Approvals

    Nothing goes live without your approval.

    What Optivate prepares is a proposal. It only goes to Shopify once you approve it, or when it falls under a rule you switched on. Also during the onboarding and the first 30 days.

    1. Optivate proposes

      Prices, promotions, copy, translations, product data and purchase orders land in your approval queue first, as a proposal.

    2. You approve

      One by one or in bulk. Or you switch on a rule yourself, such as automatic approval or a promotion that starts and ends by itself. You decide who may approve.

    3. You see what went live

      The ‘Activity’ overview shows which changes went live through Optivate, and when. Where possible we keep the previous value, so a change can be reversed.

    Questions

    What clients ask.

    All frequently asked questions

    Where is our data stored and who has access?

    Operational data (logs, configs) is hosted in the EU. LLM calls go through Anthropic and OpenAI; we enable their zero-retention settings where available, so prompts and outputs don't linger with them. Inside Optivate, access is limited to the team members working on your engagement. We're GDPR-compliant and sign a data processing agreement before we start working with your data.

    What if an AI system makes a mistake?

    Nothing goes live without your approval: prices, copy and purchase orders land in your approval queue first. We log every decision, so we can reconstruct exactly what happened. And if a meaningful mistake occurs, we help fix it directly.

    What if Optivate AI shuts down or gets acquired?

    That risk exists with every vendor. What we do about it: your data and accounts are in your name, not ours, and your data is stored in the EU. If we stop, or you do, you take your data with you. Another party can pick it up from there.

    Who owns what we build together?

    The platform and the modules, including the modules we build on request, remain ours. That way more stores can use them, and they keep getting better. Your data and accounts are in your name. If you stop, you take your data with you.

    Another question?

    Just ask us.

    In the demo we walk through what Optivate reads, what it writes back and who sees what.