Security & privacy
Your store data stays yours.
Your data is stored in the EU. Nobody trains AI models on your store data. And nothing goes live in your store without your approval.
- Stored in the EU
- No training on your data
- You approve
Access to your store
What we read, and what we write back.
You install the Optivate app in your Shopify store. With it we read what's needed and, after your approval, make changes.
What we read
Products, stock and orders from your Shopify store, every night. And where needed your other systems, such as your accounting or ad accounts.
What we write back
Only what you approve: prices, product copy and translations.
In your name
Your accounts stay in your name and under your control.
Revocable at any time
You can revoke our access at any time. Optivate then stops working, fully or partly.
Where your data lives
In the EU, and not in a training set.
Stored in the EU
We store the data Optivate uses with hosting providers in the EU.
AI through Anthropic and OpenAI
We enable their zero-retention settings where available, so prompts and outputs don't linger with them.
No training on your data
We don't train AI models on your store data, not even anonymised or aggregated. And we only use AI suppliers on terms under which they don't either.
Outside the EU with safeguards
For AI processing, data sometimes goes outside the EU. Only with appropriate safeguards, such as the EU-US Data Privacy Framework or the standard contractual clauses.
Who sees what
Only the people working on your store.
Everyone at our end who has access to your data is bound by confidentiality.
Only your team at our end
Inside Optivate, access is limited to the team members working on your engagement.
Confidentiality
Your store data, prices, margins, numbers, customer and supplier data and brand voice stay confidential. We never share them with other clients or third parties, not even after the agreement ends.
Encrypted and logged
Encryption of connections and storage, access only for those who need it, and logging. We store keys and passwords securely.
A data breach? You hear it
If a data breach affects your data, we tell you without undue delay. We aim for within 48 hours.
Your rights
Set down in writing.
Everything here is also in our terms.
Data processing agreement
Part C of our terms is the data processing agreement (article 28 GDPR). It forms part of every agreement. Rather use your own? We can discuss it.
Read the data processing agreementSub-processors
You get a current list on request. We notify you of a new sub-processor at least 30 days in advance.
Deleted within 30 days
When the agreement ends or you remove the app, we delete your store data within 30 days, including from our backups. Except what we're legally required to keep, such as invoices.
Take your data with you
Request an export before the end, for example of your settings or the ‘Activity’ overview. You receive it within the same 30 days in a common format.
Audits
Once a year, you may have an independent expert check that we comply with the data processing agreement.
Approvals
Nothing goes live without your approval.
What Optivate prepares is a proposal. It only goes to Shopify once you approve it, or when it falls under a rule you switched on. Also during the onboarding and the first 30 days.
Optivate proposes
Prices, promotions, copy, translations, product data and purchase orders land in your approval queue first, as a proposal.
You approve
One by one or in bulk. Or you switch on a rule yourself, such as automatic approval or a promotion that starts and ends by itself. You decide who may approve.
You see what went live
The ‘Activity’ overview shows which changes went live through Optivate, and when. Where possible we keep the previous value, so a change can be reversed.
Where is our data stored and who has access?
Operational data (logs, configs) is hosted in the EU. LLM calls go through Anthropic and OpenAI; we enable their zero-retention settings where available, so prompts and outputs don't linger with them. Inside Optivate, access is limited to the team members working on your engagement. We're GDPR-compliant and sign a data processing agreement before we start working with your data.
What if an AI system makes a mistake?
Nothing goes live without your approval: prices, copy and purchase orders land in your approval queue first. We log every decision, so we can reconstruct exactly what happened. And if a meaningful mistake occurs, we help fix it directly.
What if Optivate AI shuts down or gets acquired?
That risk exists with every vendor. What we do about it: your data and accounts are in your name, not ours, and your data is stored in the EU. If we stop, or you do, you take your data with you. Another party can pick it up from there.
Who owns what we build together?
The platform and the modules, including the modules we build on request, remain ours. That way more stores can use them, and they keep getting better. Your data and accounts are in your name. If you stop, you take your data with you.
Another question?
Just ask us.
In the demo we walk through what Optivate reads, what it writes back and who sees what.