Privacy Policy - B2B Wholesale Discounts Shopify App

Privacy Policy

Last updated: January 10, 2025

This Policy describes the Personal Information that Conspire LLC (“we,” “us,” or “our”) collects from you through our Shopify App (the “Services”), how we use and disclose such Personal Information, your rights and choices regarding your Personal Information, and how you can contact us if you have any questions or concerns.

1. Collecting Personal Information

When you install and use our Shopify App, we collect certain information necessary to provide our services. This includes (but may not be limited to):

Name

Company Name

Company Website URL

Email Address

Time Zone

We require this information to:

• Activate and manage your account

• Communicate with you about your account and our services

• Accurately show dates or other time-sensitive information

• Generate and process invoices

If you are a resident of the European Economic Area (“EEA”), you have certain rights regarding access to, correction of, and erasure of the Personal Information we hold about you, as well as the right to request its portability. To exercise these rights, please contact us through the information provided in the “Contact” section below.

2. Sharing Personal Information

We may share your Personal Information with third-party service providers who assist us in providing our Services to you. For example, we may share your Personal Information to:

• Comply with applicable laws and regulations

• Respond to a subpoena, search warrant, or other lawful request

• Protect our rights and fulfill our contractual obligations

3. Data Protection – Our Data Processing Agreement

Under the EU General Data Protection Regulation (GDPR) and the UK Data Protection Act (DPA), you (the “Merchant”) act as the Data Controller, and our Shopify App (the “Service”) acts as the Data Processor. We process data on your behalf, such as reading Shopify customer data to facilitate transactions. Specifically, we will:

1. Only process personal data with your knowledge and instructions.

2. Maintain technical and organizational measures to prevent unauthorized or unlawful processing of personal data, and regularly assess these measures.

3. Assist you in responding to data subject requests under the GDPR or DPA. Please contact us using the details below.

4. Delete any personal data within the timeframe specified in our Terms of Service once this agreement ends.

5. Not sell, lease, rent, or otherwise provide personal information to third parties without your consent, except as required by law or where necessary for optional services that you explicitly agree to (e.g., payment processing).

6. In the event of a data breach, notify you within 2 business days, detailing the severity and scope of the breach.

4. Sub-Processors

We may share data with authorized third-party service companies working on our behalf. These sub-processors need access to personal data only to perform their tasks, and must abide by our data privacy and security requirements. Examples of sub-processors may include:

Cloud Hosting Providers (e.g., Vercel, AWS)

Analytics Tools (e.g., Google Analytics)

Billing and Payment Processing (e.g., Stripe)

Customer Relationship Management (e.g., Slack, Intercom)

5. Lawful Basis

If you are a resident of the EEA, we process your Personal Information under the following lawful bases:

Your consent

Performance of the contract between you and our App

Compliance with legal obligations

Protection of your vital interests

Performance of a task carried out in the public interest

Legitimate interests that do not override your fundamental rights and freedoms

6. Retention

We take steps to delete or anonymize your Personal Information once it is no longer needed for the purposes for which it was collected, unless a longer retention period is required by law. Factors determining retention include:

• The type of service you receive

• The nature and length of our relationship

• Legal or regulatory retention requirements

• Relevant statutes of limitations

7. Automatic Decision-Making

If you are a resident of the EEA, you have the right to object to processing based solely on automated decision-making (including profiling) that significantly affects you. We do not engage in fully automated decision-making that has a legal or otherwise significant effect using customer data.

However, our Services may include measures such as:

• Temporary blocking (“denylisting”) of IP addresses associated with repeated failed transactions (for a limited number of hours)

• Temporary blocking of credit cards associated with denylisted IP addresses (for a limited number of days)

8. Cookies

A cookie is a small file that’s downloaded to your device when you visit certain websites. We use a variety of cookies—functional, performance, advertising, and social media/content—to improve your experience.

Cookies on Our Main Website

• We may use Google Analytics or similar cookies to better understand usage patterns on our main site.

Cookies When Using Our Shopify App

• We may store data in the customer’s browser solely for authentication purposes with our API. We do not utilize third-party tracking cookies through our App on your storefront.

You can block or delete cookies using your browser settings, although doing so may impact site functionality.

9. Do Not Track

There is no universal industry standard on how to respond to “Do Not Track” signals. Consequently, we do not alter our data collection and usage practices when we detect such a signal.

10. Security, Data & Availability

We use security-first principles when designing our software and infrastructure. Our systems may be securely hosted using reputable cloud service providers (e.g., Google Cloud, AWS). Data is generally encrypted at rest and in transit. We regularly assess and update our security measures to safeguard user data.

11. Changes

We may update this Privacy Policy from time to time to reflect changes in our practices or for other operational, legal, or regulatory reasons. Any significant changes will be indicated by updating the date at the top of this Policy.

12. Email Communications

By registering an account with us, you may receive certain email communications from Conspire LLC, including marketing messages. You can unsubscribe at any time by clicking the “unsubscribe” link in those emails. For questions regarding our email practices, please contact us.

13. Contact

For more information about our privacy practices, if you have questions, or if you would like to make a complaint, please contact us by email or mail:

Conspire LLC

1401 Union St. #3609

San Diego, CA 92101

Email: support@conspireagency.com

If you are not satisfied with our response to your complaint, you have the right to lodge a complaint with your local data protection authority.