Qommerce logo

    Privacy Policy

    Last updated: November 4, 2025

    Qommerce.ai is a brand operated by shopeyeQ GmbH. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website and use our services, in compliance with the General Data Protection Regulation (GDPR) and other applicable EU data protection laws.

    1. Data Controller

    shopeyeQ GmbH

    Finksweg 51
    21129 Hamburg
    Germany

    2. Information We Collect

    2.1 Personal Data You Provide

    We collect information that you voluntarily provide to us when you:

    • Register for an account
    • Use our services
    • Subscribe to our newsletter
    • Fill out contact forms
    • Attend our events or webinars
    • Communicate with us

    This information may include:

    • Name and surname
    • Email address
    • Company name and job title
    • Phone number
    • Business address
    • Industry and interest areas
    • Any other information you choose to provide

    2.2 Automatically Collected Information

    When you access our website, we automatically collect certain information:

    • IP address
    • Browser type and version
    • Operating system
    • Referring URLs
    • Pages visited and time spent on pages
    • Device information
    • Cookies and similar tracking technologies

    2.3 Business Client Data

    If you are a business client using our services, we may process:

    • Sales and market data
    • Customer behavior insights
    • Competitive intelligence data
    • Other business analytics data as part of our services

    3. Legal Basis for Processing (GDPR)

    We process your personal data based on the following legal grounds:

    Consent (Article 6(1)(a) GDPR)

    For marketing communications, cookies, and newsletter subscriptions where you have given explicit consent.

    Contract Performance (Article 6(1)(b) GDPR)

    To provide our services, manage your account, and fulfill our contractual obligations.

    Legitimate Interests (Article 6(1)(f) GDPR)

    For analytics, fraud prevention, network security, and improving our services.

    Legal Obligation (Article 6(1)(c) GDPR)

    To comply with applicable laws, regulations, and legal processes.

    4. How We Use Your Information

    We use the collected information for the following purposes:

    • Service Delivery: To provide, maintain, and improve our platform and services
    • Customer Support: To respond to your inquiries and provide technical support
    • Account Management: To manage your account and provide personalized experiences
    • Communications: To send you updates, newsletters, and marketing communications (with your consent)
    • Analytics: To understand usage patterns and improve our services
    • Security: To protect against fraud, unauthorized access, and security threats
    • Legal Compliance: To comply with legal obligations and enforce our terms
    • Business Operations: To conduct internal research, analytics, and business intelligence

    5. Data Sharing and Disclosure

    We may share your information with:

    5.1 Service Providers

    We work with third-party service providers who assist us in:

    • Cloud hosting and infrastructure (e.g., AWS, Google Cloud)
    • Analytics and performance monitoring
    • Customer relationship management (e.g., HubSpot)
    • Email delivery and marketing automation
    • Payment processing

    All service providers are contractually bound to protect your data and comply with GDPR requirements.

    5.2 Business Transfers

    In the event of a merger, acquisition, or sale of assets, your information may be transferred to the new entity.

    5.3 Legal Requirements

    We may disclose your information when required by law, court order, or government request.

    5.4 With Your Consent

    We may share information for other purposes with your explicit consent.

    6. International Data Transfers

    Your data may be transferred to and processed in countries outside the European Economic Area (EEA). When we transfer data internationally, we ensure appropriate safeguards are in place:

    • Standard Contractual Clauses (SCCs): We use EU-approved SCCs with our data processors
    • Adequacy Decisions: We transfer data to countries with EU adequacy decisions
    • Additional Security Measures: We implement supplementary measures to ensure data protection

    7. Your Rights Under GDPR

    As a data subject in the EU, you have the following rights:

    Right to Access

    Request a copy of your personal data we hold

    Right to Rectification

    Correct inaccurate or incomplete data

    Right to Erasure

    Request deletion of your personal data

    Right to Restriction

    Limit how we use your data

    Right to Data Portability

    Receive your data in a structured format

    Right to Object

    Object to processing based on legitimate interests

    Right to Withdraw Consent

    Withdraw consent for data processing

    Right to Lodge a Complaint

    File a complaint with your data protection authority

    To exercise any of these rights, please contact us at [email protected]. We will respond to your request within one month.

    8. Data Retention

    We retain your personal data only for as long as necessary to fulfill the purposes outlined in this policy:

    • Account Data: Retained while your account is active and for 6 months after account closure
    • Marketing Data: Retained until you unsubscribe or withdraw consent
    • Business Records: Retained for 7 years to comply with legal and tax obligations
    • Analytics Data: Anonymized and retained for statistical purposes
    • Legal Hold: Data may be retained longer if required by law or legal proceedings

    9. Security Measures

    We implement appropriate technical and organizational measures to protect your data:

    • Encryption in transit and at rest
    • Access controls and authentication
    • Regular security assessments and audits
    • Employee training on data protection
    • Incident response procedures
    • Regular backups and disaster recovery plans

    10. Cookies and Tracking Technologies

    We use cookies and similar technologies. For detailed information, please see our Cookie Policy.

    11. Children's Privacy

    Our services are not directed to individuals under 16 years of age. We do not knowingly collect personal data from children. If you become aware that a child has provided us with personal data, please contact us immediately.

    12. Changes to This Privacy Policy

    We may update this Privacy Policy periodically. We will notify you of material changes by:

    • Posting the updated policy on our website
    • Updating the "Last Updated" date
    • Sending email notifications for significant changes

    Your continued use of our services after changes constitutes acceptance of the updated policy.

    13. Contact Us

    For questions, concerns, or to exercise your rights regarding your personal data, please contact us:

    Email: [email protected]

    Data Protection Officer: Available upon request

    Response Time: We aim to respond within 30 days

    14. Supervisory Authority

    You have the right to lodge a complaint with your local data protection authority if you believe we have not complied with applicable data protection laws.

    Cookie & Privacy Settings

    We respect your privacy. Choose which cookies you're comfortable with.

    Qommerce.ai uses cookies and similar technologies to enhance your browsing experience, analyze site traffic, and understand where our audiences come from. By clicking "Accept All", you consent to our use of cookies. You can also customize your preferences below.

    Learn more about our data practices in our Privacy Policy and Cookie Policy