Privacy
Effective · Shopdeck, operated by Merravè
This page explains what Shopdeck (operated by Merravè, Belgium / Netherlands) stores, why, and how it is protected. Contact: merrave.ecom@gmail.com.
What we store
- Account data: your email address, a hashed password (handled by Supabase Auth) and sign-in timestamps.
- Workspace data: workspace names, memberships and roles, invitations, non-secret settings (currency, time zone, budget caps).
- Connected-account credentials: API tokens and keys you enter in Setup. They are encrypted with AES-256-GCM before they reach the database; the database never holds plaintext and the interface only ever shows the last four characters.
- Tool data: orders, products, refunds and ad spend read from your Shopify and ad accounts; campaigns you build; visitor events from your own storefront when you install the tracking snippet; public competitor ads (metadata and links only, no media files) from official ad libraries.
- Audit log: who changed credentials, members, roles or data, and when.
Where the data comes from
Only from official APIs (Shopify Admin API, Meta Marketing API and Ad Library API, TikTok Business API and Commercial Content API, WhatsApp Cloud API, Anthropic API) and from data you provide or import yourself. Shopdeck does not scrape websites.
How it is used
- To show you your own figures, build campaigns you ask for, and send alerts you configured.
- Optional AI assistance (Claude) receives product names and ad copy for normalisation and summaries, only when you connected an API key.
- We do not sell data, do not use it for advertising, and do not share one workspace's data with another.
Isolation and access
- Every record belongs to exactly one workspace. Database row-level security ensures a workspace can only read and write its own rows.
- Only members you invited can see a workspace; only admins and owners can see or change credentials.
- Hosting: Vercel (application) and Supabase (database and authentication), both in the EU region.
Retention and deletion
- Data stays for as long as the workspace exists. Deleting a workspace removes its data, credentials and invitations.
- You can clear any connected-account credential at any time in Setup.
- To delete your account entirely, email us; we remove the account and its personal workspace.
Cookies
Shopdeck uses only functional cookies: the sign-in session and the currently selected workspace. There are no analytics or advertising cookies on the application.