Privacy Policy
At Ecomhint, we take your privacy seriously. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website and services.
The data controller for this website and service is Jakub Rusniok, a sole trader registered in the Czech Trade Register (živnostenský rejstřík), Company ID (IČO) 05282241. In this Privacy Policy, "Ecomhint", "we", "us" and "our" refer to the data controller.
1. Information We Collect
1.1 Information You Provide
When you use Ecomhint, we may collect:
- Account Information: Email address, name, and password when you create an account
- Store Information: URLs of ecommerce stores you analyze
- Store Logins: A Basic Auth login, Shopify storefront password, or Shopify crawler access signature you enter while signed in. We store it encrypted and use it only to audit that store. You can change it in Store Settings, and removing the project there deletes it
- Payment Information: Processed securely through our payment provider (Polar.sh)
- Communication Data: Messages you send us via email or contact forms
1.2 Automatically Collected Information
We automatically collect certain information when you visit our website:
- Usage Data: Pages visited, time spent, features used
- Device Information: Browser type, operating system, IP address
- Analytics Data: Collected via Google Analytics 4 (GA4), Microsoft Clarity, Google Tag Manager (GTM), Meta Pixel, and Google Ads remarketing
1.3 Analyzed Store Data
When you analyze a store, we collect:
- Public website content and HTML structure
- Page screenshots for visual analysis
- Performance metrics via Google Lighthouse
- Technical SEO data
1.4 AI Training and Benchmarking
We use AI technology to analyze stores and provide recommendations. Your analyzed store data may be:
- Processed by AI models: To generate personalized insights and recommendations
- Used for benchmarking: Anonymized analysis results help us improve industry benchmarks and service quality
- Never used for model training: We do not use your data to train third-party AI models
All data sent to AI providers is processed according to their privacy policies and our data processing agreements.
2. How We Use Your Information
We use the collected information for:
- Service Delivery: Analyze stores and generate reports
- Account Management: Create and maintain your account
- Payment Processing: Handle subscriptions and billing
- Service Improvement: Analyze usage patterns to enhance features
- Communication: Send service updates and respond to inquiries
- Security: Detect and prevent fraud and abuse
3. Third-Party Services
We use the following third-party services that may collect data:
3.1 Analytics and Advertising Services
- Google Tag Manager (GTM): Tag orchestration platform that loads other scripts based on your consent preferences. GTM itself does not collect personal data.
- Google Analytics 4 (GA4): Measures page views, sessions, and events. Cookies: _ga (2 years), _ga_* (2 years). Data recipient: Google LLC (USA).
- Microsoft Clarity: Session recordings and heatmaps to understand user behavior. Cookies: _clck (1 year), _clsk (1 day). Data recipient: Microsoft Corporation (USA).
- Meta Pixel: Tracks page views and conversion events for advertising measurement. Cookies: _fbp (90 days), _fbc (90 days). Data recipient: Meta Platforms Inc. (USA).
- Meta Conversions API (CAPI): Server-side event processing for the same events as Meta Pixel, with deduplication via event_id. Hashed email, IP address, and user agent may be sent. Data recipient: Meta Platforms Inc. (USA).
- Google Ads Remarketing: Conversion tracking and audience building for advertising. Cookie: _gcl_au (90 days). Data recipient: Google LLC (USA).
3.2 Authentication Services
- Better Auth: User authentication and session management
- Google OAuth: Optional sign-in method via Google account
3.3 Payment Processing
- Polar.sh: Secure payment processing and subscription management
3.4 Email Services
- Resend: Transactional and marketing email delivery (password resets, service notifications, and marketing emails for users who opted in)
3.5 Infrastructure Services
- Supabase: Database hosting, user data storage, and blog images (Supabase Storage)
- VPS Server (Germany): Analysis screenshots only
3.6 AI Analysis
- OpenAI: AI-powered store analysis and recommendations. Data is processed in the United States with appropriate safeguards (Standard Contractual Clauses).
4. MCP Clients
You can connect your Ecomhint account to an MCP client such as Claude or ChatGPT. This is optional, you start it yourself, and nothing is shared until you sign in and approve it. Setup steps are in our MCP documentation.
4.1 What Is Shared
While a connection is active, the MCP client you chose can request the following from your account, and we send it to that client at your request:
- Report Content: Your audit reports, scores, and score history
- Findings: Individual check results, the pages they were found on, and the recommended fixes
- Screenshots: The captures stored with a finding, when the client asks for a single finding
- Task List: Your fix-it tasks, including any the client adds or updates on your instruction
- Store URLs and Account Status: The stores on your account, your billing period, and how many audit credits you have left
The provider of the client you connect processes that data under its own privacy policy and terms, which we do not control. We do not add a new subprocessor when you connect: the client is your choice, not a service we engaged to run Ecomhint.
4.2 What We Do Not Receive
We receive the requests your MCP client makes to us and nothing else. Your conversation, prompts, and answers stay with the client provider. We do not use anything from a connected client for advertising, and connecting one does not change how your reports are processed inside Ecomhint.
4.3 Access Tokens and Revoking Access
Connecting creates an OAuth access token for that client, plus a refresh token so it can renew access without asking you to sign in again. Tokens identify your account and the permissions you approved. They are stored on our servers and are never shown in reports, emails, or logs.
You can end a connection at any time. Remove the connector inside the client, or revoke it from MCP in Ecomhint. Revoking takes effect immediately and stops all further requests from that client.
4.4 Retention
A connection does not create a second copy of your data. Reports, screenshots, and tasks that a client reads are the same records we already hold, kept for the periods described in Data Retention below. Data a client has already received is held by that provider under its own retention rules.
5. Data Storage and Security
We implement appropriate security measures to protect your information:
- Data encrypted in transit (HTTPS/TLS)
- Secure database with access controls
- Regular security audits
- Password hashing using industry standards
However, no method of transmission over the internet is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.
6. Data Retention
We retain your data according to the following schedule:
- Account Data: Retained for as long as your account is active
- Analysis Reports: Stored for the duration of your active subscription
- Screenshots: Retained for up to 3 years from creation date
- Marketing Consent Records: Retained for 3 years after consent withdrawal (for compliance documentation)
- Payment Records: Retained for 7 years (legal requirement)
After these periods, data is permanently deleted from our systems. You can request early deletion of your data at any time by contacting us at [email protected].
7. Your Rights (GDPR)
If you are in the European Economic Area (EEA), you have the following rights:
- Access: Request a copy of your personal data
- Rectification: Correct inaccurate data
- Erasure: Request deletion of your data ("right to be forgotten")
- Restriction: Limit how we process your data
- Portability: Receive your data in a machine-readable format
- Objection: Object to processing of your data
- Withdraw Consent: Withdraw consent at any time
To exercise these rights, contact us at [email protected].
8. Cookies and Tracking
8.1 What Are Cookies
Cookies are small text files stored on your device by your browser. We also use localStorage (browser-based storage), tracking pixels (invisible images that signal page loads), and server-side tracking (data sent directly from our servers to third-party platforms). This section covers all of these technologies.
8.2 Consent Management and Google Consent Mode v2
We use Google Consent Mode v2 to manage how tracking technologies behave based on your consent choices:
- Before consent: Analytics and advertising scripts may load but will not set cookies or collect identifiable data.
- After granting consent: Cookies are activated according to the categories you accepted (analytics, marketing, or both).
- After rejecting consent: Scripts send cookieless pings with aggregated, non-identifiable data only. No cookies are set.
Your consent preferences are stored in your browser's localStorage under the key ecomhint_cookie_consent. You can change your preferences at any time by clicking "Cookie Settings" in the website footer.
8.3 Cookie Table
| Cookie | Provider | Purpose | Duration | Category |
|---|---|---|---|---|
| better-auth.session_token | Ecomhint | Authentication | Session | Necessary |
| ecomhint_cookie_consent | Ecomhint (localStorage) | Consent preferences | Until policy change | Necessary |
| _ga | Google LLC | Unique user identification (GA4) | 2 years | Analytics |
| _ga_<ID> | Google LLC | Session state (GA4) | 2 years | Analytics |
| _clck | Microsoft | Clarity user ID | 1 year | Analytics |
| _clsk | Microsoft | Session stitching (Clarity) | 1 day | Analytics |
| _fbp | Meta Platforms Inc. | Browser ID for ads | 90 days | Marketing |
| _fbc | Meta Platforms Inc. | Click ID from Meta ad | 90 days | Marketing |
| _gcl_au | Google LLC | Conversion linker (Google Ads) | 90 days | Marketing |
8.4 Third-Party Technologies in Detail
- Google Tag Manager (GTM): Manages the loading of all analytics and advertising scripts. GTM itself does not set cookies or collect personal data. It acts as an orchestrator that respects your consent preferences before activating other tags.
- Google Analytics 4 (GA4): Collects anonymized usage data including page views, session duration, and user interactions. When analytics consent is denied, GA4 sends cookieless pings that provide aggregated insights without identifying individual users.
- Microsoft Clarity: Records anonymized session replays and generates heatmaps to help us understand how users interact with Ecomhint. Clarity masks sensitive input fields by default.
- Meta Pixel and Conversions API: The Meta Pixel tracks browser-side events (page views, conversions), while the Conversions API sends the same events server-side for improved measurement accuracy. Both use event_id deduplication to avoid double-counting. Hashed email addresses may be sent for Enhanced Conversions matching.
- Google Ads Remarketing: Enables conversion tracking and audience building for Google Ads campaigns. When marketing consent is denied, no remarketing cookies are set.
8.5 How to Manage Cookies
You can manage your cookie preferences in several ways:
- Cookie Settings: Click "Cookie Settings" in the website footer to change your consent preferences at any time.
- Browser settings: Most browsers allow you to block or delete cookies. Refer to your browser's help documentation for instructions.
- Opt-out tools:
9. Children's Privacy
Our services are not intended for children under 16. We do not knowingly collect data from children. If you believe a child has provided us with personal information, please contact us.
10. International Data Transfers
Your data may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place for international transfers:
- European Economic Area (EEA): Data stored within the EEA (Supabase, VPS Server in Germany)
- United States: Some services process data in the US (Google LLC, Meta Platforms Inc., Microsoft Corporation, OpenAI, Resend). These transfers are protected by:
- EU-US Data Privacy Framework (for certified companies including Google and Meta)
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Data Processing Agreements with third-party providers
- Regular security assessments and audits
We regularly review our data transfer mechanisms to ensure compliance with evolving data protection regulations.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by:
- Updating the "Last updated" date
- Sending an email notification
- Displaying a notice on our website
12. Contact Us
If you have questions about this Privacy Policy or our data practices, contact us:
- Data controller: Jakub Rusniok
- Company ID (IČO): 05282241
- Email: [email protected]
- Website: https://ecomhint.com
Summary
We collect data to provide and improve our ecommerce analysis services. We use analytics (Google Analytics 4, Microsoft Clarity), advertising measurement (Meta Pixel, Meta Conversions API, Google Ads), tag management (Google Tag Manager), authentication (Better Auth, Google OAuth), email services (Resend), and secure payment processing (Polar.sh). All tracking respects your consent choices via Google Consent Mode v2. Your data is stored in the EEA (Germany) and processed with AI technology (OpenAI). You have rights to access, correct, or delete your data. For questions, email [email protected].
Last Updated: October 5, 2026