01 · Privacy
Privacy Policy
Deutsche Fassung: Datenschutzerklärung
This explains how this website handles personal data, under Articles 13 and 14 GDPR. It covers this website, the free scan and the Parsance app for Shopify. The controller is named in the first section below.
02 · Controller
Controller
The controller for the processing described here is Dato Bitarishvili, Nobelstraße 48, 51107 Köln, Germany. You can reach the controller at support@parsance.com.
There is no statutory data protection officer, because the § 38 BDSG threshold is not met, and no EU representative, because Article 27 GDPR does not apply to a controller established in Germany.
03 · Hosting
Hosting and server logs
This website is hosted by Vercel Inc. as a processor under Article 28 GDPR. Serving any page creates short-lived server logs that include the IP address; the legitimate interest under Article 6(1)(f) GDPR is operating the site and keeping it secure.
Vercel Inc. is based in the United States, so these transfers rely on the EU Standard Contractual Clauses set out in its data processing agreement. Error logs are stripped of form input, so they hold nothing you typed into a form. These logs are held by the host for a short operational period and then deleted automatically; we keep no separate log store.
04 · Cookies
Cookies and local storage
This site sets at most one cookie, a functional language cookie (parsance-lang), and only once you actively pick a language. There are no third-party cookies and no cross-site tracking. Page views are counted without a cookie; who receives that and on what basis is in section 10. That one cookie needs no consent under § 25 Abs. 2 Nr. 2 TDDDG, which is why you see no banner.
The full inventory, including how long the cookie lives, is in the cookie policy.
05 · Waitlist
Waitlist
If you join the early-access list, we store what you enter, your email address and your shop URL, together with the language you picked, a fixed label identifying the form, and the user agent your browser sends. This goes to our database at Supabase in Frankfurt (EU region). Supabase is a processor under Article 28 GDPR, bound by a data processing agreement; to the extent any access occurs from outside the EU, the same EU Standard Contractual Clauses apply as for hosting.
The purpose is to tell you about the product; the legal basis is the step you asked us to take, Article 6(1)(b) GDPR. Providing this is voluntary, and there is no downside to not joining. We keep the data until that purpose is fulfilled and delete it afterwards, or sooner if you ask us to.
06 · Free scan
The free scan: your data
The free scan checks a shop you enter. You provide the shop URL and, if you want the report by email, an email address. The result lives at a private, unlisted link that search engines are told to ignore (noindex). An email you provide is used only to send you that report; it is kept out of the report itself and out of the paths that read reports back. Providing the shop URL is necessary to run the scan you asked for; giving an email is optional and only changes how the report reaches you, since it is also available at the private link.
While a scan runs, your IP address is held briefly in memory to rate-limit requests and is not stored. The report itself is stored in the same EU database at Supabase. The legal basis is Article 6(1)(b) GDPR, since you requested the report. A scan report is deleted after at most 90 days.
07 · Third-party scans
Scanning other shops
To build a report, the scanner fetches publicly accessible pages of the shop you name. Those are its start page, robots.txt, products.json, sitemap.xml and llms.txt, plus a sitemap those files point to, plus a sample of at most 5product pages. To find out whether AI crawlers get through, the scanner then requests one of those pages again, once per crawler, under that crawler's own identifier. All of these pages can contain personal data of the shop operator, for example a name in the imprint or a reviewer's name on a product page. The legal basis is our legitimate interest in analysing public machine-readability for online shops, Article 6(1)(f) GDPR.
Weighed against that interest, the data is already public, the analysis is narrow, and it runs once per scan. Because we did not obtain this data from the operator directly, Article 14 GDPR applies; notifying every operator individually would take disproportionate effort under Article 14(5)(b) GDPR, so this notice serves that purpose. Any personal data of the operator that appears in a report is kept only as part of that report and deleted with it, after at most 90 days. If you operate a shop and do not want it scanned, tell us through the contact page and we will stop.
08 · The app
The Parsance app for Shopify
If you install the Parsance app on your Shopify store, we process what running the service requires: your shop's myshopify domain and name, the plan you picked, the settings you enter (for example shipping and return details), scan results and reports for your shop, and a log of applied fixes together with the backups needed to undo them. All of it lives in the same EU database at Supabase in Frankfurt. The legal basis is the contract with you, Article 6(1)(b) GDPR.
Signing in works through Shopify (OAuth); there is no password with us. The app receives a Shopify API access token to perform the actions you trigger; it is stored encrypted (AES-256-GCM) and is invalidated when you uninstall. Two functional cookies carry the login: a session cookie (__Host-parsance_session, 30 days) and a short-lived cookie protecting the sign-in itself (__Host-parsance_oauth_state). Both are strictly necessary (§ 25 Abs. 2 Nr. 2 TDDDG) and are listed in the cookie policy.
Shopify notifies the app of events in your store (webhooks): app removal, product and theme changes, plan changes and paid orders. From an order notification we keep only a hashed order reference and the order total, to verify AI-attributed revenue; we do not store your customers' names, emails or addresses. If you switch on the optional AI-referral measurement, the app records, per visit, which AI assistant referred it (referrer host and UTM parameters) and aggregates that into daily counts; no shopper profiles are built and there is no cross-site tracking. As the shop operator, you are responsible for reflecting this measurement in your own store's privacy policy; the app reminds you of this where you enable it.
Paid plans are billed by Shopify on your Shopify invoice; payment details never reach us — we store only which plan is active. When you uninstall the app, the access token is invalidated immediately, and 48hours later Shopify sends a deletion request upon which your shop's data is erased. You can also export your data or delete your account yourself at any time in the dashboard under Account.
09 · Contact
Contact and scheduling
When you email support@parsance.com, we use your message only to answer it. There is no newsletter and no marketing list.
If you book a call, scheduling runs on cal.com as an external provider. Their privacy policy applies, and processing on their side begins when you open the booking page.
10 · Recipients
Who else receives data
Four recipients are named above: Vercel Inc. (hosting), Supabase (the database), Shopify (the app, including billing) and cal.com (scheduling). Below are one further purpose at Vercel Inc. and three further recipients, each receiving data only for the purpose named here. Together with the four above, that is the whole list.
Page views are counted. Every page embeds the reach measurement of Vercel Inc. (Vercel Web Analytics), which reports to Vercel Inc. which page was opened, where the visit came from and the technical request data the host sees anyway. It builds no visitor profiles, does no cross-site tracking and sets no cookie (the full cookie inventory is in the cookie policy). The legal basis is our legitimate interest in a rough reach statistic, Article 6(1)(f) GDPR.
Resend delivers our email. Whenever the service emails you, for example an alert about your shop, and whenever you send us feedback from the dashboard, the recipient address, the subject and the message text pass through Resend.
If your plan includes the visibility sample, the app puts shopping questions to three AI assistants (OpenAI, Perplexity, Google) and checks whether your shop turns up in the answer. Such a question carries nothing but one product type from your own catalogue, in the fixed form “recommend a good ...”. Your shop name is deliberately not part of it, and no customer data and no account data go with it.
If you trigger the IndexNow fix, the app reports URLs of your shop to Microsoft's IndexNow service, so search engines fetch those pages again. Only those URLs are sent.
All three are based in the United States, so these transfers reach a third country. For Resend and the three AI providers, which process on our instructions under Article 28 GDPR, the transfer rests on the EU Standard Contractual Clauses in the respective data processing agreement; you can request a copy at support@parsance.com. The IndexNow submission is not processing on our behalf, and it carries URLs only. The legal basis for all three is the contract with you, Article 6(1)(b) GDPR, because each belongs to a function of the app you use.
11 · Your rights
Your rights and complaints
You have the right to access your data (Article 15), to have it corrected (Article 16) or erased (Article 17), to restrict its processing (Article 18), and to receive it in a portable form (Article 20). Because the server logs, the reach measurement and the third-party scan rest on legitimate interest, you also have the right to object under Article 21 GDPR. Where any processing rests on your consent, you can withdraw that consent at any time with effect for the future.
To exercise any of these rights, email support@parsance.com or use the contact page. You also have the right to lodge a complaint with a supervisory authority. The one responsible for the controller is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW), Postfach 20 04 44, 40102 Düsseldorf, ldi.nrw.de.
There is no automated decision-making or profiling under Article 22 GDPR.
Last updated: 2026-08-03