Skip to content
SPHEN.AI
Product System Readiness
DE Back to website

Last updated: September 30, 2026

Privacy

This notice explains how personal data is processed when you use the Sphen.ai Shopify app, website, waitlist, or support.

Controller

Commerce Labs GmbH
Ida-Frank-Straße 4, 79206 Breisach am Rhein, Germany

support@sphen.ai

Role for the Shopify app

Commerce Labs GmbH owns and operates the Sphen.ai Shopify app, including its public app record, listing, billing, merchant relationship, and material technical, database, AI, SEO, GEO, monitoring, and support components.

For merchant account, contract, billing, and support data, Commerce Labs GmbH generally acts as controller. To the extent Commerce Labs GmbH processes personal data contained in merchant store content on the merchant's documented instructions, it acts as a processor under the applicable data processing agreement. Commerce Labs GmbH remains controller for its own legal obligations, security records, and direct communications.

Shopify app data

When a merchant installs Sphen.ai, we process the Shopify store domain, installation and subscription status, organization and shop identifiers, granted permissions, encrypted Shopify access tokens, app settings, language, plan and usage information, support records, technical logs, and security events.

To provide catalog, audit, content, writeback, structured-data, and analytics functions, the app may process products, variants, collections, files, menus, pages, blog articles, storefront URLs, theme-app-embed status, generated drafts, approvals, before-and- after values, job history, audit results, and visibility results.

Processing is necessary to perform the app contract under Article 6(1)(b) GDPR and to operate, secure, troubleshoot, and improve the Service under Article 6(1)(f) GDPR. Where the merchant determines the purposes and means of processing personal data contained in store content, we process that data on the merchant's behalf under Article 28 GDPR.

AI processing

Product, collection, page, article, keyword, and related store content may be transmitted to enterprise AI services to generate drafts, classify issues, extract structured results, and perform visibility analysis. Depending on the enabled feature and configured provider, processing may use Microsoft Azure/OpenAI, Google Gemini or AI Overview services, Anthropic Claude, Perplexity, and Serper search services.

We configure API and enterprise processing where available and limit transmitted data to what is needed for the requested function. Merchants should not place unnecessary customer personal data, secrets, or special-category data in content sent for AI generation.

Optional analytics data

Merchants may optionally connect Google Analytics 4 through OAuth. The app requests read-only Analytics access and stores the connection tokens in encrypted form. If a merchant organization has an existing Google Search Console connection available to Sphen.ai, the app may use search-performance data from that connection for audits and content planning. Access can be revoked through Google and the app settings.

Features using Shopify protected customer data remain disabled until the required Shopify approval and runtime activation. When enabled, they may process order totals, refunds, order-to- content attribution, and first-party storefront events such as page views and purchases. Buyer names, email addresses, postal addresses, and payment-card data are not displayed as app analytics. The web pixel is analytics-only, follows Shopify customer-privacy signals, and is not used for advertising, cross-site tracking, or sale of personal data.

Product analytics in the app (Microsoft Clarity)

Microsoft Clarity is active by default in the embedded Shopify admin app. It records how merchants use app screens, including page views, clicks, scrolling, pointer movement, screen size, browser and operating system, and an approximate region derived from the IP address. Clarity creates session replays and heatmaps from these interactions. Microsoft Corporation receives and processes this data in the United States. No Clarity code runs in a merchant's storefront, and storefront visitors are not recorded.

The app masks text, inputs, and images before recording, so replays show layout and interactions rather than shop, customer, or order content. Shopify session tokens and signature parameters are removed from the recorded URL before Clarity loads. We use the data to measure and improve the app interface, not for advertising or profiling. Microsoft may also process data for its own purposes under its Clarity terms.

Our legal basis is our legitimate interest under Article 6(1)(f) GDPR. Clarity sets the first-party cookies _clck (up to one year) and _clsk (one day) in the app frame from the first use of the app to recognize sessions. Merchants can object at any time under Article 21(1) GDPR by turning off product analytics in the app under Settings > Integrations or by emailing support@sphen.ai. Turning it off stops the current recording and prevents Clarity from loading on later visits. Existing cookies can be removed in the browser; earlier recordings are deleted on request.

App recipients

Depending on the enabled functions and the applicable contractual chain, recipients, directly engaged platform providers, and subprocessors may include Shopify for app distribution, APIs, and billing; Vercel for app hosting and delivery; Supabase for database and storage infrastructure; Microsoft Azure/OpenAI, Google, Anthropic, Perplexity, and Serper for enabled AI, visibility, and research functions; Railway and Redis infrastructure for background jobs and rate limiting; Sentry for error and security monitoring; and Google for optional Analytics and Search Console connections.

Providers may process data outside the EU or EEA. Where applicable, transfers rely on adequacy decisions, the EU-US Data Privacy Framework, standard contractual clauses, data processing agreements, and supplementary safeguards.

App retention and deletion

Store and workflow data is retained while the app is installed and as needed to provide the Service, document approved changes, resolve incidents, and meet legal obligations. Raw web-pixel events are deleted after 30 days. Order-derived attribution data is deleted no later than 12 months after the relevant order date. Completed or skipped background-job records are ordinarily deleted after 14 days and failed job records after 30 days.

On uninstall, the app deactivates the shop and removes its access token. Shopify's mandatory shop/redact and customers/redact webhooks trigger deletion of Shopify-derived shop or customer data. Valid customers/data_request requests are handled within the applicable legal period. Limited billing, fraud-prevention, legal, and security records may be retained where required.

Access requests and waitlist

When you request access to Sphen.ai, we process the name, business email address, Shopify store URL, catalog-size range, selected primary challenge, optional notes, language, and source page that you submit.

We use these details to review the request, understand whether Sphen.ai fits the relevant Shopify workflow, plan access, and contact you directly. The legal basis is your consent under Article 6(1)(a) GDPR. You may withdraw that consent with effect for the future by contacting the controller listed above.

Submissions are stored in Cloudflare D1 and processed through Cloudflare Workers. Cloudflare acts as a service provider for this infrastructure and may process data outside the EU or EEA under its applicable contractual safeguards. No automated confirmation email or user account is created from the form. To document the consent, we also store the acceptance time and the applicable privacy notice version.

To enable prompt review, we forward the submitted details to a restricted internal Slack channel used by the Sphen.ai team at Commerce Labs GmbH. Slack acts as a service provider and may process data outside the EU or EEA under its applicable contractual safeguards.

We retain the submission while we review and manage the access request and any direct follow-up. We delete it when it is no longer required for those purposes and no later than 24 months after its last update, or earlier after a valid withdrawal or deletion request, unless a legal obligation requires longer retention.

Hosting and logs

The website is delivered through Cloudflare Workers and Cloudflare Static Assets. Technically necessary access data may be processed when the website is requested, including IP address, time, requested file, referrer, browser and operating system information, status code, and transferred data volume.

Processing is necessary to provide the website securely, reliably, and efficiently and is based on legitimate interests under Article 6(1)(f) GDPR. Cloudflare may process data outside the EU or EEA in accordance with its contractual and privacy terms.

Further information: Cloudflare Privacy Policy and Cloudflare Data Processing Addendum.

Local media

Videos, images, customer logos, and font files are served directly by Sphen.ai. Loading these assets does not establish a separate connection to Google Fonts, video platforms, or external image services.

Cookies and analytics

With your consent, we use Google Analytics 4, a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Analytics helps us understand how this website is used. Processed data may include visited pages, technical device and browser information, approximate location data, and interactions with the website.

Before you make a choice, Google Consent Mode denies access to analytics storage. Analytics cookies and comparable local identifiers are only used after consent. Google Signals and personalized advertising are disabled for this website.

Analytics processing is based on your consent under Article 6(1)(a) GDPR and, where information is stored on or read from your device, Section 25(1) TDDDG. Your choice is stored locally in your browser. You can change it by deleting the website data for Sphen.ai in your browser and reloading the page.

Recipients may include Google Ireland Limited and other Google companies. Processing in third countries, particularly the United States, cannot be excluded. Google relies in part on the EU-US Data Privacy Framework and standard contractual clauses for such transfers. See the Google Privacy Policy for further information.

Retention

Technical log data is retained only as long as necessary for operation, security, error analysis, and compliance with legal obligations. It is then deleted or anonymized unless overriding retention duties apply.

Your rights

Subject to the GDPR, you may have rights of access, rectification, erasure, restriction of processing, data portability, and objection. Consent may be withdrawn with effect for the future.

You also have the right to lodge a complaint with a competent data protection authority. Please use the contact details above to exercise your rights.

Changes

We update this notice when features, services, or legal requirements change. The version published on this page applies.

SPHEN.AI

Shopify SEO and GEO from catalog audit to approved change.

Product Product How it works Visibility
Resources Help Comparisons Blog
Company About Contact Support LinkedIn DE
Legal Imprint Privacy Terms
SPHEN.AI
© 2026 SPHEN.AI. All rights reserved. Commerce Labs GmbH