Last updated: July 21, 2026
Privacy
This notice explains how personal data is processed when you use the SPHEN.AI Shopify app, website, waitlist, or support.
Controllers
The company responsible for a specific processing activity depends on the relevant contact or contractual relationship. You may contact either provider with questions about this website.
App roles
NICCOS GmbH owns the public Shopify app record, listing, billing, and merchant relationship. getSichtbar GmbH develops and operates material technical, database, AI, SEO, GEO, monitoring, and support components for the app.
For merchant account, contract, billing, and support data, NICCOS GmbH generally acts as controller. To the extent getSichtbar GmbH processes merchant or store data on documented instructions, it acts as a processor or subprocessor under the applicable data processing agreement. Each company may remain a separate controller for its own legal obligations, security records, and direct communications.
Shopify app data
When a merchant installs SPHEN.AI, we process the Shopify store domain, installation and subscription status, organization and shop identifiers, granted permissions, encrypted Shopify access tokens, app settings, language, plan and usage information, support records, technical logs, and security events.
To provide catalog, audit, content, writeback, structured-data, and analytics functions, the app may process products, variants, collections, files, menus, pages, blog articles, storefront URLs, theme-app-embed status, generated drafts, approvals, before-and- after values, job history, audit results, and visibility results.
Processing is necessary to perform the app contract under Article 6(1)(b) GDPR and to operate, secure, troubleshoot, and improve the Service under Article 6(1)(f) GDPR. Where the merchant determines the purposes and means of processing personal data contained in store content, we process that data on the merchant's behalf under Article 28 GDPR.
AI processing
Product, collection, page, article, keyword, and related store content may be transmitted to enterprise AI services to generate drafts, classify issues, extract structured results, and perform visibility analysis. Depending on the enabled feature and configured provider, processing may use Microsoft Azure/OpenAI, Google Gemini or AI Overview services, Anthropic Claude, Perplexity, and Serper search services.
We configure API and enterprise processing where available and limit transmitted data to what is needed for the requested function. Merchants should not place unnecessary customer personal data, secrets, or special-category data in content sent for AI generation.
Optional analytics data
Merchants may optionally connect Google Analytics 4 through OAuth. The app requests read-only Analytics access and stores the connection tokens in encrypted form. If a merchant organization has connected Google Search Console through the related getSichtbar platform, the app may use search-performance data from that existing connection for audits and content planning. Access can be revoked through Google and the app settings.
Features using Shopify protected customer data remain disabled until the required Shopify approval and runtime activation. When enabled, they may process order totals, refunds, order-to- content attribution, and first-party storefront events such as page views and purchases. Buyer names, email addresses, postal addresses, and payment-card data are not displayed as app analytics. The web pixel is analytics-only, follows Shopify customer-privacy signals, and is not used for advertising, cross-site tracking, or sale of personal data.
App recipients
Depending on the enabled functions and the applicable contractual chain, recipients, directly engaged platform providers, and subprocessors may include Shopify for app distribution, APIs, and billing; Vercel for app hosting and delivery; Supabase for database and storage infrastructure; Microsoft Azure/OpenAI, Google, Anthropic, Perplexity, and Serper for enabled AI, visibility, and research functions; Railway and Redis infrastructure for background jobs and rate limiting; Sentry for error and security monitoring; and Google for optional Analytics and Search Console connections.
Providers may process data outside the EU or EEA. Where applicable, transfers rely on adequacy decisions, the EU-US Data Privacy Framework, standard contractual clauses, data processing agreements, and supplementary safeguards.
App retention and deletion
Store and workflow data is retained while the app is installed and as needed to provide the Service, document approved changes, resolve incidents, and meet legal obligations. Raw web-pixel events are deleted after 30 days. Order-derived attribution data is deleted no later than 12 months after the relevant order date. Completed or skipped background-job records are ordinarily deleted after 14 days and failed job records after 30 days.
On uninstall, the app deactivates the shop and removes its access
token. Shopify's mandatory shop/redact and
customers/redact webhooks trigger deletion of
Shopify-derived shop or customer data. Valid
customers/data_request requests are handled within
the applicable legal period. Limited billing, fraud-prevention,
legal, and security records may be retained where required.
Access requests and waitlist
When you request access to SPHEN.AI, we process the name, business email address, Shopify store URL, catalog-size range, selected primary challenge, optional notes, language, and source page that you submit.
We use these details to review the request, understand whether SPHEN.AI fits the relevant Shopify workflow, plan access, and contact you directly. The legal basis is your consent under Article 6(1)(a) GDPR. You may withdraw that consent with effect for the future by contacting either provider listed above.
Submissions are stored in Cloudflare D1 and processed through Cloudflare Workers. Cloudflare acts as a service provider for this infrastructure and may process data outside the EU or EEA under its applicable contractual safeguards. No automated confirmation email or user account is created from the form. To document the consent, we also store the acceptance time and the applicable privacy notice version.
To enable prompt review, we forward the submitted details to a restricted internal Slack channel used by the SPHEN.AI team at getSichtbar GmbH and NICCOS GmbH. Slack acts as a service provider and may process data outside the EU or EEA under its applicable contractual safeguards.
We retain the submission while we review and manage the access request and any direct follow-up. We delete it when it is no longer required for those purposes and no later than 24 months after its last update, or earlier after a valid withdrawal or deletion request, unless a legal obligation requires longer retention.
Hosting and logs
The website is delivered through Cloudflare Workers and Cloudflare Static Assets. Technically necessary access data may be processed when the website is requested, including IP address, time, requested file, referrer, browser and operating system information, status code, and transferred data volume.
Processing is necessary to provide the website securely, reliably, and efficiently and is based on legitimate interests under Article 6(1)(f) GDPR. Cloudflare may process data outside the EU or EEA in accordance with its contractual and privacy terms.
Further information: Cloudflare Privacy Policy and Cloudflare Data Processing Addendum.
Local media
Videos, images, customer logos, and font files are served directly by SPHEN.AI. Loading these assets does not establish a separate connection to Google Fonts, video platforms, or external image services.
Cookies and analytics
With your consent, we use Google Analytics 4, a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Analytics helps us understand how this website is used. Processed data may include visited pages, technical device and browser information, approximate location data, and interactions with the website.
Before you make a choice, Google Consent Mode denies access to analytics storage. Analytics cookies and comparable local identifiers are only used after consent. Google Signals and personalized advertising are disabled for this website.
Analytics processing is based on your consent under Article 6(1)(a) GDPR and, where information is stored on or read from your device, Section 25(1) TDDDG. Your choice is stored locally in your browser. You can change it by deleting the website data for SPHEN.AI in your browser and reloading the page.
Recipients may include Google Ireland Limited and other Google companies. Processing in third countries, particularly the United States, cannot be excluded. Google relies in part on the EU-US Data Privacy Framework and standard contractual clauses for such transfers. See the Google Privacy Policy for further information.
Retention
Technical log data is retained only as long as necessary for operation, security, error analysis, and compliance with legal obligations. It is then deleted or anonymized unless overriding retention duties apply.
Your rights
Subject to the GDPR, you may have rights of access, rectification, erasure, restriction of processing, data portability, and objection. Consent may be withdrawn with effect for the future.
You also have the right to lodge a complaint with a competent data protection authority. Please use the contact details above to exercise your rights.
Changes
We update this notice when features, services, or legal requirements change. The version published on this page applies.