Privacy Policy
Last updated: August 19, 2026
1. Controller
Outcomesy OÜ, registry code 17093201, Sepapaja tn 6, Lasnamäe linnaosa, 15551 Tallinn, Harju maakond, Estonia. Contact for privacy matters: support@outcomesy.com.
2. What we collect
- Account data: email address, login credentials (passwords are hashed; we never see them in plain text).
- Waitlist / contact data: email address and, for consultation requests, the website and message you submit.
- Customer Data you upload: advertising and store exports (e.g. spend, revenue, orders, product names). These are business records of the brand you operate; upload only data you are authorised to process.
- Usage and technical data: basic logs needed to run and secure the service (timestamps, request metadata, error logs).
- Bot-protection data: our public forms use Cloudflare Turnstile, which processes technical browser signals to distinguish humans from bots.
3. Why we process it (purposes and legal bases)
- Providing the service you request — briefings, actions, reports (performance of contract).
- Managing the waitlist and responding to consultation requests (legitimate interest / pre-contractual steps).
- Securing the service against abuse (legitimate interest).
- Communicating service messages such as invites and account emails (performance of contract / legitimate interest).
- We do not sell personal data and do not use your Customer Data for advertising.
4. AI processing
To generate briefings, recommendations, and reports, relevant Customer Data is processed by Google’s Gemini API acting as our processor. We send it on a paid API tier, and we rely on Google’s published terms for that tier, which state that submitted data is not used to train Google’s models. That is a commitment we depend on rather than one we can enforce ourselves. What is in our own control: we do not use your data to train any model of ours, outputs are generated for your workspace only, and we do not pool your data across customers.
5. Shopify store connections
When you connect your Shopify store, Outcomesy reads order and product data via Shopify's Admin API to generate aggregate analytics. Customer personal fields (name, email, phone, address) are never queried or stored. Raw order payloads are not retained — data is reduced to daily aggregates at extraction. Disconnecting the store or uninstalling the app revokes and deletes the access token. GDPR data-request and redact webhooks are implemented.
6. Sub-processors
We use a small set of infrastructure providers to run the service:
| Provider | Purpose |
|---|---|
| Supabase | Database, authentication, file storage |
| Google (Gemini API) | AI generation of briefings/reports |
| Cloudflare | Bot protection (Turnstile) |
| Lovable | Application hosting |
| Lovable (Custom Emails) | Transactional email (invites, account emails, notifications) |
Some providers may process data outside the EEA; where they do, we rely on appropriate safeguards such as EU Standard Contractual Clauses as implemented by those providers.
7. Retention
- Account and Customer Data: retained while your account is active; deleted within 90 days of account deletion, except minimal records we must keep for legal reasons.
- Waitlist data: retained until the beta programme ends or you ask us to remove you.
- Logs: retained for a short rolling window for security and debugging.
8. Your rights (GDPR)
You may request access to, correction of, deletion of, or a portable copy of your personal data, object to or restrict certain processing, and withdraw consent where processing is based on consent. Write to support@outcomesy.com. You may also lodge a complaint with a supervisory authority — in Estonia, the Data Protection Inspectorate (Andmekaitse Inspektsioon), or the authority in your country of residence.
9. Cookies
The service uses only cookies and local storage strictly necessary to operate (such as keeping you signed in). We do not currently use advertising or third-party analytics cookies. If we introduce analytics (e.g. Google Analytics), this policy will be updated and a consent banner added first.
10. Security
Data is encrypted in transit; access is scoped per workspace with row-level security; public forms are protected against automated abuse. No system is perfectly secure — if we become aware of a breach affecting your data, we will notify you as required by law.
11. Children
The service is for business use and not directed at anyone under 18.
12. Google Ads connections and advertising data
When you connect a Google Ads account, Outcomesy requests a single OAuth scope — https://www.googleapis.com/auth/adwords — and nothing wider. We use it to read aggregate performance figures for the advertising accounts you select: campaign and ad group names, spend, impressions, clicks, conversions and conversion value.
We do not retrieve or store end-consumer personal data from your advertising accounts: no customer match lists, no audience membership, no contact details, no advertising identifiers, no cross-app or cross-site browsing data.
We never use advertising data to train a model. Data obtained through the Google Ads API is used solely to produce the analysis and recommendations shown in your own workspace. We do not use it to train, fine-tune, retrain or otherwise improve any machine-learning model of ours; we do not pool it with other customers’ data for model development; and we do not sell, license or share it for advertising purposes. Where it is processed by Google’s Gemini API to produce that analysis, we rely on Google’s paid-tier terms, which state that submitted data is not used to train Google’s models.
Access and refresh tokens are held encrypted in a dedicated secret store, are never exposed to the browser, and are deleted when you disconnect. Disconnecting Google Ads affects only that connection — your Shopify store connection is unaffected. Deletion routes and timelines are documented on our data deletion page.
13. Changes
We will post updates here and, for material changes, notify you before they take effect.