Privacy Policy

Last updated June 23, 2026

This Privacy Policy describes how Ready for Commerce, Inc. ("Ready for Commerce," "we," "us," or "our") collects, uses, and discloses personal information in connection with our websites, applications, and services — including our authentication service, our account and billing service, the PIM product, and the Repricer product (together, the "Services"). It also explains the rights and choices available to you regarding your personal information.

This Privacy Policy supplements our Terms of Use. Capitalized terms not defined here have the meaning given in the Terms of Use. If you do not agree with this Privacy Policy, please do not use the Services.

How this policy applies — our two roles

What this policy covers. This Privacy Policy applies to personal information we process about visitors to our websites; individuals who register for, administer, or use the Services; prospective customers and people who contact us; and personal information contained in data that customers connect to the Services, to the limited extent described below.

When we are a controller. When we determine the purposes and means of processing — for example, when you create an account, sign in, manage an organization, pay for a subscription, contact support, or browse our sites — we act as a "controller" (or "business" under U.S. state laws). This Privacy Policy primarily describes that processing.

When we are a processor. When our customers (merchants) connect their sales channels and use the Services to manage product, pricing, and related data, we process that data — which may include limited personal information — on their behalf and under their instructions. For that processing, the customer is the controller and we are a "processor" (or "service provider"); our handling of it is governed by our agreement with the customer, including our Data Processing Addendum (the "DPA"), and not by this Privacy Policy. If your personal information was provided to the Services by a merchant (for example, because you are their customer or contact), please direct your privacy requests to that merchant; we will support them as required by our DPA and applicable law.

Limited end-customer data. The Services are designed to manage product catalogs and pricing, not to store the personal information of merchants' shoppers. The PIM does not store merchants' order or shopper personal information, and the Repricer processes sales and order metrics primarily in aggregated form. Where a connected sales channel requires us to support data-access or deletion requests concerning its customers (for example, Shopify's customer data-request, customer-redaction, and shop-redaction processes), we honor those requests in our role as processor.

Personal information we collect

We collect the categories of personal information described below. What we collect depends on how you interact with the Services.

Account and identity information. When you register for or use the Services, we collect your email address and, optionally, your first and last name, preferred language, and preferred time zone. Each account is assigned a unique identifier.

Authentication and security information. Our authentication is passwordless. When you sign in (via email one-time passcode, Google sign-in, or Shopify single sign-on) and during your session, we process technical information such as your IP address, browser and device user-agent, session identifiers, authentication events, and timestamps. We may send you security notifications (for example, "new sign-in detected" alerts) that include this information. We also use bot-mitigation technology (such as CAPTCHA) that processes signals to distinguish humans from automated traffic.

Organization and team information. We collect information about the organizations you create or belong to, including organization name, membership, roles and permissions, invitations (including the email addresses you invite), ownership, and settings such as default currency and units.

Billing and payment information. When you purchase a paid subscription, billing is processed through Stripe (for direct subscriptions) or Shopify Billing (for App Store subscriptions). We collect billing-related information such as billing contact, subscription and plan status, trial dates, billing rail and provider identifiers, and, for card payments, limited card metadata returned by Stripe (such as card brand, the last four digits, and expiry month/year). We do not collect or store full payment-card numbers or security codes; those are handled directly by our payment processors under their PCI-compliant systems.

Usage, metering, and device information. We collect information about how the Services are configured and used, including feature usage, metering data used to calculate fees (such as product count for the PIM and gross merchandise value for the Repricer), log data, error and diagnostic data, device and connection information, and information collected through cookies and similar technologies (see Cookies and similar technologies).

Communications and support. When you contact us, we collect the information you provide (such as your name, email, and the contents of your message) and records of our correspondence.

Information from third parties. We receive information from third parties you choose to connect or use, including identity providers (such as Google) when you sign in, which may provide your email, name, and profile information; Shopify, when you install or sign in through Shopify single sign-on, which may provide your shop domain and verified merchant or staff identity; and connected sales channels and our service providers, to the extent necessary to operate the Services. We do not request or knowingly collect special categories of personal data (such as health, biometric, or government-identifier data).

How we use personal information

We use personal information for the purposes below. Where the GDPR or UK GDPR applies, we rely on the legal bases indicated.

  • To provide and operate the Services — to create and manage accounts, authenticate users, provision organizations and roles, deliver features, and process your configurations and instructions. Legal basis: performance of a contract.
  • To process billing and payments — to manage subscriptions, calculate usage-based fees, process charges through Stripe or Shopify, and maintain billing records. Legal basis: performance of a contract; compliance with legal obligations such as tax and accounting.
  • To communicate with you — to send service, transactional, security, and administrative messages (such as login codes, billing notices, incident alerts, and changes to our terms). We do not send marketing or promotional emails; the messages we send are necessary to provide the Services. Legal basis: performance of a contract; our legitimate interests.
  • To secure the Services and prevent abuse — to authenticate users, detect and prevent fraud, abuse, and security incidents, enforce our terms, and protect our rights and those of our users. Legal basis: our legitimate interests in security and integrity; compliance with legal obligations.
  • To maintain, analyze, and improve the Services — to monitor performance, debug, conduct analytics, and develop new features. Where required, analytics that are not strictly necessary are used only with your consent (see Cookies and similar technologies). Legal basis: our legitimate interests; consent where required.
  • To provide support — to respond to your requests and resolve issues. Legal basis: performance of a contract; our legitimate interests.
  • To comply with law and protect rights — to comply with legal obligations, respond to lawful requests, and establish, exercise, or defend legal claims. Legal basis: compliance with legal obligations; our legitimate interests.
  • To create aggregated and de-identified insights — to produce aggregated or de-identified data and statistics that do not identify you or any individual, which we may use for any lawful business purpose, including operating, securing, benchmarking, and improving the Services. Legal basis: our legitimate interests.

Where we rely on legitimate interests, we have balanced those interests against your rights and freedoms; you may object as described under Your rights and choices. Providing certain personal information (such as your email address) is necessary to create an account and use the Services; if you do not provide it, we may be unable to make the Services available to you.

Cookies and similar technologies

What we use. We and our service providers use cookies and similar technologies to operate the Services and our websites. These fall into the following categories:

  • Strictly necessary — required to provide the Services, including authentication and session management (for example, the session cookie that keeps you signed in across our applications) and security and bot mitigation. These cannot be switched off through our systems.
  • Functional and preferences — remember choices such as your language and active organization.
  • Analytics and product measurement — help us understand how the Services are used and improve them, including error tracking and limited session replay. Our session replay captures only structural interactions with the interface; input fields and on-screen text are masked so that the contents you type and view (such as login codes, billing details, and catalog data) are not recorded, and session replay is disabled entirely on our login service. We use a product-analytics provider (PostHog) for these purposes.

Consent. Where required by law (including in the EEA and the UK), we set non-essential cookies and use analytics and session replay only after you give consent through our cookie-consent banner, and you can withdraw or change your choices at any time. Strictly necessary cookies do not require consent. Elsewhere, you can control cookies through your browser settings. For details of the specific cookies we use, see our Cookie Policy.

Preference signals. Where required by applicable law, we honor recognized opt-out preference signals (such as the Global Privacy Control) as a request to opt out of applicable processing.

How we disclose personal information

We do not sell personal information, and we do not "share" it for cross-context behavioral advertising (as those terms are defined under U.S. state privacy laws). We disclose personal information only as described below.

Service providers and subprocessors. We share personal information with vendors that process it on our behalf to provide the Services, under contracts requiring appropriate confidentiality and security. By category, these include:

  • Cloud hosting, database, and storage — Vercel, Railway, and Supabase.
  • Payments and billing — Stripe and Shopify.
  • Transactional email — Resend.
  • Product analytics and error tracking — PostHog.
  • Identity and security — Google (sign-in) and Cloudflare (bot mitigation).
  • Operational data services — foreign-exchange rate providers; and, for the Repricer's competitor-monitoring features, web-data and proxy providers (such as Bright Data) and an artificial-intelligence provider (OpenAI) used to retrieve and extract pricing information from external web pages that a customer directs us to monitor. Only the content of those external pages (such as page text or a screenshot) is processed for this purpose; your account, login, and personal information are not sent to these providers, and that content is not used to train their models.

A current list of material subprocessors is maintained and made available as described in our DPA.

Connected channels. When you connect a sales channel (such as Shopify, Amazon, Walmart, eBay, or BigCommerce), we exchange data with that channel as needed to provide the Services and at your direction. Your use of each channel is also governed by that channel's own privacy practices.

Legal and safety. We may disclose personal information to comply with applicable law, regulation, legal process, or governmental request; to enforce our terms; to detect, prevent, or address fraud, security, or technical issues; and to protect the rights, property, or safety of Ready for Commerce, our users, or others.

Business transfers. If we are involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, personal information may be transferred as part of that transaction, subject to this Privacy Policy or a successor policy.

With your direction or consent. We may disclose personal information for other purposes with your consent or at your direction, including to other users within your organization based on the roles and permissions you configure.

International data transfers

We are headquartered in the United States, and we and our service providers process personal information in the United States and other countries, which may have data-protection laws that differ from those in your country. Where we transfer personal information subject to the GDPR, UK GDPR, or Swiss law from the EEA, the United Kingdom, or Switzerland to a country that has not received an adequacy decision, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, and equivalent mechanisms. You may request more information about these safeguards through our contact page.

How long we keep personal information

We retain personal information for as long as necessary to fulfill the purposes described in this Privacy Policy, unless a longer period is required or permitted by law. In general:

  • Account and identity information is retained for the life of your account and for a limited period afterward to allow for reactivation, dispute resolution, and our backup cycles.
  • Billing, tax, and transaction records are retained for the periods required by applicable tax and accounting laws.
  • Security and log data is retained for a limited period appropriate to its purpose.
  • Analytics data is retained according to our configuration with our analytics provider.
  • Customer Data processed as a processor is retained and deleted in accordance with our DPA and the customer's instructions.

When personal information is no longer needed, we delete or de-identify it, except where retention is required for legal, accounting, or legitimate-business purposes, or for the establishment, exercise, or defense of legal claims.

Security

We implement administrative, technical, and organizational measures designed to protect personal information appropriate to the risk, including encryption in transit, access controls, tenant isolation, and secure handling of credentials and secrets. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your authentication factors and connected accounts secure and for promptly notifying us of any suspected unauthorized access. Where required by law, we will notify you and/or the relevant authorities of a personal-data breach.

Your rights and choices

Depending on where you live and applicable law, you may have some or all of the following rights regarding personal information for which we are the controller:

  • Access — to request a copy of the personal information we hold about you.
  • Rectification or correction — to request that we correct inaccurate or incomplete information.
  • Erasure or deletion — to request that we delete personal information, subject to legal exceptions.
  • Restriction — to request that we restrict processing in certain circumstances.
  • Portability — to receive certain personal information in a portable, machine-readable format.
  • Objection — to object to processing based on legitimate interests.
  • Withdraw consent — to withdraw consent at any time where processing is based on consent (such as non-essential cookies), without affecting prior processing.
  • Opt out of "sale" or "sharing" — although we do not sell or share personal information for cross-context behavioral advertising.
  • Non-discrimination — to not be discriminated against for exercising your rights.
  • Lodge a complaint — to lodge a complaint with your local data-protection or supervisory authority.

How to exercise your rights. You may exercise your rights by contacting us at privacy@readyforcommerce.com. We will verify your request (and your authority, for authorized-agent requests) and respond within the time required by applicable law. We will not charge a fee except where permitted by law.

Managing your account. You can access and update much of your information directly within the Services, including your profile, organization settings, team membership, and cookie preferences.

Requests concerning Customer Data. If your request relates to personal information that a merchant processes through the Services (where we act as a processor), we will refer you to, or assist, the relevant merchant, who is the controller of that data.

Regional disclosures

European Economic Area, United Kingdom, and Switzerland. The controller of your personal information is Ready for Commerce, Inc. We process personal information on the legal bases described under How we use personal information and transfer it internationally as described under International data transfers. You have the rights described under Your rights and choices, including the right to lodge a complaint with your supervisory authority. We have not appointed an Article 27 representative or a data protection officer at this time; you may contact us directly through our contact page.

California (CCPA/CPRA). In the preceding 12 months, we have collected the categories of personal information described under Personal information we collect (including identifiers, customer-account and commercial information, internet and network activity, and limited geolocation inferred from IP), for the business purposes described under How we use personal information, and disclosed them to the categories of recipients described under How we disclose personal information. We do not "sell" or "share" personal information. To the extent we process any information that may be considered "sensitive personal information," we do not use or disclose it for purposes that would entitle you to a right to limit its use. California residents have the rights to know, access, correct, and delete personal information, to opt out of sale or sharing (inapplicable here), and to non-discrimination, and may use an authorized agent.

Other U.S. states. Residents of other U.S. states with comprehensive privacy laws (such as Virginia, Colorado, Connecticut, Utah, Texas, and others) have rights to access, correct, delete, and obtain a portable copy of their personal information, and to opt out of targeted advertising, sale, or certain profiling. We do not engage in targeted advertising, sale, or profiling that produces legal or similarly significant effects. You may exercise these rights and, where available, appeal a decision through our contact page.

Automated decision-making

The Repricer computes and, when enabled by a customer, submits product prices automatically based on rules and constraints the customer configures. These are automated decisions about products and prices made at the customer's direction; they are not decisions that produce legal or similarly significant effects concerning individual data subjects. We do not use personal information to make solely automated decisions that produce legal or similarly significant effects about you within the meaning of Article 22 of the GDPR.

Children

The Services are intended for business and commercial use and are not directed to children. We do not knowingly collect personal information from children under the age of 16 (or the age specified by applicable law). If you believe a child has provided us personal information, please contact us so we can take appropriate action.

Other sites and services

The Services may link to, or interoperate with, third-party websites and services — including connected sales channels and payment providers — that we do not control. This Privacy Policy does not apply to those third parties, and we are not responsible for their privacy practices. We encourage you to review their privacy notices.

Changes to this policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by reasonable means, such as posting the updated policy with a new "Effective" date and, where appropriate, providing additional notice. Your continued use of the Services after the effective date constitutes acknowledgment of the updated Privacy Policy.

Privacy Policy - Ready for Commerce