Privacy Policy

Last updated August 16, 2026


This Privacy Policy describes how Ready for Commerce, Inc. ("Ready for Commerce," "we," "us," or "our") collects, uses, and discloses personal information in connection with our websites, applications, and services — including our authentication service, our account and billing service, the PIM product, and the Repricer product (together, the "Services"). It also explains the rights and choices available to you regarding your personal information.

This Privacy Policy supplements our Terms of Use. Capitalized terms not defined here have the meaning given in the Terms of Use. If you do not agree with this Privacy Policy, please do not use the Services.

How this policy applies — our two roles

What this policy covers. This Privacy Policy applies to personal information we process about visitors to our websites; individuals who register for, administer, or use the Services; prospective customers and people who contact us; and personal information contained in data that customers connect to the Services, to the limited extent described below.

When we are a controller. When we determine the purposes and means of processing — for example, when you create an account, sign in, manage an organization, pay for a subscription, contact support, or browse our sites — we act as a "controller" (or "business" under U.S. state laws). This Privacy Policy primarily describes that processing.

When we are a processor. When our customers (merchants) connect their sales channels and use the Services to manage product, pricing, and related data, we process that data — which may include limited personal information — on their behalf and under their instructions. For that processing, the customer is the controller and we are a "processor" (or "service provider"); our handling of it is governed by our agreement with the customer, including our Data Processing Addendum (the "DPA"), and not by this Privacy Policy. If your personal information was provided to the Services by a merchant (for example, because you are their customer or contact), please direct your privacy requests to that merchant; we will support them as required by our DPA and applicable law.

Limited end-customer data. The Services are designed to manage product catalogs and pricing, not to store the personal information of merchants' shoppers. The PIM does not store merchants' order or shopper personal information, and the Repricer processes sales and order metrics primarily in aggregated form. Where a connected sales channel requires us to support data-access or deletion requests concerning its customers — for example, Shopify's customer data-request, customer-redaction, and shop-redaction processes, or eBay's marketplace account-deletion notifications — we honor those requests in our role as processor.

Personal information we collect

We collect the categories of personal information described below. What we collect depends on how you interact with the Services.

Account and identity information. When you register for or use the Services, we collect your email address and, optionally, your first and last name, preferred language, and preferred time zone. Each account is assigned a unique identifier.

Authentication and security information. Our authentication is passwordless. When you sign in (via email one-time passcode, Google sign-in, or Shopify single sign-on) and during your session, we process technical information such as your IP address, browser and device user-agent, session identifiers, authentication events, and timestamps. We may send you security notifications (for example, "new sign-in detected" alerts) that include this information. We also use bot-mitigation technology (such as CAPTCHA) that processes signals to distinguish humans from automated traffic.

Organization and team information. We collect information about the organizations you create or belong to, including organization name, membership, roles and permissions, invitations (including the email addresses you invite), ownership, and settings such as default currency and units.

Billing and payment information. When you purchase a paid subscription, billing is processed through Stripe (for direct subscriptions) or Shopify Billing (for App Store subscriptions). We collect billing-related information such as billing contact, subscription and plan status, trial dates, billing rail and provider identifiers, and, for card payments, limited card metadata returned by Stripe (such as card brand, the last four digits, and expiry month/year). We do not collect or store full payment-card numbers or security codes; those are handled directly by our payment processors under their PCI-compliant systems.

Usage, metering, and device information. We collect information about how the Services are configured and used, including feature usage, metering data used to calculate fees (such as product count for the PIM and gross merchandise value for the Repricer), activity records showing which user created or changed a record and when, log data, error and diagnostic data, device and connection information, and information collected through cookies and similar technologies (see Cookies and similar technologies).

Communications and support. When you contact us, we collect the information you provide (such as your name, email, and the contents of your message) and records of our correspondence.

Information from third parties. We receive information from third parties you choose to connect or use, including identity providers (such as Google) when you sign in, which may provide your email, name, and profile information; Shopify, when you install or sign in through Shopify single sign-on, which may provide your shop domain and verified merchant or staff identity; and connected sales channels and our service providers, to the extent necessary to operate the Services. We do not request or knowingly collect special categories of personal data (such as health, biometric, or government-identifier data).

How we use personal information

We use personal information for the purposes below. Where the GDPR or UK GDPR applies, we rely on the legal bases indicated.

  • To provide and operate the Services — to create and manage accounts, authenticate users, provision organizations and roles, deliver features, and process your configurations and instructions. Legal basis: performance of a contract.
  • To process billing and payments — to manage subscriptions, calculate usage-based fees, process charges through Stripe or Shopify, and maintain billing records. Legal basis: performance of a contract; compliance with legal obligations such as tax and accounting.
  • To communicate with you — to send service, transactional, security, and administrative messages (such as login codes, billing notices, incident alerts, and changes to our terms). We do not send marketing or promotional emails; the messages we send are necessary to provide the Services. Legal basis: performance of a contract; our legitimate interests.
  • To secure the Services and prevent abuse — to authenticate users, detect and prevent fraud, abuse, and security incidents, enforce our terms, and protect our rights and those of our users. Legal basis: our legitimate interests in security and integrity; compliance with legal obligations.
  • To maintain, analyze, and improve the Services — to monitor performance, debug, conduct analytics, and develop new features. Where required, analytics that are not strictly necessary are used only with your consent (see Cookies and similar technologies). Legal basis: our legitimate interests; consent where required.
  • To provide support — to respond to your requests and resolve issues. Legal basis: performance of a contract; our legitimate interests.
  • To comply with law and protect rights — to comply with legal obligations, respond to lawful requests, and establish, exercise, or defend legal claims. Legal basis: compliance with legal obligations; our legitimate interests.
  • To create aggregated and de-identified insights — to produce aggregated or de-identified data and statistics that do not identify you or any individual, which we may use for any lawful business purpose, including operating, securing, benchmarking, and improving the Services. Legal basis: our legitimate interests.

Where we rely on legitimate interests, we have balanced those interests against your rights and freedoms; you may object as described under Your rights and choices. Providing certain personal information (such as your email address) is necessary to create an account and use the Services; if you do not provide it, we may be unable to make the Services available to you.

Cookies and similar technologies

What we use. We and our service providers use cookies and similar technologies to operate the Services and our websites. These fall into the following categories:

  • Strictly necessary — required to provide the Services, including authentication and session management (for example, the session cookie that keeps you signed in across our applications) and security and bot mitigation. These cannot be switched off through our systems.
  • Functional and preferences — remember choices such as your language and active organization.
  • Analytics and product measurement — help us understand how the Services are used and improve them, including error tracking and limited session replay. Our session replay captures only structural interactions with the interface; input fields and on-screen text are masked so that the contents you type and view (such as login codes, billing details, and catalog data) are not recorded, and session replay is disabled entirely on our login service. We use a product-analytics provider (PostHog) for these purposes.

Consent. Where required by law (including in the EEA and the UK), we set non-essential cookies and use analytics and session replay only after you give consent through our cookie-consent banner, and you can withdraw or change your choices at any time. Strictly necessary cookies do not require consent. Elsewhere, you can control cookies through your browser settings. For details of the specific cookies we use, see our Cookie Policy.

Preference signals. Where required by applicable law, we honor recognized opt-out preference signals (such as the Global Privacy Control) as a request to opt out of applicable processing.

How we disclose personal information

We do not sell personal information, and we do not "share" it for cross-context behavioral advertising (as those terms are defined under U.S. state privacy laws). We disclose personal information only as described below.

Service providers and subprocessors. We share personal information with vendors that process it on our behalf to provide the Services, under contracts requiring appropriate confidentiality and security. By category, these include:

  • Cloud hosting, database, and storage — Vercel, Railway, and Supabase.
  • Payments and billing — Stripe and Shopify.
  • Transactional email — Resend.
  • Product analytics and error tracking — PostHog.
  • Identity and security — Google (sign-in and One Tap) and Cloudflare (bot mitigation and DNS).
  • Website content management — Sanity, which hosts the published copy of our marketing website.
  • Artificial intelligence — fal.ai, for the PIM's image operations (upscaling, background removal, and subject isolation), which receives the product image a user chooses to transform; and OpenAI, for the Repricer's competitor monitoring, which receives the content of an external page — its text or a screenshot of it — to read a price from it. Neither receives your account, login, or billing information, and neither uses the data we send to train its models. See Artificial intelligence in the Services.
  • Web-page retrieval — IPRoyal and Browserless, which fetch and render the external competitor web pages a customer directs the Repricer to monitor. They receive the addresses of those pages and return their content; no account or personal information is sent to them.
  • Reference data — ExchangeRate-API, for daily currency-conversion rates. We request only the published rate table; no personal information is sent.

The complete, current list — including each provider's legal entity, the function it performs, and where it processes data — is published on our Subprocessors page, which also explains how we notify customers of changes and how you can subscribe to those notifications.

Connected channels. When you connect a sales channel (such as Shopify, Amazon, Walmart, eBay, BigCommerce, Square, or Google Merchant Center), we exchange data with that channel as needed to provide the Services and at your direction. Those channels are not our subprocessors: they receive your data under the account and agreement you hold with them directly, and your use of each channel is governed by that channel's own privacy practices.

Legal and safety. We may disclose personal information to comply with applicable law, regulation, legal process, or governmental request; to enforce our terms; to detect, prevent, or address fraud, security, or technical issues; and to protect the rights, property, or safety of Ready for Commerce, our users, or others.

Business transfers. If we are involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, personal information may be transferred as part of that transaction, subject to this Privacy Policy or a successor policy.

With your direction or consent. We may disclose personal information for other purposes with your consent or at your direction, including to other users within your organization based on the roles and permissions you configure.

International data transfers

We are headquartered in the United States, and we and our service providers process personal information in the United States and other countries, which may have data-protection laws that differ from those in your country. Where we transfer personal information subject to the GDPR, UK GDPR, or Swiss law from the EEA, the United Kingdom, or Switzerland to a country that has not received an adequacy decision, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, and equivalent mechanisms. You may request more information about these safeguards through our contact page.

How long we keep personal information

We retain personal information for as long as necessary to fulfill the purposes described in this Privacy Policy, unless a longer period is required or permitted by law. In general:

  • Account and identity information is retained for the life of your account and for a limited period afterward to allow for reactivation, dispute resolution, and our backup cycles.
  • Billing, tax, and transaction records are retained for the periods required by applicable tax and accounting laws.
  • Security and log data is retained for a limited period appropriate to its purpose.
  • Analytics data is retained according to our configuration with our analytics provider.
  • Customer Data processed as a processor is retained and deleted in accordance with our DPA and the customer's instructions.

When personal information is no longer needed, we delete or de-identify it, except where retention is required for legal, accounting, or legitimate-business purposes, or for the establishment, exercise, or defense of legal claims.

Security

We implement administrative, technical, and organizational measures designed to protect personal information appropriate to the risk, including encryption in transit, access controls, tenant isolation, and secure handling of credentials and secrets. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your authentication factors and connected accounts secure and for promptly notifying us of any suspected unauthorized access. Where required by law, we will notify you and/or the relevant authorities of a personal-data breach.

Your rights and choices

Depending on where you live and applicable law, you may have some or all of the following rights regarding personal information for which we are the controller:

  • Access — to request a copy of the personal information we hold about you.
  • Rectification or correction — to request that we correct inaccurate or incomplete information.
  • Erasure or deletion — to request that we delete personal information, subject to legal exceptions.
  • Restriction — to request that we restrict processing in certain circumstances.
  • Portability — to receive certain personal information in a portable, machine-readable format.
  • Objection — to object to processing based on legitimate interests.
  • Withdraw consent — to withdraw consent at any time where processing is based on consent (such as non-essential cookies), without affecting prior processing.
  • Opt out of "sale" or "sharing" — although we do not sell or share personal information for cross-context behavioral advertising.
  • Non-discrimination — to not be discriminated against for exercising your rights.
  • Lodge a complaint — to lodge a complaint with your local data-protection or supervisory authority.

How to exercise your rights. You may exercise your rights by contacting us at privacy@readyforcommerce.com. We will verify your request (and your authority, for authorized-agent requests) and respond within the time required by applicable law. We will not charge a fee except where permitted by law.

Managing your account. You can access and update much of your information directly within the Services, including your profile, organization settings, team membership, and cookie preferences.

Requests concerning Customer Data. If your request relates to personal information that a merchant processes through the Services (where we act as a processor), we will refer you to, or assist, the relevant merchant, who is the controller of that data.

Regional disclosures

European Economic Area, United Kingdom, and Switzerland. The controller of your personal information is Ready for Commerce, Inc. We process personal information on the legal bases described under How we use personal information and transfer it internationally as described under International data transfers. You have the rights described under Your rights and choices, including the right to lodge a complaint with your supervisory authority. Representative and data protection officer. We assess periodically, and whenever our processing changes materially, whether we are required to designate a representative under Article 27 of the GDPR or a data protection officer under Article 37. Our processing is business-to-business, is limited to the categories described in this policy, does not involve large-scale processing of special categories of data, and does not involve regular and systematic monitoring of individuals on a large scale. On that basis we have not designated a representative or a data protection officer, and we will do so if that assessment changes. In the meantime, you may raise any data-protection matter directly with us at privacy@readyforcommerce.com or through our contact page, and we will respond within the periods required by applicable law.

California (CCPA/CPRA). In the preceding 12 months, we have collected the categories of personal information described under Personal information we collect (including identifiers, customer-account and commercial information, internet and network activity, and limited geolocation inferred from IP), for the business purposes described under How we use personal information, and disclosed them to the categories of recipients described under How we disclose personal information. We do not "sell" or "share" personal information. To the extent we process any information that may be considered "sensitive personal information," we do not use or disclose it for purposes that would entitle you to a right to limit its use. California residents have the rights to know, access, correct, and delete personal information, to opt out of sale or sharing (inapplicable here), and to non-discrimination, and may use an authorized agent.

Other U.S. states. Residents of other U.S. states with comprehensive privacy laws (such as Virginia, Colorado, Connecticut, Utah, Texas, and others) have rights to access, correct, delete, and obtain a portable copy of their personal information, and to opt out of targeted advertising, sale, or certain profiling. We do not engage in targeted advertising, sale, or profiling that produces legal or similarly significant effects. You may exercise these rights and, where available, appeal a decision through our contact page.

Artificial intelligence in the Services

Where we use it. Two features of the Services are performed with the help of artificial-intelligence models operated by providers on our behalf. In the Repricer, when a competitor's page cannot be read by ordinary means, we ask an AI provider to read the price from that page's text or from a screenshot of it. In the PIM, when a user asks for it, we ask an AI provider to transform a specific product image — increasing its resolution, removing its background, or isolating a subject within it.

What we send. We send only what the requested operation needs: the content of the external page in question, or the selected image and the parameters of the operation. We do not send your account credentials, authentication data, billing information, or your catalog as a whole to an AI provider.

Training. We do not use your information to train, fine-tune, or develop generally available artificial-intelligence models. We do not authorize our AI providers to use the data we submit to train their models, and where a provider offers a control for this, we set it accordingly.

Accuracy. AI output is probabilistic and may be inaccurate or incomplete. It concerns products, images, and prices rather than people, and it is always reviewable: a suggested price is subject to the rules and limits the customer configures, and a transformed image is presented to the user before it is saved.

Automated decision-making

The Repricer computes and, when enabled by a customer, submits product prices automatically based on rules and constraints the customer configures. These are automated decisions about products and prices made at the customer's direction; they are not decisions that produce legal or similarly significant effects concerning individual data subjects. We do not use personal information to make solely automated decisions that produce legal or similarly significant effects about you within the meaning of Article 22 of the GDPR, and we do not use it for profiling.

Children

The Services are intended for business and commercial use and are not directed to children. We do not knowingly collect personal information from children under the age of 16 (or the age specified by applicable law). If you believe a child has provided us personal information, please contact us so we can take appropriate action.

Other sites and services

The Services may link to, or interoperate with, third-party websites and services — including connected sales channels and payment providers — that we do not control. This Privacy Policy does not apply to those third parties, and we are not responsible for their privacy practices. We encourage you to review their privacy notices.

Changes to this policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by reasonable means, such as posting the updated policy with a new "Effective" date and, where appropriate, providing additional notice. Your continued use of the Services after the effective date constitutes acknowledgment of the updated Privacy Policy.