Woopify.app

Privacy Policy

Last updated: September 2026

1. Controller

Data controller: Woopify (online sole-proprietor operation based in Morocco), contact: [email protected] (privacy requests: [email protected]).

2. Data we collect

  • Account: email address (magic-link login).
  • Scrape jobs: source store URLs, extracted public product data (titles, prices, images).
  • Payments: processed by Paddle (Merchant of Record and seller of record — billing, tax, chargebacks). We never see or store card numbers (we keep Paddle transaction IDs).
  • Analytics: only if you consent via the cookie banner (Google Analytics 4).

3. Purposes & legal bases (GDPR)

  • Provide the Service (contract): account, scrapes, exports, downloads.
  • Payments & fraud prevention (contract / legitimate interest).
  • Audience measurement (consent, via the cookie banner).

4. Subprocessors

  • Supabase (database, auth, file storage — EU infrastructure).
  • Railway (hosting).
  • Paddle (payments as Merchant of Record — billing, tax calculation/remittance, chargebacks — under Paddle's DPA and transfer safeguards).
  • Google Analytics 4 (only with consent).

5. Retention

  • Scrape jobs & products: 30 days, then purged.
  • Export files & signed links: 7 days.
  • Account: until you delete it (Account page → Danger zone removes everything).
  • Invoices: kept as required by tax law.

6. Your rights

Access, rectification, erasure, restriction, portability, objection: write to [email protected] — reply within one month. You may lodge a complaint with your data protection authority (in France: CNIL).