Privacy Policy

Last updated: 26.09.2026

Privacy Policy of PROGUS

1. Data Controller and Collection of Personal Data

Progus sp. z o.o., with its registered office at ul. Sklepowa 27, 97-500 Radomsko, Poland, entered in the Register of Entrepreneurs of the National Court Register kept by the District Court for Łódź-Śródmieście in Łódź, XX Commercial Division of the National Court Register, under KRS number 0001078024, NIP 7722434496, share capital PLN 10,000.00 (hereinafter "PROGUS"), is the controller of the personal data of the merchants who use our applications, our partners, visitors of our websites, job candidates and the business contacts described in this Policy. We process personal data in accordance with:

  • Regulation (EU) 2016/679 (GDPR) and the UK GDPR
  • The California Consumer Privacy Act (CCPA), as amended
  • Nevada state regulations

For the personal data of a merchant's own customers and store visitors that our applications process (for example orders, deliveries, subscriptions or map searches), PROGUS is a processor acting on behalf of the merchant, who is the controller; where the merchant is itself a processor for another company, PROGUS is a sub-processor. That processing is governed by our Data Processing Agreement and described in the "Application-Specific Provisions" below. If you are a customer of a store, please contact the store first about your data.

2. Contact Information

All inquiries regarding this Privacy Policy or your data rights should be directed to:
privacy@progus.com

We have not appointed a Data Protection Officer, as we are not required to do so under Article 37 GDPR. All data-protection matters can be addressed to the contact above.

3. Purposes and Legal Grounds for Personal Data Processing

We process personal data for the following purposes:

A. Providing our applications to merchants:
Installing and running the applications, the merchant account, billing and service communication, to perform our contract with the merchant (Art. 6(1)(b) GDPR); keeping accounting and tax records (Art. 6(1)(c) GDPR); and our legitimate interests (Art. 6(1)(f) GDPR) in keeping the applications secure, preventing abuse, and establishing, exercising or defending legal claims.

B. Support (chat and e-mail):
Answering your questions and support requests, to perform or prepare a contract (Art. 6(1)(b) GDPR) and, for other inquiries, on the basis of our legitimate interest in answering the people who contact us (Art. 6(1)(f) GDPR).

C. Marketing and newsletters:
Sending newsletters and electronic marketing on the basis of your consent (Art. 6(1)(a) GDPR), which you may withdraw at any time by unsubscribing, without affecting the lawfulness of processing before withdrawal; and informing merchants who use our applications about our own similar products, on the basis of our legitimate interest in promoting our products (Art. 6(1)(f) GDPR), to which you may object at any time.

D. Product analytics, error reports and logs:
Understanding how merchants use our applications, finding and fixing errors and securing our systems, on the basis of our legitimate interest in providing reliable, secure and useful applications (Art. 6(1)(f) GDPR).

E. Website, cookies and advertising:
Operating and securing our websites (Art. 6(1)(f) GDPR, our legitimate interest in a working and secure website); analytics and marketing cookies and pixels only with your consent (Art. 6(1)(a) GDPR). See section 12.

F. Social media:
Running our social media profiles and communicating with the people who interact with them, on the basis of our legitimate interest in presenting our products and communicating with our audience (Art. 6(1)(f) GDPR); your name (or pseudonym) and photo will be visible.

G. Job applications:
Carrying out recruitment: data required by labour law on the basis of Art. 6(1)(c) GDPR, other data needed to decide on entering into a contract with you on the basis of Art. 6(1)(b) GDPR, and any additional data you choose to give us, or use of your application in future recruitments, on the basis of your consent (Art. 6(1)(a) GDPR). Providing the data is voluntary, but without it we cannot consider your application.

H. Business outreach emails:
Emailing online stores and e-commerce agencies to present our applications and partner program, on the basis of our legitimate interest in direct marketing of our own products to businesses (Art. 6(1)(f) GDPR). Details are in section 19.

I. Partner (affiliate) program:
Running the program, attributing referrals and paying commissions, to perform our contract with the partner (Art. 6(1)(b) GDPR); keeping accounting and tax records (Art. 6(1)(c) GDPR); and our legitimate interest in preventing fraud and pursuing claims (Art. 6(1)(f) GDPR). See the section "Progus Affiliate Program" below.

J. Signing the Data Processing Agreement online:
Keeping a record of the conclusion of the Data Processing Agreement, which the law requires to be in writing (Art. 6(1)(c) GDPR in connection with Art. 28(9) GDPR), and our legitimate interest in being able to prove it (Art. 6(1)(f) GDPR). See section 20.

4. Types of Data Processing

We may collect and process various forms of personal data based on the functionalities you utilize:

A. Applications: If you install and use our applications, we process your identification data, including your name, store name and domain, country and email address, and your subscription and billing status.

We may also automatically collect information, including:

  • Usage and log information, encompassing data on your activity, log files, diagnostic, crash, website, and performance logs and reports.
  • Subscription information.
  • Location information that you enter into our applications, such as location name, location address, latitude and longitude, and location contact details: email, phone, fax.

B. Contacting Us: When contacting us via our chat or email, we will process your identification data, such as your name and email address, along with any other data you provide.

C. Marketing and Newsletter: Your email address, name and basic information about your use of our applications, if you subscribe to our newsletter, consent to marketing, or use our applications.

D. Social Media: When you interact with our social media profiles, we may process personal data posted on your profile and other data related to our use of social media functionality.

E. Job Applications: The data in your CV and application, in the scope permitted by the Labour Code and other applicable laws, and any other data you choose to give us.

5. Right to Object

You have the right, at any time, to object to the processing of your data based on legitimate interests. We will then stop the processing unless we demonstrate compelling legitimate grounds that override your interests or need the data to establish, exercise or defend legal claims. If you object to processing for direct marketing, we stop it in every case.

6. Data Retention

We retain data for the following periods, depending on the purpose:

  • Merchant account and application data: for as long as the application is installed or the account is active; application data is deleted after uninstalling as described for each application below.
  • Billing, accounting and tax records: 5 years from the end of the calendar year in which the tax obligation arose.
  • Data needed to establish, exercise or defend legal claims: until the limitation period for those claims expires (generally 3 years for claims related to business activity and 6 years for other claims under Polish law).
  • Support conversations: for the duration of our cooperation with the merchant and then until claims related to it are time-barred.
  • Marketing and newsletters: until you withdraw consent, unsubscribe or object; after that we keep only your email address on a suppression list so that we do not contact you again.
  • Job applications: until the end of the recruitment process; if you consent to future recruitments, for 12 months or until you withdraw consent.
  • Social media: for as long as the content remains on our profile or on the platform.
  • Product analytics (PostHog): for the period set by its plan, at most 7 years. Error reports (Sentry): up to 90 days.
  • Technical logs: kept by our hosting and logging providers for a limited period (7 days on Fly.io; in Better Stack 15 days for Progus Store Locator and 8 days for its storefront API); Cloudflare does not keep request logs.
  • Website analytics and advertising cookies: for the periods shown in the cookie declaration of our consent banner, and never after you withdraw consent.
  • Business outreach data: up to 60 months from our last contact, or only the email address on a suppression list after an objection (see section 19).
  • Partner program: see the section "Progus Affiliate Program".
  • Records of Data Processing Agreements signed online: for the duration of the agreement and then until claims related to it are time-barred (see section 20).

7. Data Recipients

We share personal data only with the service providers that support our activities, acting on our behalf and under contracts with us, and with entities entitled to receive it by law. The providers we use as a controller (for merchants, partners, website visitors and other persons described in sections 1 to 6) are:

  • Hosting and infrastructure: Amazon Web Services (databases, United States), Heroku by Salesforce (application servers, United States), Fly.io (application servers, European Union and United States) and Cloudflare (content delivery, security, website hosting on Cloudflare Pages, bot protection with Cloudflare Turnstile, file and backup storage in Cloudflare R2). See the Heroku, AWS, Fly.io and Cloudflare privacy policies.
  • Support: Gleap (support chat and session replays of our applications' admin panels, European Union; see the Gleap Privacy Policy), and AI tools from Anthropic (Claude) and OpenAI, used under their business terms with training on our data turned off; the content of messages you send to our support may be processed by these tools.
  • Email: Google Workspace (our company mailboxes, including service emails sent from no-reply@progus.com and contact@progus.com), and Brevo, our email marketing and customer relationship platform, to which we synchronise the email address, name and basic app-usage information of merchants who use our applications, to send product communications and manage our mailing lists (see the Brevo Privacy Policy).
  • Product analytics: PostHog (PostHog Cloud EU, European Union), which processes in-app usage events, technical data (such as browser and device information) and session replays of the merchant admin panels of Progus Store Locator, Progus Subscriptions and Progus AI Studio, without cookies and with form inputs and third-party personal data masked (see the PostHog Privacy Policy). Progus Store Locator also sends plan purchase events from our server to Google Analytics 4 (Measurement Protocol); no analytics cookies or tags run in its admin panel.
  • Error reports and logs: Sentry (error reports, configured not to include user details, cookies, request headers or form contents; Progus Store Locator reports are stored in the EU) and Better Stack (server logs with technical request data such as IP addresses). See the Sentry and Better Stack privacy policies.
  • Sign-in and payments: Google and Apple (if you sign in with them to the Progus Store Locator dashboard or the partner portal); Shopify, Wix, Shoper and Paddle (billing for our applications, depending on the platform); PayPal (partner commission payouts).
  • Website and advertising: Cookiebot by Usercentrics, Google (Tag Manager, Analytics, Ads, Fonts, YouTube), Meta Platforms (Meta Pixel), Vimeo, X, and Sanity (content and images of progus.com). See section 12.
  • Business outreach: Smartlead, Microsoft 365, MillionVerifier and Serper (see section 19).
  • Social media providers (e.g., Meta Platforms Ireland Limited, X Corp., Google LLC), for our profiles on their platforms.
  • Our accounting office, legal advisers, auditors, banks, and public authorities where the law requires it.

The providers our applications use to process the data of merchants' customers on the merchant's behalf are listed for each application below and in Annex III of our Data Processing Agreement.

8. Your Rights as a Data Subject

You have the right to:

  • Obtain information regarding data processing
  • Access your data
  • Rectify inaccurate or incomplete data
  • Request deletion of data ("right to be forgotten"), subject to exceptions
  • Restrict processing
  • Request data portability
  • Object to data processing (including for marketing purposes)
  • Withdraw consent (without affecting the lawfulness of previous processing)
  • Lodge a complaint with a data protection authority
  • Request explanation and human intervention in the case of automated decision-making

To exercise your rights, write to privacy@progus.com. We respond free of charge, within one month, unless requests are manifestly unfounded or excessive.

9. Information on Data Transfers Outside of the EEA

Our main application databases are hosted by Amazon Web Services in the United States, and several of our providers process data outside the European Economic Area (EEA). Personal data is therefore transferred in particular to:

  • the United States: Amazon Web Services, Heroku (Salesforce), Fly.io (US servers), Cloudflare, Google (Workspace, Analytics, Ads, Maps Platform, Fonts, Sign in with Google), Microsoft 365, Apple (Sign in with Apple, MapKit), Meta Platforms, Mapbox, Resend, Klaviyo, OpenAI, Anthropic, NexusAI Services LLC (Kie.ai), Functional Software (Sentry), Better Stack, Cloudinary, Smartlead, MillionVerifier, Serper, LocationIQ (US endpoint), Sanity (content delivery network) and PayPal;
  • India: MSG91 (Walkover Web Solutions, SMS for Progus COD Form, with its service hosted in the United States or Germany) and LocationIQ (Unwired Labs);
  • the United Kingdom: the OpenStreetMap Foundation and Paddle.

Transfers take place under an adequacy decision of the European Commission (including the EU-US Data Privacy Framework for certified recipients, and the decision for the United Kingdom) or under the European Commission's Standard Contractual Clauses (SCCs). You can request a copy of the safeguards at privacy@progus.com. You may lodge a complaint regarding the processing of your personal data with a supervisory authority (in Poland, the President of the Personal Data Protection Office, UODO) or with the authority in your country of residence.

10. Automated Decision-Making, Including Profiling

Some of our applications use automated processing and artificial intelligence to generate content and suggestions (for example product images, subscription-plan suggestions, and upsell or cross-sell recommendations). These features assist merchants and do not make decisions that produce legal or similarly significant effects concerning an individual within the meaning of Article 22 GDPR. With your consent, we use cookies for analytics and advertising, which may involve profiling. Where any solely automated decision producing legal or similarly significant effects is ever made, you have the right to obtain human intervention, to express your point of view, and to contest the decision.

11. Security of Your Personal Data

We implement measures to protect data against loss, destruction, unauthorized access, or disclosure; however, no method of transmission or storage guarantees 100% security. The measures are described in Annex II of our Data Processing Agreement and on our security page.

  • Data in transit is encrypted using TLS.
  • Data stored in our application databases is encrypted using the AES-256 algorithm.
  • Limiting access: only the managing director and the employees who need it for their work have access to production systems and databases, and access is removed on the day a person leaves.
  • Two-factor authentication on all administrative accounts (hosting, source code, Shopify Partner account).
  • A written incident response procedure (see section 18), which every person with access reads before access is granted.
  • Automated, encrypted database backups, kept for 35 days for Progus Store Locator and 7 days for our other applications, deleted automatically after that period and accessible only to authorised personnel.

12. Cookies, Website Tools and Embedded Content

We use cookies to:

  • Provide and secure our websites and Services
  • Remember your preferences (e.g., language, cookie choices)
  • Measure how our websites are used (with your consent)
  • Measure and personalise our advertising (with your consent)

We use Cookiebot by Usercentrics to collect, manage, and document cookie consents and consent withdrawals on progus.com and on our partner portal. Consent preferences can be changed or withdrawn at any time via the cookie settings available on our websites. Necessary cookies are used without consent; statistics and marketing cookies only after you consent. See the Cookiebot Privacy Policy.

Statistics and marketing (only with your consent): Google Tag Manager, which loads our measurement tags; Google Analytics 4, to measure website usage (page views, interactions, conversions); Google Ads, to measure campaign performance and conversions and support advertising features; and the Meta Pixel (Meta Platforms Ireland Limited), to measure our Facebook and Instagram campaigns and show our ads to relevant audiences. These tools may process cookie identifiers, device and browser information, IP address, approximate location, pages visited and conversion events. See the Google Privacy Policy, How Google uses information from sites and apps and the Meta Privacy Policy.

Website hosting and content: progus.com is hosted on Cloudflare Pages. Images and content of the website are delivered by Sanity's content delivery network, which receives your IP address and browser data. Our content management system uses OpenAI to translate website content; no personal data is sent for this purpose.

Embedded content: some pages embed videos or posts from YouTube (Google), Vimeo or X. When such content loads, the provider receives your IP address and browser data and may set its own cookies; on the Progus Store Locator page, the YouTube video loads only after you click it. Our Store Locator pages also embed a live demo of the Progus Store Locator map, which uses the providers listed for that application below.

Forms: if you request a report from our consumer-law compliance scanner (DMCCA scan), your email address and the scanned store domain are sent to the Progus Subscriptions application, which prepares and sends the report (see "Progus Subscriptions" below).

13. Information and Notice for California Residents

This section covers the collection, use, disclosure, and sale of personal data of California consumers in accordance with the CCPA as amended by the California Privacy Rights Act.

  • We do not sell personal information for money. On our websites, advertising and analytics technologies (such as Google Ads, Google Analytics, and the Meta Pixel) load only after you opt in through our Cookiebot consent banner; if you do not consent, no related "sharing" for cross-context behavioral advertising takes place. You can withdraw your consent at any time in the cookie settings, or ask us to stop any sharing by writing to privacy@progus.com with the subject "Do Not Sell or Share".
  • In our applications, we act as a service provider to merchants for the data of their customers. For example, in Progus COD Form, conversion tracking to advertising platforms runs only where the merchant enables it, and the merchant is responsible for it.
  • We do not use or disclose sensitive personal information for purposes that would trigger the right to limit its use.
  • Data may be used for the business and commercial purposes described in this Policy.

You have the right to know, access, correct, delete and port your data, and not to be discriminated against for exercising these rights. Please send requests to privacy@progus.com or by post to PROGUS, ul. Sklepowa 27, 97-500 Radomsko, Poland (Attn: CCPA Request). We verify requests by matching the information you give us with the information we hold.

14. Nevada Residents

Nevada law allows customers to "opt out" of the sale of certain personal information, known as "covered information." We do not sell covered information as defined in the law, and we have no plans to change this practice. If you wish to be notified if we change this practice, you can email us and provide your name, Nevada resident address, and email address. We will contact you if there are any changes, and you can complete your opt-out at that time. If your contact information changes, please contact us to update it. We may share your data for different purposes as explained in this Privacy Policy, which are separate from your opt-out request.

15. Links to Other Sites

Our website and applications may contain links to, or integrations with, third-party websites and services that we do not control (for example Shopify, payment providers, social media, and the providers listed in this Policy). This Privacy Policy does not apply to those third parties, and we are not responsible for their content or privacy practices. We encourage you to review the privacy policy of any third-party website or service you use.

16. Children's Privacy

Our Services are directed to businesses and are not intended for children. We do not knowingly collect personal data from children under the age of 16 (or the lower minimum age of digital consent that may apply in your country, which in some jurisdictions is 13). If we learn that we have collected such data without the consent of a parent or legal guardian, we will take steps to delete it.

17. Changes to this Privacy Policy

This Privacy Policy may be updated periodically. Changes will be communicated by publishing a new version on the website, with the last updated date clearly indicated at the beginning of the document.

18. Incident Response and Data Breach Notification

We have implemented an internal Incident Response Policy to promptly detect, investigate, and mitigate security incidents.

In the event of a personal data breach that poses a risk to your rights or freedoms, we will:

  • Immediately work to contain and eliminate the threat,
  • Assess the impact and affected data,
  • Notify the competent supervisory authority (for example, the Polish Personal Data Protection Office) within 72 hours if required by applicable law,
  • Inform affected users without undue delay when the breach may result in a high risk to their rights and freedoms,
  • Notify affected merchants within 48 hours where the breach concerns data we process on their behalf,
  • Document the incident and the actions taken.

For security incidents not involving personal data, we will still investigate and take remediation measures to protect the Services and user accounts.

19. Business Outreach Emails

We sometimes email online stores and agencies that build online stores which have not been in contact with us before, to present our applications and our partner program. This section explains how we handle the personal data involved, including the information required by Article 14 GDPR where the data was not obtained from you.

Who we contact. Business contacts of online stores and e-commerce agencies, for example an owner or manager, or a general company address such as hello@ or info@.

What data we process. Your business email address; your name and role, where they are published; the company name and website domain; public information about the store or agency (such as the e-commerce platform it uses, apps visible on its website, its country, and its partner directory listing); and our correspondence with you, including whether a message was delivered, replied to or unsubscribed from.

Where the data comes from. Publicly available sources: the company's own website, public business directories (such as the Shopify Partners directory and databases of online stores compiled from public websites, for example Store Leads), public company registers, and publicly available professional profiles found through a search engine. In a small number of cases we derive a likely business address from a published name and the company's domain. Before sending, we check that each address can receive email.

Purpose and legal basis. Offering our applications and our partner program to businesses, based on our legitimate interest in direct marketing of our own products to businesses (Art. 6(1)(f) GDPR). We write only to business addresses, a sequence has at most three messages, and every message contains an unsubscribe link. We do not send such emails to recipients in countries whose law requires prior consent for commercial email to businesses, such as Poland.

Recipients. Smartlead (sending and managing the emails), Google Workspace and Microsoft 365 (the mailboxes we send from and receive replies in), MillionVerifier (checking that an address can receive email), Serper (a search API we use to find publicly listed company contacts), Anthropic (Claude, which helps us draft replies to your messages, with training on our data turned off), and our hosting and backup providers, including Cloudflare. Some of these providers are based outside the EEA, in particular in the United States; such transfers take place under the European Commission's Standard Contractual Clauses (SCCs) or, for certified entities, the EU-US Data Privacy Framework (DPF), as described in section 9.

Retention. We keep this data for up to 60 months from our last contact with you. If you object or unsubscribe, we stop immediately and delete your data, except for your email address, which we keep on a suppression list only to make sure we never contact you again.

Your rights. You can object at any time, free of charge, by replying to our email, by using the unsubscribe link in any message, or by writing to privacy@progus.com. You also have the rights described in section 8, including access, rectification, erasure and restriction, and you may lodge a complaint with a supervisory authority (in Poland, the President of the Personal Data Protection Office, UODO) or with the authority in your country of residence. We do not make automated decisions about you that produce legal or similarly significant effects.

20. Signing the Data Processing Agreement Online

When a merchant signs our Data Processing Agreement at progus.com/dpa/sign, we process the name, job title and email address of the person signing, the company's name, address, country and registration number, the store domain, the applications covered, and the technical record of the signature: the IP address, browser user agent and time of the request and of the confirmation. We use this data to send the confirmation link and the signed PDF, to keep a record of the agreement, and to notify the signatory of changes to the agreement and its sub-processors. The legal basis is Art. 6(1)(c) GDPR in connection with Art. 28(9) GDPR, which requires the agreement to be in writing, and our legitimate interest in proving its conclusion (Art. 6(1)(f) GDPR). We keep the record for the duration of the agreement and then until claims related to it are time-barred. The emails are sent through Google Workspace; the record is stored on our own server and in our encrypted off-site backups.


The above provisions apply to the progus.com website and to all services and applications offered by PROGUS SP. Z O.O. The following provisions apply exclusively to the specified services/applications.

Application-Specific Provisions

Merchant data and end-customer (shopper) data

Our applications are distributed mainly through the Shopify App Store, the Wix App Market, WordPress.org and Shoper. For the personal data of the merchants who install and use our applications (for example the account owner's name, email address, store domain, and billing details), PROGUS acts as the data controller.

Where an application processes the personal data of the merchant's own customers or store visitors (for example order, delivery, contact, or phone data), PROGUS acts as a data processor (or as a sub-processor, where the merchant itself processes the data for another company) and processes that data only on behalf of, and under the instructions of, the merchant, who remains the controller of that data. This processing is governed by our Data Processing Agreement, which lists the providers involved for each application, and by the relevant platform's terms (including, for Shopify apps, the Shopify API License and Terms of Use and Shopify's Protected Customer Data requirements). We do not sell this data and do not use it for our own purposes; we improve our applications only with aggregated or anonymised data.

Legal basis when we act as a processor. The legal basis for processing a shopper's personal data is determined by the merchant as controller, typically the performance of the merchant's contract with the shopper (Art. 6(1)(b) GDPR) and the merchant's legitimate interests, for example in preventing fraud (Art. 6(1)(f) GDPR). Transactional messages such as the OTP verification SMS are sent as a necessary part of providing the requested service and are not marketing communications. Some features that a merchant may enable, such as advertising pixels, may require the shopper's consent, which the merchant is responsible for obtaining.

Integrations the merchant selects. Some applications can send data to services that the merchant connects with its own account (for example payment providers, email marketing tools, shipping services, advertising platforms, or map styles the merchant chooses). These services act under their own terms with the merchant and are listed for each application below and in part B of Annex III of the Data Processing Agreement.

Shopify platform and data deletion

Our Shopify applications run on Shopify's infrastructure and access store data through Shopify's APIs, limited to the permissions (scopes) you grant when installing the app. We comply with Shopify's Protected Customer Data requirements and process Shopify's mandatory privacy/compliance webhooks (customers/data_request, customers/redact, and shop/redact). When we receive a verified data-deletion or data-access request through Shopify, we delete, redact, or provide the related personal data we hold, except where we are required to retain it by law. When you uninstall Progus Store Locator, Progus Subscriptions, InPost by Progus, Progus AI Studio, Progus COD Form, Progus Upsell or Progus Trust Badges, we delete the store's data, at the latest when Shopify sends its shop/redact request 48 hours later. For more information, see the Shopify Privacy Policy.

Progus Affiliate Program

1. Purpose of Data Collection in the Affiliate Program

We operate an affiliate program ("Progus Partners") that allows participants to earn commissions for referring new users to our products and services. Partners use our partner portal.

The data processed in connection with the affiliate program includes:

  • Partner identification details (name, email address, company, partner ID) and, if you sign in with them, your Google or Apple account identifier.
  • Referred stores, referral and click statistics, and commissions.
  • Payout details: your PayPal email address and payout history.

We process this data to run the program, attribute referrals, calculate and pay commissions and communicate with you (Art. 6(1)(b) GDPR), to keep accounting and tax records (Art. 6(1)(c) GDPR), and on the basis of our legitimate interest in preventing fraud and pursuing claims (Art. 6(1)(f) GDPR).

Affiliate cookie. When a visitor clicks an affiliate link, a cookie with the referring partner's ID may be stored in their browser, only after they consent to marketing cookies, and is kept for up to 45 days unless deleted earlier. It is used solely to attribute the referral.

Providers. The partner portal is hosted on Heroku (United States) with our databases on Amazon Web Services (United States). We also use Google and Apple (sign-in), Cloudflare Turnstile (bot protection), Cookiebot, Google Tag Manager and the Meta Pixel (only after consent), Google Fonts, Brevo (partner emails and newsletters), Gleap (support chat), Google Workspace (service emails), PayPal (commission payouts) and the Shopify Partner API (to see which referred stores installed our apps).

Retention. Settlement and payout data: 5 years from the end of the calendar year in which the payout was made. Other partner data: until the end of our cooperation and then for 3 years, to handle claims.

Progus Store Locator

1. Purpose of Data Collection in the Application

Progus Store Locator is an application for locating stores that enables the presentation of physical store locations on a map and their management. We use personal data to:

  • Provide and operate the Service and the Application
  • Communicate with you
  • Improve the Application, using data about merchants' use of the admin panel and only aggregated or anonymised data about their customers
  • Provide you with information about our products or services

We do not sell personal data. It is disclosed only to the providers listed below, or where required by law.

2. Types of Personal Data Collected

Merchant data: first name, last name, country, website URL, email address, subscription data, application settings and login sessions. We may also automatically collect usage data and logs: details about your activity, log files, diagnostics, failure reports, and performance data.

Location Information:

  • Location name
  • Location address
  • Latitude and longitude of the location
  • Opening hours
  • Contact details (email, phone, fax)
  • Social media links
  • The location's website URL
  • Tags, tag categories, and group names
  • Location photos
  • Translations of location data into other languages
  • Appearance data for map markers
  • Custom data fields created by the user

Customer Search Information on the Map: When a visitor searches for nearby locations on the map, the application may determine the visitor's approximate position, either with the browser's geolocation feature (only after the visitor allows it) or from the visitor's IP address, depending on the merchant's settings. The IP-based estimate is made by Cloudflare, our content delivery provider, which already handles every request to the map; we do not store the IP address for this purpose. The position or the address the visitor typed is used to show the nearest locations.

Search statistics for the merchant. Each search is also saved as a statistic for the merchant's analytics panel and reports. A statistic contains the coordinates of the searched place (or the visitor's approximate position when they use "find me"), the country, city, region and postal code of that place, the nearest store location and, where relevant, the product searched for. It contains no IP address, no visitor identifier, no browser or device data and no account data, so it cannot be linked to a person by us. Search statistics are deleted automatically after 12 months, and immediately when the merchant uninstalls the application.

Dealer and retailer requests: If the merchant enables the "become a dealer" form, a person who submits it provides the details of their business location (for example name, address, email, phone number, website, social media links, opening hours and images). We store these details on the merchant's behalf so the merchant can review the request. They are deleted when the merchant deletes the request, when the merchant uninstalls the application, or when we receive a verified deletion request for that person through the platform.

Application Operation Data: History of location imports, connection data for file synchronization (e.g., Google Sheets), application settings, login sessions, and subscription data.

Service providers used by Progus Store Locator. To run the application we use the following providers, each only for the purpose stated:

  • Hosting and database: Amazon Web Services (database, United States), Heroku (application servers and storefront API, United States), Fly.io (application servers in the European Union and storefront API in the United States) and Cloudflare (content delivery, security, the approximate IP-based position, and storage of location photos and dealer images in Cloudflare R2). Older location photos are still served by Cloudinary.
  • Converting the merchant's store addresses and the addresses from dealer requests into map coordinates (geocoding): Google Maps Platform and TomTom.
  • On the storefront map: map tiles from the OpenStreetMap Foundation (the default Progus map style, and as a fallback), OpenStreetMap Nominatim (turning a browser-provided position into an address), LocationIQ (address suggestions in the search bar, US endpoint). On paid plans, the dealer request form uses Google Places address suggestions and Google Fonts. These providers receive the visitor's IP address and browser data.
  • Map styles the merchant may choose instead: Google Maps, Mapbox, Apple MapKit, or the "Cold" style of OpenStreetMap France; the chosen provider then serves the map to the visitor.
  • Error reports from the storefront map: Sentry (stored in the EU, sampled, without visitor details, cookies or form contents). Server logs: Better Stack.
  • Merchant account and communication: PostHog (EU instance) for usage analytics of the admin panel, Google Analytics 4 for plan purchase events sent from our server, Sign in with Google and Sign in with Apple for the dashboard outside Shopify, Gleap (support chat), Google Workspace (service emails) and Brevo (product news and marketing to merchants).

Transfers of personal data outside the European Economic Area take place under the safeguards described in section 9. All connections between our application servers and the database are encrypted (TLS).

Deletion when the application is uninstalled. When a merchant uninstalls Progus Store Locator, we delete the store's data (locations, settings, search statistics, dealer requests, imports, API keys and related records) immediately. Records kept for a short time for customer support, such as a pending setup request, are deleted when Shopify sends its shop data erasure request 48 hours later. Backup copies expire within 35 days.

Data processing agreement. Where we process personal data on the merchant's behalf, our Data Processing Agreement applies. It lists our sub-processors and security measures.

Payment Data:

Depending on the platform you use, payment processing may be handled by different providers:

For users of the application outside of Shopify, Wix and Shoper:

  • To process payments and manage subscriptions, we use an external payment provider, Paddle.
  • Payment data (including the credit card number and billing address) is processed by Paddle and is subject to their privacy policy.
  • Our application may retrieve and display some payment details (e.g., the last four digits of the card, billing address, and payment history) solely to enable users to manage their subscription plan.
  • We do not store full credit card data or any other payment information on our servers.

Paddle Privacy Policy

For users of the application on Shopify, Wix or Shoper:

All payment processing is handled by the platform, with payment data processed according to its privacy policy and payment terms. See the Shopify and Wix privacy policies and the privacy policy of Shoper.

Progus COD Form & OTP SMS

1. Purpose of Data Collection in the Application

Progus COD Form & OTP SMS is a Shopify application that provides a Cash on Delivery (COD) order form, optional phone-number verification by SMS one-time password (OTP), and management of the visibility and limits of the COD payment method. For your account data we are the controller; for the data of your store's customers we act as your processor under our Data Processing Agreement. The application processes this data to:

  • Provide the COD order form: process the data a customer enters at checkout to create and manage their order.
  • Verify phone numbers (OTP): when OTP verification is enabled, send a one-time code by SMS to the customer's phone number and confirm that the customer controls that number, in order to reduce fake and fraudulent COD orders.
  • Prevent fraud and abuse: detect and block repeat fraudulent or abusive orders.
  • Manage COD availability and limits: for stores on the free plan, count COD orders to enforce plan limits and, where configured, automatically disable the COD method and notify the store administrator when a limit is exceeded.
  • Conversion tracking (optional): where the merchant enables it, send order and conversion events to the advertising and analytics platforms the merchant has connected.

Personal data is not sold.

2. Types of Personal Data Collected

Merchant data: identifying data such as your email address, account owner name, and store domain, together with subscription and usage/log information (activity, diagnostics, failure reports, and performance data).

Customer (shopper) data submitted in the COD form: first and last name, phone number, email address (where the form asks for it), delivery address (street, city, postal code, country), and order contents (products, quantities, and totals).

Phone verification (OTP) data: to deliver the SMS code and to enforce sending limits and prevent abuse, we process the customer's phone number and country/calling code and log SMS events (such as send status, destination metadata, and timestamps). SMS messages are delivered through our SMS gateway provider, MSG91 (Walkover Web Solutions Pvt. Ltd., India; its service is hosted in the United States or Germany), which receives the destination phone number and the shop name solely to send the message. See the MSG91 Privacy Policy.

Fraud-prevention data: to detect repeat fraudulent or abusive orders we store hashed identifiers (such as a hashed email address and hashed phone number) together with order-blocking events, so that the raw identifiers are not kept for this purpose.

Order analysis: basic order information such as the order ID and selected payment method, processed to apply COD rules and limits.

Conversion tracking (merchant-controlled): where the merchant enables it, the application sends order and conversion events to the platforms the merchant connects: server-side to Meta (Conversions API), TikTok (Events API) and Google Analytics 4 (Measurement Protocol), with the customer's hashed email, phone, name, city, region, postal code and country, and the IP address and browser user agent; and through browser pixels of Meta, Google Ads, TikTok, Snapchat, Pinterest, X, Microsoft Bing, Taboola, Reddit, Kwai and ShareChat loaded on the form. The merchant decides whether to use these platforms, is responsible for obtaining any consent they require, and the platforms process the data under their own terms with the merchant.

Service providers: Heroku (application servers, United States), Amazon Web Services (database, United States), Cloudflare (content delivery; storage of geographic reference data and icons in Cloudflare R2), MSG91 (SMS), Better Stack (server logs), Google Fonts (fonts of the storefront form, loaded in the customer's browser), Google Workspace (service emails) and Gleap (support chat).

Retention: OTP verification sessions are deleted after 7 days, SMS event logs after 60 days and form events after 180 days. All other store data is deleted when the application is uninstalled, at the latest when Shopify sends its shop/redact request 48 hours later.

Payments: payment processing on Shopify is handled by Shopify in accordance with the Shopify Privacy Policy.

3. Relationship with the General Policy

All other rules regarding the legal basis for processing, data retention periods, security, and data sharing are defined in the general section of this privacy policy (sections 3, 6, 7, 11) and in the "Application-Specific Provisions" above, and apply equally to this application.

Progus Subscriptions

1. Purpose of Data Collection in the Application

Progus Subscriptions is a Shopify application that enables merchants to offer recurring subscription plans, manage subscription contracts, and give customers a portal to manage their subscriptions (for example to skip, pause, swap products, or update delivery). We use personal data collected from you and your store's customers to provide and operate the application, process recurring orders and communicate with you. For your customers' data we act as your processor. Personal data is not sold.

2. Types of Personal Data Collected

Merchant data: email address, account owner name, store domain, subscription/billing status for the app, and usage and log information.

Subscription and customer data: subscription plan and contract details (intervals, discounts, plan names, prices), the products and variants included, delivery schedules and related order records, and the subscriber's name, email address, phone number, delivery address, Shopify customer ID and the identifiers of their payment method at the payment provider (customer, mandate or token IDs). We do not store card numbers or bank account numbers. If the merchant imports subscriptions from another subscription app (such as Recharge, Skio, Loop, Appstle or Seal), the same kinds of data are taken from that app.

Hosting: Fly.io (application servers in the United States; the MCP connector in the European Union) and Amazon Web Services (database, United States).

Payments: recurring payments are processed by Shopify or, if the merchant connects one on its own account, by Mollie or Tpay (an Adyen integration exists but cannot currently be connected). We send the chosen provider the subscriber's email address and name (and, for Tpay BLIK payments, the IP address and browser user agent required by the payment). See the Mollie, Tpay and Adyen privacy policies.

Emails to subscribers: all emails to subscribers (for example upcoming order reminders and payment updates) are sent through Resend (United States). See the Resend Privacy Policy.

Klaviyo integration (optional): if the merchant connects its own Klaviyo account, the application sends it, for each event type the merchant enables, the subscriber's email address, phone number, name and Shopify customer ID and the subscription contents with prices, so that the merchant can send subscription communications. See the Klaviyo Privacy Policy.

MCP connector (optional): if the merchant connects its own AI assistant (for example Claude or ChatGPT) through the Progus Subscriptions MCP connector, the assistant receives the subscriber and subscription data the merchant asks it for. See the connector privacy notice.

AI plan generator: to suggest subscription plans, the application sends store catalog data (such as product titles and attributes), and no personal data, to OpenAI. See the OpenAI Privacy Policy.

Support: in the Gleap support chat, our AI support agent can look up a subscriber by email address when the merchant's staff asks about that subscriber.

Compliance scan: if you request a report from our consumer-law compliance scanner, we store your email address and the scanned store domain to send you the report, until you ask us to delete them at privacy@progus.com.

Product analytics: we use PostHog (hosted in the EU, PostHog Cloud EU) to collect in-app usage events and session replays of the merchant-facing admin. Form inputs, and screens that display customer data, are masked in replays. Emails about the application to merchants are sent through Brevo; subscriber data is never sent to Brevo.

Deletion: when the merchant uninstalls the application, we delete the store's data, at the latest when Shopify sends its shop/redact request.

3. Relationship with the General Policy

All other rules regarding the legal basis for processing, data retention periods, security, and data sharing are defined in the general section of this privacy policy (sections 3, 6, 7, 11) and in the "Application-Specific Provisions" above, and apply equally to this application.

Progus Trust Badges & Icons

1. Purpose of Data Collection in the Application

Progus Trust Badges & Icons is a Shopify application that lets merchants display trust badges, payment-method icons, and guarantee symbols on their storefront. It does not store the personal data of store visitors; to deliver the badges, visitors' IP addresses and browser data are processed transiently by our hosting providers (Fly.io in the United States, and Cloudflare).

2. Types of Personal Data Collected

Merchant data: email address, store domain, the application's display and customization settings, images you upload (stored in Cloudflare R2), and usage and log information. View statistics are counted with Cloudflare Workers and D1 and contain only the shop name and view counts. Support is provided through Gleap. When you uninstall the application, we delete the store's data.

3. Relationship with the General Policy

All other rules regarding the legal basis for processing, data retention periods, security, and data sharing are defined in the general section of this privacy policy (sections 3, 6, 7, 11) and in the "Application-Specific Provisions" above, and apply equally to this application.

Progus AI Studio

1. Purpose of Data Collection in the Application

Progus AI Studio is a Shopify application that uses artificial intelligence to generate product image variants and campaign images (for example clean-background, studio, or lifestyle images) from a merchant's product photos and save them to the store's media library. The application does not collect the personal data of store visitors; it processes the personal data of real people only when a merchant creates a model profile of a real person (see below), in which case we act as the merchant's processor. Personal data is not sold.

2. Types of Personal Data Collected

Merchant data: email address, store domain, subscription/usage information, and usage and log data.

Product content: the product images and related product metadata you choose to process, together with the generated images. To generate images and texts, this content is processed by our AI providers Kie.ai (NexusAI Services LLC, United States; image generation, which Kie.ai carries out with image models of OpenAI or Google) and OpenAI (text generation and quality checks of generated images). Campaign images are stored in Cloudflare R2; generated images are saved to your store's Shopify Files. The application runs on Fly.io servers in the United States. See the OpenAI Privacy Policy and the Kie.ai Privacy Policy.

Model profiles of real people: if you create a model profile of a real person, we process that person's photos, name and email address. We first ask the person for consent by email (sent through Resend; the consent link expires after 7 days). With their consent, the photos are sent to OpenAI to create the profile, and the person's likeness is sent to Kie.ai for every campaign that uses the profile; copies of the images showing the person are stored in Cloudflare R2. The source photos are deleted after the profile is generated or when consent is withdrawn. The photos are used only to generate images of that person, not to identify anyone.

Emails: if you join a waiting list or ask for campaign notifications, we store your email address and send those emails through Resend.

Product analytics: we use PostHog (hosted in the EU, PostHog Cloud EU) to collect in-app usage events and error diagnostics for the merchant-facing admin. When you uninstall the application, we delete the store's data.

3. Relationship with the General Policy

All other rules regarding the legal basis for processing, data retention periods, security, and data sharing are defined in the general section of this privacy policy (sections 3, 6, 7, 11) and in the "Application-Specific Provisions" above, and apply equally to this application.

Progus Sticky Add to Cart Bar

1. Purpose of Data Collection in the Application

Progus Sticky Add to Cart Bar is a Shopify application that displays a persistent "add to cart" bar on product pages to improve conversion. The application works with product and storefront information and does not store the personal data of store visitors; to deliver the bar, visitors' IP addresses and browser data are processed transiently by our hosting providers (Fly.io in the United States, and Cloudflare). Personal data is not sold.

2. Types of Personal Data Collected

Merchant data: email address, store domain, the application's display and customization settings, sticker images you upload (stored in Cloudflare R2), reviews you leave in the application (with your email address), and usage and log information. The bar uses product information (such as title, price, and image) and the visitor's cart on their own device. Support is provided through Gleap.

3. Relationship with the General Policy

All other rules regarding the legal basis for processing, data retention periods, security, and data sharing are defined in the general section of this privacy policy (sections 3, 6, 7, 11) and in the "Application-Specific Provisions" above, and apply equally to this application.

Progus Upsell AI

1. Purpose of Data Collection in the Application

Progus Upsell AI is a Shopify application that provides AI-driven upsell and cross-sell product recommendations at different stages of the shopping journey. We use data collected from the store to generate relevant product recommendations, report the revenue they bring, operate the application, and communicate with you. For your customers' data we act as your processor. Personal data is not sold.

2. Types of Personal Data Collected

Merchant data: email address, store domain, subscription/usage information, and usage and log data. Emails about the application are sent through Brevo, and support is provided through Gleap.

Catalog and order data: recommendations are generated from product and catalog information and counts of products bought together. To produce recommendations, the catalog data and these counts, which contain no personal data, are processed by OpenAI. See the OpenAI Privacy Policy. To report the revenue from upsell offers, we store the order ID, the order email address and the products of orders attributed to an offer. The application runs on Fly.io servers in the United States, with its database on Amazon Web Services. When you uninstall the application, we delete the store's data. This application does not process payment-card data.

3. Relationship with the General Policy

All other rules regarding the legal basis for processing, data retention periods, security, and data sharing are defined in the general section of this privacy policy (sections 3, 6, 7, 11) and in the "Application-Specific Provisions" above, and apply equally to this application.

InPost by Progus

1. Purpose of Data Collection in the Application

InPost by Progus is a Shopify application that lets a store's customers select an InPost parcel locker or pickup point during checkout and helps merchants generate shipping labels for InPost deliveries. We use personal data collected from you and your store's customers to provide locker selection, create shipments and labels, and enable delivery and tracking. For your customers' data we act as your processor. Personal data is not sold.

2. Types of Personal Data Collected

Merchant data: email address, store domain, subscription/usage information, and usage and log data.

Customer (shopper) and shipment data: the selected parcel locker or pickup point, and the delivery details needed to create a shipment and label, which may include the customer's name, delivery/contact address, phone number, email address, and order/parcel information. The application runs on Fly.io servers in the European Union, with its database on Amazon Web Services (United States).

InPost carrier services: to create shipments, labels, and tracking with the merchant's own InPost account, the relevant data is sent to InPost through its ShipX, points and InPost Global (international shipments) APIs. See the InPost Privacy Policy.

Other shipping integrations (optional): if the merchant connects its Apilo or Apaczka account, the receiver's name, email address, phone number and delivery address are sent to that service to create the shipment; Apaczka passes them to the carrier that handles the parcel (ORLEN Paczka or DPD). See the Apilo and Apaczka privacy policies.

Pickup point search and reminders: an address the customer types to find a pickup point is sent to LocationIQ (US endpoint) to find nearby points. If a customer chooses pickup delivery but does not select a pickup point, we may send them an email reminder to choose one, through Resend. Reminders are sent only while we have them turned on for the application and the merchant has the pickup point block active on the order status page; the customer's email address is stored for this purpose.

Map for locker selection: the parcel-locker selection map is provided using the Google Maps API, which processes technical data such as IP address and approximate location to render the map in the customer's browser. See the Google Privacy Policy. When you uninstall the application, we delete the store's data.

3. Relationship with the General Policy

All other rules regarding the legal basis for processing, data retention periods, security, and data sharing are defined in the general section of this privacy policy (sections 3, 6, 7, 11) and in the "Application-Specific Provisions" above, and apply equally to this application.