SaleSense ("we", "us", "our") operates the website at salesense.co and provides an AI-powered sales assistant platform for e-commerce merchants (the "Service"). For the purposes of the EU General Data Protection Regulation (GDPR) and applicable privacy law, SaleSense is the Data Controller of the personal data of merchants and their account holders who use our platform directly.
With respect to personal data of end consumers who interact with a SaleSense chat widget embedded on a merchant's website, SaleSense acts as a Data Processor on behalf of the merchant (who is the Data Controller for that data).
Contact:
Email: support@salesense.co
For data protection inquiries: support@salesense.co
We collect different categories of data depending on how you interact with SaleSense:
2.1 Merchant Account Data
When you create a SaleSense account, we collect:
Legal basis (GDPR): Contractual necessity (Art. 6(1)(b)) and legitimate interests (Art. 6(1)(f)).
2.2 Shopify Integration Data
For Shopify merchants, we receive and store:
Legal basis: Contractual necessity (Art. 6(1)(b)); Shopify Partner Agreement.
2.3 Chat Widget and Visitor Data
When a visitor interacts with a SaleSense-powered widget on a merchant's website:
Legal basis: Legitimate interests of the merchant in providing customer service (Art. 6(1)(f)), or consent where required.
2.4 Technical and Usage Data
Legal basis: Legitimate interests in security and service improvement (Art. 6(1)(f)).
We do not: sell personal data to third parties; use data for behavioural advertising; profile individual end consumers; share data between unrelated merchants; use chat conversations to train AI models without explicit consent.
We share data with the following carefully selected processors:
Google LLC (Gemini API)
AI language model processing. Chat messages (without personal identifiers where possible) are sent to Google's Gemini API to generate responses.
Safeguard: Standard Contractual Clauses (SCCs); Google Cloud Data Processing Addendum · policies.google.com/privacy
Google LLC (OAuth)
Sign-in with Google authentication. We receive your Google account ID, email, and name when you sign in with Google.
Safeguard: Standard Contractual Clauses (SCCs) · policies.google.com/privacy
Supabase (PostgreSQL)
Database hosting for all merchant and conversation data. Servers located in EU (Frankfurt).
Safeguard: EU-based processing; SCCs for international transfers · supabase.com/privacy
Render (Hosting)
Application server hosting (EU region). Runs the SaleSense application.
Safeguard: EU-based processing · render.com/privacy
Paddle.com Market Limited
Payment processing and billing for all SaleSense paid subscriptions. Paddle acts as Merchant of Record, handling payment processing, invoicing, tax calculation, and compliance. We share your billing email and subscription plan details with Paddle. Card numbers are processed solely by Paddle and are never stored by SaleSense.
Safeguard: GDPR-compliant; Standard Contractual Clauses (SCCs); Paddle Data Processing Agreement · paddle.com/legal/gdpr
Shopify Inc.
Shopify OAuth and app platform integration for Shopify merchants. We receive a scoped access token to read products, inventory, and orders. Shopify does not process billing on our behalf.
Safeguard: Shopify Partner Agreement; Shopify DPA · shopify.com/legal/privacy
Resend (Email)
Transactional email delivery (verification emails, password resets).
Safeguard: Data Processing Agreement; SCCs · resend.com/legal/privacy-policy
Google LLC (Google Analytics 4) — optional, consent-gated
Website analytics on salesense.co. Activated only when a visitor explicitly accepts analytics cookies. Collects anonymised traffic data (page views, session duration, feature usage). No personally identifiable information is sent. We use Google Consent Mode v2 — the gtag.js script loads in 'denied' mode by default and only begins collecting data after the user accepts.
Safeguard: Standard Contractual Clauses (SCCs); Google Ads Data Processing Terms. You may opt out via the Google Analytics Opt-out Browser Add-on (tools.google.com/dlpage/gaoptout). · policies.google.com/privacy
Meta Platforms Ireland Ltd. (Meta Pixel) — optional, consent-gated
Ad effectiveness measurement on salesense.co. Activated only when a visitor explicitly accepts analytics cookies. Used to measure the performance of our own advertising campaigns and build anonymised audiences. The Pixel script is not injected into the DOM until consent is given. We do not use this data for retargeting third-party audiences or to sell data.
Safeguard: Standard Contractual Clauses (SCCs); Meta Business Terms. You may opt out via Meta Ad Preferences (facebook.com/ads/preferences). · facebook.com/privacy/policy
SaleSense primarily stores and processes data within the EU (Frankfurt, Germany). Where data is transferred to third countries (e.g., the United States for Google APIs), we rely on appropriate safeguards including EU Standard Contractual Clauses (SCCs) approved by the European Commission under GDPR Article 46(2)(c). By using the Service, you acknowledge these transfers.
For UK users, equivalent safeguards apply under UK GDPR and the ICO's International Data Transfer Agreement (IDTA).
If you are located in the EU, EEA, or UK, you have the following rights under GDPR / UK GDPR:
To exercise any of these rights, contact us at support@salesense.co. We will respond within 30 days. Identity verification may be required.
If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA) as amended by the CPRA:
To submit a CCPA request, email support@salesense.co with the subject line "CCPA Request". We will respond within 45 days.
Categories of personal information collected in the past 12 months: identifiers (email, name); commercial information (subscription plan, billing history); internet activity (chat conversations, product interactions); inferences drawn from the above.
We implement industry-standard technical and organizational security measures to protect your data, including:
Despite these measures, no system is completely secure. In the event of a data breach affecting your rights and freedoms, we will notify affected users and, where required, the relevant supervisory authority within 72 hours of becoming aware of the breach (GDPR Art. 33).
We use cookies and similar technologies on salesense.co. For full details of which cookies we use, why, and how to manage your preferences, please see our Cookie Policy.
The Service is intended for use by businesses and is not directed at children under the age of 16 (or the applicable minimum age in your jurisdiction). We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, please contact us immediately at support@salesense.co and we will delete it.
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email (for account holders) or by displaying a prominent notice on our website at least 30 days before the changes take effect. The "Last updated" date at the top of this page will always reflect the most recent revision. Your continued use of the Service after changes become effective constitutes acceptance of the updated policy.
For EU/EEA merchants who require a formal Data Processing Agreement under GDPR Article 28, please contact support@salesense.co with the subject "DPA Request". We will provide a signed DPA incorporating the Standard Contractual Clauses (SCCs) for controller-to-processor transfers.
For any privacy-related questions, requests, or complaints, contact our privacy team:
SaleSense — Privacy
Email: support@salesense.co
Response time: within 30 days (GDPR) / 45 days (CCPA)
If you are not satisfied with our response, you have the right to lodge a complaint with your local Data Protection Authority. EU residents may use the EU Online Dispute Resolution platform.