ProfNerve

Legal

Privacy Policy

This policy explains how ProfNerve processes personal data when merchants use the service and connect ecommerce or advertising platforms.

Effective 5 September 2026Version 2026-09-05Spain

1. Controller and contact

ProfNerve is operated by Carlos Bondia Casino, established in Spain. Privacy requests can be sent to privacy@profnerve.com.

2. Data we process

We process merchant account information, connected-store identifiers, server-restricted integration credentials, store configuration, product and order information, technical customer identifiers, historical order counts, advertising performance data, audit results and security logs.

Shopify customer names, addresses, telephone numbers and email addresses are not requested for the current ProfNerve audit. We request only the protected customer data required to calculate customer, order and retention statistics.

3. Purposes and legal bases

Data is processed to authenticate merchants, maintain requested integrations, calculate ecommerce and advertising metrics, generate profit audits and recommendations, provide reports, prevent abuse, troubleshoot failures and comply with law.

Merchant account and integration data is processed to perform the service agreement. Security and limited operational logging rely on legitimate interests in operating a safe service. Merchants remain responsible for an appropriate legal basis for customer data made available through connected platforms.

4. Minimisation and automated analysis

ProfNerve limits processing to information needed for merchant-facing reports and statistics. Individual Shopify order and customer records are retrieved for transient processing and are not persisted as customer lists. Recommendations support merchant decisions and do not make decisions about consumers with legal or similarly significant effects.

5. Service providers and transfers

We use Shopify for commerce integration, Supabase for authentication and database infrastructure, Vercel for hosting, and OpenAI for restricted analysis generation. Each provider processes data only as needed for its service and under applicable contractual and security terms. Restricted international transfers use a recognised legal safeguard where required.

6. Retention and deletion

Raw Shopify order and customer responses are processed transiently. Integration credentials are removed when access is disconnected or revoked. Personal data associated with a disconnected Shopify store is deleted or irreversibly anonymised no later than 30 days after disconnection, unless a shorter legal deadline applies.

Aggregated reports are retained while the merchant account is active. They are deleted or anonymised on account deletion, except for narrowly limited records that law requires us to retain.

7. Security

ProfNerve uses encrypted network connections, server-side access controls, user and store ownership checks, restricted administrative access, provider encryption at rest, safe error responses and security logging.

8. Rights and merchant instructions

Depending on applicable law, individuals may request access, correction, deletion, restriction, portability or objection. Shopify customer requests should normally be made to the relevant merchant. We assist merchants with verified requests and honour Shopify privacy webhooks. Contact privacy@profnerve.com.

9. Changes

We may update this policy when the product, providers or legal requirements change. Material changes will be communicated and a new version will require acceptance where appropriate.