Privacy Policy
What data we collect, why, who we share it with, how long we keep it, and how to exercise your rights.
- Last updated :
- August 5, 2026
- In force since :
- August 5, 2026
- Published by :
- WeKrea LLC
In short
- We are the controller for your account data, and a processor for the customer data you put into the platform.
- We never sell or rent personal data, and we do not use your customer data to train AI models for other customers.
- Data from Google APIs is used only for the features you enable, in line with the Google API Services User Data Policy (Limited Use).
- You can request access, correction, export or deletion at [email protected].
1. Data controller
WeKrea LLC, a limited liability company registered in the State of Wyoming, United States, 30 North Gould Street, STE R, Sheridan, WY 82801, United States, operates IziStore (https://izistore.app).
For any data-protection question: [email protected] (subject: "Privacy request").
2. Our two roles: controller and processor
Controller: for data about your account, billing, use of the service, support and platform security.
Processor: for the personal data of your own customers (shoppers, contacts, message recipients) that you or your connected platforms put into the platform. You are the controller of that data; we process it only on your instructions, under the Data Processing Agreement (/legal/data-protection).
3. Data we collect
3.1 Data you give us
- Account: name, email address, password (hashed), phone number, language, time zone.
- Business: company name, country, sector, logo, contact details displayed on your stores.
- Content: products, images, descriptions, message templates, automations, training documents.
- Support: messages sent to support, attachments, screenshots.
- Affiliate and payments: payout details and transaction references (card numbers never reach our servers; they are handled by the payment provider).
3.2 Data we collect automatically
- Technical logs: IP address, user agent, timestamp, pages and API endpoints called, error codes.
- Usage data: features used, order and message volumes, quota consumption.
- Cookies and local storage: authentication session, preferences (language, theme), audience measurement — see the Cookie Policy (/legal/cookies).
3.3 Data from the platforms you connect
- Shopify, WooCommerce, YouCan: orders, line items, the customer attached to an order, stock, shipping status.
- Meta / WhatsApp Business: ad-account identifiers, ad spend and performance, numbers and messages of the conversations you manage.
- Google: the content of the spreadsheets you link, your email address and basic profile on OAuth sign-in, and sending or reading messages only where you explicitly enable that feature.
- Telegram: chat identifiers and notification messages.
- Payment providers: transaction status, amount, currency, reference (never full card data).
3.4 Your shoppers’ data
When a shopper orders from a store built with IziStore, we process on your behalf: name, phone, delivery address, cart contents, order history, order-related messages, and storefront browsing data.
4. Purposes and legal bases
Where the GDPR (EU/EEA), the UK GDPR or an equivalent law applies, we rely on the following legal bases.
| Purpose | Data | Legal basis |
|---|---|---|
| Provide the platform and perform the contract | Account, content, store data | Performance of a contract |
| Process orders and messages on your behalf | Your shoppers’ data | Contract / controller instructions |
| Security, fraud and abuse prevention | Logs, IP, technical fingerprints | Legitimate interest |
| Support and customer service | Contact details, support threads | Contract / legitimate interest |
| Product improvement and aggregate statistics | Usage data, anonymised metrics | Legitimate interest |
| Marketing about our own services | Email, preferences | Consent or legitimate interest (with opt-out) |
| Non-essential cookies and analytics | Cookie identifiers | Consent |
| Accounting, tax and legal obligations | Invoicing, transactions | Legal obligation |
5. Artificial-intelligence features
To deliver AI features (conversational agent, product-description and image generation, summaries), strictly necessary content is sent to model providers (OpenAI, Google Gemini, DeepSeek, OpenRouter, or a provider you configure yourself).
Those providers act as sub-processors and are contractually bound not to use that content to train their models.
You can disable AI features in your account settings; no data is then sent to any model provider.
6. Google API data (Limited Use)
IziStore’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
- We use Google data only to provide the features you enabled (Google Sheets sync, OAuth sign-in, email sending where enabled).
- We do not transfer that data to third parties except to provide or improve those features, for security purposes, or where required by law.
- We do not use that data for advertising and we do not sell it.
- No human reads that data, except with your explicit consent, for security reasons, to comply with law, or where the data is aggregated and anonymised.
- You can revoke our access at any time at https://myaccount.google.com/permissions.
7. Protected data from partner platforms
- Shopify: we process protected customer data solely for the features you enable, apply data minimisation, encrypt data in transit and at rest, and delete or anonymise data when the app is uninstalled or at the end of the stated retention periods.
- Meta / WhatsApp: platform data is used only to provide the features you request, is never resold, is not used to build independent advertising profiles, and is deleted when you disconnect the integration.
- WooCommerce and YouCan: API credentials and imported order data are used exclusively for the synchronisation you configured.
8. Sharing
We do not sell or rent personal data. We share it only with:
- The sub-processors listed at /legal/subprocessors (hosting, database, transactional email, CDN, messaging, payments, AI model providers).
- The platforms you voluntarily connect, within the scope of the permissions you grant.
- Competent authorities, where a legal obligation or valid legal process requires it.
- An acquirer, in a merger, acquisition or asset sale, subject to equivalent protection and prior notice.
9. International transfers
We are established in the United States and our users are worldwide, so data may be transferred outside your country of residence, in particular to the United States and the European Union.
For transfers from the EEA, the UK or Switzerland we rely on the European Commission Standard Contractual Clauses (Decision 2021/914) with the UK Addendum and Swiss annex, supported by technical measures (encryption in transit and at rest, access control, logging).
10. Retention
| Category | Retention |
|---|---|
| Active account and related content | For the life of the account |
| Data after account deletion | Deleted or anonymised within 30 days (subject to legal obligations) |
| Technical and security logs | 12 months maximum |
| Messages and conversations | As configured by you, 24 months by default |
| Accounting records and transactions | Applicable statutory period (up to 10 years) |
| Encrypted backups | 35 rolling days |
11. Security
- TLS in transit; encryption at rest for databases and backups.
- Multi-tenant isolation: every query is scoped by user and store identifier.
- Signed-session authentication, role-based access control, secrets kept outside the source tree.
- Administrative access logging, error monitoring, regular and tested backups.
- Notification of a personal-data breach to the affected controller within 72 hours of becoming aware of it.
12. Your rights
Depending on where you live, you have all or some of the following rights: access, rectification, erasure, restriction, objection, portability, withdrawal of consent, and the right not to be subject to a solely automated decision producing legal effects.
To exercise them, write to [email protected] with the subject "Privacy request". We respond within 30 days at most. We may ask for reasonable identity verification.
California residents (CCPA/CPRA): you have the rights to know, delete, correct and not be discriminated against. We do not sell or share personal information as defined by the CPRA, and we do not process sensitive categories to infer characteristics.
If you are a shopper of a store built with IziStore, address your request to that merchant; we assist them as a processor.
You may also lodge a complaint with your supervisory authority (CNIL in France, ICO in the UK, APDP in Benin, or the authority of your country).
13. Children
The service is not intended for people under 18 and we do not knowingly collect their data. If you believe a minor gave us data, contact us and we will delete it.
15. Changes
This policy may change. Any material change will be announced by email or in the app at least 30 days before it takes effect.
16. Contact
WeKrea LLC — 30 North Gould Street, STE R, Sheridan, WY 82801, United States. Data protection: [email protected]. Security: [email protected].