Legal
Privacy Policy
Effective date: 2 June 2026
1. Who we are
AutoNewsletterAI ("we", "us") operates the plugin and SaaS application available at autonewsai.com and integrated with OpenCart, WordPress + WooCommerce, PrestaShop and Shopify stores. This policy explains what personal data we process, why, and what your rights are.
2. What we collect
About you (the merchant / admin user)
- Account data — email address, password hash (bcrypt), display name, the plan you're on, your monthly quota counter, and the date your email was verified.
- Billing data — handled by Stripe. We see your Stripe customer ID and subscription status; we do not see your full card number.
- Usage data — number of generations per month, model selected, timestamps of API calls, which platform sent the request. Used to enforce your plan limits and improve the service.
- Diagnostic logs — IP address and user-agent for security and debugging, retained for up to 30 days.
About your store's customers
To generate a personalized newsletter, the plugin reads — at the time of generation — the following from your e-commerce platform:
- Customer name, email address, country, language preference.
- Order history: order dates, product line items, totals, order status.
- Product details for the products you select for the campaign.
This data is sent to OpenAI as part of the generation prompt so the model can write a relevant email. We retain only the generated email (subject + body) plus the recipient's email address and a status flag in your store's local database — used to populate the Ready / History tabs and to let you re-send. We do not store the underlying customer profile data on our servers (it stays in your store).
3. What we do NOT do
- We do not sell, rent, or share your data or your customers' data with advertisers.
- We do not use your data to train AI models. OpenAI is contractually obligated, via the API agreement we have with them, not to train on inputs from API customers.
- We do not operate an outbound mail relay — your newsletters are sent via the SMTP server you configure. We never see the recipient list outside of the generation request itself.
4. Third-party processors
We rely on a small number of vetted providers to deliver the service. Each one only receives the data strictly necessary for its function.
- OpenAI (United States) — generation engine. Receives the structured prompt described above. Subject to OpenAI's API Data Usage Policies.
- Stripe (Ireland / United States) — payment processing. Receives your billing information directly via Stripe Checkout / Customer Portal; we receive only a customer ID and status.
- Our hosting provider (European Union, on autonewsai.com infrastructure) — operates the
servers that run the SaaS components, including the embedded Shopify app at
app.autonewsai.com.
5. Lawful basis (GDPR)
If you are in the European Economic Area, the United Kingdom, or another jurisdiction with equivalent protections, our lawful basis for processing is:
- Contract — to provide the service you signed up for (account, billing, generation).
- Legitimate interest — for service-improvement diagnostics, security logging, and anti-abuse enforcement.
- Legal obligation — for record-keeping required by tax / consumer-protection law.
6. Shopify GDPR webhooks
For merchants using AutoNewsletterAI on Shopify, we implement the three mandatory GDPR webhooks:
customers/data_request— within 30 days of receipt we provide whatever data we hold about the named customer (typically: the generated email rows where that customer was the recipient).customers/redact— within 30 days of receipt we delete that customer's generated email rows and any cached data.shop/redact— within 30 days of shop uninstall + 48 hours, we delete the entire shop record and all associated campaigns / generation history from our database.
7. Retention
- Account data — kept while your account is active, deleted within 30 days of account closure.
- Diagnostic / security logs — 30 days, then rotated.
- Generation history — stored in your store's local database, controlled by you (the History tab has bulk-delete + clear).
- Shopify shop records — deleted within 48 hours of
shop/redactwebhook (plus Shopify's own 48-hour grace period after uninstall).
8. Your rights
Depending on your jurisdiction you may have the right to:
- Access the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Erase your data (subject to legal-retention obligations).
- Restrict or object to certain processing.
- Receive your data in a portable, machine-readable format.
- Lodge a complaint with your local data-protection authority.
To exercise any of these rights, email us at info@autonewsai.com. We respond within 30 days.
9. Security
We follow industry-standard practices including TLS 1.2+ on all endpoints, bcrypt password hashing, libsodium (or AES-256-GCM) authenticated encryption for SMTP credentials at rest, HMAC-validated webhook payloads, and least-privilege database access. No system is 100% secure, but we treat your data as we'd want our own treated.
10. Cookies
The marketing site (autonewsai.com) does not set tracking cookies. The in-store plugin uses your e-commerce platform's native session cookie to remember your AutoNewsletterAI sign-in — that cookie never leaves your platform.
11. Children
AutoNewsletterAI is a B2B service for shop owners. We do not knowingly process personal data of children under 16. If you believe we have, contact us and we will delete it.
12. International transfers
Some of our processors (notably OpenAI and Stripe) are based in the United States. Where we transfer personal data outside the EEA we rely on the European Commission's Standard Contractual Clauses or equivalent safeguards offered by those processors.
13. Changes to this policy
We may update this Privacy Policy when our practices change. Material changes will be highlighted on autonewsai.com and, for active subscribers, by email.
14. Contact
Privacy questions, data-subject requests, or anything else covered by this policy: info@autonewsai.com.