Legal
Privacy Policy
Last updated 2026-07-20
1. Who we are (data controller)
BlendBadger is operated by Andes Trade EOOD, D-R Hristo Momchilov 1, Elena 5070, Bulgaria, VAT BG203691176 ("BlendBadger", "we", "us"). We operate the website blendbadger.com and the BlendBadger application at app.blendbadger.com — a profit and efficacy analytics service for e-commerce sellers.
Andes Trade EOOD is the data controller for account data and a data processor for the store data our customers connect (see section 12 for the Shopify-specific controller/processor split).
We have not appointed a Data Protection Officer. Contact for all privacy matters: [email protected].
2. Data we collect
2.1 Account data (you, the seller)
- Name, email address, password hash, locale and account settings.
- Billing details processed by our payment provider Stripe — we never see or store full card numbers.
- Support correspondence you send us.
2.2 Connected platform data (your store's data)
- Orders, order lines, refunds, discounts, fees, payouts, products, inventory levels, fulfillment records and advertising performance from the platforms you explicitly connect (e.g. Shopify; later Amazon, Google, Meta, TikTok). Details per platform: sections 11–16.
- Pseudonymized customer identifiers. To compute repeat-purchase and lifetime-value metrics, customer identifiers from your store are one-way hashed (SHA-256) at the moment of ingestion and the raw values are discarded. The resulting hashes are pseudonymized personal data and we treat them as personal data under GDPR. Raw names, email addresses, phone numbers and street addresses of your customers are never stored in our systems. Coarse geographic fields from order shipping data — country, province/state and postal code — are retained alongside the hashed identifier for regional profit analytics (see the retention table in section 5); no street-level address component is ever kept.
- Expense records you enter, upload or import, including invoice/receipt images you choose to submit for automated extraction.
2.3 Technical data
- Server logs (IP address, user agent, request path, timestamps) kept for security and debugging, and an essential session cookie (see section 9).
Source of platform data (GDPR Art. 14): the connected platform data described above is not collected from the individuals it may relate to; it is received from the platforms you, the account holder, choose to connect via their official APIs.
3. Why we process it (purposes and legal bases)
| Purpose | Legal basis (GDPR) |
|---|---|
| Providing the service — syncing your platform data, computing profit analytics, showing dashboards, sending the alerts you configure. | Performance of a contract — Art. 6(1)(b). |
| Billing and account management. | Performance of a contract — Art. 6(1)(b); legal obligation — Art. 6(1)(c) for tax and accounting records. |
| Security, abuse prevention and debugging — server logs, audit trails, encrypted token storage. | Legitimate interests — Art. 6(1)(f): keeping the service secure and reliable. |
| Invoice-photo extraction — when you submit a receipt or invoice image, it is processed by an AI model to pre-fill the expense entry, which you review before saving. | Performance of a contract — Art. 6(1)(b). |
| Third-party personal data in your uploads — an invoice you submit may show personal data of someone who is not our customer (e.g. a supplier contact name). We process it only as part of extracting your expense entry and it stays inside that expense record. | Legitimate interests — Art. 6(1)(f): providing you the extraction feature you requested, with minimal impact on the third party (data they placed on a commercial invoice, used for no other purpose). |
| AI chat — answering the questions you type about your own store's analytics. Prompts contain your question and your tenant's aggregate metrics; raw connected-platform records, hashed customer identifiers and Google API data are never included in AI prompts. | Performance of a contract — Art. 6(1)(b). |
| Product communication — service emails about your account, syncs and alerts. We do not send marketing email without your consent. | Performance of a contract — Art. 6(1)(b); consent — Art. 6(1)(a) for anything promotional. |
| Aggregated benchmarks (optional, opt-in only) — if you opt in, aggregated, k-anonymized cohort metrics (e.g. average refund rate for stores of a similar category and size) may include your store's contribution. No store-identifiable data is ever shown, and cohorts below a minimum size are never displayed. Benchmark contributions are limited to store-level aggregate metrics computed by BlendBadger; the following never contribute to benchmarks in any form: Shopify Protected Customer Data and hashed customer identifiers (section 12), Amazon SP-API and Amazon Ads data (section 13), Google API data (section 14), Meta data (section 15) and TikTok data (section 16). | Consent — Art. 6(1)(a), withdrawable at any time. |
We do not use your data for advertising, we do not profile your customers, and we do not sell personal data to anyone.
4. Subprocessors and international transfers
We keep the subprocessor list short and purposeful. Where a subprocessor is outside the EEA, transfers rely on the European Commission's Standard Contractual Clauses (Commission Decision 2021/914) and, where available, adequacy decisions or the EU-US Data Privacy Framework (DPF).
| Subprocessor | Purpose | Location | Transfer mechanism |
|---|---|---|---|
| Hostinger | VPS hosting — all application databases (Postgres, ClickHouse) run here. | EU data center | Intra-EEA processing |
| Cloudflare, Inc. | CDN, DDoS protection and R2 object storage for PII-scrubbed sync archives and encrypted backups; R2 is configured with EU jurisdiction. | US company; EU jurisdiction configured for stored data | EU-US Data Privacy Framework + SCCs |
| Stripe Payments Europe, Ltd. / Stripe, Inc. | Subscription billing and payment processing (planned for commercial launch). | Ireland (EU) / US | EU-US Data Privacy Framework + SCCs |
| SMTP2GO (SMTP2GO Ltd.) | Transactional email delivery — account, security and service emails (e.g. password resets, verification links). Processes recipient email addresses and message content in transit. | New Zealand; EU-based sending infrastructure | EU adequacy decision for New Zealand |
| OpenRouter, Inc. | AI processing of invoice/receipt images you submit for expense extraction and of the questions you type into AI chat. Invoice images you upload may contain personal data of your suppliers (e.g. a contact name on a supplier invoice); connected-platform customer data is not sent to AI providers. | US | SCCs |
We will update this list and notify account holders at least 14 days before adding or replacing a subprocessor, so you can object before the change takes effect.
5. Retention
| Data | Retention period |
|---|---|
| Connected platform business data (orders, refunds, fees, payouts, catalog, inventory, ad performance) | While the platform connection is active, within the history window of your plan. Data from a connection you disconnect is deleted within 30 days of disconnection; everything is deleted within 30 days of account closure. |
| Pseudonymized (hashed) customer identifiers | Life of the platform connection; deleted within 30 days after you disconnect the connection or close the account. |
| Raw customer / buyer personal data (names, emails, phones, addresses) | Never persisted — hashed at ingestion, raw values discarded. |
| PII-scrubbed payload archive (raw API responses with direct identifiers removed before storage; retains hashed customer identifiers and coarse geography — country, province/state, postal code) | Life of the platform connection; a disconnected connection's archives are deleted within 30 days of disconnection, and all archives within 30 days of account closure. |
| Account data (name, email, settings) | While your account exists; deleted within 30 days of account deletion. |
| Server logs | Up to 90 days. |
| Encrypted backups | Rolling schedule (14 daily + 8 weekly backups) — the oldest backup is at most 56 days old, so deleted data leaves all backups within 56 days. |
| Billing and accounting records | 10 years, as required by the Bulgarian Accountancy Act. |
| Amazon buyer personal data | Never persisted — hashed or discarded in memory during ingestion, so Amazon's 30-days-after-delivery limit is never reached because nothing is stored (see section 13). |
| Uploaded invoice/receipt images | Until you delete the expense record they belong to; deleted within 30 days of account closure. |
| Support correspondence | Up to 24 months after the request is resolved, then deleted. |
6. Your rights
If you are in the EU/EEA/UK (and in many other jurisdictions with similar laws), you have the rights set out in GDPR Articles 15–22:
- Access the personal data we hold about you (Art. 15);
- Rectify inaccurate data (Art. 16);
- Erase your data — the "right to be forgotten" (Art. 17);
- Restrict specific processing (Art. 18);
- Export your data in a portable, machine-readable format (Art. 20);
- Object to processing based on legitimate interests (Art. 21);
- Withdraw consent at any time where processing is based on consent;
- Not be subject to solely automated decisions with legal or similarly significant effects (Art. 22 — see section 7).
To exercise any right, email [email protected]. We respond within 30 days. You do not have to wait for us for erasure: Settings → Delete account in the app closes your account and purges your tenant's data on the schedule in section 5, and Settings → Connections → Disconnect deletes a single platform's data the same way.
You also have the right to lodge a complaint with the Bulgarian Commission for Personal Data Protection (Комисия за защита на личните данни), 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592, Bulgaria — www.cpdp.bg — or with the supervisory authority of your own EU member state.
Your customers' rights: we store only pseudonymized (one-way hashed)
customer identifiers and no raw customer personal data, so we cannot look an individual
shopper up by name or email and we never attempt to reverse a hash. Requests from your
customers about their data at your store should be directed to you as their merchant;
deleting a customer in your store platform removes the source data, and the
pseudonymized identifiers are purged with your tenant's data. For Shopify, a
customers/redact webhook additionally clears that customer's hashed
identifier from our analytical databases automatically; archived payloads contain only
pseudonymized hashes (no direct identifiers) and are deleted on disconnection or
account closure per section 5 (see section 12).
7. Automated decision-making (GDPR Art. 22)
BlendBadger does not use your data for automated decision-making or profiling that produces legal or similarly significant effects for any individual. AI features (invoice extraction, AI chat, forecasts, anomaly alerts) produce analytics and suggestions for you to review and act on — AI invoice extraction only suggests field values, which you confirm or correct before anything is saved. No automated decision is made about any individual.
8. Security
- All traffic is encrypted in transit with TLS 1.2 or higher.
- Databases, archives and backups are encrypted at rest.
- Platform access tokens are encrypted at rest with keys held outside the database.
- Every data row is tenant-isolated; access to your data requires your tenant's authentication.
- Administrative access by our staff is role-based, logged and auditable — including any support session that views your account.
- Backups are encrypted and restore-tested.
9. Cookies
We use one essential session cookie (bb_sess) whose sole
purpose is to keep you signed in to the application; it lasts up to 30 days on a
rolling basis and is invalidated when you sign out or the session expires. That's it. No analytics
cookies, no advertising cookies, no third-party trackers, no fingerprinting — which is
why you don't see a cookie banner.
10. Children
BlendBadger is a business tool and is not directed at children under 16. We do not knowingly collect data from children.
11. Data received from connected platforms (read-only)
BlendBadger reads only the data needed to compute true profit and ad efficacy, and presents it back to you and your invited users. Every platform connection is read-only: BlendBadger never creates, changes or deletes anything in your connected accounts, and there is no code path that writes to a connected platform. You can revoke any connection at any time in Settings → Connections inside the app, or from the platform's own authorized-apps settings.
From a connected Shopify store we read:
- Order history — line items, prices, discounts and refunds — to build the contribution ladder and your historical profit.
- Catalog, product and variant details, weights and inventory snapshots — to map listings to canonical SKUs and work out shipping cost.
- Fulfillment records — to compare real shipping cost against what was quoted.
- Discounts and price rules — so profit swings during promotions are explainable.
- Customer identifiers — one-way hashed (SHA-256) at the moment of ingestion for repeat-purchase and lifetime-value analysis, and treated as pseudonymized personal data. Raw names, emails, phone numbers and addresses are never stored.
- Returns — feeding refund lines and refund-rate checks.
- Payment fees and payout reports — for the payment-fee line of the ladder and to reconcile computed revenue against the deposits actually made.
Amazon, Google, Meta and TikTok connections are described in sections 13–16. eBay, Etsy and accounting tools such as QuickBooks and Xero follow the same pattern: read access covering only orders, fees, inventory, advertising performance or expense records; no write access; no campaign or listing management; customer identifiers hashed or excluded. As each connection goes live, the exact data it reads is documented here.
11.1 What we never do
- Never write to your accounts — no orders touched, listings edited, campaigns changed or messages sent.
- Never sell or share your platform data; it is used solely to provide the service to you.
- Never store raw customer personal data — customer identity is one-way hashed at ingestion; the hash is pseudonymized personal data we never attempt to reverse.
- Never mix accounts — every row of data is isolated to your account throughout the pipeline.
- Never use connected-platform data to train AI or machine-learning models.
12. Shopify Protected Customer Data
When you connect a Shopify store, BlendBadger receives data that Shopify classifies as Protected Customer Data. For this data, you (the merchant) are the data controller and BlendBadger (Andes Trade EOOD) is your data processor, processing it only on your instructions as described here.
- What we receive: orders, order lines, refunds, discounts, fees, payouts, catalog, inventory, fulfillment records, and customer identifiers — which are one-way hashed (SHA-256) at ingestion and treated as pseudonymized personal data; raw customer names, emails, phone numbers and addresses are never stored.
- Why (exhaustive list of purposes): (1) computing per-order profit; (2) allocating refunds and fees to the correct orders and SKUs; (3) deduplicating repeat purchases for repeat-purchase and lifetime-value metrics — in every case for you, the installing merchant, only. Never for marketing, retargeting, cross-merchant tracking, benchmarking across merchants, or sale.
-
How long: for the life of your active subscription. When you
uninstall the app, Shopify's
shop/redactwebhook triggers deletion of your store's data within 30 days; encrypted backups roll off within 56 days. -
Mandatory webhooks (implemented): we have implemented and honor
Shopify's three mandatory compliance webhooks —
customers/data_request,customers/redactandshop/redact. Acustomers/redactrequest clears the hashed identity for that customer from our analytical databases; ashop/redactrequest revokes the connection immediately and the store's data is deleted within 30 days. - Who it is shared with: only the subprocessors listed in section 4, under contract; it is never sold.
- Rights: you can access, export and delete your store's data at any time (section 6). Your customers exercise their rights through you as their merchant; we support you in fulfilling their access and deletion requests, including automatically via the webhooks above.
- Data Processing Agreement: our processor obligations under GDPR Article 28 — documented instructions, confidentiality, sub-processor terms, assistance with data-subject requests, deletion on termination and audit rights — are set out in our Data Processing Agreement, which is incorporated into the Terms of Service for every account.
13. Amazon Selling Partner API (SP-API) and Amazon Ads API
When you connect an Amazon seller account or Amazon Ads account, BlendBadger accesses Amazon Selling Partner data (orders, refunds, fees, settlements, inventory, catalog) and Amazon Advertising performance data (campaigns, spend, performance metrics) on a read-only basis, solely to provide profit analytics and reconciliation to the Amazon seller that authorized the connection.
- Buyer personal data is not persisted. Any buyer identifiers are pseudonymized with a one-way hash (SHA-256) at ingestion and the raw values are discarded; archived payloads are PII-scrubbed before storage. Buyer names, street addresses, email addresses and phone numbers are never written to our databases or archives; only coarse geography (country, province/state, postal code) is retained for regional analytics, as disclosed in sections 2 and 5.
- No buyer personal data is stored at rest — it is hashed or discarded in memory during ingestion, so Amazon's limit of 30 days after order delivery is never reached, in accordance with the Amazon Data Protection Policy.
- Amazon business data (orders, fees, settlements, ad performance) is retained while the Amazon connection is active and deleted within 30 days of disconnecting the connection or revoking authorization — independent of overall account status — and in all cases within 30 days of account closure; encrypted backups roll off within 56 days. The same applies to Amazon Ads data.
- All Amazon data is encrypted in transit (TLS 1.2+) and at rest.
- We never contact buyers, never use Amazon data for cross-seller benchmarking (Amazon data is excluded from the opt-in benchmark feature in section 3), never resell Amazon data, never commingle it across sellers, and never use it to train AI or machine-learning models.
14. Google API Services User Data Policy — Limited Use
When you connect Google Ads, Google Analytics 4 (GA4) or Google Search Console, BlendBadger reads advertising and site performance data (campaigns, spend, conversions, traffic and search metrics) via the Google Ads API, the GA4 Data API and the Search Console API on a read-only basis, in compliance with the applicable Google API terms.
BlendBadger's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In particular, we affirm that data received from Google APIs is:
- used only to provide and improve the connected analytics features you see in the product — never sold;
- never used for advertising purposes, including ad targeting or retargeting;
- not read by humans, except (a) with your affirmative consent for a specific piece of data, (b) as necessary for security purposes such as investigating abuse, or (c) to comply with applicable law;
- not transferred to anyone else, except to the subprocessors in section 4 as necessary to provide the service, for security purposes, to comply with applicable law, or as part of a merger, acquisition or sale of assets — and in that case only after notice to you and only where the recipient remains bound by this policy's Limited Use commitments;
- never included in prompts sent to AI models (the AI features in section 4 operate without Google API data);
- never used to train AI or machine-learning models;
- never included in cross-customer benchmarks (section 3).
You can revoke BlendBadger's access to your Google data at any time in Settings → Connections inside the app, or via myaccount.google.com/permissions. Disconnecting or revoking a Google connection deletes the Google-sourced data within 30 days, independent of overall account status.
15. Meta (Facebook and Instagram) Marketing API
When you connect a Meta (Facebook/Instagram) ad account, BlendBadger reads ad-account data via the Meta Marketing API on a read-only basis: ad accounts, campaigns, ad sets, spend and performance metrics. This data is used exclusively to provide advertising-efficacy and profit analytics to you, the authorizing advertiser — never to build audiences, never for end-user profiling, and never shared with or sold to anyone beyond the subprocessors in section 4.
Removing BlendBadger from your Facebook settings (Settings & Privacy → Settings → Apps and Websites) triggers our automated Data Deletion Callback: we delete the associated data and Facebook shows you a confirmation code and a status URL you can check at blendbadger.com/data-deletion. Full step-by-step instructions are on that page. Disconnecting your Meta ad account inside the app (Settings → Connections) likewise deletes the associated Meta data within 30 days, per the retention table in section 5.
16. TikTok for Business
When you connect a TikTok advertiser account, BlendBadger reads advertising performance data (campaigns, spend, performance metrics) via TikTok's Business API on a read-only basis, used exclusively to provide analytics to you, the authorizing advertiser. TikTok data is stored on our EU-hosted infrastructure (section 4) and deleted when you disconnect the connection, per the retention table in section 5. Deletion requests follow the same routes described on our data-deletion page.
17. Changes to this policy
We will post changes on this page and update the date above. For material changes we will notify account holders by email before the change takes effect.
18. Contact
Andes Trade EOOD (operating BlendBadger)
D-R Hristo Momchilov 1, Elena 5070, Bulgaria
VAT BG203691176
[email protected]