Privacy policy
Last updated: Aug 13, 2025
This Privacy Policy explains how Atomato Inc. and our affiliates ("Atomato," "we," "us," or "our") collect, use, share, and protect information in connection with our websites, dashboards, Shopify app, browser extensions, APIs, and related services (the "Services"). Our Services are designed for businesses and are not intended for personal or household use. By using the Services, you agree to this Privacy Policy.
If you do not agree, do not use the Services and do not provide us with your information.
1. Scope
This Policy applies to information we process about visitors to our sites, account owners and users, agency partners, and merchant customers whose data may be processed through the Services on behalf of a merchant. When we process personal information about a merchant's customers, we act as a service provider or processor to that merchant. The merchant's own privacy policy governs how the merchant uses that data.
2. Personal information we collect
The term "personal information" means information that identifies or relates to an identified or identifiable person. We collect the following categories:
- Account and contact information such as name, email address, phone number, company, role, and login credentials.
- Billing and transactional information such as billing contact, payment method tokens, and records of purchases and plan selections. Payment card data is handled by our payment processor and not stored in full by Atomato.
- Usage and device information such as IP address, approximate location based on IP, user agent, device type, operating system, browser type and version, language and locale, pages viewed, referring and exit pages, timestamps, feature use, error logs, session diagnostics, and cookie identifiers.
- Support and communications such as messages, survey responses, feedback, and recordings or transcripts if you agree to them during support calls or chats.
- Integrations and merchant data when you connect third party platforms like Shopify. This can include store configuration, theme assets, products, collections, orders, discounts or offers, and operational webhooks required to provide the Services. For merchant customer data, we process that information on the merchant's behalf and under their instructions.
- Cookies and similar technologies which we describe in Section 8.
We may create aggregated, de identified, or anonymized data that no longer identifies an individual. We may use and share such data for any purpose.
3. Sources of information
We collect information from:
- You when you create an account, configure settings, contact us, or otherwise use the Services.
- Automatic collection through cookies, pixels, SDKs, and server logs when you visit our sites or use the Services.
- Third party integrations such as Shopify Admin APIs and webhooks when you authorize a connection.
- Service providers and partners who help us operate, secure, and improve the Services.
4. How we use information
We use personal information to:
- Provide, operate, maintain, and secure the Services.
- Authenticate users and manage accounts and subscriptions.
- Process transactions and send invoices and renewal notices.
- Deliver on site widgets, notifications, offers, and analytics features you enable.
- Monitor performance, troubleshoot, and improve the Services.
- Personalize the experience and recommend relevant features.
- Communicate with you about the Services, including operational messages and security alerts.
- Send marketing communications where permitted. You can opt out at any time.
- Protect the Services and our users, detect and prevent fraud and abuse, and enforce our Terms.
- Comply with law and respond to lawful requests.
If you upgrade from Starter to Grow or higher, analytics and data collection begin on the upgrade date and are not backfilled.
5. Shopify data and role
When you install or connect the Atomato Shopify app, you authorize us to access certain Shopify Admin API objects and webhooks, such as Theme, Assets, Products, Collections, Discounts or Offers, and Orders, in order to run features like on-site widgets, notifications, and analytics.
- For data about your customers that we process through your store, Atomato acts as a service provider or processor to you as the merchant.
- Atomato does not sell or use your merchant customer personal information for our own advertising. We may use aggregated or de-identified data to improve the Services.
- You are responsible for publishing your own customer-facing privacy disclosures and obtaining any required consents.
Shopify uninstall and privacy webhooks
- We subscribe to Shopify privacy topics related to data access and erasure, including app/uninstalled, shop/redact, customers/data_request, and customers/redact.
- When your store uninstalls the Atomato app, we mark the store as pending deletion and stop collecting new data.
- When we receive Shopify’s shop/redact webhook, which Shopify issues after an uninstall (typically 48 hours after uninstall), we permanently erase store-specific personal information from our systems and logs.
- If you reinstall before erasure is completed, we clear the pending deletion flag and continue service. If erasure has already completed, you will start fresh and may reconfigure settings during onboarding.
- We may retain billing records, tax documentation, fraud-prevention logs, and de-identified aggregate analytics that cannot reasonably be linked to your store or an individual, as permitted by law.
6. Legal bases for processing for EEA and UK users
If you are in the EEA or UK, our legal bases include performance of a contract, legitimate interests in operating and improving the Services, compliance with legal obligations, and consent where required, for example for certain cookies or marketing emails.
7. How we share information
We may share personal information as follows:
- Within Atomato with our affiliates for purposes consistent with this Policy.
- Service providers that perform services for us, for example hosting, cloud infrastructure, logging, analytics, email delivery, payments, and customer support. These providers are bound by confidentiality and security obligations and may only use information to provide services to us.
- Integration partners when you connect a third party service, consistent with your settings and their terms.
- Business transfers in connection with a merger, acquisition, financing, or sale of assets, subject to standard confidentiality obligations.
- Legal and safety to comply with law, court order, or lawful requests, to enforce our agreements, and to protect the rights, property, or safety of Atomato, our users, or the public.
- With your direction or consent when you ask us to share or publish information.
We do not sell personal information. For site visitors, we may engage in interest based advertising as described in Section 8. Where required by law, you can opt out of targeted advertising and the sharing of personal information for cross context behavioral advertising.
8. Cookies, analytics, and online ads
We and our partners use cookies and similar technologies to operate and improve the Services. These include:
- Strictly necessary cookies to provide core functionality and security.
- Preferences cookies to remember settings like language or region.
- Analytics cookies to understand how the Services are used and to improve performance.
- Advertising cookies on our marketing sites to help show ads that may be relevant to you. These do not run inside the Shopify admin of our app.
Your choices:
- You can control cookies through your browser settings. Some features may not work if you disable cookies.
- You can opt out of interest based advertising on your browser by visiting the Digital Advertising Alliance tool at aboutads.info choices or the Network Advertising Initiative tool at networkadvertising.org choices. On mobile, use the AppChoices app.
- If you are in the EEA or UK, you will be asked for consent for non essential cookies.
Our Services do not respond to Do Not Track signals.
9. Your privacy rights
Depending on where you live, you may have rights such as access, correction, deletion, portability, and the right to opt out of sales or sharing for targeted advertising. You also may have the right to restrict or object to processing and the right to withdraw consent.
To exercise your rights, contact us at legal@atomato and include your name, the nature of your request, and your email address used with the Services. We will verify your request and respond within the time required by law. You may designate an authorized agent as permitted by law.
Residents of California, Virginia, Colorado, Connecticut, Utah, and Texas have additional rights under their state laws. Texas residents may exercise rights under the Texas Data Privacy and Security Act. We do not discriminate against you for exercising your rights.
For EEA and UK residents, you may contact your local data protection authority and you have the right to lodge a complaint. You can also contact our EU or UK representatives if appointed.
10. Security
We use reasonable technical and organizational measures to protect personal information, taking into account the nature of the data and the risks involved. No method of transmission or storage is fully secure. You are responsible for keeping your account credentials confidential.
11. Retention
We retain personal information for as long as needed to provide the Services, comply with legal obligations, resolve disputes, and enforce agreements. When we no longer need information, we will delete it, de identify it, or anonymize it.
12. International transfers
We are based in the United States and process information in the United States. If we transfer personal information from the EEA, UK, or Switzerland, we use appropriate safeguards such as Standard Contractual Clauses.
13. Children
The Services are intended for users who are at least 18 years old. We do not knowingly collect personal information from children under 16. If you believe a child has provided us information, contact us and we will take appropriate steps to delete it.
14. Third party links and widgets
The Services may contain links to third party websites or include third party widgets and SDKs. This Policy does not apply to those third parties. Their policies govern their practices.
15. Changes to this Policy
We may update this Policy from time to time. For material changes we will notify you in the account portal or by email. The updated Policy will be effective on the date posted unless stated otherwise.
16. Contact us
Controller: Atomato Inc.
Address: 1606 Headway Cir STE 9708 Austin, TX 78754
Email: legal@atomato.com
If you are a merchant and need a Data Processing Agreement, contact us at the email above.