Legal
Privacy Policy
Last updated: April 2, 2026 · Effective: April 2, 2026
EcomSpy is a free platform operated by CreatPix Infotech LLP, a registered entity in India. We do not collect payment information. This policy applies to all users of EcomSpy regardless of location.
1. Who We Are
EcomSpy ("we", "us", "our") is a free AI-powered ecommerce toolkit built and maintained by CreatPix Infotech LLP. We offer 23 AI tools to help ecommerce store owners analyse, optimise, and grow their businesses. You can reach us at [email protected].
2. What Data We Collect
We collect only the minimum data required to provide the service:
- Account data: your name, email address, and hashed password when you register
- Store data: your Shopify store URL, niche, and primary goal if you choose to provide them in your profile
- Usage data: the tools you run, URLs you analyse, and the date/time of each tool use — stored as your activity history
- Device data: IP address, browser type, and operating system collected automatically via server logs
- Session cookie: a single login cookie to keep you signed in for up to 30 days
We do not collect payment information — EcomSpy is completely free.
3. How We Use Your Data
- To create and manage your account
- To provide all 23 AI-powered ecommerce tools and generate reports
- To pre-fill tool inputs with your saved store URL for a faster experience
- To store your tool history so you can review previous results
- To send transactional emails (e.g. password reset)
- To detect abuse and maintain platform security
- To improve the platform based on aggregated, anonymised usage patterns
4. Third-Party Services
When you run a tool, the URL or content you submit may be sent to:
- Anthropic / Claude AI — powers the AI-generated analysis and content across all tools. See anthropic.com/privacy.
- Hosting provider — our servers run on cloud infrastructure. Server logs may contain IP addresses.
We do not sell, rent, or share your personal data with any third parties for marketing purposes.
5. Legal Basis for Processing (GDPR)
For users in the UK and EU, our legal bases are:
- Contract performance — processing necessary to provide the free service you signed up for
- Legitimate interests — security, fraud prevention, and platform improvement
- Consent — for the session cookie essential to keeping you logged in
6. Data Retention
- Account data: retained until you delete your account
- Tool history: retained for 12 months, then automatically purged
- Server logs: retained for 14 days, then automatically rotated
7. Your Rights
Depending on your location, you may have the right to:
- Access — request a copy of the personal data we hold about you
- Correction — ask us to fix inaccurate data
- Deletion — request deletion of your account and all associated data
- Portability — receive your data in a machine-readable format
- Objection — object to processing based on legitimate interests
- Opt-out of sale (CCPA) — we do not sell personal data, so this right is already fulfilled
To exercise any of these rights, email [email protected]. We will respond within 30 days.
8. Cookies
We use one functional cookie:
- Session cookie — keeps you logged in for up to 30 days. This is essential for the service to function and does not track you across other websites.
We do not use advertising cookies, tracking pixels, or third-party analytics cookies.
9. Data Security
We implement industry-standard security including HTTPS encryption in transit, hashed passwords (never stored in plaintext), and restricted database access. If you believe your account has been compromised, contact us immediately at [email protected].
10. International Transfers
Your data may be processed in the USA (cloud servers, Anthropic AI) and India (our engineering team). We take reasonable steps to ensure equivalent data protection standards apply in all jurisdictions.
11. Changes to This Policy
We may update this policy from time to time. We will notify registered users by email for material changes. The "Last updated" date at the top of this page will always reflect the current version.
13. Contact Us
For any privacy-related queries, contact: