Early accessMethodology and figures are provisional and may change. The example record shown uses RecommendedByAI's own measured data.
Vol. 2026 · Edition I
Privacy

Privacy

A plain, honest statement of what we collect and why.

01 Scope & controller

Scope and controller

This Privacy Policy explains how RecommendedByAI processes personal data through recommendedbyai.com and, when applicable, its merchant application, accounts and related services.

The data controller is:

Technology Pro Bono S.L. · CIF B88502364 · Núñez de Balboa 120, 28006 Madrid, Spain · Email: contact@recommendedbyai.com

Technology Pro Bono S.L. is established in Spain and therefore processes personal data in accordance with applicable Spanish and European data-protection law, including the GDPR and applicable Spanish implementing legislation.

The company does not currently appoint a separate EU representative because it is itself established in the EU. A Data Protection Officer is not designated in this version; this should be reviewed if the scale or nature of processing changes such that a DPO becomes legally required.

02 Data we collect

Data we collect

Store and business information

When you use a free category check or contact us, we may collect: store/domain name; business name; email address; information voluntarily entered into forms; information necessary to provide the requested service.

Account information

If accounts are introduced, we may collect: name; business details; contact information; account credentials and authentication information; service configuration.

Billing information

For paid services, billing may be handled through Shopify or another payment provider. Where payment-card data is handled directly by a payment provider, RecommendedByAI does not intentionally store the full payment-card number.

Technical information

We may process: IP address; approximate IP-derived region; browser and device information; operating system; pages visited; referrer; timestamps; security and error logs.

Badge analytics

If the Shopify application provides badge analytics, we may process information such as badge impressions; clicks; referring page; product/store context; aggregated performance information. We intend to configure these analytics to minimise personal data and, where information can reasonably be aggregated or anonymised, we will prefer that approach.

03 Purposes & legal bases

Purposes and legal bases

Providing a requested category check

We process submitted store/domain and contact information to perform or queue the requested check and provide the result. Legal basis: performance of a requested service and/or legitimate interest in responding to a business inquiry, as applicable.

Communications

We use contact information to respond to requests, provide service-related messages and, where permitted, send relevant commercial communications. Service communications may be based on contract or legitimate interest. Optional marketing communications will be based on consent where consent is legally required; you may withdraw marketing consent at any time.

Security

Technical data and logs may be processed to protect the service, detect abuse, investigate incidents, maintain availability and prevent fraud. Legal basis: legitimate interest and, where applicable, legal obligation.

Accounts and billing

Account data is processed to provide contracted services (basis: performance of a contract). Billing and accounting data may be processed to administer payments and comply with tax and accounting obligations (basis: contract and legal obligation).

Analytics

Where analytics is used, it will be configured to minimise personal data. Non-essential analytics technologies requiring consent will not be activated until valid consent has been obtained. Where a particular analytics processing can lawfully rely on legitimate interest without consent, the company will document that basis and apply appropriate safeguards.

04 Cookies

Cookies and similar technologies

RecommendedByAI intends to operate the website with strictly necessary technologies for security and core functionality; and optional analytics or other non-essential technologies only where the required legal basis and consent have been obtained.

Where consent is required, users will be offered a clear choice to accept, reject or configure non-essential cookies. Rejecting non-essential cookies will be as easy as accepting them.

The website will maintain a cookie inventory identifying, as applicable: cookie/provider; purpose; duration; first- or third-party status; whether it is essential; legal basis. The final cookie table must be updated whenever the technical stack changes.

05 Retention

Retention

We keep personal data only for as long as reasonably necessary for the relevant purpose or as required by law. Current operational targets are:

  • Free category-check submissions: 12 months after the last interaction;
  • Ordinary technical/server logs: 30 days;
  • Security/incident logs: longer where reasonably necessary to investigate or defend against an incident or comply with law;
  • Accounting and tax records: generally 6 years where required by applicable Spanish commercial/tax rules;
  • Account data: for the duration of the account and afterwards only as necessary for legal, contractual or security purposes;
  • Badge analytics: up to 24 months, preferably in aggregated/anonymised form where practical.

These are operational retention targets, not a commitment to retain every data item for the full period.

06 Processors

Processors and disclosures

We do not sell personal data. We may use service providers acting as processors, including:

  • Cloudflare — for hosting, CDN, DNS, security and related infrastructure where used.
  • Shopify — for merchant application functionality and billing where used.
  • Payment processors — no separate payment processor is designated in this version beyond the payment infrastructure actually used by the applicable commercial platform. If a separate processor such as Stripe is introduced, it will be incorporated into the relevant privacy/subprocessor documentation before processing begins.
  • Analytics, email and CRM — no specific provider is designated by this policy. If such providers are introduced, the provider, purpose and applicable data-processing/transfer arrangements will be documented.

We may also disclose information where required by law; necessary to comply with a binding legal request; necessary to protect rights or safety; necessary to investigate fraud or abuse; or required as part of a corporate transaction.

07 International transfers

International transfers

Because some technology providers may process data outside the EEA, international transfers will be performed using an appropriate legal mechanism. Where an applicable US provider participates in the EU-US Data Privacy Framework, that mechanism may be relied upon where appropriate. Where the relevant provider is not covered by an applicable adequacy mechanism, RecommendedByAI will use appropriate safeguards such as EU Standard Contractual Clauses, together with supplementary measures where required. The exact mechanism will depend on the provider and the processing actually performed.

08 Your rights

Your rights

Depending on applicable law, you may have rights including: access; rectification; erasure; restriction; objection; data portability; withdrawal of consent where processing is based on consent. You may also have the right to complain to the relevant supervisory authority.

In Spain, the competent data-protection authority is the Agencia Española de Protección de Datos (AEPD). Requests may be submitted to contact@recommendedbyai.com. We may request reasonable information to verify identity before fulfilling a request. Under GDPR, requests will generally be answered within one month, subject to lawful extensions. Where California privacy law applies, applicable statutory rights and response periods will be respected.

09 California privacy

California privacy

Where CCPA/CPRA applies, Technology Pro Bono S.L. does not intend to sell personal information or share it for cross-context behavioural advertising. Applicable California residents may have rights concerning:

  • access/know;
  • deletion;
  • correction;
  • opting out of sale or sharing;
  • limiting certain uses of sensitive personal information where applicable;
  • non-discrimination.

Requests can be sent to contact@recommendedbyai.com.

10 Automated decisions

Automated decision-making and profiling

RecommendedByAI does not use personal data to make decisions that produce legal or similarly significant effects about individuals through solely automated decision-making. The AI recommendation measurements concern products, brands and categories rather than scoring individual website visitors.

11 Security

Security

We apply technical and organisational measures appropriate to the risks associated with the data we process. Measures may include access controls, authentication, encryption in transit, infrastructure security, logging and restricted access. No internet transmission or storage system can be guaranteed to be completely secure.

12 Children

Children

RecommendedByAI is intended for businesses and adults. We do not knowingly seek to collect personal data from children. The minimum age for using the service is 18, subject to mandatory local law.

13 Changes

Changes

We may update this Privacy Policy when the service, legal requirements or processing activities change. The “Last updated” date will be updated accordingly.

14 Contact

Contact

Technology Pro Bono S.L. · CIF B88502364 · Núñez de Balboa 120, 28006 Madrid, Spain · Email: contact@recommendedbyai.com