Last updated: October 2, 2026

Privacy Policy

This Privacy Policy explains how Intern Charlie collects, uses, and protects information when you use our website, our Shopify app, and the Google and Meta connections you authorize.

We ask Shopify, Google, and Meta for read-only access, and only for the permissions needed to produce your analytics, reports, and advice.

Your data is used to run the service for your account. We never sell it, and we never hand it to advertising platforms for their own targeting.

You can disconnect any platform at any time, and you can ask us to erase what we collected from it. See "Deleting your data" below.

Who is responsible

  • Intern Charlie is the data controller for the information described on this page. The service is built and operated from Denmark, so EU data protection law applies to it.
  • Privacy questions, access requests, and deletion requests go to privacy@interncharlie.com and are handled by the people who run the service.
  • We aim to reply within a few working days and to complete a verified request within one month, as the GDPR requires.

Data we collect

  • Account and contact information: name, email, and authentication details you provide when creating or signing in to an account.
  • Shopify data (read-only): store domain, store metadata, orders, products, customers, and analytics metrics provided through approved scopes.
  • Google OAuth data (read-only): connected Analytics accounts, reporting metrics, property metadata, and OAuth tokens to access them.
  • Meta advertising data (read-only): the business and ad account you select, campaign metadata, the performance figures Meta reports for them, and the access token that lets us read those figures.
  • Product usage and device data: log data, IP address, browser/device information, and cookies for security and performance.

How we use data

  • Provide the service: sync the platforms you connect and turn them into analytics dashboards, reports, and video recaps.
  • Answer your questions: the AI advisor retrieves documents built from your own connected data so its answers are about your store.
  • Security and reliability: prevent abuse, monitor uptime, and protect accounts.
  • Support and communication: respond to support requests and send important operational notices.
  • Compliance: meet legal, accounting, and audit requirements.

Legal bases (EEA/UK)

  • Performance of a contract: to deliver the Shopify app and Google-connected analytics you asked us to provide.
  • Legitimate interests: improving the service, keeping it secure, and preventing fraud, balanced against your rights.
  • Consent: for optional cookies/marketing (where shown) and for connections you authorize.
  • Legal obligation: to comply with laws, court orders, or enforce our agreements.

Sharing and processors

  • Hosting and infrastructure: the application, its database, and its file storage run on DigitalOcean in European regions.
  • AI providers: OpenAI generates insights, advisor answers, and embeddings, Jina reorders retrieved documents, and Synthesia produces video recaps. Each processes the data only to fulfil the request we send.
  • Operational providers: email delivery through Mailgun in the EU, plus logging and error monitoring so we can keep the service running.
  • Professional advisors and authorities when required to meet legal obligations or defend legal claims.
  • We do not sell or rent personal data, we do not give it to advertising platforms for their own targeting, and we do not provide it to anyone for training general-purpose AI models.

Retention

  • Account data is kept while you have an account and for a reasonable period afterward to comply with legal requirements.
  • Shopify, Google, and Meta access tokens are deleted as soon as you disconnect that platform or uninstall the app.
  • Disconnecting stops new collection but does not by itself erase what we already collected. Metrics, reports, and retrieval documents remain until you ask us to delete them or close the account.
  • Application logs are written to our logging pipeline and retained for 30 days, and encrypted database backups are kept by our managed database provider for a short, bounded window so we can recover from failure.
  • Aggregated statistics that can no longer identify a person or a store may be kept after accounts are closed.

Your choices and rights

  • Request access, correction, deletion, or export of your personal data by emailing us.
  • Revoke Google access from your Google Account permissions page, and Meta access from your Meta Business settings or from Settings, Apps and Websites on Facebook.
  • Uninstall the Shopify app to stop new data sharing from your store.
  • Object to processing we base on legitimate interests, and withdraw cookie consent at any time from our cookie policy page.
  • Lodge a complaint with your local supervisory authority. In Denmark that is Datatilsynet.

Shopify merchant data

  • We request read-only scopes needed to surface revenue, orders, and product performance; we do not change store settings or process payments.
  • Data received from Shopify is used only to provide analytics, insights, and video recaps to you.
  • If you disconnect the Shopify connection or request deletion, we remove tokens and associated store data that are no longer necessary, except where retention is required by law.

Google user data

  • We use Google OAuth only to read the Analytics resources you select so we can generate dashboards and insights.
  • Google data is not transferred to third parties except to subprocessors acting on our behalf under data protection terms.
  • The use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Meta advertising data

  • We request only the read-only ads_read permission, so you can pick an ad account and we can read how it performed. We never create, edit, pause, or pay for advertising, and we never post on your behalf.
  • We read the ad accounts available to you, the campaigns in the account you select, and account- and campaign-level insights: spend, impressions, clicks, reach, frequency, CPM, CPC, and the actions and action values Meta reports.
  • Those figures are Meta-reported. We show them next to your Shopify revenue so you can compare the two, but we do not independently verify Meta attribution and we never match Meta data to individual customers.
  • Meta access tokens are encrypted at rest and are used only to read the account you connected. We send no store, customer, or advertising data from your account back to Meta.
  • Our use of information received from the Meta Marketing API follows the Meta Platform Terms. Disconnecting Meta deletes the token and stops collection; to erase what was already collected, delete your account as described below.

AI processing and generated content

  • Your connected data is summarized into retrieval documents and numerical embeddings stored against your account, so the advisor can find the right context for a question.
  • Prompts, the documents retrieved for them, and the resulting answers are sent to our AI providers to produce a response for you, and are processed for that request only.
  • We do not use your data, and do not permit our providers to use it, to train or fine-tune general-purpose models.
  • AI output can be incomplete or wrong. Treat insights, advisor answers, and video recaps as input to your own decisions rather than verified fact.

Deleting your data

  • You can delete your account yourself: sign in, open Settings, then Profile, and choose to delete your account. You confirm with your password, and the deletion runs straight away.
  • Deleting your account removes everything we hold for you: your Shopify, Google, and Meta connections and their access tokens, every metric collected from them, your reports and the figures behind them, the retrieval documents and embeddings built from your data, your advisor conversations, and your generated videos along with the stored files.
  • Disconnecting a platform is not the same as deleting. Disconnecting removes that platform’s access token and stops new collection, but what we already collected stays until you delete your account.
  • If you cannot sign in — because you already closed the account, never finished signing up, or lost access — email privacy@interncharlie.com with the subject Data deletion and tell us the email address on the account. Never send us a password, an access token, or a verification code.
  • For emailed requests we confirm that the request comes from the account holder or someone authorized for that business before deleting anything, normally by replying to the email address registered on the account.
  • Copies of generated videos held by our video provider expire under that provider’s own retention schedule rather than being removed on request.
  • We may keep the minimum required for legal, accounting, or security reasons, and encrypted backups age out on their own schedule rather than being edited. Nothing retained that way is used to run the service for you.
  • Deleting your account from Settings takes effect immediately. For emailed requests we confirm by email once the deletion is complete, and aim to finish within 30 days of verifying the request.

International transfers

  • The application, its database, and its file storage are hosted in the EU, and email is delivered through an EU region.
  • Some providers, including Meta, Google, OpenAI, and Synthesia, operate from or transfer data to the United States.
  • Those transfers rely on the European Commission Standard Contractual Clauses, on the EU-US Data Privacy Framework where the provider is certified, and on the connection you explicitly authorize. Ask us and we will point you to the safeguards for a specific provider.

Security

  • Encryption in transit (HTTPS) and restricted, role-based access to production systems.
  • Platform access tokens are encrypted at rest, and data belonging to each merchant is separated by account in the database.
  • Least-privilege access to customer data, monitoring for unusual activity, vendor due diligence, and data processing agreements with subprocessors.

Contact

If you have questions about privacy or these terms, reach out and we will respond promptly.

Need the short version?

We collect only the data required to generate your insights, keep it secure, and let you leave anytime.