Privacy Policy

Effective date: 17 July 2026

This Privacy Policy explains how Alytic ("Alytic", "we", "us") collects, uses, discloses, and safeguards information when you use our website, dashboard, APIs, and integrations (collectively, the "Service"). This page is maintained by Alytic to answer common privacy questions. It is not a certification or legal advice.

1. Information we collect

  • Account data: name, work email, password hash, workspace and role, preferences (language, theme).
  • Google OAuth profile: if you sign in with Google, we receive your basic profile (name, email, avatar) and a unique Google user ID. We request only the openid, email and profile scopes.
  • Commerce integration data: when you connect Shopify, WooCommerce, PrestaShop, Magento, OpenCart, Zapier or a similar store, we receive the data you authorize — typically products, variants, inventory levels, orders, refunds, customers (limited fields), fulfillments, and shop settings.
  • Payment & finance metadata: settlement reports, gateway identifiers, and reconciliation data from providers such as Stripe, Tap, NeoPay, EdfahPay. We do not store full card numbers.
  • Product & operational data you upload: raw materials, suppliers, recipes, fixed costs, inventory movements.
  • Usage & device data: IP address, browser, pages viewed, and diagnostic logs used to secure and improve the Service.

2. How we use information

  • Provide, operate, and secure the Service and your workspace.
  • Sync your store data and produce analytics, forecasts, and AI insights.
  • Authenticate you and manage sessions.
  • Communicate service, billing, and security messages.
  • Comply with legal obligations and prevent abuse.

3. Google API user data — limited use

Alytic's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  • We use Google user data only to provide user-facing features of Alytic (sign-in, identity, workspace membership).
  • We do not sell Google user data, and we do not use it for advertising.
  • We do not use Google user data to train generalized or third-party AI/ML models. Your data never trains public models.
  • Humans do not read Google user data unless (a) you give explicit consent for specific messages, (b) it is required for security (e.g. investigating abuse), (c) to comply with law, or (d) it is aggregated and anonymized for internal operations.

You can revoke Alytic's Google access at any time from your Google Account permissions page.

4. Shopify & commerce plugin data

When you install the Alytic app or plugin for Shopify, WooCommerce, PrestaShop, Magento or OpenCart, we access only the scopes required to deliver analytics — for example: read products, read inventory, read orders, read fulfillments, read customers (limited), and read shop settings. We handle this data in line with Shopify's API License and Terms of Use and equivalent policies of each platform.

  • Merchant store data is used solely to power the merchant's own workspace.
  • We do not sell merchant or customer data.
  • Personal data of your end-customers (names, emails, addresses) is stored only when required for reporting and is never shared with third parties for marketing.
  • When you uninstall the app or disconnect the store, we stop syncing and delete associated data within 30 days, subject to legal retention.
  • We honor customers/data_request, customers/redact and shop/redact webhooks (or the equivalent on other platforms).

5. Sharing & subprocessors

We share data only with subprocessors that support the Service (cloud hosting, database, email delivery, error monitoring, AI inference). Each subprocessor is bound by a data protection agreement. We do not sell personal data.

6. Data storage & security

  • Encryption in transit (TLS) and at rest.
  • AES-256-GCM for sensitive fields such as integration credentials.
  • Row-level security in Postgres to isolate every workspace.
  • Role-based access, audit logs, and least-privilege service credentials.

7. Data retention

We retain workspace data while your account is active. After disconnection or account closure, data is deleted within 30 days, unless a longer period is required by law (e.g. tax records).

8. Your rights

Subject to applicable law (including PDPL in the Kingdom of Saudi Arabia and GDPR where applicable), you may request access, correction, deletion, export, or restriction of your personal data. Contact us at info@alytic.sa.

9. International transfers

Data may be processed outside your country. We use appropriate safeguards (standard contractual clauses or equivalent) for cross-border transfers.

10. Children

Alytic is a B2B service not directed to children under 16, and we do not knowingly collect their data.

11. Changes to this policy

We will post material changes on this page and update the effective date. If changes are significant, we will notify workspace admins by email.

12. Contact

Questions or privacy requests: info@alytic.sa.