Back to home

Privacy Policy

Last updated:

Accurate, but not yet legally reviewed. Every section describes what Opteno actually does — what it processes, where in the world that happens, who else touches it, how long it is kept and how to export or delete it — and each claim was checked against the code rather than copied from a template. The last section carries a “to be completed” badge and lists the decisions the company has still to make. Nothing has been invented in their place.

This policy explains what Opteno does with your data — both the account you create with us and the Shopify and Google Ads data you connect.

1. Who we are

Opteno is operated by Ksel Technology Limited, a company incorporated in Hong Kong. Its company registration number is 76991590 and its business registration number is 76991590-000. Its registered address is Unit B, 3/F., Kai Wan House, 146 Tung Choi Street, Mongkok, Kowloon, Hong Kong.

Ksel Technology Limited is the data controller for everything described in this policy: it decides what Opteno collects and why. Your own customers are a separate matter — the orders and customer records that sit in your Shopify store are yours, you are the controller of them, and Opteno reads them on your instructions and for your purposes only.

Write to [email protected] about anything in this policy. It reaches a mailbox on Opteno’s own mail server that a person reads. Post reaches us at the registered address above.

Opteno has not appointed a Data Protection Officer. Two facts bear on whether it needs one, and both are true today: it does no large-scale monitoring of people, and it processes none of the special categories of data — health, beliefs, biometrics. Whether that settles the question is on the open list at the foot of this page. If an officer is appointed, their contact details will be published here.

2. What we process

Account data you give us: your name, email address, password (stored only as a one-way hash), your language and timezone, your two-factor settings, and the workspaces and stores you belong to.

Business data we read from the providers you connect. From Shopify: products, variants, orders, order lines, refunds and refund lines, cost-per-item, markets, price lists and publications. From Google Ads: campaign and Performance Max asset-group structure, daily spend in the ad account’s currency, impressions, clicks and conversions, and the Merchant Center offer identifiers Google reports against that spend.

Operational records: an audit log of what was done in your workspace and by whom, and a security log of sign-ins, permission changes and failed attempts. The audit log records the action, the thing acted on, the time, the email address of whoever did it, and the before-and-after values of the change. The security log records the event, its severity and the time. Both also record an IP address and a browser user agent. A failed sign-in records why it failed — an unknown account, a wrong password — and not the address that was typed.

Competitor research you ask for: the publicly available catalogue and pricing information of storefronts you add, read from those stores’ own public product listings. Opteno reads only what a shopper could see without signing in.

Anything you write to us. Mail to our support address lands in a mailbox on our own server and stays there until it is deleted by hand.

Opteno does not use advertising trackers, session recording or behavioural profiling, it makes no automated decision that has an effect on you, and it does not buy data about you from anyone.

To compute the metrics the product exists to provide — per-product ad spend, revenue, cost of goods, refunds, ROAS, POAS, gross margin and net profit — and to show you where a figure could not be computed and why. To carry out the changes you approve: drafting or archiving a product, excluding or including an offer in a Performance Max asset group, publishing a product to a market, changing a price. To run your account, send you the mail the service itself requires (verification, password reset, a security notice, an invitation you were sent) and to bill you once billing is switched on. For people in the EU, EEA or UK this is processing necessary to perform our contract with you — GDPR Article 6(1)(b).

To keep the service secure and to be able to reconstruct what happened after an incident, which is what the audit and security logs are for, and to count page views on this marketing site. That is our legitimate interest, and yours, in a service that can be defended and audited — Article 6(1)(f). We use no advertising or profiling data for this, the page-view counter sets no cookie, and you can object to processing on this basis; the section on your rights says how.

To keep the records that tax and company law require of us once we start charging for the service — Article 6(1)(c). Nothing is charged today.

No part of Opteno relies on your consent, because no part of it does anything that would need consent: there is no marketing tracking, no advertising cookie and no profiling.

As a Hong Kong company, Ksel Technology Limited is also subject to Hong Kong’s Personal Data (Privacy) Ordinance. Its collection principle asks that data be collected lawfully and fairly, for a purpose directly related to what we do, and that no more be collected than that purpose needs; its use principle asks that it then be used only for that purpose. Everything above is written to the same standard, so the two frameworks do not pull in different directions here.

4. Provider credentials

The tokens that let Opteno reach Shopify, Google Ads and any other provider you connect are encrypted before they are stored, with AES-256-GCM and a fresh 96-bit initialisation vector for every value. The authentication tag is stored with the ciphertext, so a tampered value fails to decrypt rather than decrypting into something plausible. Your two-factor secret is held the same way.

They are never written to logs and never shown back to you in full. Disconnecting a provider in Opteno destroys the stored credentials for it immediately — the token columns are emptied, not flagged. The data Opteno has already synced stays until you delete the store or the workspace, and the app stays installed on Shopify’s side until you remove it there; revoking Opteno’s access in Shopify or Google ends our access from their side just as completely.

5. Google user data, and how we are limited in using it

When you connect a Google Ads account, Opteno asks for one permission — the Google Ads scope — and uses it only to read the figures the product shows you: your campaign and asset-group structure, daily spend, impressions, clicks and conversions, and, where you ask for it, to apply the product exclusions you choose. It is never used for anything else.

Opteno’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In plain terms: that data is used only to provide and improve the features you can see in Opteno; it is not sold; it is not used for advertising of any kind; it is not transferred to anyone except where you direct it, where the law requires it, or to the infrastructure providers named below who process it on our behalf; and no human at Opteno reads it except where you ask us to for support, where it is necessary for security, or where the law requires it. It is not used to train any model.

Disconnecting Google Ads in Opteno destroys the stored credentials immediately, and you can revoke Opteno’s access from your Google Account at any time, which ends it from Google’s side just as completely.

6. Where it is stored and processed

Opteno’s servers — the application, the database, the job queue and the mail server — run on a single machine rented from Contabo GmbH and located in Lauterbourg, Grand Est, France. Your data is stored and processed in the European Union. Staging runs on the same machine.

Backups are taken daily and kept for fourteen days. They stay where the data itself is, in France; there is no backup copy in any other country. One consequence worth stating plainly: after you delete something, a copy of it can remain inside a backup for up to fourteen days before that backup ages out.

The company that decides all of this is in Hong Kong, so the people who administer Opteno reach those servers from outside the European Economic Area. Hong Kong is not a country the European Commission has ruled adequate, which means that access is a transfer and needs a safeguard of its own. Several of the services listed below are also outside the EEA. Putting the formal transfer paperwork in place is on the open list at the foot of this page, and we would rather say so than print the name of a mechanism we have not signed.

7. Who else processes it

Contabo GmbH — the machine itself. It provides the hardware, the network and the datacentre in Lauterbourg, Grand Est; it does not use what is on the disks.

Cloudflare — the only way traffic reaches Opteno. Every request to this site, the dashboard, the API and the webmail passes through a Cloudflare tunnel, so Cloudflare terminates TLS and sees request metadata including your IP address. On this marketing site, Cloudflare’s own cookieless page-view counter is the single piece of measurement we allow. It is injected at Cloudflare’s edge, not by us, and it is blocked by the content security policy on the dashboard and the admin console — so there is no measurement of any kind on the screens where merchant data is shown.

Shopify — the source of your store data and the target of the writes you approve. Two smaller things follow from that: your product images are loaded in the dashboard straight from Shopify’s image CDN, so Shopify sees the address of the browser looking at your dashboard, and a product you publish is created in your own store under your own account.

Google (Google Ads API) — the source of your advertising spend and performance data and the target of the exclusions you approve.

Stripe — payments. Checkout, the billing portal and every payment page are hosted by Stripe: card details are entered there and never reach Opteno, and we hold only the payment method identifier, the card brand, the last four digits and the expiry date. Today this runs against Stripe’s test mode and nothing is charged.

Slack — only if you connect it, and only to deliver the automation notifications you ask for.

jsDelivr — one page only. The public API documentation page loads its documentation viewer from jsDelivr’s CDN, so opening that page tells jsDelivr your IP address. Nothing about your account or your store is sent to it, and nothing else on Opteno loads anything from another origin.

Email has no third party in it at all. Opteno runs its own mail server on the same machine in France and delivers straight to your mail provider — there is no sending service in between, and no company other than your own email provider sees a message we send you. We used to name one here; we no longer use one.

Two flows leave Opteno because you told them to, and the destination is your choice rather than ours: a webhook you configure receives the automation data you point it at, and competitor research fetches public pages from the storefronts you add, identifying itself as OptenoBot and sending nothing about you.

Opteno’s database and job queue are run by us, not by a third party. There is no analytics vendor, no session-replay vendor, no error-reporting vendor, no advertising network and no AI service anywhere in the product — not as a dependency, not as an embedded script, not as a background call.

8. How long we keep it

Account and workspace data is kept while the account exists. Deleting your account removes it, your workspace memberships, your API keys and any authorisation you have granted a third-party app — permanently, immediately, with no recovery window. A workspace you are the only member of is deleted with you, together with its stores, products, orders, ad spend, billing records and every metric derived from them. Deleting a store rather than a workspace is gentler: it stops syncing and hides the store, and its rows are kept until the workspace itself goes.

Two records outlive a deletion, and both are stripped of personal data when it happens. The audit log keeps that an action occurred — what was done, to what, and when — because a security trail that can be erased on request is not a security trail. The security log keeps sign-in and permission events on the same terms. At the moment you delete your account, the personal columns in those rows are emptied: the email addresses and names recorded as labels, the before-and-after values, the IP addresses, the browser user agents and the free-form details. What remains is the event itself, and an opaque identifier pointing at a row that no longer exists.

Independently of any deletion, an hourly job empties the IP address and the browser user agent from both logs once a row is more than 400 days old. The event record is not deleted — those columns in it are emptied. Four hundred days is a year plus a five-week margin: long enough for a year-on-year investigation and an annual security review, and no longer. Be clear about what this job does not do: it does not remove the email address of whoever performed an action, or the before-and-after values of what they changed. Age alone is not a reason to forget who did something. Erasing the account is what clears those.

Billing and tax records are a case where the law, not us, sets the period — and today there is nothing there to keep. Nothing has been charged, so no invoice exists, and deleting a workspace destroys its billing rows along with everything else; all that survives is a record that a payment provider sent us an event, carrying provider identifiers and a status and no personal data. That changes the moment real money moves: company and tax law will require certain records to be kept for a set number of years regardless of a deletion request. The exact periods will be named here before the first charge, and they are on the open list below.

9. Your rights

Access and portability. Settings → Account → Your data gives you a JSON file, downloaded there and then in your browser rather than emailed or left on a server. It contains your account, the workspaces you belong to, the stores you can reach, your API key details without their secrets, and your saved preferences. It deliberately excludes credentials — they are stored one way and cannot be read back — and your workspace’s business data, which comes from Shopify and Google Ads and is exported at source, where it is complete and authoritative. A very large account (over 200 memberships, 1,000 stores or 500 API keys) is refused rather than truncated, and you have to write to us; there is no automated route for that case yet.

Erasure. The same page deletes your account. It asks for your password, a re-authentication within the last five minutes and your email address typed back, because there is no undo and no grace period — the deletion happens the moment you confirm it. If you are the only owner of a workspace other people still belong to, the request is refused and each such workspace is named: that workspace holds their data as well as yours, so you transfer ownership or remove the other members first. Deleting a workspace on its own is a separate action, asks for its name typed back and a recent re-authentication, and leaves everyone’s accounts intact.

Rectification. Your name is editable on the same page, and your role and store access are changed by you or by a workspace administrator in Settings. Your email address is not editable, by you or by anyone else — there is no mechanism anywhere in Opteno that changes the address on an account, so putting a different address on the same account means writing to us or starting a new one. We would rather tell you that than leave you hunting for a button.

Objection and restriction. You can object to the processing we do on the legitimate-interest basis, and ask us to restrict processing while a dispute about accuracy or grounds is worked out. Neither is a button in the product — there is no self-service flow for them — so both are handled by writing to us, and we will tell you what we can and cannot do about the security logs in particular, since a trail that can be switched off on request stops being a trail.

How we check it is you. A request made from inside your account is already authenticated, which is why erasure asks you to prove it again rather than asking who you are. A request by email is answered to the address on the account and not to another one.

How long we take. The GDPR gives us one month to answer a request of this kind, extendable for genuinely complex ones. Opteno has not published a faster commitment of its own, and this page is not going to invent one — see the open list below.

If you cannot complete a request yourself — you have lost access to the account, or you own a workspace others are in — our support team can carry out an erasure for you. Every staff erasure requires a written reason, which is recorded on the audit trail with it, and staff hit exactly the same refusal you would if the workspace still has other members in it.

Complaints. If you are in the EU or EEA you can complain to the data protection authority of the country you live or work in; if you are in the UK, to the Information Commissioner’s Office. In Hong Kong, where Ksel Technology Limited is registered, the regulator is the Office of the Privacy Commissioner for Personal Data. Because Opteno has no establishment in the EU, there is no single lead authority for it, and your own country’s authority is the right place to start. We would rather you wrote to us first, but nothing here requires you to.

10. Cookies

Signing in sets two cookies on the dashboard and nothing else does. One is the session cookie: opaque, readable only by the server, never by a script in your browser, and valid for twelve hours. The other carries a token that protects against a request being forged from another site; it is readable by the page, as it has to be, and on its own it grants nothing. Both are cleared when you sign out and when you delete your account.

The dashboard also remembers a few things in your own browser’s storage and nowhere else: whether the sidebar is collapsed, which columns you chose on a table and at what image size, and which store you last had selected. None of it leaves your machine, and none of it is used to track you across sites.

This marketing site sets no cookie of its own. It loads no third-party script, no external font and no external image: its Content-Security-Policy allows scripts only from this origin, each carrying a nonce issued for that single response. The one exception is described above — Cloudflare’s page-view counter, injected at the edge, which stores nothing in your browser.

11. Changes to this policy

The current version is the one on this page, and the date at the top is when it last changed. There is no announcements list and no in-product notice for a change to this policy today, so this page is the only place it is published.

Whether a material change will also be emailed to account holders, and how much notice is given before it takes effect, has not been decided — it is on the list immediately below rather than promised here.

12. What is still openTo be completed

Everything above this section describes the product as it is built and was checked against the code. What follows is the short list of things Ksel Technology Limited has to decide, and which this page will not fill with something that merely sounds right.

A dedicated privacy address. Today privacy mail goes to [email protected], which is a real mailbox a person reads. Whether to publish a separate one is undecided.

Whether a representative in the European Union is appointed under Article 27 of the GDPR, and who it is. Opteno has no establishment in the EU, its customers include people in the EU, and its servers are in France — whether that triggers the requirement is a legal question, and it has not been answered. The same advice settles whether a Data Protection Officer is needed.

The transfer safeguards: the instrument covering administrative access from Hong Kong to the servers in France, and a record confirming that the data processing terms of each service named above have been accepted.

A published response time for a privacy request, faster than the one month the law allows, if the company wants to commit to one.

The statutory retention periods for billing and tax records, to be named here before the first charge is taken.

How a material change to this policy is announced.

None of this page has been reviewed by a lawyer, and none of it is legal advice.

Privacy Policy — Opteno