Privacy Policy

Who we are

APPSOLVE SRL (“Company”, “Vitals”, “we”), a Romanian company registered with the Trade Register under no. J40/16347/2017, VAT number RO38260784, having its registered headquarters at 11, Grigore Mora St, Room 1, 3rd Floor, 011885, Bucharest, Romania, processes personal data in compliance with the applicable legal regulations on the protection of natural persons with regard to the processing of personal data.

APPSOLVE SRL is the controller of the personal data described in this Privacy Policy. You can reach us about privacy at [email protected] or at the address above.

Introduction

This General Privacy Policy describes why and how we process personal data in different situations and provides you with information about your rights when our Company acts as a personal data Controller. It also explains, in the section “Information from customers”, the cases where we act as a Processor for merchants.

We may process personal data in relation to:

  • merchants using Shopify and their representatives, and users (we are the Controller)
  • the customers and visitors of our merchants' stores (we are the Processor and the merchant is the Controller; our Data Processing Agreement applies)
  • other partners and (potential) clients
  • visitors to Appsolve websites and pages or anyone contacting us

This Privacy Policy will help you better understand how we collect, use, and share personal data. If we change our privacy practices, we may update this privacy policy.

General information on processing personal data

Personal data means any information relating to an identified or identifiable natural person (data subject); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

Processing means any operation or set of operations which is performed on personal data or on sets of personal data, whether by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

Controller means the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.

Processor means a natural or legal person, public authority, agency, or other body which processes personal data on behalf of the controller.

Recipient means a natural or legal person, public authority, agency, or another body, to which the personal data are disclosed, whether a third party or not.

The main data/categories of data processed by the Company

The main data/categories of data processed by the Company depend, as the case may be, on the purposes associated with the processing, and include data such as:

  • identity data (such as name, surname)
  • contact details (such as email address, mobile telephone number, instant messaging accounts)
  • data related to you being a representative of an entity / legal person that enters/has a legal relation (such as position held, place of work, signature)
  • data obtained when accessing the Company’s pages/site (such as the online identifier of the persons accessing one or more of the Company’s site or pages, identifier processed for the purposes mentioned in the Cookies Policy related to that page/site)
  • data obtained when accessing the Company’s products, services, and/or online platforms; we may process the data, content, other user/mobile account information, and other information you provide when you use our products, services, and/or online platforms and/or information which is provided about you by social networking platforms and other engagement channels providers according to your settings preferences within such engagement channels (such as your username, hometown, age range, likes, other data you set in you profile to be public or to be provided to others by that channel provider).

Information from merchants

Privacy matters! If you are a merchant, your customers need to understand how you (and how APPSOLVE) collect and process their personal information. Accordingly, you agree to post an up-to-date and accurate privacy policy on your storefront that complies with the laws applicable to your business. You also agree to tell your customers that APPSOLVE processes their personal information on your behalf, and to obtain their consent where the law that applies to you requires it.

What information do we collect from merchants and why?

When you install Vitals, Shopify gives us access to data about your store and about the people who open Vitals in the Shopify admin. We also collect data directly while you use Vitals. We are the Controller for the data below.

  • Store and owner details, from Shopify: store name and Shopify domain, the store owner’s name, the owner’s contact email, the store’s public contact email, the store’s phone number, the billing address (city, state or province, postal code, country), your Shopify plan, country, currency, language and theme name, and the number of products and orders.
  • The Shopify login of each person who opens Vitals in the Shopify admin: Shopify user ID, first name, last name, email address, whether the person is the account owner or a collaborator (for example an agency), language, whether the email is verified, and the language chosen in Vitals.
  • Subscription and billing details: your Vitals plan, price, trial and billing dates, and subscription status. Shopify handles the payment. We do not receive card details.
  • Other contact addresses for your store: a support address, and the contact address published on your store’s privacy policy page.
  • We collect data about the APPSOLVE websites that you visit. We also collect data about how and when you access your account and the APPSOLVE platform, including information about the device and browser you use, your IP address, and information about how you browse through the APPSOLVE interface.
  • Advertising identifiers: if you reach us from an ad or a partner link, we keep the click identifier and the cookie identifier set by that ad platform, and the affiliate or campaign that referred you.
  • Emails we send you and whether they were delivered, opened or clicked.
  • What you tell us in support conversations.
  • We collect personal information about your customers that are shared by you via Shopify's API. In order to deliver the Service, you provide us with access to your orders. The access is granted when you install the app and give us permission to access your orders. We use this information only to provide you with our Service. For this data you are the Controller and we are your Processor (see “Information from customers”).

Why we use merchant data, and on what legal basis

1. To provide Vitals to you. We use your store, login, subscription and usage data to install and run the apps, confirm who you are, give your team access, bill you through Shopify, send service messages (billing, activation, uninstall) and answer support requests. Legal basis: performance of our contract with you (GDPR Article 6(1)(b)).

2. To comply with the law. We keep invoices and accounting records and answer lawful requests from authorities. Legal basis: legal obligation (Article 6(1)(c)).

3. To keep Vitals secure and to improve it. We use usage data, IP addresses and device data to detect abuse, fix errors and understand which features are used. Legal basis: our legitimate interest in a secure and useful product (Article 6(1)(f)).

4. To send you onboarding and product emails. After you install Vitals we email you setup guidance, product updates and offers about Vitals. We send them to the store owner’s email, to the person who opened Vitals, and we may send them to the other store contact addresses listed above. By installing Vitals and accepting our Merchant Agreement and this Privacy Policy, you agree to receive these emails. Legal basis: our legitimate interest in helping customers use, and keep using, a product they installed (Article 6(1)(f)).

How to unsubscribe: every onboarding and marketing email has an unsubscribe link, and your mail app may show a one-click unsubscribe button. Unsubscribing stops onboarding and marketing emails for every store that uses that email address. You can also write to [email protected]. We still send service messages about billing, activation and uninstall, because you need them to use Vitals.

5. To measure our own advertising. We advertise Vitals on online advertising platforms, such as search engines and social networks, and we use analytics services. To measure and improve our advertising, we tell these platforms when you install Vitals, when you are sent to approve a plan, and when you approve a subscription. We do this for every merchant, including merchants who did not reach us through an ad.

Depending on the platform, an event can include:

  • in hashed form (SHA-256), so they are not sent in readable form: your email address, your first and last name, your phone number, your billing location (city, state or province, postal code and country, or the city and country estimated from your IP address if we have no billing address), and an identifier for your store;
  • your IP address and browser details;
  • the advertising click identifier and cookie identifier that the platform itself set, if you came from one of its ads or visited a page with its tracking;
  • your Shopify plan, the landing page you came from, and the value of your subscription.

If you enter your email address on one of our landing pages before installing Vitals, we send a hashed copy of it to these platforms in the same way.

We do not send any data about your customers.

The platform matches these details against its own users to count the result of our ads and to improve how they are delivered. It also uses the data under its own terms and privacy policy.

By installing Vitals and accepting our Merchant Agreement and this Privacy Policy, you expressly authorise us to use and share your account details in this way. Legal basis: our legitimate interest in knowing which advertising works (Article 6(1)(f)). You can object at any time by writing to [email protected], and we will stop sharing this information for your store.

Information from customers

  • We collect our merchants' customers' ID, name, email, phone number, shipping and billing address, order details, and the content customers submit or generate through Vitals apps on the store (for example product reviews and photos, wishlists, back-in-stock and email sign-ups, and visit data such as session recordings).
  • We only use this information to provide our merchants with the Service. For our merchants' customers, we process your information solely as a data processor on behalf of our merchants. The merchant is the Controller. Our Data Processing Agreement sets out the terms. If you are a customer of a store and want to use your privacy rights, please contact that store. If you write to us, we pass your request to the merchant.
  • APPSOLVE does not sell your customers' information and does not use it for our own advertising. We share it only with the service providers (sub-processors) that help us run Vitals, such as hosting, email and SMS delivery, and with the services a merchant chooses to connect, such as an email marketing platform.

Information from APPSOLVE website visitors and support users

What information do we collect and why?

  • As you visit or browse the APPSOLVE websites, we collect information about the device and browser you use, your network connection, your IP address, and information about the cookies installed on your device. We also collect personal information submitted by you via any messaging feature available from any of our websites (“Messaging Feature”).
  • We may also receive personal information when you contact us via any of our websites.
  • From chat support users, we collect your name, email address, information about the device and browser you use chat transcript, and other personal information you provide us during our chat.

Information from cookies and similar tracking technologies

What is a cookie? A cookie is a small amount of data, which may include a unique identifier. Cookies are sent to your browser from a website and stored on your device. We assign a different cookie to each device that accesses our website.

Data is processed for the purposes mentioned in the Cookies Policy related to that page/site.

Sources from which we collect personal data and, if the case may be, publicly available sources

We generally collect personal data directly from you when you are in a legal relationship with our Company or you are the representative of an organization that is in legal relationship with the Company.

In other cases, we may process personal data collected from other sources such as Merchants, suppliers or partners, publicly available sources, Shopify, and other channels/platforms providers, according to your settings preferences within such channels/platforms. For merchants, most of the data described under “What information do we collect from merchants and why?” comes from Shopify when you install or open Vitals. Some store contact addresses come from your public storefront.

Types of data processing

Our company processes personal data for the purposes stated in this Privacy Policy and for each purpose one or more data processing operations may be used such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction. This Privacy Policy does not cover any processing carried out by our Company in the name of its clients.

Purposes for which personal data are processed

For merchants, the purposes and the legal basis for each are set out under “Why we use merchant data, and on what legal basis”. The list below applies to all other cases.

The Company processes personal data for multiple purposes. The methods of processing, the legal basis for processing, retention periods, and other such aspects may be different, depending on each purpose.

We may use personal data for one or more of the purposes described in this Privacy Policy. If the Company will subsequently process personal data for a purpose other than that for which you have already been informed and which is not compatible with the purposes you were informed of/for which the data were initially collected, the Company will provide information on that additional purpose and any relevant related information.

We process personal data mainly for the following purposes:

  • Carrying out the activity of the Company, providing products and providing services related in particular to the main scope of work of the Company, respectively Vitals Services
  • Managing our relationships with customers, suppliers, and professionals in various fields of activity, correspondence, offers, negotiations, contracts, and account management.
  • Improving the activity and services of the Company in relation to our customers and partners
  • We process personal data in order to fulfill our contractual obligations and commitments
  • Managing the risks related to our activity, meaning that we take security measures to protect personal data, measures that involve the detection, investigation, and resolution of security threats.
  • In accordance with applicable law, we use the contact details to directly or indirectly provide information that we believe is of interest to you
  • In case of visiting our sites or our pages on social networks, it is possible to process some information for the purposes mentioned in the Cookies Policy  
  • Compliance with legal and/or regulatory requirements, such as those of a fiscal nature or those requested by special normative acts that regulate our object of activity or, as the case may be, archiving
  • Economic-financial-administrative management
  • Exercising or defending our legal rights in court
  • Statistics

Legal basis on which data processing is based

For merchants, the legal basis for each purpose is set out under “Why we use merchant data, and on what legal basis”. The list below applies to all other cases.

The legal bases of the processing take into account the provisions of the applicable normative acts regarding the processing of personal data and the provisions of the applicable legislation in the Company’s field of activity.

The processing is based on at least one of the following conditions of the legality of the processing:

  • processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract;
  • processing is necessary for compliance with a legal obligation to which the Company as controller is subject;
  • processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party,
  • the data subject has given consent to the processing of his or her personal data for one or more specific purposes, only when mandatory under the law;
  • for the management of our relations with potential customers and clients or our partners, including,
  • for managing the risks related to our activity
  • managing the notifications/complaints in connection with our services
  • to improve our products and/or services,
  • to ascertain the exercise or defense of our rights in court

How long do we keep personal data

We retain the personal data we process only for as long as is necessary for the purpose for which it was collected (including in accordance with applicable law or regulations), such as:

  • During the execution of the contract / legal relation for the personal data necessary for its conclusion/ for its execution,
  • During the period provided by law in situations where there are normative acts applicable in this regard (e.g. in the case of mandatory accounting records and supporting documents underlying the financial records)
  • During the management period of the relationship with potential clients/clients/beneficiaries of our services/partners of the Company and their representatives, respectively until the exercise of opt-out for the data used for the purpose of transmitting commercial communications containing information and offers regarding services and/or products,
  • Until the withdrawal of consent for the processing of personal data based exclusively on consent
  • For the archiving period mentioned by law or by the applicable policies of the Company, as the case may be, for the data contained in the documents for which the law or the Company provided for the archiving
  • In any other case and/or in the absence of specific legal, regulatory or contractual requirements, our reference period for keeping personal data is no more than 3 years from the date of termination of relations / last contact between the Company and the data subject
  • Marketing email: until you unsubscribe or object. We then keep your address on a suppression list so we do not email you again.

Any data may be retained by the Company, except from the foregoing provisions where applicable, until the expiry of the limitation period, in respect of situations in which the Company would have a legitimate interest in retaining certain personal data in connection with potential litigation that may arise between the parties.

In any case, except for the situations provided by the applicable legislation, we delete your data at the time you request such deletion. The applicable exceptional situations will be communicated to the data subject through the response submitted by our company in connection with the request to delete the data.

Your rights and how to exercise them

Our company is responsible for facilitating the exercise of your rights mentioned below.

Any of these rights may be exercised by sending an e-mail to [email protected], or you can submit/send it to our headquarters address: APPSOLVE SRL, 11, Grigore Mora St, Room 1, 3rd Floor, 011885, Bucharest, Romania.

For the protection of your data, in order to prevent the abuse of malicious people who would follow the access to your data, if we receive a request from you regarding the exercise of the below-mentioned rights, we may ask you for additional information to verify your identity before acting on your request.

If you submit an application in electronic format for the exercise of your rights, the information will be provided by our company also in electronic format where possible.

We will try to respond promptly to any request from you and, in any case, within the time limits expressly mentioned by the applicable legal provisions (usually one month from the registration of the request). In certain situations, expressly provided by the applicable legislation, we may charge an access request which will take into account the administrative costs necessary to fulfill the request.

In the event that, as a result of the application of legal provisions, our company cannot comply, in whole or in part, with a request received from you as a data subject, then the applicable exceptional situations will be communicated to you by means of the reply submitted by our company in connection with the request in question.

The right to access your personal data

You have the right to access your data we process as controller, respectively to obtain from the Company a confirmation whether it processes personal data concerning you and, if so, the following information:

  • the purposes of the processing;
  • the categories of personal data concerned;
  • the recipients or categories of recipients to whom the personal data have been or are to be disclosed, in particular recipients from third countries or international organizations;
  • where possible, the period for which personal data are expected to be processed or, if this is not possible, the criteria used to establish the retention period;
  • the existence of the right to request the rectification or deletion of personal data or the restriction of the processing of personal data or the right to oppose the processing;
  • the right to lodge a complaint with a supervisory authority;
  • if personal data are not collected from you, any available information on their source;
  • the existence of an automated decision-making process including profiling, as well as, at least in those cases, relevant information on the logic used and on the importance and expected consequences of such processing for the data subject.

If you fall under the protection of GDPR and your personal data are transferred to a third country or an international organization, you have the right to be informed of the appropriate safeguards.

The right to rectification of data

You have the right to obtain from the Company, without undue delay, the rectification of inaccurate personal data concerning you. Taking into account the purposes for which the data were processed, you have the right to obtain the completion of personal data that are incomplete, including by providing an additional statement. When possible or necessary we will make corrections (as appropriate) based on updated information and inform you about this if necessary.

The right to delete data

You have the right to obtain from the Company the deletion of personal data concerning you, without undue delay, except for certain cases provided by the law, if one of the following reasons applies:

  • personal data are no longer necessary for the purposes for which they were collected or processed;
  • you withdraw your consent on the basis of which the processing takes place insofar as the processing is based exclusively on the consent and there is no other legal basis for the processing;
  • you object to the processing carried out for the purpose of public interest or for the purpose of the legitimate interests pursued by the Company or a third party and there are no legitimate reasons to prevail over your interests / fundamental rights and freedoms regarding the processing
  • personal data have been processed illegally;
  • personal data must be deleted in order to comply with a legal obligation incumbent on the Company under the law governing it and/or its activity;
  • other situations provided by the applicable legislation insofar as they are applicable

The right to restrict processing

You have the right to obtain a restriction on processing in the following cases:

  • you contest the accuracy of the data, for a period that allows the Company to verify the accuracy of the data;
  • the processing is illegal, and you object to the deletion of personal data, requesting in return the restriction of their use;
  • the company no longer needs the personal data for the purpose of processing, but you request them for the ascertainment, exercise or defense of a right in court; or
  • you have objected to the processing in processing for the purpose of the legitimate interests pursued by the Company or by a third party, for the period during which it is verified whether the legitimate rights of the controller prevail over those of the data subject.

The right to data portability

You have the right to receive your personal data which you have provided to the Company, in a structured, commonly used format that can be read automatically and when transmitted to another controller, without obstacles on the part of the Company, if (i) the processing is based on consent or contract and (ii) processing is carried out by automatic means.

In case of exercising the right to portability of personal data, they may be transmitted directly from the Company to another controller expressly indicated by you, where this is technically feasible.

The right to opposition

At any time you have the right to object, for reasons related to your particular situation, to the processing carried out for the purpose of public interest or for the purpose of the legitimate interests pursued by the Company or a third party, including the creation of profiles. In this case, the Company will no longer process your personal data, unless it demonstrates that it has legitimate and compelling reasons justifying the processing and prevailing over your interests, rights, and freedoms or that the purpose is to establish, exercise, or defend a right in court.

How to object: write to [email protected] from the email address we have for you, or tell us your store’s Shopify domain, and say what you object to. For merchants this covers, in particular, product analytics and the advertising measurement described above.

The right to object to processing for direct marketing purposes

When the processing has direct marketing as scope, you have the right to object at any time to the processing of personal data concerning you for this purpose, including the creation of profiles, insofar as it is related to that direct marketing. We inform you that the Company may send you offers, information, and other types of communications in the light of situations such as following your participation in an event organized by the Company as a main organizer or as a partner, the fact that you have agreed to receive commercial communications from us.

If you object to the processing for direct marketing purposes, personal data will no longer be processed for this purpose. You do not need to give a reason. This right covers our onboarding and marketing emails and the use of your data to measure or target our advertising. To stop emails, use the unsubscribe link in any of them. To stop the use of your details for advertising measurement, write to [email protected].

The right to withdraw consent

If the processing is based on your consent, you have the right to withdraw your consent at any time. Withdrawal of consent does not affect the lawfulness of the processing carried out on the basis of the consent before its withdrawal. The assumption of withdrawal of consent is not applicable in cases where the basis for processing is not consent.

The right to submit a complaint

If you want to complain about the use of your personal data, please send an e-mail /letter with the details of your complaint to us. We will analyze and respond within the legal deadlines to any complaint we receive. You also have the right to file a complaint with the competent data protection supervisory authority. In Romania this is the National Supervisory Authority for Personal Data Processing (ANSPDCP), www.dataprotection.ro. You may also complain to the authority of the EU country where you live or work.

Recipients or categories of recipients of personal data

The company may transmit/grant access / disclose personal data mainly to the following categories of entities:

  • public authorities and entities (such as tax authorities, etc.)
  • service providers (like Cloud providers, and providers of hosting, email delivery, analytics and customer support)
  • persons who process personal data in the name of the Company and/or under the authority of the Company, in accordance with the instructions received from us and comply with this Privacy Policy, data protection laws, and any other appropriate confidentiality and security measures (like software developers and IT&C service providers)
  • advertising platforms, for the measurement described under “To measure our own advertising”

For the advertising platforms, the platform also uses the data it receives under its own terms and privacy policy.

Transfers outside the European Economic Area. Most of the recipients above are in the United States or send data there. Our databases are hosted in the United States. If you fall under the protection of GDPR and the Company transfers your personal data to a third country or to an international organization, we will ensure that it is adequately protected, ie that we transmit the data in a country that provides an adequate level of protection as assessed by the competent entities (for the United States, recipients certified under the EU-US Data Privacy Framework) or, if the country is considered not to have laws equivalent to GDPR data protection standards, we will ask the third party to conclude a legally binding contract/agreement/instrument that reflects the latter standards (the European Commission’s Standard Contractual Clauses) or provides other appropriate guarantees in this sense. You can ask us for a copy of these safeguards at [email protected].

Consequences of refusal of the provision of personal data

If personal data is collected directly from you, we inform you that, as a rule, you are not obliged to provide your personal information to the Company, unless their provision constitutes a legal or contractual obligation or an obligation /is necessary for concluding a legal relationship/contract. Thus, to the extent that you opt to enter into a legal relationship with the Company or otherwise benefit from our services/product, the provision of personal data is a necessity from the perspective of legal requirements and/or the legal relationship with us, because this information is necessary to honor the obligations undertaken by the Company in relation to you or to provide services and/or products to you. So, in these situations, depending on the data you refuse to provide, it is possible that:

  • our company is unable to conclude the contract or to continue the contractual relationship with you
  • it may be impossible to partially / fully fulfill our obligations and to provide our services

If you consider that the information contained herein is ambiguous or contains ambiguities, you can request clarifications in this regard from us.

Additional information for California residents

This section applies to California residents. It adds to the rest of this Privacy Policy and covers the California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA”). It covers the personal information we handle as a business, mainly about merchants and their staff. For the customers of our merchants' stores we act as a service provider to the merchant, and the merchant’s own privacy policy applies.

Categories of personal information we collected in the last 12 months

CategoryExamplesSourceDisclosed for a business purpose to
IdentifiersName, email, phone, Shopify user ID, IP address, online identifiersShopify, youHosting, email, support and analytics providers. Advertising platforms.
Commercial informationVitals plan, subscription historyShopify, youHosting and analytics providers. Advertising platforms (plan and subscription value).
Internet or network activityUse of the Vitals admin and our websites, email opens and clicksYour deviceHosting, analytics and email providers
Geolocation data (approximate)Billing city, state, postal code, country. Location inferred from IP address.Shopify, your deviceHosting providers. Advertising platforms (hashed).
Professional informationYour role in the store (owner or collaborator)ShopifyHosting providers

We do not collect sensitive personal information as the CCPA defines it.

Why we use it: the purposes are listed under “Why we use merchant data, and on what legal basis”. How long we keep it: see “How long do we keep personal data”.

Sale and sharing. We do not sell personal information for money. We send limited merchant information to advertising platforms to measure our own advertising, as described above. We do not knowingly sell or share the personal information of anyone under 16.

Your rights. If you are a California resident you can ask us:

  • to tell you what personal information we collected, used and disclosed about you, and to give you a copy;
  • to delete it;
  • to correct it;
  • to opt out of the sale or sharing of your personal information;
  • not to be treated differently because you used these rights.

How to use them. Write to [email protected]. We check your identity by matching your request against the email address or Shopify store we have for you. You can use an authorised agent, who must show written permission from you. We answer within 45 days. If we need more time, up to 45 more days, we tell you.

Our contact information for data protection purposes

APPSOLVE SRL, Trade Register no. J40/16347/2017, VAT number RO38260784

Email: [email protected]

Address: 11, Grigore Mora St, Room 1, 3rd Floor, 011885, Bucharest, Romania

This Privacy Policy may change from time to time. You have the opportunity to read the up-to-date policy here before you choose to continue using our products and/or services.

Through this Privacy Policy, you have read the information provided by APPSOLVE with regard to personal data processing, and you have been informed about the rights conferred to you.

Effective date and date of last revision: October 6, 2026

‍