Privacy Policy

Last updated: 26 September 2026

1. Introduction

Autone Solutions (“we”, “our”, “us”) operates the Autone platform at autone.app. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our creator marketing platform and related services, including the Autone app for Shopify, our app-free Shopify connection, and integrations with third-party e-commerce platforms.

2. Information We Collect

Account Information

When you create an account, we collect your name, email address, company name, and billing information necessary to provide our services.

Email Integration Data

When you connect your email account (Google or Microsoft) via OAuth, we receive an access token that allows our platform to send emails on your behalf. We request only the minimum permissions required:

  • Google: gmail.send (send emails only) and userinfo.email (your email address)
  • Microsoft: Mail.Send (send emails only) and User.Read (your profile)

We do not read, access, or store the contents of your inbox. We cannot view your existing emails or contacts. The only emails we access are those sent through our platform on your behalf.

Shopify Store Data

There are two ways to connect a store to Autone, and they give us different access. You can see which kind of connection your store has, and disconnect it, in Settings > Integrations.

If you installed the Autone app from the Shopify App Store, Shopify issues us an Admin API access token for your store. We store it encrypted (AES-256-GCM) and use it only within the four scopes you approved at install:

  • read_orders: to receive your orders and attribute sales to the right creator. Customer name, email, phone and addresses are stripped from each order before it is stored; we keep a one-way hash of the customer identifier and the order and discount fields listed below.
  • read_products: to research your brand and choose products for creator gifting.
  • write_discounts: to create one discount code per creator in your store, so their sales can be attributed.
  • write_draft_orders: to create draft orders for gifted product.

We do not change your theme, prices, customers or settings, and we request no scope beyond these four.

If you connected without installing the app (a store on another platform, or a Shopify store connected through a webhook you create yourself), we hold no access token and cannot read, create, or change anything in your Shopify admin. We receive store data in only two ways:

  • Order notifications you configure: You create a webhook in your own Shopify settings that sends us new orders. It carries the same order fields as the app connection, and we minimise it the same way.
  • Publicly available product data: We read your storefront's public product listing (the same information any visitor to your site can see) to research your brand and help select products for creator gifting. This requires no authentication and no special access.

Order data we keep, on either connection: the order ID and number, totals, currency, discount codes used, line items, timestamps, the referring and landing URL, and the customer's order count (to tell new customers from returning ones).

Customer data: We do not store your customers' names, email addresses, phone numbers, shipping or billing addresses, or browser details. They are removed from every order at the moment it reaches us, before anything is saved. We retain only a one-way SHA-256 hash of the customer identifier — which cannot be reversed — solely to tell new customers from returning ones and to avoid counting the same order twice.

Discount codes: With the app installed, Autone creates one unique discount code per creator in your store using the write_discounts scope. Without the app, Autone proposes the code and you choose whether to create it in Shopify yourself. In both cases we store the code and which creator it belongs to so that sales can be attributed when it is used.

Autopilot and Outreach Data

We store autopilot settings, outreach messages, and response data that you create through the platform. This includes email templates, creator communications, and autopilot analytics.

3. How We Use Your Information

  • To provide and maintain our creator marketing platform
  • To attribute e-commerce sales to creator autopilots using discount codes
  • To calculate autopilot ROI, conversion rates, and revenue metrics
  • To send outreach emails to creators on your behalf via your connected email account
  • To receive and process replies to your outreach messages
  • To provide AI-powered autopilot recommendations and creator matching
  • To create (with the Shopify app) or propose (without it) one discount code per creator, and to attribute sales when it is used
  • To bill your subscription, through Shopify or Stripe depending on how you connected (see section 5), and to process the creator payments you approve
  • To send you service-related communications (account updates, billing)
  • To improve our platform and develop new features

We limit our use of personal data to the purposes listed above. We do not use merchant or customer data for advertising, marketing to end customers, or any purpose unrelated to providing our services.

4. Email Sending and Receiving

When you connect your email account and start outreach:

  • Emails are sent from your own email address using your connected account's OAuth credentials
  • Outgoing emails include a Reply-To header that routes creator replies to our processing system
  • We process incoming replies to classify them (interested, not interested, questions, etc.) and present them in your dashboard
  • All email content is encrypted in transit and at rest

You can disconnect your email account at any time from Settings, which immediately revokes our access to send emails on your behalf.

5. Shopify Integration, Merchant Customer Data and Billing

Autone receives your store's orders, through the Autone app for Shopify or through an order notification you configure yourself, in order to attribute sales to creators. We handle that data with the following safeguards:

  • Least access: With the app installed, we hold an access token limited to the four scopes listed in section 2 (read orders, read products, write discount codes, write draft orders) and use it for nothing else. Without the app, we hold no access token at all and receive only the order notifications you send us plus publicly available storefront product data
  • Personal data minimisation: Customer names, email addresses, phone numbers, shipping and billing addresses, and browser details are stripped from orders before storage
  • Customer identifiers: Attribution uses a one-way SHA-256 hash of the Shopify customer ID. The plain customer ID is kept only on the stripped order record, solely so that a Shopify customers/redact request can be matched and honoured, and it is removed when that request arrives
  • Endpoint protection: Webhooks from the Shopify app are verified with an HMAC-SHA256 signature using the app secret. On the app-free connection each store's notification endpoint carries a unique, unguessable token, the sending store is verified against your connected store, and signatures are verified via HMAC-SHA256 where a signing secret is configured
  • No customer marketing: We never contact, market to, or share data about your Shopify customers with third parties
Shopify Privacy Webhooks

If you installed the Autone app, Shopify delivers its three mandatory privacy webhooks to us. We act on each within 30 days of receiving it; the two erasure webhooks are completed automatically on receipt.

  • customers/data_request: a customer of your store has asked for their data. We record the request, look up the orders attributed under that customer's hashed identifier, and send what we hold to you, the merchant, so you can pass it on to your customer
  • customers/redact: a customer of your store has asked to be erased. We replace the hashed customer identifier on their attributed orders with a redaction marker, blank the stored order payload, and record completion
  • shop/redact: sent by Shopify 48 hours after you uninstall the app. We delete the raw order records for your store, anonymise the attribution records (removing hashed customer identifiers, line items, order numbers and referring/landing URLs, leaving only totals for your aggregate reporting), clear the stored access token, and record completion

Records of these requests are kept for 180 days after completion as proof that they were handled, then deleted.

Billing and Creator Payments

Merchants who installed the Autone app from the Shopify App Store are billed for their subscription by Shopify through Shopify App Pricing. The charge appears on your Shopify invoice, and you upgrade, downgrade or cancel on the app's plan page in your Shopify admin or by uninstalling the app. We do not charge you for the subscription outside Shopify's billing.

Brands not on Shopify, or connected without the app, are billed for their subscription by Stripe. Card and bank details are entered on Stripe's hosted pages and never reach our servers. The store URL you give us is your public website address.

Creator payments are separate from the subscription and are not app charges. Every payment to a creator is approved by you first, at every plan and autonomy level. The approved amount is funded from a card you add under Settings → Billing → Creator payout funding (the card details are entered on Stripe's hosted page and never reach our servers) and is paid to the creator at face value through Stripe or PayPal. Merchants billed through Shopify pay no processing fee on creator payments; brands billed through Stripe pay a 4% processing fee on top of the approved amount.

Data When You Disconnect

You can stop sharing data at any time by uninstalling the Autone app from your Shopify admin, by deleting the order notification (webhook) in your Shopify settings, or by disconnecting your store in Autone. When you do:

  • We stop receiving new orders from your store immediately
  • Any access token we hold for your store is deleted, and your store's notification endpoint is deactivated and stops accepting data
  • If you uninstall the app, Shopify sends us shop/redact 48 hours later and we delete the raw order records and anonymise the attribution records as described above
  • On the app-free connection, order records we already hold are retained for your reporting history. They carry no customer name, email, phone or address — we remove those fields the moment an order reaches us and never store them (see “Personal data minimisation” above). Email us and we will delete the remaining order records too.
  • Aggregated, anonymized attribution data (revenue totals, order counts) may be retained for your autopilot reporting history
Exercising your data rights

Email support@autone.app to request access to, correction of, or erasure of your personal data, and we will action it within 30 days. Requests are handled by a person — we do not rely on an automated intake — so please say which store or creator account the request concerns.

Creators: if you have received outreach from a brand using Autone, you can ask us to erase what we hold about you — your email and phone numbers, any shipping address you gave a brand, the text of your messages, and your profile details. Email the address above from, or naming, the account concerned. Financial records of payments already made to you are kept where we are legally required to keep them; nothing in those records carries your address or contact details.

If you installed the Autone app, Shopify's privacy webhooks (customers/data_request, customers/redact and shop/redact) are delivered to us and handled as described above. If your store is connected without the app, Shopify does not deliver those webhooks to us, so please contact us directly at the address above.

6. Data Security

We implement industry-standard security measures to protect your data:

  • All OAuth tokens (email, Shopify) are encrypted using AES-256-GCM before storage
  • All data is transmitted over HTTPS/TLS
  • Database access is restricted via role-based access controls
  • We use Supabase (built on AWS) for database hosting with SOC 2 Type II compliance
  • Application hosting on Vercel with enterprise-grade security and SOC 2 compliance
  • Database backups are encrypted at rest
  • Staff access to personal data is limited and logged

7. Data Sharing

We do not sell, rent, or trade your personal data or your customers' personal data. We share data only with:

  • Infrastructure: Supabase (database and authentication), Vercel (application hosting), Fly.io (the automation engine that runs longer research and outreach tasks), Inngest (schedules and retries the engine's background jobs; it carries job identifiers and the data those jobs need)
  • Your connected mailbox: Google (Gmail) or Microsoft (Microsoft 365), whichever you connect. Outreach is sent through that provider's API from your own account under the permissions listed in section 2.
  • Payments: Shopify (subscription billing for merchants who installed the Autone app), Stripe (subscription billing for all other brands, and funding of the creator payments you approve), Stripe Global Payouts and PayPal (payouts to creators)
  • Email: Resend (transactional and notification email we send you), Postmark (receives replies sent to our outreach.autone.app reply addresses so we can route them back to the right conversation)
  • AI processing: Anthropic and OpenAI
  • Research and creator data: Perplexity and Firecrawl (public web research about your brand), influencers.club (creator discovery: public creator profile and audience data), ScrapeCreators and RapidAPI providers (public creator profile and post data, used to detect and measure creators' posts)
  • When required by law: To comply with legal obligations or valid legal processes
  • With your consent: When you explicitly authorize sharing

All service providers are contractually bound to process data only as instructed and to maintain appropriate security measures. Data transferred internationally is protected by appropriate safeguards including standard contractual clauses where applicable.

8. Data Retention

We retain data only as long as necessary to provide our services:

  • Account data: Retained while your account is active, deleted within 30 days of account closure
  • Autopilot and outreach data: Retained for the duration of your subscription plus 30 days
  • Shopify order data: Raw order payloads are minimised at receipt (section 5) and purged 90 days after we receive them. Attribution records (order ID, totals, discount code, hashed customer identifier) are retained while your store is connected. If you uninstall the app they are anonymised on receipt of Shopify's shop/redact webhook; on the app-free connection they are kept, without any customer personal data, for your reporting history until you ask us to delete them
  • Shopify privacy-request records: Deleted 180 days after the request is completed
  • Attribution analytics: Aggregated, non-personally-identifiable analytics may be retained for historical reporting
  • OAuth and access tokens: Deleted immediately upon disconnection of the respective service or uninstall of the Shopify app

You can request deletion of your data at any time by contacting us at support@autone.app.

9. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data:

  • Access: Request a copy of the personal data we hold about you
  • Rectification: Request correction of inaccurate personal data
  • Erasure: Request deletion of your personal data
  • Portability: Request your data in a portable format
  • Objection: Object to processing of your personal data
  • Restriction: Request restriction of processing your personal data
  • Withdraw consent: Where processing is based on consent, withdraw at any time
  • Non-discrimination: Exercise your rights without receiving discriminatory treatment
For Shopify Merchants

You can disconnect your Shopify store at any time from Settings > Integrations, or by uninstalling the Autone app from your Shopify admin. Either one deletes the access token, so we can no longer reach the Shopify Admin API; on a webhook connection it stops us accepting further order notifications. Uninstalling the app also ends a subscription billed through Shopify and triggers Shopify's shop/redact webhook (section 5). You can also request complete deletion of all store data by contacting us.

For Creators

If you received an email from a brand using Autone, or found your profile in our creator database, this section is for you. We did not collect your details from you directly, so here is exactly what we hold and how to change it.

What we hold, and where it came from. Publicly available information from your social profiles — your handle, display name, bio, profile picture, follower and engagement figures, sample posts, and any contact address you have published on your profile or in your bio link. It is gathered from the platforms' own public pages and from data providers who do the same, and it is used to suggest you to brands whose products look like a genuine fit. If you go on to work with a brand through Autone we also hold the emails exchanged, the shipping address you give us, the content you submit, and the payout details you enter.

Why we are allowed to. Our legal basis is legitimate interest (GDPR Art. 6(1)(f)): connecting creators with brands who want to pay them. You can object to that at any time, and we will act on it — see below.

Who sees it. Only the brand considering working with you, and the processors listed in section 7. We do not sell creator data.

How to stop it. Reply “unsubscribe” to any outreach email and you are suppressed immediately — that brand stops, and we stop suggesting you to others. Or email support@autone.app from any address on your profile and ask us to remove you. You can also ask for a copy of everything we hold about you, ask us to correct it, or ask us to delete it outright. We answer within 30 days and never require you to create an account to exercise any of this.

For Shopify Store Customers

If you are a customer of a Shopify store that uses our platform, your data rights requests should be directed to the store owner (the merchant). We will cooperate with merchants to fulfill all valid data requests. You may also contact us directly at support@autone.app.

10. Consent and Cookies

We respect customer consent decisions as communicated through Shopify's Customer Privacy API and merchant cookie consent configurations. Our platform does not place tracking cookies on merchant storefronts. We do not engage in cross-site tracking, behavioral advertising, or selling of personal data.

11. Third-Party Services

Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We only use Google user data for the purposes described in this policy and do not use it for serving advertisements.

Our Shopify store integration follows Shopify's privacy requirements for apps, including protected customer data access policies and mandatory GDPR compliance webhooks.

12. Legal Basis for Processing (GDPR)

For users in the European Economic Area (EEA), United Kingdom, and Switzerland, we process personal data under the following legal bases:

  • Contract performance (Art. 6(1)(b)): Processing necessary to provide our services under your subscription agreement
  • Legitimate interests (Art. 6(1)(f)): Platform improvement, security, and fraud prevention
  • Consent (Art. 6(1)(a)): Where you have given explicit consent for specific processing activities
  • Legal obligation (Art. 6(1)(c)): Where processing is required by applicable law

If you wish to lodge a complaint regarding our data processing, you may contact your local data protection authority.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy on this page, updating the “Last updated” date, and where required, notifying you by email.

14. Contact Us

If you have questions about this Privacy Policy or wish to exercise your data rights, contact us at:

Email: support@autone.app
Website: autone.app