Legal

Privacy Policy

How we process personal data at MagicDots — clear, transparent and GDPR-compliant. This is the official Privacy Policy required for the Shopify App Store listing.

Last updated: July 8, 2026

1. Introduction — who we are

MagicDots is a CRM-type SaaS platform for merchants running online stores on WooCommerce and Shopify, in Romania and worldwide. Our platform provides modules for visibility in AI answers (AI Visibility), profitability analysis (Profit Intelligence), abandoned-cart recovery via email and WhatsApp (Revenue Recovery), customer analysis (Customer Intelligence), as well as marketing and review-request tools.

The platform is provided by PREDA BOGDAN-MARIAN PERSOANĂ FIZICĂ AUTORIZATĂ, an authorized natural person (persoană fizică autorizată) registered in Romania, with its registered office at Jud. Prahova, Municipiul Ploiești, Str. Cameliei nr. 9B, bl. 59, sc. 1, et. 3, ap. 14, tax ID (CUI) 51692615, referred to below as “MagicDots”, “we” or “the controller”, as applicable.

The public website is available at magicdots.io and the application at app.magicdots.io. This Privacy Policy explains what personal data we process, for what purposes, on what legal bases, with whom we share it, and what rights you have in relation to it, in accordance with Regulation (EU) 2016/679 (GDPR) and applicable Romanian data-protection law.

Please read this policy together with our Terms and Conditions and Cookie Policy. If you do not agree with the processing described here, please do not use the platform.

2. Our dual role: controller and processor

A key point to understand is that MagicDots processes two different categories of data, in two distinct legal capacities under the GDPR.

As a CONTROLLER, we determine the purposes and means of processing for the account data of the merchant who registers and uses the platform — for example name, email address, billing data and account usage data. For this data, we are directly accountable to you, the merchant, as the data subject.

As a PROCESSOR, we process, ON BEHALF of and for the merchant, the personal data of the store’s end customers (shoppers) — for example orders, abandoned carts, and shoppers’ email addresses and phone numbers. For this data, the CONTROLLER remains the merchant, not MagicDots. The merchant determines the purposes of processing, is responsible for the legal basis and for obtaining consent where required, and we act solely on the merchant’s documented instructions.

In short: for your merchant-account data, contact us. For a store’s shopper data, the controller is that merchant, and shoppers exercise their rights primarily through that merchant (see sections 10 and 14).

3. What data we collect

We collect and process different data depending on the capacity in which we act. We present it separately below.

(a) Merchant account data (MagicDots = controller): name or business name, email address, password (stored encrypted/hashed), billing and payment data (processed via Stripe), country/region and time zone, language preferences, and platform usage data (access logs, in-app actions, IP address, device/browser information for technical and security purposes).

(b) Store data and shopper data processed on behalf of the merchant (MagicDots = processor): data about the connected store (domain, products, orders, sales statistics) and personal data of the merchant’s end customers, namely orders and their contents, abandoned carts and the products in them, the shopper’s email address and, where applicable, phone number, interaction history relevant to recovery, reviews and marketing. This data originates from the merchant’s store (via connecting the WooCommerce/Shopify platform) and, where applicable, via the MagicDots pixel/plugin installed by the merchant (see section 13).

We do not request and do not wish to process special categories of data (sensitive data) through the platform. Please do not enter such data into free-text fields in the application.

4. Legal bases for processing

We process personal data only where we have a valid legal basis under Article 6 GDPR.

For merchant-account data (where we are the controller), we rely primarily on: performance of the contract between you and MagicDots (Art. 6(1)(b)), to provide and administer the service; our legitimate interests (Art. 6(1)(f)), for platform security, fraud prevention, service improvement and administrative communications; legal obligations (Art. 6(1)(c)), for example in tax and accounting matters; and consent (Art. 6(1)(a)) where required, for example for certain marketing communications.

For shopper data (where we are a processor), the legal basis is determined and ensured by the merchant, as the controller. We process it solely on the merchant’s instructions and under the data processing agreement (DPA) between us and the merchant (see section 14).

5. Purposes of processing

We process data for the following main purposes: creating and administering the merchant account and authentication; providing platform functionality (AI Visibility, Profit Intelligence, Revenue Recovery, Customer Intelligence, marketing and review requests); processing payments and subscriptions and issuing related documents; administrative and support communications; security, technical monitoring, and prevention of abuse and fraud; improving and developing the service; and complying with legal obligations.

As regards shopper data processed on behalf of the merchant, the purposes are those determined by the merchant — primarily abandoned-cart recovery, sending review requests, marketing actions and customer analysis — carried out according to the merchant’s configuration and instructions.

We do not use a merchant’s shopper data for our own marketing purposes and we do not sell it.

6. Sub-processors

To provide the service, we use trusted third-party providers that process data on our behalf or, where applicable, as sub-processors of the merchant. We select them so as to offer adequate data-protection guarantees.

Our current sub-processors: Supabase (database and authentication, hosted in the European Union / Frankfurt); Resend (email delivery); Vercel (application hosting); Stripe (payment and subscription processing); OpenAI and Anthropic (AI processing of text, for example content generation and analysis for the AI modules).

The up-to-date list of sub-processors is available at magicdots.io/subprocessors. We will notify merchants at least 30 days before adding or replacing a sub-processor. The merchant may object on reasoned grounds within that period; if the objection cannot reasonably be resolved, the merchant may terminate the affected part of the service.

Processing through artificial intelligence. The AI features (provided via OpenAI and Anthropic) process only text written by the merchant (for example message copy and its settings), information from the product catalog (titles, descriptions, prices) and aggregate, non-personal statistics (for example the number of carts or customers in a segment). We do NOT transmit shoppers' personal data — email address, phone number, order contents or customer names — to the AI providers. AI calls take place at the merchant's configuration time (once, with the result saved), not on every email sent and not through cookies in the visitor's browser. Under these providers' API terms, data sent through the API is not used to train their models.

7. International data transfers

We prioritize hosting and processing data within the European Union — for example, the database is hosted in the EU (Frankfurt) via Supabase. However, some of our sub-processors (for example AI-processing or payment providers) may process data outside the European Economic Area.

Where transfers occur to countries outside the EEA that do not benefit from a European Commission adequacy decision, we ensure appropriate safeguards under Chapter V of the GDPR, in particular Standard Contractual Clauses (SCC) and, where applicable, supplementary measures. A copy of the Standard Contractual Clauses can be requested at contact@magicdots.io.

8. Retention periods

We keep personal data only for as long as necessary for the purposes for which it was collected, plus the periods required by legal obligations (for example tax and accounting obligations).

As a matter of principle: merchant-account data is kept for as long as the account exists and for a reasonable period after its closure; billing documents are kept for the legal archiving periods; shopper data processed on behalf of the merchant is kept according to the merchant’s instructions and deleted or returned when the relationship ends, in accordance with the DPA.

Account data is retained for the duration of the contractual relationship and for 30 days after account closure; technical logs for up to 12 months; abandoned-cart data for up to 12 months; marketing data until consent is withdrawn or after 24 months of inactivity; and financial and accounting documents for 10 years, as required by Romanian law.

9. Data subject rights

In accordance with the GDPR, you have the following rights in relation to your personal data: the right of access; the right to rectification of inaccurate or incomplete data; the right to erasure (“the right to be forgotten”); the right to restriction of processing; the right to data portability; the right to object to processing; and the right to withdraw your consent at any time, where processing is based on consent (without affecting the lawfulness of processing carried out before withdrawal).

You also have the right to lodge a complaint with a supervisory authority. In Romania, this is the National Supervisory Authority for Personal Data Processing (ANSPDCP), without prejudice to your right to seek a remedy before the competent courts.

Important regarding roles: if you are a merchant, you exercise these rights towards us for your account data. If you are a shopper (a store’s end customer), the controller of your data is the relevant merchant, and requests concerning your rights should be directed primarily to that merchant (see sections 10 and 14).

US / California privacy rights: MagicDots does not sell or share personal information. For shoppers in the United States, the same controller/processor split applies — rights are exercised through the relevant merchant, as controller. US-resident merchants may exercise their access and deletion rights through the self-service features in the application and at contact@magicdots.io.

10. How to exercise your rights

Merchants: you can access, export and delete your account data directly in the application, via the self-service features available in the dashboard. In addition, you can contact us at any time to exercise your rights at contact@magicdots.io. We will respond to requests within the time limits set by the GDPR and may request additional information to verify your identity.

Shoppers (a store’s end customers): because the controller of your data is the merchant, you exercise your rights through that merchant. For Shopify stores, shoppers’ GDPR requests are also handled through Shopify’s compliance webhooks (customers/data_request, customers/redact, shop/redact), which we process as a processor to support the merchant in meeting its obligations.

11. Data security

We apply technical and organizational measures to protect data against unauthorized access, loss, alteration or disclosure. These include encryption of data both in transit and at rest, secure storage of credentials (hashed passwords), restricted access on a need-to-know basis, data isolation between merchant accounts (multi-tenant), and technical monitoring of the platform.

Payments are processed by Stripe, a certified payment processor; MagicDots does not store full card data.

Although we apply appropriate measures, no system can guarantee absolute security.

12. Cookies

The platform and website use cookies and similar technologies for operation, authentication, security and, where applicable, analytics. Full details about the types of cookies, their purposes and how you can manage your preferences are set out in our Cookie Policy.

In the context of abandoned-cart recovery and attribution, the MagicDots pixel/plugin installed on the merchant’s store may set its own cookies on the store’s domain — for example magicdots_cart_token (identifying the cart for recovery) and magicdots_utm (retaining the traffic source for attribution). These cookies are set in the context of the merchant’s store, which remains the controller of the shoppers’ data and is responsible for the applicable legal basis and consent (see section 13).

Please consult the Cookie Policy for detailed information and to manage consent for cookies that are not strictly necessary.

13. Pixel collection on merchant stores

MagicDots provides the merchant with a pixel/plugin that can be installed on the merchant’s store and that can capture, at checkout, the shopper’s email address and phone number, for the purpose of abandoned-cart recovery and other functionality configured by the merchant.

In this flow, MagicDots acts as a processor, and the merchant remains the CONTROLLER of its shoppers’ data. The merchant is solely responsible for the existence of a valid legal basis and for obtaining shoppers’ consent where the law requires it, as well as for properly informing shoppers through the merchant’s own privacy policy.

We recommend that merchants configure the consent mechanisms on their own store in accordance with the GDPR and with the legislation on electronic communications and cookies.

WhatsApp recovery is carried out through a pre-filled 'click-to-chat' (wa.me) link: MagicDots does not itself transmit WhatsApp messages and is not a user of the WhatsApp Business API or a Business Solution Provider (BSP). The merchant sends the message from their own WhatsApp account and is the sender of it.

14. MagicDots as a processor — processing terms (DPA)

When we process shopper data on behalf of the merchant, we do so as a processor. This section constitutes the Data Processing Agreement (DPA) within the meaning of Article 28(3) GDPR, is incorporated by reference into the MagicDots Terms of Service, and is deemed accepted by the merchant, as controller, upon account creation. It is the binding legal act governing the processing of Shopper Data, and is not conditional on the signing of a separate document.

Subject matter and duration: processing of shopper data for the duration of the provision of the service to the merchant. Nature and purpose: cart recovery, review requests, marketing and analysis, on the merchant’s instructions. Types of data: contact identifiers (email, phone), order and cart data, interaction history. Categories of data subjects: the merchant’s end customers (shoppers).

Our obligations as a processor include: processing solely on the merchant’s documented instructions; ensuring the confidentiality of persons authorized to process the data; applying appropriate security measures (Art. 32); engaging sub-processors only with the merchant’s authorization and subject to equivalent obligations; assisting the merchant in responding to data subject requests; assisting with security-breach notification and notifying the merchant without undue delay; deleting or returning the data at the end of the relationship; and making available the information necessary to demonstrate compliance, including allowing for audits. We will also immediately inform the merchant if, in MagicDots' opinion, an instruction from the merchant infringes the GDPR or another applicable data-protection provision. We will notify the merchant without undue delay and, in any event, within 48 hours of becoming aware of a breach of the security of Shopper Data, providing the information set out in Article 33(3) GDPR to the extent available.

US Privacy Addendum (CCPA/CPRA). To the extent it processes personal data of United States residents on behalf of the merchant, MagicDots acts as a 'service provider' and: (a) does not sell or share shopper data; (b) does not retain, use or disclose it for any purpose other than performing the contracted services or as permitted by law; (c) does not combine it with personal data from other sources except as permitted by the CCPA; (d) certifies that it understands and will comply with these restrictions; and (e) imposes equivalent obligations on its sub-processors.

15. Minors

The platform is intended exclusively for merchants and professional (B2B) users and is not directed at minors. We do not knowingly collect personal data of minors through merchant accounts.

As regards shopper data processed on behalf of the merchant, responsibility for complying with requirements applicable to minors lies with the merchant, as the controller. If you believe we have inadvertently processed a minor’s data, please contact us so we can take the necessary measures.

16. Changes to this policy

We may update this Privacy Policy from time to time to reflect legislative, technical or service changes. The version in force is the one published on the website, with the last-updated date indicated at the top of the document.

In the event of significant changes, we will make reasonable efforts to inform you through appropriate means (for example by email or an in-app notice). Continued use of the platform after the changes take effect constitutes acceptance of the updated version.

17. Contact and Data Protection Officer

For any question about this policy or the processing of your data, you can contact us at contact@magicdots.io or at Jud. Prahova, Municipiul Ploiești, Str. Cameliei nr. 9B, bl. 59, sc. 1, et. 3, ap. 14.

The data controller is PREDA BOGDAN-MARIAN PERSOANĂ FIZICĂ AUTORIZATĂ, tax ID (CUI) 51692615. We have not appointed a Data Protection Officer; data-protection matters are handled at contact@magicdots.io.

Language and interpretation: the Romanian-language version of this policy is the CANONICAL version and prevails in the event of any discrepancy with any translation, including the English version.

The Romanian-language version of this document is the official version and prevails in case of any discrepancy with translations.