Last updated: September 23, 2026 · Version 1.3.0
Privacy Policy
Summary
This policy explains what personal data Dinero collects, how we use it, who we share it with, and what rights you have under the EU General Data Protection Regulation (GDPR). It applies to merchants who use Dinero. Where we process the personal data of your customers, we do so as a processor under our Data Processing Agreement.
1. Who we are
Dinero is operated by Sienna Kjellman, sole trader (enskild näringsidkare) based in Sweden. We are the data controller for the personal data described in this policy. For privacy questions or to exercise your rights, email hello@dinero.agency.
2. What we collect
| Category | Source | Legal basis |
|---|---|---|
| Account data: email, hashed password, Shopify store domain | You, at signup | Performance of contract |
| OAuth tokens for Meta and Shopify (encrypted at rest) | Connected services, with your authorization | Performance of contract |
| Brand profile: voice, products, USP, target audience, scraped homepage and about-page text | You + automated scraping of your public website | Performance of contract |
| Creative assets: image and video URLs, thumbnails from your Google Drive folder | Google Drive (with your authorization) | Performance of contract |
| Performance metrics: ROAS, spend, purchases, revenue | Meta API | Performance of contract + legitimate interest in product improvement (aggregated only) |
| Audit logs and IP address at login | Automatic | Legitimate interest in security |
| Consent records: which Terms, Privacy Policy, DPA and content-rights confirmations you accepted, with version, time, IP address and browser | Automatic, when you accept | Legitimate interest in being able to demonstrate acceptance |
| Support communications | You, when you contact us | Legitimate interest in providing support |
3. How we use your data
- To run, optimize, and report on your advertising campaigns
- To authenticate you and secure your account
- To send transactional emails (account verification, password reset, billing receipts)
- To provide support when you contact us
- To improve Dinero in aggregated, anonymized form
We do not sell your data, and we do not use it to train AI models. Where we use third-party AI services (OpenAI) to generate ad copy, we only send the minimum information needed to produce the copy, and these providers do not use API inputs to train their models by default.
4. Sub-processors
We use the following third-party services to operate Dinero. They process personal data on our behalf under appropriate safeguards (EU adequacy, EU-US Data Privacy Framework, or Standard Contractual Clauses).
| Provider | Purpose | Region |
|---|---|---|
| Render | Hosting | EU (Frankfurt) |
| Upstash | Redis database | EU |
| Resend | Transactional email | EU (Ireland) |
| Shopify | E-commerce platform and billing | Canada / Global (Adequacy decision) |
| Meta (Facebook/Instagram) | Advertising platform | US / Global (DPF) |
| Google Drive | Creative asset storage | Global (DPF) |
| OpenAI | Ad copy generation and image-based product matching (LLM) | US (DPF) |
| Jina AI | Image embeddings for visual product matching | EU (Germany) |
| Plausible | Cookie-less analytics on public landing pages | EU (Germany) |
We will notify you at least thirty (30) days before adding a new sub-processor. You can object to a new sub-processor by contacting us; if we cannot resolve your objection, you may terminate the affected subscription.
5. Where data is stored
Primary storage (database, hosting, email) is in the EU. Some sub-processors (Meta, OpenAI, Google) may transfer data outside the EU. Such transfers rely on the EU-US Data Privacy Framework or Standard Contractual Clauses.
6. How long we keep data
- While your subscription is active: as long as needed to operate the Service
- Audit logs and IP addresses at login: retained while your account is active
- Consent records: retained while your account is active and for as long as needed to demonstrate acceptance; never edited or overwritten
- When you uninstall the app: access tokens (Shopify, Meta, TikTok) are deleted immediately
- All other identifiable account data is kept for thirty (30) days after uninstall — so if you reinstall within that window, your settings and history are restored — and is then deleted automatically and permanently
- Aggregated, anonymized performance data may be retained indefinitely for product improvement
- You can request deletion of your data at any time by emailing us
7. Your rights
Under GDPR you have the right to:
- Access your data — export from your dashboard or email us
- Correct inaccurate data — directly in your dashboard
- Delete your data — uninstall Dinero from Shopify, which triggers deletion within 30 days
- Portability — email us and we'll provide a copy of your data in a structured, commonly used format
- Object to processing based on legitimate interest
- Withdraw consent where consent is the legal basis
- Lodge a complaint with your supervisory authority. In Sweden this is IMY (Integritetsskyddsmyndigheten).
To exercise any right, email hello@dinero.agency. We respond within thirty (30) days.
8. Cookies
Dinero uses cookies only where strictly necessary for the Service to function:
- Session cookie — keeps you logged in to your dashboard.
- CSRF token cookie — protects against cross-site request forgery on state-changing requests.
- Language cookie (
lang) — set only when you actively choose a dashboard language; remembers your preference.
These are essential and are exempt from consent requirements under the ePrivacy Directive. We do not use marketing cookies, advertising cookies, or third-party tracking cookies on the dashboard.
On our public landing pages (dinero.agency) we use Plausible Analytics, a cookie-less, EU-hosted analytics tool that does not set cookies, does not track individuals, and does not collect personal data.
9. Security
We protect your data with: encryption in transit (TLS, provided by our hosting platform), encryption at rest for OAuth tokens (AES-128 via Fernet), hashed passwords (PBKDF2 with 200,000 iterations and per-user salt), CSRF protection on state-changing endpoints, rate limiting on authentication endpoints, secure session cookies (Secure, HttpOnly, SameSite=Lax), and HTTP Strict Transport Security (HSTS). Where we suffer a personal data breach affecting your data we will notify the supervisory authority and you (where required) within 72 hours of becoming aware of it. Under our Data Processing Agreement we will notify Merchants of breaches affecting their data within 24 hours.
10. Children
Dinero is a B2B service and is not directed at children under 16. We do not knowingly collect data from children.
11. Changes to this policy
If we make material changes we will notify you by email at least thirty (30) days before they take effect. The current version and effective date are shown at the top of this page.
12. Contact
For privacy questions or to exercise your rights, email hello@dinero.agency.