Privacy Notice: Bobook Store Care
This notice explains how Bobook Limited handles personal data for Bobook Store Care and on this website (care.bobook.club).
1. Who is responsible
The controller is Bobook Limited, a company registered in Ireland (CRO 785764), Venture Hub, 136 Capel Street, Dublin 1, D01 T2C9, Ireland. Contact for any privacy question or request: info@bobook.club.
2. What data we collect
- Contact details: your name, email address, business name and the messages you send us (for example when you ask for a free store check or join the EU waitlist).
- Store details: your Shopify store URL and the country where your business is established (we need this to check eligibility during this test).
- Billing details: name, billing address, optional tax ID, subscription and payment status. Payments are processed by Stripe. We don't see or store your full card number.
- Store data accessed through collaborator access: the products, collections, online store pages and sales-channel settings you give us access to, and Google Merchant Center diagnostics if you add us as a user. We don't ask for access to your customers or orders.
- Service records: your kickoff answers, approvals, our monthly reports, our work log and our emails with you.
- Website technical data: when you visit this site, our hosting provider processes technical data such as your IP address and browser details to deliver the page and keep it secure.
3. Why we use it and our lawful bases
- To answer your enquiry and run the free store check: steps you ask us to take before entering a contract (GDPR Art. 6(1)(b)).
- To provide Bobook Store Care (access, monthly work, reports, support, cancellation and refunds): performance of our contract with you (Art. 6(1)(b)).
- To bill you (invoices, payments and the billing portal): performance of our contract with you (Art. 6(1)(b)).
- To keep billing, invoice and accounting records: compliance with a legal obligation (GDPR Article 6(1)(c)) under Irish company, tax and VAT law.
- To keep you on the EU waitlist and write when we open to EU stores: your consent (Art. 6(1)(a)), which you can withdraw at any time.
- To keep our website and service secure and to deal with legal claims: our legitimate interests (Art. 6(1)(f)).
We don't sell your data, we don't use it for advertising, and we don't make decisions about you by automated means that have legal or similarly significant effects.
4. Your customers' data
We don't need your customers' personal data to deliver the service. If any becomes visible to us through the access you grant, we use it only as needed to deliver the service on your instructions and for no other purpose. If an excerpt we analyse with OpenAI contains some, OpenAI processes it as our sub-processor (see section 5).
5. Who we share it with
We use these service providers (processors), who handle data on our behalf under contract:
- Stripe: checkout, payments, invoices and the billing portal. Stripe also acts as an independent controller for some purposes, such as fraud prevention and legal compliance (see stripe.com/privacy).
- Google Workspace: our email and documents.
- Cloudflare: hosting and delivery of this website.
- OpenAI (the OpenAI API): our AI provider. We use the OpenAI API, through our own API account, to help analyse issues with your store and to draft and check product and collection copy. To do that, we may send it excerpts of your store data, settings, code or diagnostics (for example product, collection and page content, sales-channel settings or Merchant Center diagnostics). We don't put passwords, API keys, tokens or other credentials or secrets into it: we remove them from excerpts before sending. We don't put payment data into it. If an excerpt contains personal data, OpenAI processes it as our processor (and, for any of your customers' data, as our sub-processor). If we add or change an AI provider, we update this list first.
What OpenAI's API data policy says (checked 6 October 2026; see openai.com/enterprise-privacy and OpenAI's data controls documentation): data sent to the OpenAI API is not used to train OpenAI's models unless the customer opts in to share it, and we don't opt in. Except for certain endpoints and features listed in OpenAI's documentation, OpenAI may keep API inputs and outputs for up to 30 days to provide the service and identify abuse, and then removes them, unless longer retention is required by law or is reasonably necessary to protect OpenAI's services or others from harm.
Your store data stays on Shopify and Google Merchant Center under your own accounts with them, apart from the excerpts described above. We may also share data with our professional advisers (for example our accountant) or with authorities where the law requires it.
6. International transfers
Some of our providers, including Stripe, Google and Cloudflare, may process data outside the European Economic Area, for example in the United States. Where they do, the transfer is protected by the EU–US Data Privacy Framework (where the provider is certified) or by the European Commission's Standard Contractual Clauses.
For the OpenAI API, OpenAI's Data Processing Addendum says that, for customers based in the EEA such as us, OpenAI Ireland Limited processes the data, and that any transfer of it outside the EEA is made under the European Commission's Standard Contractual Clauses or an EU adequacy decision.
7. How long we keep it
- Billing, invoice and payment records: We keep billing, invoice and payment records (including those processed through Stripe) for six years after the end of the financial year to which they relate, as required by Irish company, tax and VAT law. We may keep them for longer where this is needed for an ongoing tax enquiry or audit, or to establish, exercise or defend a legal claim.
- Service records and store data: while you're a customer, then deleted within 90 days after your plan ends, except what we must keep for billing or legal claims. Our collaborator and Merchant Center access is removed the same day your plan ends.
- Excerpts sent to the OpenAI API: kept by OpenAI only as described in section 5.
- Free store check enquiries that don't lead to a subscription: up to 12 months.
- EU waitlist: until we open to EU stores and contact you, or until you ask us to remove you.
8. Your rights
You have the right to access your data, correct it, have it deleted, restrict or object to its use, receive it in a portable format, and withdraw consent at any time (without affecting earlier use). To use any of these rights, email info@bobook.club. We reply within one month.
You can also complain to the Irish Data Protection Commission (www.dataprotection.ie), or to the data protection authority where you live. We'd appreciate the chance to sort it out first.
9. Cookies and analytics
This website does not set cookies and does not use analytics, advertising or tracking tools, external fonts or third-party scripts. Stripe's checkout page is run by Stripe and is covered by Stripe's own privacy and cookie policies.
10. Changes
We may update this notice. The "Last updated" date above shows the current version.
11. Contact
Bobook Limited, Venture Hub, 136 Capel Street, Dublin 1, D01 T2C9, Ireland · CRO 785764 · info@bobook.club