Research previewTechnologyConnectorsResults
TITAN-REC 3.0
TITAN-HORIZON 2.5
TITAN-CORE 2.4
TITAN-TREND 1.7
TITAN-LINK 2.2
TITAN-FIRSTSOON
TITAN-ARCSOON
FR/EN
Back to home
Legal

Privacy Policy

Last updated: July 9, 2026

1.Data Controller

Titane Intelligence provides AI services for ecommerce merchants: product recommendations, segmentation, forecasting, marketing analysis and activation through merchant-authorized connectors. This policy explains what data we collect through our website, Shopify app and connectors, why, how we protect it, and what your rights are.

For the website, prospecting and direct contacts, the data controller is:

SAS TITANE INTELLIGENCE

SIREN: 105 840 060

Address: 51 rue Villedieu, 33000 BORDEAUX, France

Privacy contact: privacy@titane-intelligence.com

2.Scope

This policy applies to:

Merchants who install Titane Intelligence or connect a Titane connector, including Shopify, PrestaShop, Magento, WooCommerce, Klaviyo, Mailchimp, Brevo, Google Analytics 4, Google Ads, Google Merchant Center, Meta (Business Portfolio, Ads, Catalog and advertising measurement tools), TikTok, Gorgias and Zendesk.

• The end-customers of those merchants when their data is processed on the merchant's instructions.

Visitors to titane-intelligence.com.

Each connector is enabled only by the merchant or an authorized person. Titane requests only the permissions needed for the selected connector.

3.Data collected via the Shopify app

When you install Titane Intelligence on your store, we collect data via the Shopify Admin API and Shopify webhooks, according to the scopes you authorize:

Product catalog (titles, descriptions, prices, variants, images, stock levels) — scopes `read_products`, `read_inventory`.

Recent orders (order id, dates, status, totals, order line items, product id, variant id, quantity, Shopify customer id) — scope `read_orders`.

Customer identity for recommendations: only the Shopify customer id and email — scope `read_customers`.

Store installation information needed to operate the app and associate the store with the right merchant account.

Purpose: generate personalized product recommendations displayed on your store. The customer email is used only to deduplicate customer records and to match a logged-in shopper to their recommendation profile.

4.Data collected via the Google connector

When a merchant connects Google accounts or properties to Titane Intelligence through OAuth and Google APIs, Titane processes only the data, accounts and assets explicitly authorized by the merchant.

Data read from Google:

Connection and authorization information: connected Google accounts or properties, granted permissions and connection status.

Google Analytics 4: aggregated ecommerce and marketing reports needed for analysis.

Google Ads: aggregated advertising reports, campaign status and performance data needed for measurement.

Google Merchant Center: catalog data, product availability, product statuses and diagnostics needed for ecommerce activation.

Audiences and conversions: metadata and statuses for merchant-authorized audiences or conversions.

Data sent to Google:

Authorized audiences: contact identifiers provided by the merchant, protected by a secure cryptographic mechanism required by Google before transmission when authorized by the merchant.

Authorized conversions: merchant-authorized ecommerce conversion events needed for advertising measurement.

Merchant Center: catalog data and non-personal product attributes needed for authorized ecommerce activations.

Authorization context: information needed to apply the Google accounts or properties selected by the merchant.

Titane does not read Gmail, Google Drive, Google Calendar, personal Google profiles, or the individual identity of people who viewed or clicked an ad. GA4 data mentioned here comes from properties connected by the merchant; it does not mean that titane-intelligence.com sets GA4 cookies.

Google APIs Limited Use: Titane Intelligence's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including Limited Use requirements. Titane uses Google data only to provide or improve visible features requested by the merchant: connector installation, reporting, measurement, authorized audience synchronization, Merchant Center activations and security. Titane does not sell Google data or transfer it to data brokers, surveillance platforms or unauthorized third parties.

No training of generalized AI models: Titane does not use or transfer information received from Google APIs to develop, train, retrain or improve generalized or foundation artificial-intelligence or machine-learning models. This data is used only for the merchant-facing features the merchant requests, for the merchant's own accounts and campaigns. Titane does not use Google data for its own personalized advertising, and no humans read this data except with the merchant's explicit consent, for security purposes, or to comply with applicable law.

5.Data collected via the Meta connector

When a merchant connects their Meta Business Portfolio to Titane Intelligence through Facebook Login for Business, Titane processes only the data and assets explicitly authorized by the merchant.

Data read from Meta:

Connection and authorization information: connected Meta Business account, granted permissions and connection status.

Authorized advertising assets: ad accounts, catalogs, pixels or datasets selected by the merchant.

Aggregated advertising data: performance reports, statuses and campaign settings needed for analysis.

Catalog data: products, categories, prices, availability, URLs and product images.

Audience data: metadata and statuses for audiences created or synchronized for the merchant.

Meta advertising measurement data: linking status, technical delivery metadata and diagnostics needed for the integration.

Titane does not read personal Facebook or Instagram profiles, messages, friends, private posts, or the individual identity of people who viewed or clicked an ad.

Data sent to Meta:

Authorized audiences: contact identifiers provided by the merchant, protected by a secure cryptographic mechanism required by Meta before transmission when authorized by the merchant.

Server-side advertising events: merchant-authorized events needed for advertising measurement or optimization.

Catalogs: catalog data and non-personal product attributes used for authorized catalog campaigns.

Authorization context: information needed to apply the Meta assets selected by the merchant.

Titane does not send payment card data, passwords, private messages, intentional sensitive data, or clear-text emails or phone numbers to Meta for audiences. Protected identifiers sent for audiences remain subject to applicable personal data obligations where required by law.

6.What we do NOT collect

Through Titane connectors, we do not collect:

• Payment card data.

• Passwords for merchants, end-customers or connected accounts.

• Personal Facebook, Instagram or Google profiles.

• Private messages, friends, private posts, Gmail, Drive or Calendar files.

• The individual identity of people who viewed or clicked a Meta or Google ad.

• Clear-text emails or phone numbers sent to advertising platforms for audience matching.

• Intentional sensitive data, unless separately documented and contracted by the merchant.

Through the Shopify app, we do not collect customer names, IP addresses, phone numbers, postal addresses, store staff personal data, or payment data handled by Shopify Payments.

7.Data collected via the website

7.1. Contact form

Data collected: Name, business email, company name, role and message content. The content is sent by email to our contact address. No data is stored in a database, CRM or third-party tool by the form itself.

7.2. Interactive demos (ephemeral)

Inputs provided in the public demos are processed in real time and immediately deleted from our active memory. They are never stored or used to train our models.

8.Purposes

Each category of data is processed for a declared purpose.

Meta data is used to install and maintain the merchant-authorized integration, read advertising performance, connect Meta spend to the merchant's ecommerce analytics, create/synchronize/remove authorized audiences, maintain catalog activations, send authorized server-side advertising events, audit synchronizations, prevent abuse, handle deletion requests and ensure security.

Google data is used to install and maintain the merchant-authorized integration, read GA4 / Ads / Merchant Center performance, connect Google spend and conversions to the merchant's ecommerce analytics, create or synchronize authorized audiences, maintain non-personal Merchant Center product attributes, send authorized conversions and ensure audit, security and troubleshooting.

PurposeDescriptionLegal basis (GDPR)
Product recommendationsCatalog, stock availability, recent order line items, customer id, customer email when needed.Performance of the contract / Legitimate interest (Art. 6.1.b/f)
CRM and email connectorsSync scores, segments and recommendation blocks into Klaviyo or similar authorized connectors.Performance of the contract / Merchant instruction
Google connectorMerchant-authorized Google connection, aggregated reports, audiences, conversions and non-personal product attributes.Performance of the contract / Merchant instruction
Meta connectorMerchant-authorized Meta connection, aggregated reports, audiences, server-side advertising events and catalog activations.Performance of the contract / Merchant instruction
Stock-aware filteringAvoid recommending out-of-stock products.Legitimate interest (Art. 6.1.f)
Support & monitoringAggregated logs, security, audit and troubleshooting, without clear-text email, phone, token or sensitive data.Legitimate interest (Art. 6.1.f)
Website requestsAnswer the contact form, schedule calls.Pre-contractual measures (Art. 6.1.b)

9.Role and legal basis for connectors

For processing related to Shopify, Klaviyo, Google and Meta connectors, the merchant remains the controller for its customer data, advertising accounts, marketing tools and activation decisions. Titane Intelligence acts as the merchant's processor and processes data only on the merchant's instructions.

Before any real synchronization to Meta, Google or a third-party marketing tool, the merchant must confirm its applicable legal basis, for example consent or legitimate interest depending on its use case, have a data processing agreement with Titane, inform its own customers in its privacy policy, and accept the applicable advertising, analytics, catalog and business tools terms of the relevant platform.

For the website, contact forms, prospecting and direct exchanges with Titane, Titane acts as controller.

10.Data retention

Active merchant accounts: connector data, product, stock, recent orders and customer email when needed are retained for the duration of your subscription.

After uninstall or merchant account deletion: a 30-day recovery window may apply where contractually provided. Beyond that, merchant-account data is deleted from active systems under our operational retention policy.

Shopify, Google, Klaviyo and Meta tokens: tokens are encrypted and retained only while the integration is active. They are revoked or deleted on disconnect or account deletion.

Temporary synchronization and advertising measurement logs: retained only for execution, deduplication, audit, security and troubleshooting, then deleted under Titane's operational retention policy and no later than the contractual deletion window.

Shopify compliance requests: deletion of customer email, associated recommendation records or store data depending on the applicable request type, within 30 days.

After Meta or Google disconnect: Titane deletes merchant-account data, removes or stops synchronizing relevant audiences where technically possible, and keeps only necessary security logs with no clear-text email, phone or token.

Website: form emails purged after handling; demo inputs deleted at session end.

11.Where your data lives

Titane primary infrastructure: Amazon Web Services, region `eu-west-3` (Paris, France).

Encryption at rest: customer-bearing data is stored in encrypted systems. Access tokens are encrypted with a key adapted to the merchant account or processing context.

Encryption in transit: TLS 1.2+ for all API, OAuth and webhook traffic.

Google and Meta: when the merchant authorizes data to be sent to Google or Meta, those platforms process the data according to their own infrastructure, terms and applicable international transfer mechanisms.

12.Subprocessors and platforms

We rely in particular on the following providers and platforms:

Amazon Web Services (AWS) — compute, storage, ML training on aggregated merchant data (excluding information received from Google APIs) — EU (eu-west-3).

Vercel — application and website hosting.

Shopify — source data and webhooks from your store, per Shopify's policy.

Klaviyo — CRM/email marketing when the merchant enables the connector.

Google — Google Analytics 4, Google Ads, Google Merchant Center and Google APIs when the merchant enables the connector.

Meta — Meta Business Portfolio, Ads, Catalog and advertising measurement tools when the merchant enables the connector.

Postmark (optional) — transactional support and alert emails.

A data processing agreement is put in place with Titane subprocessors where required. Data sent by the merchant to Google or Meta through connectors is also processed by Google or Meta under their own terms, policies and compliance mechanisms.

13.Platform webhooks and requests

Per Shopify requirements, we process compliance requests related to customer and store data access or deletion within 30 days.

Each technical Shopify request is protected by a secure cryptographic mechanism compliant with platform requirements. Deletion requests related to Google, Meta or Klaviyo connectors are handled through connector disconnection, the relevant platform management tools, or a merchant request to privacy@titane-intelligence.com.

14.Your rights and deletion

Under GDPR and similar laws, data subjects have rights to access, rectify, delete, restrict processing, portability and object.

Merchants: write to privacy@titane-intelligence.com to exercise these rights or request deletion of a merchant account or connector. Response within 30 days.

End-customers: exercise your rights with the merchant, who remains the controller. Titane assists the merchant in access, deletion or objection requests.

Shopify: when Shopify sends us a compliance request related to customer or store data, we process it within 30 days.

Meta: the merchant may disconnect the Meta integration from Titane or from Meta Business Manager > Business Settings > Integrations > Connected apps. Meta data deletion URL: https://meta.titane-intelligence.com/data-deletion

Google: the merchant may disconnect the Google integration from Titane and revoke access in the relevant Google, Google Ads, GA4 or Merchant Center settings.

15.Data breach, children, changes

Data breach: when a breach affecting your data requires notification under GDPR, we notify the competent supervisory authority (CNIL in France) and affected individuals within 72 hours.

Children's data: Titane Intelligence is a B2B service. We do not knowingly collect data from children under 16.

Changes: material updates are communicated to merchants via in-app banner and email at least 30 days before they take effect where required.

16.Cookies

The website sets no non-essential cookies: no analytics, marketing or behavioral tracking cookies. Only cookies strictly necessary for technical operation (session, security) may be set; these do not require consent under GDPR.

References to GA4 in this policy concern Google Analytics 4 properties connected by merchants for their own use of the Titane service.

Questions about your data?

Contact us to exercise your rights or for any question relating to privacy.

privacy@titane-intelligence.com