18 January 202604:41:40 PM
18 January 202604:41:40 PM
18 January 202604:41:40 PM

Privacy Policy

Privacy Policy

11 January 2026

With 4 million books published every year globally, finding the right book can often feel like searching for a needle in a haystack. Most book recommendation systems are popularity-driven.

Information We Collect

From Merchants

When you install Substanz, we collect:

  • Your store's product catalog, including product images, titles, descriptions, prices, and variants

  • Store configuration and settings related to our app

  • Your contact information for support and service delivery

From Your Customers

When customers use the search functionality on your store, we collect:

  • Search queries and search terms

  • Product interaction data, including clicks, add-to-cart events, and purchases

  • Anonymous usage analytics to improve search accuracy

Automatically Collected Information

We automatically collect certain technical information to operate our service, including:

  • Device and browser information

  • IP addresses

  • Usage patterns and interaction data

How We Use Your Information

We use collected information to:

  • Provide AI-powered visual search functionality for your fashion products

  • Process and index your product catalog to enable accurate search results

  • Analyze search behavior to improve search accuracy and relevance

  • Generate analytics and insights about search performance

  • Improve our machine learning models and algorithms

  • Maintain and optimize service performance

  • Provide customer support and communicate about our services

We may use anonymized and aggregated data to improve our services and machine learning models. This data cannot be used to identify individual merchants or customers.

Data Processing and Storage

We process product images using machine learning models to enable visual search functionality. All data processing and storage occurs on industry-standard cloud infrastructure located in the European Union.

When customers access the search functionality:

  • Search queries are transmitted from the customer's location to our EU-based servers for processing

  • Relevant product data is then transmitted from our EU servers back to the customer to display search results

This means data may be transferred internationally as part of normal service operation, regardless of where the merchant or customer is located.

Data Retention and Deletion

  • Merchant Data: We retain your product catalog data for as long as you have our app installed

  • Search Data: Customer search queries and analytics are retained to improve our service

  • Deletion: Upon uninstallation or deletion request, all merchant data is permanently deleted within 48 hours

Data Sharing and Disclosure

We do not sell, rent, or share your data with third parties, except in the following circumstances:

  • Service Providers: We use third-party cloud infrastructure providers to host and store data. All providers are located in the EU and comply with GDPR requirements.

  • Legal Requirements: We may disclose information if required by law, court order, government request, or to protect our legal rights.

  • Business Transfers: In the event of a merger, acquisition, or sale of assets, your data may be transferred to the acquiring entity.

We may share anonymized, aggregated information that cannot identify individual merchants or customers to analyze usage trends and improve our services.

Data Security

We implement industry-standard security measures to protect your data:

  • All data is encrypted in transit using TLS/SSL

  • Data at rest is encrypted using industry-standard method

  • Access to data is restricted to authorized personnel only

  • Regular security monitoring and audits

  • Infrastructure hosted in secure EU data centers

Your Rights

You have the following rights regarding your data:

  • Access: Request access to the personal data we hold about you

  • Correction: Request correction of inaccurate or incomplete data

  • Deletion: Request deletion of your data (we will comply within 48 hours)

  • Data Portability: Request a copy of your data in a machine-readable format

  • Objection: Object to certain types of data processing

  • Withdraw Consent: Withdraw consent for data processing where consent was provided

To exercise any of these rights, contact us at support@substanz.io.

GDPR Compliance

For users in the European Economic Area (EEA), we comply with the General Data Protection Regulation (GDPR). Our legal basis for processing your data includes:

  • Contract Performance: Processing necessary to provide our services

  • Legitimate Interests: Improving our services and search algorithms

  • Consent: Where you have explicitly provided consent

You have the right to lodge a complaint with a supervisory authority if you believe we have not complied with applicable data protection laws.

CCPA Compliance

For California residents, under the California Consumer Privacy Act (CCPA), you have the right to:

  • Know what personal information we collect and how it's used

  • Request deletion of your personal information

  • Opt-out of the sale of personal information (note: we do not sell personal information)

  • Non-discrimination for exercising your privacy rights

To exercise these rights, contact us at support@substanz.io with "California Privacy Rights" in the subject line.

Cookies and Tracking Technologies

We use cookies and similar technologies to:

  • Maintain session information and user preferences

  • Analyze usage patterns and improve service performance

  • Provide personalized search experiences

You can control cookie preferences through your browser settings. Please note that disabling cookies may affect the functionality of our service.

Children's Privacy

Our services are not directed to individuals under the age of 16. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child under 16, we will delete it promptly. Parents and guardians should monitor their children's internet usage and contact us if they believe a child has provided personal information without consent.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or for legal, operational, or regulatory reasons. When we make material changes, we will update the "Last Updated" date at the top of this policy and notify you through the app or via email. Continued use of our services after changes constitutes acceptance of the updated policy.

Shopify Integration

As a Shopify app, we:

  • Access only the data necessary to provide search functionality

  • Comply with Shopify's API Terms of Service and data protection requirements

  • Integrate with Shopify's authentication and billing systems

  • Follow Shopify's app development best practices

When you uninstall our app from your Shopify store, we automatically begin the deletion process and remove all your data within 48 hours.

Contact Us

If you have questions about this Privacy Policy or our data practices, please contact us:

Email: support@substanz.io

Website: https://substanz.io

For privacy-related requests (access, deletion, correction, or data portability), please email support@substanz.io with "Privacy Request" in the subject line. We will respond to your request within 30 days.

Information We Collect

From Merchants

When you install Substanz, we collect:

  • Your store's product catalog, including product images, titles, descriptions, prices, and variants

  • Store configuration and settings related to our app

  • Your contact information for support and service delivery

From Your Customers

When customers use the search functionality on your store, we collect:

  • Search queries and search terms

  • Product interaction data, including clicks, add-to-cart events, and purchases

  • Anonymous usage analytics to improve search accuracy

Automatically Collected Information

We automatically collect certain technical information to operate our service, including:

  • Device and browser information

  • IP addresses

  • Usage patterns and interaction data

How We Use Your Information

We use collected information to:

  • Provide AI-powered visual search functionality for your fashion products

  • Process and index your product catalog to enable accurate search results

  • Analyze search behavior to improve search accuracy and relevance

  • Generate analytics and insights about search performance

  • Improve our machine learning models and algorithms

  • Maintain and optimize service performance

  • Provide customer support and communicate about our services

We may use anonymized and aggregated data to improve our services and machine learning models. This data cannot be used to identify individual merchants or customers.

Data Processing and Storage

We process product images using machine learning models to enable visual search functionality. All data processing and storage occurs on industry-standard cloud infrastructure located in the European Union.

When customers access the search functionality:

  • Search queries are transmitted from the customer's location to our EU-based servers for processing

  • Relevant product data is then transmitted from our EU servers back to the customer to display search results

This means data may be transferred internationally as part of normal service operation, regardless of where the merchant or customer is located.

Data Retention and Deletion

  • Merchant Data: We retain your product catalog data for as long as you have our app installed

  • Search Data: Customer search queries and analytics are retained to improve our service

  • Deletion: Upon uninstallation or deletion request, all merchant data is permanently deleted within 48 hours

Data Sharing and Disclosure

We do not sell, rent, or share your data with third parties, except in the following circumstances:

  • Service Providers: We use third-party cloud infrastructure providers to host and store data. All providers are located in the EU and comply with GDPR requirements.

  • Legal Requirements: We may disclose information if required by law, court order, government request, or to protect our legal rights.

  • Business Transfers: In the event of a merger, acquisition, or sale of assets, your data may be transferred to the acquiring entity.

We may share anonymized, aggregated information that cannot identify individual merchants or customers to analyze usage trends and improve our services.

Data Security

We implement industry-standard security measures to protect your data:

  • All data is encrypted in transit using TLS/SSL

  • Data at rest is encrypted using industry-standard method

  • Access to data is restricted to authorized personnel only

  • Regular security monitoring and audits

  • Infrastructure hosted in secure EU data centers

Your Rights

You have the following rights regarding your data:

  • Access: Request access to the personal data we hold about you

  • Correction: Request correction of inaccurate or incomplete data

  • Deletion: Request deletion of your data (we will comply within 48 hours)

  • Data Portability: Request a copy of your data in a machine-readable format

  • Objection: Object to certain types of data processing

  • Withdraw Consent: Withdraw consent for data processing where consent was provided

To exercise any of these rights, contact us at support@substanz.io.

GDPR Compliance

For users in the European Economic Area (EEA), we comply with the General Data Protection Regulation (GDPR). Our legal basis for processing your data includes:

  • Contract Performance: Processing necessary to provide our services

  • Legitimate Interests: Improving our services and search algorithms

  • Consent: Where you have explicitly provided consent

You have the right to lodge a complaint with a supervisory authority if you believe we have not complied with applicable data protection laws.

CCPA Compliance

For California residents, under the California Consumer Privacy Act (CCPA), you have the right to:

  • Know what personal information we collect and how it's used

  • Request deletion of your personal information

  • Opt-out of the sale of personal information (note: we do not sell personal information)

  • Non-discrimination for exercising your privacy rights

To exercise these rights, contact us at support@substanz.io with "California Privacy Rights" in the subject line.

Cookies and Tracking Technologies

We use cookies and similar technologies to:

  • Maintain session information and user preferences

  • Analyze usage patterns and improve service performance

  • Provide personalized search experiences

You can control cookie preferences through your browser settings. Please note that disabling cookies may affect the functionality of our service.

Children's Privacy

Our services are not directed to individuals under the age of 16. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child under 16, we will delete it promptly. Parents and guardians should monitor their children's internet usage and contact us if they believe a child has provided personal information without consent.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or for legal, operational, or regulatory reasons. When we make material changes, we will update the "Last Updated" date at the top of this policy and notify you through the app or via email. Continued use of our services after changes constitutes acceptance of the updated policy.

Shopify Integration

As a Shopify app, we:

  • Access only the data necessary to provide search functionality

  • Comply with Shopify's API Terms of Service and data protection requirements

  • Integrate with Shopify's authentication and billing systems

  • Follow Shopify's app development best practices

When you uninstall our app from your Shopify store, we automatically begin the deletion process and remove all your data within 48 hours.

Contact Us

If you have questions about this Privacy Policy or our data practices, please contact us:

Email: support@substanz.io

Website: https://substanz.io

For privacy-related requests (access, deletion, correction, or data portability), please email support@substanz.io with "Privacy Request" in the subject line. We will respond to your request within 30 days.