Privacy Policy
Privacy Policy
11 January 2026
With 4 million books published every year globally, finding the right book can often feel like searching for a needle in a haystack. Most book recommendation systems are popularity-driven.
Information We Collect
From Merchants
When you install Substanz, we collect:
Your store's product catalog, including product images, titles, descriptions, prices, and variants
Store configuration and settings related to our app
Your contact information for support and service delivery
From Your Customers
When customers use the search functionality on your store, we collect:
Search queries and search terms
Product interaction data, including clicks, add-to-cart events, and purchases
Anonymous usage analytics to improve search accuracy
Automatically Collected Information
We automatically collect certain technical information to operate our service, including:
Device and browser information
IP addresses
Usage patterns and interaction data
How We Use Your Information
We use collected information to:
Provide AI-powered visual search functionality for your fashion products
Process and index your product catalog to enable accurate search results
Analyze search behavior to improve search accuracy and relevance
Generate analytics and insights about search performance
Improve our machine learning models and algorithms
Maintain and optimize service performance
Provide customer support and communicate about our services
We may use anonymized and aggregated data to improve our services and machine learning models. This data cannot be used to identify individual merchants or customers.
Data Processing and Storage
We process product images using machine learning models to enable visual search functionality. All data processing and storage occurs on industry-standard cloud infrastructure located in the European Union.
When customers access the search functionality:
Search queries are transmitted from the customer's location to our EU-based servers for processing
Relevant product data is then transmitted from our EU servers back to the customer to display search results
This means data may be transferred internationally as part of normal service operation, regardless of where the merchant or customer is located.
Data Retention and Deletion
Merchant Data: We retain your product catalog data for as long as you have our app installed
Search Data: Customer search queries and analytics are retained to improve our service
Deletion: Upon uninstallation or deletion request, all merchant data is permanently deleted within 48 hours
Data Sharing and Disclosure
We do not sell, rent, or share your data with third parties, except in the following circumstances:
Service Providers: We use third-party cloud infrastructure providers to host and store data. All providers are located in the EU and comply with GDPR requirements.
Legal Requirements: We may disclose information if required by law, court order, government request, or to protect our legal rights.
Business Transfers: In the event of a merger, acquisition, or sale of assets, your data may be transferred to the acquiring entity.
We may share anonymized, aggregated information that cannot identify individual merchants or customers to analyze usage trends and improve our services.
Data Security
We implement industry-standard security measures to protect your data:
All data is encrypted in transit using TLS/SSL
Data at rest is encrypted using industry-standard method
Access to data is restricted to authorized personnel only
Regular security monitoring and audits
Infrastructure hosted in secure EU data centers
Your Rights
You have the following rights regarding your data:
Access: Request access to the personal data we hold about you
Correction: Request correction of inaccurate or incomplete data
Deletion: Request deletion of your data (we will comply within 48 hours)
Data Portability: Request a copy of your data in a machine-readable format
Objection: Object to certain types of data processing
Withdraw Consent: Withdraw consent for data processing where consent was provided
To exercise any of these rights, contact us at support@substanz.io.
GDPR Compliance
For users in the European Economic Area (EEA), we comply with the General Data Protection Regulation (GDPR). Our legal basis for processing your data includes:
Contract Performance: Processing necessary to provide our services
Legitimate Interests: Improving our services and search algorithms
Consent: Where you have explicitly provided consent
You have the right to lodge a complaint with a supervisory authority if you believe we have not complied with applicable data protection laws.
CCPA Compliance
For California residents, under the California Consumer Privacy Act (CCPA), you have the right to:
Know what personal information we collect and how it's used
Request deletion of your personal information
Opt-out of the sale of personal information (note: we do not sell personal information)
Non-discrimination for exercising your privacy rights
To exercise these rights, contact us at support@substanz.io with "California Privacy Rights" in the subject line.
Cookies and Tracking Technologies
We use cookies and similar technologies to:
Maintain session information and user preferences
Analyze usage patterns and improve service performance
Provide personalized search experiences
You can control cookie preferences through your browser settings. Please note that disabling cookies may affect the functionality of our service.
Children's Privacy
Our services are not directed to individuals under the age of 16. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child under 16, we will delete it promptly. Parents and guardians should monitor their children's internet usage and contact us if they believe a child has provided personal information without consent.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or for legal, operational, or regulatory reasons. When we make material changes, we will update the "Last Updated" date at the top of this policy and notify you through the app or via email. Continued use of our services after changes constitutes acceptance of the updated policy.
Shopify Integration
As a Shopify app, we:
Access only the data necessary to provide search functionality
Comply with Shopify's API Terms of Service and data protection requirements
Integrate with Shopify's authentication and billing systems
Follow Shopify's app development best practices
When you uninstall our app from your Shopify store, we automatically begin the deletion process and remove all your data within 48 hours.
Contact Us
If you have questions about this Privacy Policy or our data practices, please contact us:
Email: support@substanz.io
Website: https://substanz.io
For privacy-related requests (access, deletion, correction, or data portability), please email support@substanz.io with "Privacy Request" in the subject line. We will respond to your request within 30 days.
Information We Collect
From Merchants
When you install Substanz, we collect:
Your store's product catalog, including product images, titles, descriptions, prices, and variants
Store configuration and settings related to our app
Your contact information for support and service delivery
From Your Customers
When customers use the search functionality on your store, we collect:
Search queries and search terms
Product interaction data, including clicks, add-to-cart events, and purchases
Anonymous usage analytics to improve search accuracy
Automatically Collected Information
We automatically collect certain technical information to operate our service, including:
Device and browser information
IP addresses
Usage patterns and interaction data
How We Use Your Information
We use collected information to:
Provide AI-powered visual search functionality for your fashion products
Process and index your product catalog to enable accurate search results
Analyze search behavior to improve search accuracy and relevance
Generate analytics and insights about search performance
Improve our machine learning models and algorithms
Maintain and optimize service performance
Provide customer support and communicate about our services
We may use anonymized and aggregated data to improve our services and machine learning models. This data cannot be used to identify individual merchants or customers.
Data Processing and Storage
We process product images using machine learning models to enable visual search functionality. All data processing and storage occurs on industry-standard cloud infrastructure located in the European Union.
When customers access the search functionality:
Search queries are transmitted from the customer's location to our EU-based servers for processing
Relevant product data is then transmitted from our EU servers back to the customer to display search results
This means data may be transferred internationally as part of normal service operation, regardless of where the merchant or customer is located.
Data Retention and Deletion
Merchant Data: We retain your product catalog data for as long as you have our app installed
Search Data: Customer search queries and analytics are retained to improve our service
Deletion: Upon uninstallation or deletion request, all merchant data is permanently deleted within 48 hours
Data Sharing and Disclosure
We do not sell, rent, or share your data with third parties, except in the following circumstances:
Service Providers: We use third-party cloud infrastructure providers to host and store data. All providers are located in the EU and comply with GDPR requirements.
Legal Requirements: We may disclose information if required by law, court order, government request, or to protect our legal rights.
Business Transfers: In the event of a merger, acquisition, or sale of assets, your data may be transferred to the acquiring entity.
We may share anonymized, aggregated information that cannot identify individual merchants or customers to analyze usage trends and improve our services.
Data Security
We implement industry-standard security measures to protect your data:
All data is encrypted in transit using TLS/SSL
Data at rest is encrypted using industry-standard method
Access to data is restricted to authorized personnel only
Regular security monitoring and audits
Infrastructure hosted in secure EU data centers
Your Rights
You have the following rights regarding your data:
Access: Request access to the personal data we hold about you
Correction: Request correction of inaccurate or incomplete data
Deletion: Request deletion of your data (we will comply within 48 hours)
Data Portability: Request a copy of your data in a machine-readable format
Objection: Object to certain types of data processing
Withdraw Consent: Withdraw consent for data processing where consent was provided
To exercise any of these rights, contact us at support@substanz.io.
GDPR Compliance
For users in the European Economic Area (EEA), we comply with the General Data Protection Regulation (GDPR). Our legal basis for processing your data includes:
Contract Performance: Processing necessary to provide our services
Legitimate Interests: Improving our services and search algorithms
Consent: Where you have explicitly provided consent
You have the right to lodge a complaint with a supervisory authority if you believe we have not complied with applicable data protection laws.
CCPA Compliance
For California residents, under the California Consumer Privacy Act (CCPA), you have the right to:
Know what personal information we collect and how it's used
Request deletion of your personal information
Opt-out of the sale of personal information (note: we do not sell personal information)
Non-discrimination for exercising your privacy rights
To exercise these rights, contact us at support@substanz.io with "California Privacy Rights" in the subject line.
Cookies and Tracking Technologies
We use cookies and similar technologies to:
Maintain session information and user preferences
Analyze usage patterns and improve service performance
Provide personalized search experiences
You can control cookie preferences through your browser settings. Please note that disabling cookies may affect the functionality of our service.
Children's Privacy
Our services are not directed to individuals under the age of 16. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child under 16, we will delete it promptly. Parents and guardians should monitor their children's internet usage and contact us if they believe a child has provided personal information without consent.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or for legal, operational, or regulatory reasons. When we make material changes, we will update the "Last Updated" date at the top of this policy and notify you through the app or via email. Continued use of our services after changes constitutes acceptance of the updated policy.
Shopify Integration
As a Shopify app, we:
Access only the data necessary to provide search functionality
Comply with Shopify's API Terms of Service and data protection requirements
Integrate with Shopify's authentication and billing systems
Follow Shopify's app development best practices
When you uninstall our app from your Shopify store, we automatically begin the deletion process and remove all your data within 48 hours.
Contact Us
If you have questions about this Privacy Policy or our data practices, please contact us:
Email: support@substanz.io
Website: https://substanz.io
For privacy-related requests (access, deletion, correction, or data portability), please email support@substanz.io with "Privacy Request" in the subject line. We will respond to your request within 30 days.