Privacy Policy
Last updated: September 5, 2026
This Privacy Policy explains how Composerie collects, uses, shares and protects personal data when you use our product-personalization platform, our websites and our related services (together, the Service). We are committed to handling personal data lawfully, fairly and transparently in accordance with the EU General Data Protection Regulation (GDPR), the UK GDPR and applicable Dutch law.
1. Who We Are
The data controller responsible for personal data processed in connection with your Composerie account is:
Composerie
Registered with the Dutch Chamber of Commerce (KvK) under number 80513573
Markerkant 13-11, 1314 AL Almere, Flevoland
VAT: NL003449094B70
The Netherlands
Email: support@composerie.com
Our two roles. For data about our merchant customers and their account (such as your name, email and billing details), we act as a controller. For data that merchants and their shoppers submit through the personalization tools we provide (such as the text, images and design choices used to personalize a product), we act as a processor on the merchant's behalf — the merchant is the controller of that data. Our Data Processing Agreement forms part of our Terms for merchants and governs that processing.
2. Who This Policy Covers
- Merchants — businesses and the individuals who register, configure and operate a Composerie account.
- Shoppers / end customers — people who personalize products on a merchant's store using tools powered by Composerie. We process their data on the merchant's instructions.
- Website visitors — people who browse our public websites.
3. Information We Collect
We collect information you provide directly and information generated through your use of the Service. The categories of personal data we process include:
3.1 Account information
- Name and email address
- Company name and business details
- Account credentials (passwords are stored only in hashed form)
- If you sign in with Google or Microsoft: the name, email address and profile picture that provider shares with us
- Profile, language and accessibility preferences
3.2 Connected platform data
- Your store URL and the access tokens needed to connect your e-commerce platform (for example Shopify); tokens are encrypted at rest
- Product, inventory, publication and theme data needed to publish the customizer and keep it in sync with your store
- Order data for personalized products, received from Shopify through the read_orders access scope: order and line-item details, the recipient's name and email address, and the shipping address limited to address lines, city, region, postal code and country
What we deliberately do not take from Shopify. We do not request access to Shopify customer profiles (no read_customers scope), we only receive orders from Shopify's standard 60-day window, and we do not store buyer phone numbers or billing addresses: both are removed before an order is stored, and our database rejects a Shopify order that still carries a billing address. We use this protected customer data only to identify, produce, deliver and support the personalized order and to answer Shopify's mandatory data-request and erasure webhooks — never for marketing, profiling or analytics.
3.3 Design and personalization content
- Product templates and design files you create
- Images, fonts and media you upload
- Personalization content submitted by shoppers (such as text and images), processed on the merchant's behalf
3.4 Billing information
- Billing address, company and tax/VAT details
- Shopify merchants approve and pay app charges through Shopify; Composerie does not collect their card details
- For services not billed through Shopify, payment card details are collected and stored directly by our payment processor; we do not store full card numbers
- Transaction history and invoices
3.5 Product, customizer and storefront usage and technical data
- Pages visited, features used and actions taken within the authenticated product, customizer and connected storefront experience
- Device type, browser and operating system
- IP address and approximate (city-level) location
- Timestamps and diagnostic logs
On connected Shopify storefronts, the Composerie Web Pixel sends bounded personalization-funnel events only while Shopify's Customer Privacy API reports that analytics processing is allowed. Composerie Web Pixel event payloads exclude personally identifiable information (PII): product and cart events are rebuilt from a closed allowlist of product and variant IDs plus quantity, and checkout events contain no event data. Buyer identity, contact details, addresses and checkout tokens are not included in those event payloads. This payload statement does not extend to the limited network and hosting data needed to deliver and secure a request.
3.6 Public website operations
Our public marketing website and Help Center do not run optional analytics or tracking technologies. We do not set analytics cookies, create a public analytics identifier or run session replay on those public surfaces. Hosting and security infrastructure may still process limited request data, such as an IP address, timestamp and requested URL, as needed to deliver pages, prevent abuse and diagnose errors.
3.7 Support and status communications
When you contact us (including through the contact form on our website) we process your name, email address and the content of your message to answer you. If you subscribe to status updates on our status page, we store the email address you confirm (double opt-in) until you unsubscribe.
4. Legal Bases for Processing
Under the GDPR, we rely on the following legal bases:
- Performance of a contract (Art. 6(1)(b)) — to provide the Service, manage your account, process payments and meet our obligations to you.
- Legitimate interests (Art. 6(1)(f)) — for security, fraud prevention, operational reliability, error diagnosis and improvement analysis within the authenticated product and Service operations, balanced against your rights.
- Legal obligation (Art. 6(1)(c)) — to comply with tax, accounting and other applicable laws.
- Consent (Art. 6(1)(a)) — where required, such as for optional marketing communications and consent-gated Web Pixel events on connected Shopify storefronts. You may withdraw consent at any time; later Web Pixel events stop when Shopify reports that analytics processing is no longer allowed.
5. How We Use Your Information
- Provide, maintain, secure and improve the Composerie platform
- Process transactions, send invoices and manage subscriptions
- Generate production-ready print files from personalizations and route orders to fulfillment partners
- Send service and security notices and respond to support requests
- Monitor performance, diagnose issues and improve reliability
- Detect, prevent and address fraud, abuse and security incidents
- Comply with legal obligations and enforce our terms
6. Sub-processors and Other Recipients
We do not sell your personal data. We share it only with the service providers below, who process it on our behalf, under contract and only as instructed by us. Shopify handles app charges for Shopify merchants, so no card data reaches us for them; for services not billed through Shopify, card data is handled by Stripe and is not stored by us. Product, customizer and storefront usage is analyzed on our own infrastructure; external product-analytics processing stays disabled unless its retention and erasure controls have been verified, and nothing in this section runs optional analytics or tracking on our public marketing website or Help Center.
| Sub-processor | Purpose | Location and safeguard |
|---|---|---|
| Hetzner Online GmbH | Application hosting, databases, background job queues and backups on dedicated servers | Germany (EU) |
| Cloudflare, Inc. | DNS, TLS, content delivery, DDoS and bot protection, and object storage (R2) for uploads, previews, print files and encrypted backups | EU/US edge network; EU-US Data Privacy Framework and Standard Contractual Clauses |
| Upstash, Inc. | Managed Redis for rate limiting and short-lived caches | Frankfurt, Germany (EU); Standard Contractual Clauses |
| Resend, Inc. | Transactional email delivery (account, billing, order, status and support notices) and routing of inbound support email | United States; EU-US Data Privacy Framework and Standard Contractual Clauses |
| Functional Software, Inc. (Sentry) | Error monitoring and performance diagnostics | EU data residency (Frankfurt, Germany) |
| Stripe Payments Europe, Ltd. / Stripe, Inc. | Payment processing and invoicing for merchants who are not billed through Shopify | Ireland (EU) and United States; Standard Contractual Clauses |
Recipients you choose. The following parties receive personal data on your instruction and under your own agreement with them; they are not our sub-processors:
| Recipient | What they receive | Location |
|---|---|---|
| Shopify International Ltd. / Shopify Inc. | The merchant's e-commerce platform: store, product, order and billing data are exchanged through the Shopify APIs the merchant authorizes | Canada and Ireland; governed by the merchant's Shopify agreement |
| Print and fulfillment partners the merchant connects (for example Printful, Printify, MerchOne) | Receive order line items, print files and the recipient's shipping details to produce and ship personalized orders | Per partner; governed by the merchant's agreement with that partner |
| AI providers the merchant connects with its own account (for example OpenAI, Anthropic, Google, Stability AI, Replicate, fal.ai, remove.bg) | Receive the images, text and prompts the merchant submits to the optional AI design and product-description tools | Per provider; governed by the merchant's agreement with that provider |
| Google LLC / Microsoft Corporation | Identity provider when a user chooses to sign in with Google or Microsoft; shares the name, email address and profile picture with Composerie | Per provider; independent controller of the sign-in |
The same list is Annex 1 of our Data Processing Agreement; we announce additions there at least 30 days before a new sub-processor handles merchant or shopper data. We also disclose information where required by law, to protect our rights, or in connection with a corporate transaction (subject to equivalent protections).
7. International Data Transfers
Your data is primarily stored within the European Economic Area (EEA). Where data is transferred outside the EEA, we put appropriate safeguards in place — such as European Commission adequacy decisions or Standard Contractual Clauses (SCCs) together with any supplementary measures required under the GDPR.
8. Data Security
We apply technical and organizational measures appropriate to the risk, including:
- Encryption in transit (TLS) and encryption at rest for sensitive data
- Encryption of connected-platform access tokens
- Role-based access controls and the principle of least privilege
- Hashed password storage and CSRF protection
- Automated monitoring, logging and regular security review
No method of transmission or storage is completely secure, but we work continuously to protect your data and will notify you and the relevant authority of a personal data breach where legally required.
9. Data Retention
We keep personal data only as long as necessary for the purposes described in this policy, then delete or anonymize it:
10. Your Rights
Subject to applicable law, you have the right to:
- Access (Art. 15) — obtain a copy of the personal data we hold about you.
- Rectification (Art. 16) — correct inaccurate or incomplete data.
- Erasure (Art. 17) — request deletion of your personal data.
- Restriction (Art. 18) — limit how we process your data in certain cases.
- Portability (Art. 20) — receive your data in a structured, machine-readable format.
- Object (Art. 21) — object to processing based on legitimate interests or to direct marketing.
- Withdraw consent (Art. 7) — at any time, where processing is based on consent.
To exercise any of these rights, contact us at support@composerie.com. We will respond within 30 days. If you are a shopper exercising rights in relation to a merchant's store, we may direct your request to that merchant as the controller.
11. AI Features & Automated Decision-Making
Composerie offers optional AI-assisted design tools for merchants (for example background removal, image generation, upscaling and AI-written product descriptions) and optional AI photo effects that merchants can publish to their shoppers. When these tools are used:
- Merchant AI tools run on the AI provider account you connect in your settings (for example OpenAI, Anthropic, Google, Stability AI, Replicate, fal.ai or remove.bg). The content you submit is sent to that provider under your agreement with it; we transmit the request and store the result in your workspace.
- Shopper photo effects run on our own infrastructure with open-source models; no shopper photo is sent to a third-party AI provider.
- We process only the content needed to perform the requested task and do not use your or your shoppers' personal data or content to train our own or third-party general-purpose AI models.
- Outputs are suggestions you remain in control of and can edit or discard.
We use limited automated processing to protect the Service, such as rate limiting and abuse detection. These do not produce legal or similarly significant effects on you, and you may request human review of any automated decision by contacting us.
13. Children's Privacy
Composerie is a business-to-business service intended for users aged 18 and over. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.
15. Changes to This Policy
We may update this Privacy Policy from time to time. For material changes we will give notice — by email and/or a notice on our website — at least 30 days before they take effect. The current version is always available on this page, with the effective date shown at the top.
16. Contact Us
If you have questions about this Privacy Policy or wish to exercise your rights, contact us: