Composerie
Back to login

Privacy Policy

Last updated: September 5, 2026

This Privacy Policy explains how Composerie collects, uses, shares and protects personal data when you use our product-personalization platform, our websites and our related services (together, the Service). We are committed to handling personal data lawfully, fairly and transparently in accordance with the EU General Data Protection Regulation (GDPR), the UK GDPR and applicable Dutch law.

1. Who We Are

The data controller responsible for personal data processed in connection with your Composerie account is:

Composerie

Registered with the Dutch Chamber of Commerce (KvK) under number 80513573

Markerkant 13-11, 1314 AL Almere, Flevoland

VAT: NL003449094B70

The Netherlands

Email: support@composerie.com

Our two roles. For data about our merchant customers and their account (such as your name, email and billing details), we act as a controller. For data that merchants and their shoppers submit through the personalization tools we provide (such as the text, images and design choices used to personalize a product), we act as a processor on the merchant's behalf — the merchant is the controller of that data. Our Data Processing Agreement forms part of our Terms for merchants and governs that processing.

2. Who This Policy Covers

  • Merchants — businesses and the individuals who register, configure and operate a Composerie account.
  • Shoppers / end customers — people who personalize products on a merchant's store using tools powered by Composerie. We process their data on the merchant's instructions.
  • Website visitors — people who browse our public websites.

3. Information We Collect

We collect information you provide directly and information generated through your use of the Service. The categories of personal data we process include:

3.1 Account information

  • Name and email address
  • Company name and business details
  • Account credentials (passwords are stored only in hashed form)
  • If you sign in with Google or Microsoft: the name, email address and profile picture that provider shares with us
  • Profile, language and accessibility preferences

3.2 Connected platform data

  • Your store URL and the access tokens needed to connect your e-commerce platform (for example Shopify); tokens are encrypted at rest
  • Product, inventory, publication and theme data needed to publish the customizer and keep it in sync with your store
  • Order data for personalized products, received from Shopify through the read_orders access scope: order and line-item details, the recipient's name and email address, and the shipping address limited to address lines, city, region, postal code and country

What we deliberately do not take from Shopify. We do not request access to Shopify customer profiles (no read_customers scope), we only receive orders from Shopify's standard 60-day window, and we do not store buyer phone numbers or billing addresses: both are removed before an order is stored, and our database rejects a Shopify order that still carries a billing address. We use this protected customer data only to identify, produce, deliver and support the personalized order and to answer Shopify's mandatory data-request and erasure webhooks — never for marketing, profiling or analytics.

3.3 Design and personalization content

  • Product templates and design files you create
  • Images, fonts and media you upload
  • Personalization content submitted by shoppers (such as text and images), processed on the merchant's behalf

3.4 Billing information

  • Billing address, company and tax/VAT details
  • Shopify merchants approve and pay app charges through Shopify; Composerie does not collect their card details
  • For services not billed through Shopify, payment card details are collected and stored directly by our payment processor; we do not store full card numbers
  • Transaction history and invoices

3.5 Product, customizer and storefront usage and technical data

  • Pages visited, features used and actions taken within the authenticated product, customizer and connected storefront experience
  • Device type, browser and operating system
  • IP address and approximate (city-level) location
  • Timestamps and diagnostic logs

On connected Shopify storefronts, the Composerie Web Pixel sends bounded personalization-funnel events only while Shopify's Customer Privacy API reports that analytics processing is allowed. Composerie Web Pixel event payloads exclude personally identifiable information (PII): product and cart events are rebuilt from a closed allowlist of product and variant IDs plus quantity, and checkout events contain no event data. Buyer identity, contact details, addresses and checkout tokens are not included in those event payloads. This payload statement does not extend to the limited network and hosting data needed to deliver and secure a request.

3.6 Public website operations

Our public marketing website and Help Center do not run optional analytics or tracking technologies. We do not set analytics cookies, create a public analytics identifier or run session replay on those public surfaces. Hosting and security infrastructure may still process limited request data, such as an IP address, timestamp and requested URL, as needed to deliver pages, prevent abuse and diagnose errors.

3.7 Support and status communications

When you contact us (including through the contact form on our website) we process your name, email address and the content of your message to answer you. If you subscribe to status updates on our status page, we store the email address you confirm (double opt-in) until you unsubscribe.

5. How We Use Your Information

  • Provide, maintain, secure and improve the Composerie platform
  • Process transactions, send invoices and manage subscriptions
  • Generate production-ready print files from personalizations and route orders to fulfillment partners
  • Send service and security notices and respond to support requests
  • Monitor performance, diagnose issues and improve reliability
  • Detect, prevent and address fraud, abuse and security incidents
  • Comply with legal obligations and enforce our terms

6. Sub-processors and Other Recipients

We do not sell your personal data. We share it only with the service providers below, who process it on our behalf, under contract and only as instructed by us. Shopify handles app charges for Shopify merchants, so no card data reaches us for them; for services not billed through Shopify, card data is handled by Stripe and is not stored by us. Product, customizer and storefront usage is analyzed on our own infrastructure; external product-analytics processing stays disabled unless its retention and erasure controls have been verified, and nothing in this section runs optional analytics or tracking on our public marketing website or Help Center.

Sub-processorPurposeLocation and safeguard
Hetzner Online GmbHApplication hosting, databases, background job queues and backups on dedicated serversGermany (EU)
Cloudflare, Inc.DNS, TLS, content delivery, DDoS and bot protection, and object storage (R2) for uploads, previews, print files and encrypted backupsEU/US edge network; EU-US Data Privacy Framework and Standard Contractual Clauses
Upstash, Inc.Managed Redis for rate limiting and short-lived cachesFrankfurt, Germany (EU); Standard Contractual Clauses
Resend, Inc.Transactional email delivery (account, billing, order, status and support notices) and routing of inbound support emailUnited States; EU-US Data Privacy Framework and Standard Contractual Clauses
Functional Software, Inc. (Sentry)Error monitoring and performance diagnosticsEU data residency (Frankfurt, Germany)
Stripe Payments Europe, Ltd. / Stripe, Inc.Payment processing and invoicing for merchants who are not billed through ShopifyIreland (EU) and United States; Standard Contractual Clauses

Recipients you choose. The following parties receive personal data on your instruction and under your own agreement with them; they are not our sub-processors:

RecipientWhat they receiveLocation
Shopify International Ltd. / Shopify Inc.The merchant's e-commerce platform: store, product, order and billing data are exchanged through the Shopify APIs the merchant authorizesCanada and Ireland; governed by the merchant's Shopify agreement
Print and fulfillment partners the merchant connects (for example Printful, Printify, MerchOne)Receive order line items, print files and the recipient's shipping details to produce and ship personalized ordersPer partner; governed by the merchant's agreement with that partner
AI providers the merchant connects with its own account (for example OpenAI, Anthropic, Google, Stability AI, Replicate, fal.ai, remove.bg)Receive the images, text and prompts the merchant submits to the optional AI design and product-description toolsPer provider; governed by the merchant's agreement with that provider
Google LLC / Microsoft CorporationIdentity provider when a user chooses to sign in with Google or Microsoft; shares the name, email address and profile picture with ComposeriePer provider; independent controller of the sign-in

The same list is Annex 1 of our Data Processing Agreement; we announce additions there at least 30 days before a new sub-processor handles merchant or shopper data. We also disclose information where required by law, to protect our rights, or in connection with a corporate transaction (subject to equivalent protections).

7. International Data Transfers

Your data is primarily stored within the European Economic Area (EEA). Where data is transferred outside the EEA, we put appropriate safeguards in place — such as European Commission adequacy decisions or Standard Contractual Clauses (SCCs) together with any supplementary measures required under the GDPR.

8. Data Security

We apply technical and organizational measures appropriate to the risk, including:

  • Encryption in transit (TLS) and encryption at rest for sensitive data
  • Encryption of connected-platform access tokens
  • Role-based access controls and the principle of least privilege
  • Hashed password storage and CSRF protection
  • Automated monitoring, logging and regular security review

No method of transmission or storage is completely secure, but we work continuously to protect your data and will notify you and the relevant authority of a personal data breach where legally required.

9. Data Retention

We keep personal data only as long as necessary for the purposes described in this policy, then delete or anonymize it:

Account dataDuration of the account + 30 days after closure
Design and personalization filesDuration of the account + 30 days
Order history7 years for accounting and tax records; the recipient's name, email address and shipping address are removed earlier when a merchant or shopper exercises an erasure right or when Shopify sends a customers/redact or shop/redact request
Payment & invoice records7 years (legal / tax obligation)
Shopper photos uploaded for AI photo effects7 days; generated results 90 days
Design export files and customizer session tokens30 days
Encrypted database backups30 days. We always keep the four most recent backups so that a period of failed backups cannot leave us without a recovery point; a backup held for that reason is deleted as soon as newer backups replace it
Security and audit logs24 months
Raw product, customizer and storefront usage events90 days
Hourly organization-level analytics rollups1 year
Daily aggregate analytics metricsRetained for longitudinal reporting while the organization record exists; these metrics contain no raw event payloads
Support communications3 years after the last interaction

10. Your Rights

Subject to applicable law, you have the right to:

  • Access (Art. 15) — obtain a copy of the personal data we hold about you.
  • Rectification (Art. 16) — correct inaccurate or incomplete data.
  • Erasure (Art. 17) — request deletion of your personal data.
  • Restriction (Art. 18) — limit how we process your data in certain cases.
  • Portability (Art. 20) — receive your data in a structured, machine-readable format.
  • Object (Art. 21) — object to processing based on legitimate interests or to direct marketing.
  • Withdraw consent (Art. 7) — at any time, where processing is based on consent.

To exercise any of these rights, contact us at support@composerie.com. We will respond within 30 days. If you are a shopper exercising rights in relation to a merchant's store, we may direct your request to that merchant as the controller.

11. AI Features & Automated Decision-Making

Composerie offers optional AI-assisted design tools for merchants (for example background removal, image generation, upscaling and AI-written product descriptions) and optional AI photo effects that merchants can publish to their shoppers. When these tools are used:

  • Merchant AI tools run on the AI provider account you connect in your settings (for example OpenAI, Anthropic, Google, Stability AI, Replicate, fal.ai or remove.bg). The content you submit is sent to that provider under your agreement with it; we transmit the request and store the result in your workspace.
  • Shopper photo effects run on our own infrastructure with open-source models; no shopper photo is sent to a third-party AI provider.
  • We process only the content needed to perform the requested task and do not use your or your shoppers' personal data or content to train our own or third-party general-purpose AI models.
  • Outputs are suggestions you remain in control of and can edit or discard.

We use limited automated processing to protect the Service, such as rate limiting and abuse detection. These do not produce legal or similarly significant effects on you, and you may request human review of any automated decision by contacting us.

12. Cookies

Our public marketing website and Help Center do not run optional analytics or tracking technologies. We do not set analytics cookies, create a public analytics identifier or run session replay on those public surfaces. The authenticated application uses essential cookies and preference storage; limited operational, security and error processing may also occur there as described above. We do not use advertising or cross-site tracking cookies. For details, see our Cookie Policy.

13. Children's Privacy

Composerie is a business-to-business service intended for users aged 18 and over. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.

14. Supervisory Authority

You have the right to lodge a complaint with a data protection authority. Our lead supervisory authority is:

Autoriteit Persoonsgegevens (Dutch Data Protection Authority)

Postbus 93374, 2509 AJ The Hague, The Netherlands

Website: autoriteitpersoonsgegevens.nl

15. Changes to This Policy

We may update this Privacy Policy from time to time. For material changes we will give notice — by email and/or a notice on our website — at least 30 days before they take effect. The current version is always available on this page, with the effective date shown at the top.

16. Contact Us

If you have questions about this Privacy Policy or wish to exercise your rights, contact us:

Composerie

Email: support@composerie.com

Legal response time: within 30 days.