Privacy policy for Shopeye
1. Who is responsible for your information?
Shopeye is operated and published by:
You can request access, correction, or deletion of your data at any time by contacting us at bo@shopeye.app.
BoK ApS is the data controller for the processing of personal data described in this privacy policy.
2. What does this privacy policy cover?
This privacy policy applies when you use Shopeye's:
- website
- mobile app
- browser extensions for, for example, Safari and Chrome
- user profile and overview of previous webshop checks
- waitlist, newsletter, contact forms, and support
- other features and services that refer to this privacy policy
The website, app, browser extensions, and related features are collectively referred to as "Shopeye" or "the service".
Links to webshops, review services, public registers, and other external services are not covered by this privacy policy. Those services have their own terms and privacy policies.
3. Our basic approach
Shopeye is developed to analyze webshops, not to monitor users or build a general history of their internet usage.
We do not sell personal data, browsing data, or information about your webshop checks to advertisers or data brokers.
We do not use your webshop checks for:
- targeted advertising
- cross-site advertising
- building advertising profiles
- reselling information about your interests or purchase considerations
The browser extension automatically examines the active page to assess whether the page is a webshop. If the page is identified as a webshop, Shopeye can automatically start a webshop check without you first pressing the Shopeye button.
In this context, the browser extension may briefly read the original URL on your device. Before the URL is sent to Shopeye's servers or stored, Shopeye removes:
- everything from and including the question mark ?
- everything from and including the hash symbol #
This means that Shopeye, as a rule, only sends and stores the part of the URL that consists of protocol, domain, and path.
Example:
Original URL: https://webshop.dk/produkt/jakke?utm_source=facebook#storrelse
URL that Shopeye sends and stores: https://webshop.dk/produkt/jakke
Removing query parameters and fragments reduces the risk that session information, campaign parameters, search terms, or other information in the URL is sent to Shopeye.
However, the path in a URL may still contain product names, categories, identifiers, or other information that the webshop itself has placed in the address.
4. What information do we process?
4.1 Visits to Shopeye's website
When you visit Shopeye's website, we may automatically process:
- IP address
- date and time
- browser and device type
- operating system
- language
- approximate country or geographic area
- visited pages
- features used
- technical events and errors
- referring website
- performance and response time information
The information is used to:
- provide the website
- protect it against misuse
- identify and fix technical errors
- understand how Shopeye is used
- improve the user experience and service features
4.2 Cookieless analytics with PostHog
We use PostHog to understand how Shopeye's website, app, and features are used.
PostHog is configured for cookieless analytics. This means Shopeye's analytics setup does not use persistent PostHog identifiers in:
- cookies
- localStorage
- sessionStorage
PostHog may still receive and process information such as:
- visited Shopeye pages
- features used
- clicks and technical events
- time and duration
- browser and device type
- operating system
- approximate geographic area
- referring website
- performance and error information
- IP address or information derived from the IP address
Cookieless analytics therefore does not mean that no data is processed at all. It means analytics is carried out without persistent analytics identifiers stored in browser cookies or local storage.
PostHog may use technical information to temporarily distinguish visits and calculate aggregate use of the service.
We do not use PostHog for:
- targeted advertising
- cross-site advertising
- sale of user data
- tracking users across other companies
- linking web analytics to the user's name or email address
4.3 Waitlist, beta signup, newsletter, and product information
When you sign up for the waitlist, beta signup, newsletter, or request product information, we may process:
- email address
- time of your sign-up
- language
- any selected interests
- consent information
- time of unsubscription
- technical information necessary to prevent misuse
We use this information to send the information you have requested. This may include:
- launch notifications
- access to beta versions
- material product news
- information about new features
- relevant news about safe online shopping
You can unsubscribe at any time via the unsubscribe link in an email or by contacting us.
4.4 User profile and login
When you create a user profile, we may process:
- name, if you provide it
- email address
- internal user ID
- login method
- date of creation
- date of latest login
- account status
- selected settings
- possible profile picture from a login provider
- information about accepted terms and privacy policy
If you log in with, for example, Apple, Google, or another external login provider, we receive the information the provider makes available in accordance with your settings with that provider.
We do not receive your password for Apple, Google, or other external accounts.
4.5 Automatic webshop detection
The browser extension automatically examines the active page to assess whether the page is a webshop.
This assessment may, among other things, be based on:
- the page's domain
- the page's URL and path
- technical metadata
- structured data
- visible elements on the page
- product-, price-, cart-, or checkout-related elements
- other technical indications that the page is a webshop
The assessment is performed fully or partly automatically.
If the page is not identified as a webshop, the intention is that the URL is not sent to Shopeye's servers as a webshop check.
Automatic detection can, however, make mistakes. A page that is not a webshop may therefore in some cases be incorrectly identified as a webshop.
4.6 URLs and webshop checks
When a page is identified as a webshop, Shopeye may automatically start a webshop check.
In this context, we may process:
- the webshop's domain
- the cleaned URL of the active page
- date and time of the check
- the analyses and signals Shopeye finds
- the calculated result
- the explanations behind the assessment
- technical information about how the check is carried out
- information about whether the result is stored, hidden, or deleted
The browser extension removes everything from and including ? and # before the URL is sent to Shopeye's servers or stored.
As a rule, we therefore send and store:
- protocol
- domain
- any port number
- the page path
As a rule, we do not send or store:
- query parameters
- campaign parameters
- URL fragments
- information placed after ?
- information placed after #
The cleaned URL may still contain:
- product names
- category names
- product numbers
- language indicators
- shop-specific identifiers
- other information the webshop has placed in the path
Shopeye does not use such information to identify you, market products to you, or build a profile of your interests.
The cleaned URL may be stored and later used to revisit and analyze the publicly available page again.
Stored webshop checks may be linked to your user profile so you can view and compare previous checks.
4.7 Content from the analyzed webshop
Shopeye may automatically visit, fetch, and analyze publicly available content from the cleaned URL and from other relevant public pages on the same domain.
This may include, among other things:
- company name
- CVR or VAT number
- company type and company status
- address
- phone number
- email address
- terms and conditions
- return and cancellation terms
- delivery terms
- payment information
- product names
- product descriptions
- product images
- image URLs
- prices and currency
- stock information
- metadata
- structured data
- links and navigation
- domain information
- secure connection information
- links to social media
- public reviews and mentions
- possible dropshipping signals
- other public signals relevant to the assessment
Shopeye may fetch, analyze, and store:
- relevant text excerpts
- structured information
- metadata
- image URLs
- copies or technical representations of publicly available images
- analyzed signals
- derived results
- explanations and assessments
The information may be used to:
- carry out the webshop analysis
- explain the result
- check changes over time
- reuse already collected public information
- reduce response time for later checks
- improve Shopeye's ability to identify risk signals
We aim to limit collection to public content relevant to assessing the webshop.
4.8 Browser extension access
Depending on browser and device, the browser extension may request technical permission to:
- view the URL of the active page
- check whether the page is a webshop
- read relevant parts of the page's publicly displayed content
- clean the URL of query parameters and fragments
- send the cleaned URL to Shopeye's servers
- start a webshop check automatically
- show Shopeye's button, panel, or result on the page
- communicate with Shopeye's servers
- store local settings on the device
The browser may describe these permissions more broadly than how Shopeye actually uses them.
Shopeye is not intended to send or analyze content from:
- online banking
- webmail
- private messages
- personal documents
- other pages not relevant to a webshop check
You can disable or remove the browser extension at any time through your browser or device settings.
4.9 Technical operation, security, and errors
When you use the service, we may process:
- IP address
- app version
- browser version
- device and operating system version
- time of requests
- error messages
- diagnostic information
- performance and response time data
- failed login attempts
- security incidents
- suspected misuse
- technical information about webshop checks
We use the information to:
- provide a stable service
- identify and fix errors
- protect user accounts
- prevent automated misuse
- protect Shopeye's infrastructure
- investigate security incidents
We strive to avoid error reports containing more content or personal data than necessary.
4.10 Contact and support
When you contact us, we may process:
- name
- email address
- other contact information
- the content of your message
- any files or screenshots you send
- information about your account
- information about a specific webshop check
- our correspondence with you
We use the information to:
- respond to your inquiry
- provide support
- investigate errors
- handle complaints
- process requests for access, correction, or deletion
Do not send us sensitive personal data, payment card details, or passwords.
4.11 Payments and subscriptions
At this time, Shopeye does not offer purchases, payments, or paid subscriptions to users. We therefore do not process payment card data or subscription data as part of Shopeye.
If Shopeye later introduces paid features, we will update the privacy policy before the payment feature is put into use.
The updated policy will, among other things, describe:
- which payment provider is used
- which payment and subscription information Shopeye receives
- the purpose of the processing
- the legal basis for processing
- storage periods
- any transfers outside the EU and EEA
4.12 Information about webshops, owners, and contacts
Shopeye processes publicly available information about webshops and the businesses behind them.
For companies, the information will usually concern a legal entity and therefore not in itself constitute personal data.
For sole proprietorships and smaller businesses, information such as name, business address, phone number, and role may, however, be linked to a natural person.
We may process:
- name
- business role
- business address
- business phone number
- business email
- CVR and VAT number
- company type
- company status
- registration information
- domain registration information
- information published on the company's website
- public reviews
- public warnings and mentions
- Shopeye's assessment and related signals
The purpose is to:
- identify the trader
- verify public business information
- compare information from different sources
- detect inconsistencies
- give users a better basis for assessing a webshop
The information typically comes from:
- the webshop itself
- public business registers
- domain registers
- review platforms
- social media
- public warning lists
- other publicly available sources
You can request access, correction, or deletion of your data at any time by contacting us at bo@shopeye.app.
- be informed about which personal data we process
- draw attention to errors
- request correction of outdated or incorrect information
- object to processing
- request that specific matters be reviewed
5. Purpose and legal basis for processing
We process personal data for the following purposes and on the following legal bases.
5.1 Delivery of Shopeye
We process account, login, URL, and webshop data to:
- create and manage your user profile
- identify webshops
- carry out automatic webshop checks
- display results
- store previous checks
- provide the features you use
The legal basis is generally Article 6(1)(b) of the GDPR, because the processing is necessary to provide the service to you.
When you use Shopeye without an account, processing may also be based on our legitimate interest in providing the requested feature, cf. Article 6(1)(f).
5.2 Operation, security, and misuse prevention
We process technical information and logs to:
- protect users and systems
- prevent fraud and misuse
- control access
- troubleshoot
- investigate security incidents
- maintain a stable service
The legal basis is our legitimate interest, cf. Article 6(1)(f), in operating and protecting Shopeye.
5.3 Development and improvement
We may use usage data, technical events, webshop results, and feedback to:
- understand how the service is used
- improve existing features
- develop new features
- improve webshop detection
- improve the quality of Shopeye's analyses
- identify and fix errors
The legal basis is our legitimate interest in developing and improving the service, cf. Article 6(1)(f).
Where legislation requires consent for storing or accessing information on your device, we use consent as the legal basis.
5.4 Waitlist, newsletter, and marketing
We send newsletters and marketing on the basis of your consent, cf. Article 6(1)(a).
You can withdraw your consent at any time.
The withdrawal does not affect the lawfulness of processing already carried out based on consent.
5.5 Support and inquiries
We process your inquiry to:
- answer questions
- provide support
- investigate errors
- process complaints and requests
The legal basis is either performance of our agreement with you, cf. Article 6(1)(b), or our legitimate interest in handling inquiries, cf. Article 6(1)(f).
5.6 Webshop analysis and fraud prevention
We process publicly available business and contact information based on our and users' legitimate interest in:
- identifying traders
- verifying public information
- detecting risk signals
- preventing fraud
- making more informed purchasing decisions
The legal basis is Article 6(1)(f) of the GDPR.
We balance these interests against the rights of affected persons and strive only to process and display information that is relevant in a commercial context.
5.7 Legal obligations and legal claims
We may process and store information when necessary to:
- comply with the law
- comply with valid authority requests
- comply with bookkeeping rules
- establish a legal claim
- assert a legal claim
- defend against a legal claim
The legal basis may be Article 6(1)(c) or Article 6(1)(f).
6. Automated analysis and artificial intelligence
Shopeye uses automated analyses to find, structure, and compare signals about a webshop.
The analysis may, for example, include:
- domain age
- domain registration
- business information
- contact options
- terms and conditions
- return terms
- delivery information
- security conditions
- public reviews
- product texts
- product images
- metadata
- similarities with information from other websites
- possible dropshipping signals
- possible fraud or risk signals
Shopeye uses OpenAI's API to structure, enrich, and explain parts of the results.
Information sent to OpenAI may include, among other things:
- the webshop's domain
- the cleaned URL
- publicly available text excerpts
- public product and business information
- metadata
- signals identified by Shopeye
- instructions on how the information should be analyzed or explained
We strive not to send the following to OpenAI together with the webshop analysis:
- the user's name
- the user's email address
- the user's internal user ID
- login details
- other direct account identifiers
Data sent through OpenAI's API is not used by default to train or improve OpenAI's models.
OpenAI may store API input, output, and related metadata for a limited period, normally up to 30 days, for purposes including security and misuse prevention, unless longer storage is required by law or other special circumstances apply.
A Shopeye assessment may be fully or partially generated automatically.
The result is a decision-support tool. It is not a legal decision and does not in itself have legal effect for the user or the webshop.
A high score is not a guarantee that a webshop is safe.
A low score or warning is not in itself a determination of fraud, unlawful activity, or dishonest conduct.
7. Who do we share information with?
We do not sell your information.
We may share information with suppliers that help us operate and deliver Shopeye.
7.1 Hetzner
Shopeye's applications, servers, and databases are hosted by Hetzner.
In this context, Hetzner may process:
- account and user information
- cleaned webshop URLs
- stored webshop checks
- public webshop content
- analysis results
- technical logs
- IP addresses
- support and operational information
Hetzner processes the information as a hosting and infrastructure provider on our behalf.
7.2 OpenAI
OpenAI is used to structure, enrich, and explain webshop analyses.
OpenAI may receive:
- the cleaned URL
- the webshop's domain
- public webshop content
- public text excerpts
- metadata
- signals identified by Shopeye
- instructions for the analysis
As a rule, we do not send the user's name, email address, or internal user ID to OpenAI as part of the webshop analysis.
7.3 PostHog
PostHog is used for cookieless web and product analytics.
PostHog may process:
- visited Shopeye pages
- features used
- clicks and technical events
- browser and device type
- operating system
- timestamp
- performance information
- approximate geographic area
- IP address or information derived from the IP address
PostHog is not used for targeted advertising or to track users across different companies' websites.
7.4 Other suppliers
We may also use providers of:
- login and identity verification
- email and customer communication
- error logging and security
- domain information
- CVR and business information
- public reviews
- other relevant webshop signals
When suppliers act as our processors, they may only process information on our instructions and for the agreed purposes.
Some suppliers may be independent data controllers for their own processing. This may, for example, be login providers, public registers, and review services.
We may also disclose information:
- when required by law
- upon a valid authority request
- to protect Shopeye, users, or others' rights and safety
- in connection with a merger, business transfer, or similar transaction
8. Transfer to countries outside the EU and EEA
Shopeye's primary hosting and database processing takes place at Hetzner.
OpenAI, PostHog, and their subprocessors may in certain cases process personal data outside the EU and EEA.
When personal data is transferred to a country outside the EU and EEA, we ensure a valid transfer mechanism.
This may include, among other things:
- an adequacy decision from the European Commission
- the European Commission's standard contractual clauses
- relevant data processing agreements
- supplementary technical and organizational safeguards
- other lawful transfer mechanisms
You can request access, correction, or deletion of your data at any time by contacting us at bo@shopeye.app.
9. How long do we store information?
We only store personal data as long as necessary for the purpose for which it was collected.
As a rule, the following applies:
- Account information is stored while your account is active.
- Stored webshop checks are kept until you delete them or close your account.
- Cleaned URLs may be stored as part of a webshop check.
- Public webshop content may be stored and reused as long as it is relevant for analyses.
- When an account is deleted, personal data is removed or anonymized from active systems within a reasonable time.
- Information may still temporarily exist in backups.
- Technical operation logs are normally stored for up to 30 days.
- Logs related to security incidents or misuse may be stored longer if necessary to investigate the incident.
- Support inquiries are normally stored for up to 24 months after closure.
- Waitlist and newsletter information is stored until you unsubscribe or the purpose ceases.
- We may keep a limited record of your unsubscription to ensure we do not contact you again.
- Cookieless analytics information is stored as long as necessary for product analytics and is then deleted or anonymized.
- Public information about a webshop may be stored and reused in later analyses as long as it remains relevant.
- Webshop information may be updated or overwritten when the webshop is checked again.
We may store information for longer if necessary to comply with law or to establish, exercise, or defend a legal claim.
10. Cookies and local storage
Shopeye's website, app, and browser extensions may use cookies or local storage when necessary for:
- login and session management
- security and misuse prevention
- language settings
- the user's chosen settings
- browser extension functionality
- remembering whether specific messages have been shown
Technically necessary cookies and local storage are used to make the service work.
We use PostHog in cookieless mode for web and product analytics.
In this mode, PostHog does not store persistent analytics identifiers in:
- cookies
- localStorage
- sessionStorage
PostHog may still receive events and technical information from the browser and process them on its servers.
Cookieless therefore does not mean that no information is processed at all.
We do not use PostHog for:
- advertising
- marketing profiles
- cross-site advertising
- tracking users across other companies
If we later introduce analytics, personalization, or marketing technologies that require consent, they will only be activated after user consent.
Blocking or deleting necessary cookies or local storage may cause login or other features to stop working properly.
11. Data security
We apply appropriate technical and organizational security measures based on the nature of the information and the risks involved in the processing.
Measures may include, among other things:
- encrypted communication via HTTPS
- access control
- limited administrator rights
- secure handling of login and sessions
- backups
- logging and monitoring of security incidents
- continuous updating of systems and dependencies
- data minimization
- URL cleaning
- limited storage periods
- separation of account identifiers and AI processing
No internet-based service can guarantee complete security.
Contact us as soon as possible if you believe your account or information has been compromised.
12. Your rights
Depending on the circumstances, you have the right to:
- be informed about which personal data we process about you
- access the information
- receive a copy of the information
- have incorrect or incomplete information corrected
- have information deleted
- have processing restricted
- object to processing based on legitimate interests
- receive certain information in a structured, commonly used, and machine-readable format
- withdraw consent
- lodge a complaint with a data protection authority
These rights are not absolute.
In some cases, we may be entitled or required to reject a request or retain specific information.
This may, for example, be the case if the information is necessary to:
- comply with the law
- protect others' rights
- establish a legal claim
- assert a legal claim
- defend against a legal claim
We may ask for information necessary to verify your identity before processing a request.
You can request access, correction, or deletion of your data at any time by contacting us at bo@shopeye.app.
13. Objection to processing based on legitimate interests
When we process personal data based on legitimate interests, you have the right to object to the processing.
If you object, we assess:
- your specific situation
- the purpose of the processing
- our and users' interests
- the nature of the information
- whether there are compelling legitimate grounds to continue processing
A webshop owner or another registered person can contact us if they believe that information or an assessment is incorrect, outdated, or misleading.
14. Complaint to the Danish Data Protection Agency
You are welcome to contact us first if you are dissatisfied with our processing of your personal data.
You also have the right to complain to:
Datatilsynet Carl Jacobsens Vej 35 2500 Valby
You can find additional contact details on the Danish Data Protection Agency's website.
If you live in another EU or EEA country, you may also contact the data protection authority in your country of residence.
15. Children and young people
Shopeye is not specifically directed at children.
Persons under 18 should only create an account or use features that involve entering into an agreement with permission from a parent or guardian when required by applicable law.
Contact us if you believe we unintentionally process information about a child in a way that is not lawful.
16. Changes to this privacy policy
We may update this privacy policy when:
- Shopeye changes
- we introduce new features
- we change suppliers
- we change the way we process information
- legislation or authority requirements change
The latest version will always be available on Shopeye's website.
For material changes, we will provide notice through the service, by email, or in another appropriate way before changes take effect, where relevant.
17. Contact
Questions about this privacy policy, our processing of personal data, or your rights can be sent to:
You can request access, correction, or deletion of your data at any time by contacting us at bo@shopeye.app.
Last updated: July 12, 2026