Privacy Policy

Last updated: February 19, 2026

1. Introduction

Innovativa ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our dropshipping management platform and services.

By using Innovativa, you agree to the collection and use of information in accordance with this policy.

2. Information We Collect

2.1 Information from Shopify

When you connect your Shopify store to Innovativa, we access the following data through Shopify's API:

  • Products: Product titles, prices, variants, inventory levels, and SKUs
  • Orders: Order totals, status, dates, and line items (SKUs, quantities, prices). We access the destination country code (e.g., "US", "DE") for shipping cost calculations, but not full shipping addresses.
  • Fulfillments: Fulfillment status, tracking numbers, and shipping carrier information

We only request read-only access to your Shopify store. We cannot modify your products, orders, or any other store data.

2.2 Data We Do NOT Collect

To protect your customers' privacy, we specifically avoid collecting:

  • Customer email addresses
  • Customer phone numbers
  • Customer names
  • Full shipping or billing addresses
  • Payment or credit card information

We only access the minimum data necessary to provide our COGS tracking, analytics, and order management services.

2.3 Account Information

When you create an Innovativa account, we collect:

  • Email address
  • Full name
  • Company name (optional)
  • Phone number (optional)

2.4 Usage Data

We automatically collect certain information when you use our platform, including your IP address, browser type, pages visited, and time spent on pages.

3. How We Use Your Information

We use the information we collect to:

  • Provide and maintain our services
  • Display your store analytics and profit metrics
  • Calculate cost of goods sold (COGS) and profitability
  • Facilitate supplier sourcing and quote management
  • Send you service-related notifications
  • Respond to your inquiries and support requests
  • Improve our platform and develop new features
  • Comply with legal obligations

4. Data Sharing and Disclosure

We do not sell your personal information. We may share your information in the following circumstances:

  • Service Providers: We use third-party services (e.g., hosting, analytics) that may process your data on our behalf
  • Legal Requirements: When required by law or to protect our rights
  • Business Transfers: In connection with a merger, acquisition, or sale of assets

5. Data Security

We implement appropriate technical and organizational measures to protect your data, including:

  • Encryption of data in transit (HTTPS/TLS)
  • Secure storage with access controls
  • Regular security assessments
  • Employee access restrictions

6. Data Retention

We retain your data for as long as your account is active or as needed to provide our services. Our retention practices are as follows:

  • Active accounts: Data is retained and actively processed to provide our services
  • After disconnection: Historical order and analytics data is retained for your records and our operational purposes (invoicing, support, accounting, dispute resolution)
  • Legal requirements: Financial records such as invoices are retained for up to 7 years as required by law

You may request complete deletion of your data at any time by contacting us at business@innovativa.ch. We will process deletion requests within 30 days, except where retention is required for legal compliance.

7. Your Rights (GDPR)

If you are located in the European Economic Area (EEA), you have the following rights:

  • Access: Request a copy of your personal data
  • Rectification: Request correction of inaccurate data
  • Erasure: Request deletion of your personal data
  • Portability: Request transfer of your data
  • Objection: Object to certain processing activities
  • Restriction: Request limitation of processing

To exercise these rights, contact us at business@innovativa.ch.

8. Shopify Store Data

When you uninstall Innovativa from your Shopify store:

  • We immediately revoke our access to your Shopify store
  • Syncing of new data stops immediately
  • Historical order and analytics data is retained for your records and our operational purposes
  • We process Shopify's mandatory GDPR webhooks for data deletion requests

You may request complete deletion of all your data at any time by contacting us. Since we do not store customer personal information (emails, names, addresses), uninstalling the app does not impact your customers' privacy.

9. No Marketing Use of Customer Data

We do NOT use your customers' data for our own marketing purposes. We will never add your customers to our mailing lists, use their information for advertising, or sell customer data to third parties. Your store data is used solely to provide our analytics and order management services to you.

10. Cookies and Tracking

We use essential cookies to maintain your session and preferences. We may also use analytics cookies to understand how you use our platform. You can control cookies through your browser settings.

11. Children's Privacy

Our services are not intended for individuals under 18 years of age. We do not knowingly collect personal information from children.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new policy on this page and updating the "Last updated" date.

13. Prohibited Technical Conduct

To protect the privacy and security of all users, you expressly agree NOT to:

  • Attempt to access, query, read, or manipulate any database, data store, or backend system beyond what is explicitly made available through the Innovativa user interface
  • Reverse-engineer, decompile, disassemble, or attempt to derive the source code, architecture, or internal logic of the platform
  • Exploit, probe, or test for vulnerabilities in any part of the platform, its APIs, authentication systems, or infrastructure
  • Intercept, monitor, or tamper with network traffic between your device and Innovativa's servers
  • Attempt to bypass, circumvent, or disable any access control, authentication mechanism, row-level security policy, or permission boundary
  • Access data, records, or functionality belonging to other users or accounts for which you have not been explicitly granted access
  • Use automated tools, bots, scripts, or crawlers to extract data beyond what is accessible through normal use of the Service
  • Attempt to elevate your privilege level beyond what has been assigned to your account role

Violation of any of the above constitutes a material breach and will result in immediate account termination without refund. You agree to pay liquidated damages of $25,000 USD per incident, representing a reasonable estimate of the minimum harm caused, including security audit costs, reputational damage, legal expenses, and remediation costs. This is in addition to any other legal remedies Innovativa may pursue.

Such conduct may also expose you to criminal and civil liability under applicable law, including:

  • United States: The Computer Fraud and Abuse Act (CFAA, 18 U.S.C. § 1030), the Electronic Communications Privacy Act (ECPA), and applicable state computer crime statutes
  • Switzerland: The Swiss Federal Act on Data Protection (nDSG/FADP) and Article 143 of the Swiss Criminal Code (unauthorised access to data processing systems)
  • European Union: The EU Directive on Attacks Against Information Systems (2013/40/EU) and the General Data Protection Regulation (GDPR)

14. Contact Us

If you have questions about this Privacy Policy or our data practices, please contact us:

Innovativa

Email: business@innovativa.ch

Website: innovativa.io