Privacy Policy
Data controller
The data controller is Christopher Lasgi, publisher of the platform www.boostecom.app, operating under the BoostEcom brand.
Contact: contact@boostecom.app
Two roles, and the difference matters
BoostEcom holds two distinct positions, and your rights differ between them:
- Controller, for your account: email, organization, billing, the conversations you have with the assistant, the stores you register. We decide why and how this is processed, and this policy governs it.
- Processor, for the data inside a store you connect, including your own customers' orders and personal data. We act on your instructions only. That relationship is governed by the Data Processing Agreement, not by this policy.
Scope
This policy applies to every BoostEcom surface:
- The web platform: www.boostecom.app: dashboard, chat, scanner, Studio, Intelligence, marketplace
- BoostEcom Spy: the Chrome extension, linked to a BoostEcom account
- The API and the MCP server: programmatic access under an Intelligence token or an OAuth-authorized MCP client
- The public scanner: storefront analysis run without an account, from BoostEcom-Scanner/1.0
Data collected on the platform
When using the platform, the following may be collected:
- Account data: email address, name, authentication state
- Organization data: organization name, members, roles
- Store data: configurations, connectors, settings, OAuth tokens (encrypted at rest with AES-256-GCM)
- Google data, only if you connect a Google account: read-only access to Google Analytics (scope analytics.readonly) and, if you grant it separately, to Search Console (scope webmasters.readonly). From Search Console we keep daily page statistics and the search queries with at least 10 impressions over 28 days (clicks, impressions, click-through rate, average position), for 16 months at most. We never write to your Google account, and you can disconnect it at any time
- Conversation data: messages exchanged with the AI assistant, and files attached to them
- Billing data: subscription and credit history. Card details are held by Stripe and never reach our servers
- Browsing data: IP address, browser type, pages viewed, timestamps
- Scanner data: the URL submitted, the analysis produced, and a salted hash of the submitter's IP address used only to enforce rate limits
- Identity verification: for marketplace deals above the KYC threshold only, the documents a verification provider collects. Reports are encrypted at rest and never rendered in the product
Data processed by BoostEcom Spy
The extension powers Spy, Page diagnostics and Tools. When you are signed in, account state is cached from boostecom.app:
- Page signals: storefront detection, theme, on-page metrics, script hosts and trackers, read on your device on the page you are on, plus the HTML or text of an element you select. Only the domain of the page is sent to boostecom.app, when you open the panel
- Optional captures: screenshots or crops made by the browser when you use the Page tab, the picker or the capture tool. They leave your browser only if you attach them to a conversation
- Account session cache: connection state, plan label and linked-store index, read from authenticated requests to www.boostecom.app
- Preferences and library: language and display settings (synchronized by Chrome across your profile), and your saved library in the extension's own storage on your device
The session lives in cookies on boostecom.app, never in the extension's own origin. Selections you initiate may be relayed to an open www.boostecom.app tab via postMessage. We do not sell this data.
Permissions, third-party requests, retention and the Chrome Web Store Limited Use statement are detailed in the extension privacy policy.
Storefronts we analyze that are not yours
Intelligence and the public scanner read storefronts that belong to other people. We read what those sites publish to any visitor, we identify ourselves as BoostEcom-Scanner/1.0 on every request, and the user-agent cites our bot policy.
If you own a storefront and do not want it in the graph, the opt-out is self-service and needs no account. It removes the record, its signals in the store graph, and its creatives.
Purpose of processing
- Provide the services: dashboard, chat, scanner, Studio, Intelligence, marketplace
- Manage accounts, organizations, roles and subscriptions
- Send transactional email: confirmation, billing, alerts, weekly digests
- Improve platform performance and reliability
- Ensure security, prevent abuse and enforce spend limits
- Operate the marketplace: listings, offers, deals, escrow and dispute mediation
Legal basis
Processing rests on:
- Contract performance (GDPR Art. 6.1.b): providing the subscribed services and operating marketplace transactions
- Legitimate interest (GDPR Art. 6.1.f): service improvement, security, abuse prevention, and analyzing publicly published storefront data, balanced against the opt-out above
- Consent (GDPR Art. 6.1.a): non-essential cookies, analytics and attribution
- Legal obligation (GDPR Art. 6.1.c): accounting retention, KYC and anti-money-laundering checks on marketplace deals
Sub-processors
More than thirty providers appear in the path of at least one feature. The full list (what each one does, where it runs, which data reaches it, and whether it is active by default) is published and generated from the codebase.
Data retention
Every period below is the one a scheduled job actually enforces. A test fails the build if a number here stops matching the code.
International transfers
Several sub-processors operate in the United States. Those transfers rely on the European Commission's standard contractual clauses and, where the provider is certified, the EU-U.S. Data Privacy Framework. The region of each provider is shown on the sub-processors page.
AI models and your content
Prompts, conversations and store data sent to a model travel through the Vercel AI Gateway to Anthropic, OpenAI or Google. We do not train models on your content, and we do not license it to anyone. Providers process it to return a response under their own commercial terms, which exclude training on API traffic.
Google API services
BoostEcom's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google data is used only to show it to you and to let @Atlas answer your questions about your own store. We do not sell it, we do not use it for advertising, and we do not use it to develop, improve or train generalized AI or machine learning models. The models that answer you process it under the terms described in “AI models and your content”.
Your rights, and where to exercise them
Under the GDPR you hold the rights below. Four of the six are self-service: use the link rather than writing to us, and the effect is immediate.
For anything not covered above, write to contact@boostecom.app. You may also lodge a complaint with the CNIL, the French data protection authority.
Last updated October 2, 2026