Privacy Policy

Last updated: August 21, 2026

This page explains how we process and protect personal data across the NeuroCheckout website and services.

Contact details and responsible entity

Responsible entity
NeuroCheckout
Contact email
[email protected]

1. Scope of this policy

This policy explains how NeuroCheckout uses and protects personal data.

We operate a B2B service and primarily process professional contact, account, and security data, with limited direct collection.

We apply data minimization: only data needed for declared purposes, enabled features, and security or legal obligations is processed.

We do not use this data for unrelated purposes without a valid basis, merchant instruction, or appropriate notice.

2. Data we collect directly

We collect only the data needed to run the service, provide support, and keep the platform secure.

  • Business contact data: name, email, company, phone (if provided).
  • Account data: login identifier, hashed password, language, login history.
  • Technical and security data: IP, technical logs, browser, anti-abuse diagnostics.
  • Support data: contact form content (including Talk to an expert), optional attachments, resolution tracking.
  • Contractual and billing data: minimum data required by payment providers.

3. Customer store data and roles

When a merchant connects a store, NeuroCheckout processes the e-commerce data required to run AI agents: customers, carts, orders, products, browsing events, campaigns, emails, and conversion signals.

This data is used to generate recommendations, recovery emails, segments, alerts, and performance metrics for the connected store.

For orders and purchase journeys, processed data may include order or cart identifiers, dates, statuses, amounts, currencies, line items, quantities, attribution signals, recovery events, and contact information strictly needed for actions authorized by the merchant.

  • The merchant remains the controller for its store data and end-customer data.
  • NeuroCheckout acts as a processor/service provider under contract, enabled features, and merchant instructions.
  • Access to store data is governed by the applicable terms and, where required, a data processing agreement with the merchant.
  • We limit processing to data needed by enabled agents and result measurement.
  • Data is used for analytics, personalization, and recovery actions authorized by the merchant.
  • We respect consent, unsubscribe, objection, and opt-out preferences communicated by the store or its tools.
  • We do not sell this data and do not contact end customers outside actions authorized by the store.
  • We do not use this data to make automated decisions that produce legal or similarly significant effects for end customers.

4. Purposes of processing

We use personal data to:

  • Create and administer accounts.
  • Deliver SaaS features and customer support.
  • Attribute conversions, measure recovered revenue, and display e-commerce performance metrics.
  • Personalize recovery actions, recommendations, and agent priorities based on cart, product, order, segmentation, and available consent context.
  • Orchestrate marketing or recovery actions authorized by the merchant without exceeding received consent preferences.
  • Apply consent, unsubscribe, and objection preferences received from connected stores.
  • Protect the platform (fraud prevention, abuse prevention, and incident response).
  • Measure and improve service quality in a proportionate way.
  • Comply with contractual and legal obligations.

5. Legal grounds

Depending on the situation, processing is based on:

  • Contract performance or pre-contractual steps.
  • Legitimate interests (security, abuse prevention, service quality).
  • Consent where required (for example non-essential cookies).
  • Merchant instructions and, for end-customer marketing communications, consent or opt-out signals transmitted by the store or its tools.
  • Compliance with legal obligations.

6. Data sharing

We do not sell personal data or share it with third parties for resale. Sharing is limited to technical and operational needs.

  • Hosting, security, authentication, support, and messaging providers.
  • Payment and billing providers where relevant.
  • Providers bound by confidentiality, security, and data protection obligations appropriate to their role.
  • Competent authorities when legally required or to protect rights.

7. Data retention

We use retention periods by category and retain data only for a reasonable period aligned with the purposes described, then delete or anonymize it.

  • Active accounts: for the duration of the contractual relationship, then limited retention.
  • Contact and support requests: for the time needed to process them, then a limited archive period.
  • Connected store data: deletion or anonymization after disconnection, uninstall, or a valid merchant request, subject to applicable legal and security requirements.
  • Technical logs, consent records, and security traces: limited retention for evidence, diagnostics, security, and compliance.
  • Legal and accounting records: statutory retention periods where applicable.

8. Data security

We apply safeguards designed to protect confidentiality, integrity, and availability of account, store, end-customer, and order data.

Data from connected stores is processed in a controlled environment, with access restricted to technical, support, or security needs.

  • Encryption in transit and encryption at rest where supported by the storage infrastructure; access controls, logging, and traceability for sensitive processing.
  • Logical separation by store, environment segmentation, and least-privilege access model.
  • Human access limited to support, supervision, maintenance, or security needs.
  • Security monitoring, backups, incident response procedures, and progressive minimization of data no longer needed.

9. Your rights

Depending on your jurisdiction, you may exercise rights of access, correction, deletion, objection, restriction, and where applicable portability.

For end-customer data from a connected merchant store, the first contact point is generally that merchant.

We support our customers in handling these requests when required under contract, including deletion, anonymization, objection, unsubscribe, and opt-out requests.

End customers can also use unsubscribe or opt-out mechanisms offered by the merchant or communication channel; we apply the signals received.

10. Cookies and similar technologies

We primarily use essential technical cookies required for website operation.

Limited analytics cookies may be used depending on configuration and applicable consent rules.

Visitors can accept or reject analytics or marketing cookies when available; choices are stored for a limited period.

11. Children data

Services are not intended for direct use by children.

If child data is reported as collected inappropriately, we will take appropriate action.

12. Updates and contact

This policy may be updated to reflect legal, technical, or operational changes.

For any question or request regarding personal data, please contact us at: [email protected].

We will handle requests within a reasonable timeframe in line with applicable legal requirements.