Privacy Policy
1. Who We Are
Vantemo is a software-as-a-service e-commerce platform that enables businesses to create and operate online stores.
Data controller:
Inovacijų dialogas, MB
Company registration number: 306672068
VAT number: LT100016637613
Registered address: P. Vileišio g. 15-25, LT-10306 Vilnius, Lithuania
Privacy contact: For all privacy-related enquiries, data subject requests, and complaints: [email protected]
We do not have a designated Data Protection Officer. The founder is responsible for GDPR compliance. If you cannot resolve your concern with us directly, you have the right to lodge a complaint with the Lithuanian State Data Protection Inspectorate (VDAI) at www.vdai.lrv.lt.
2. How This Policy Is Structured
Vantemo operates in two distinct roles depending on whose data is being processed:
Role A — Data Controller (for merchant data). When you sign up for Vantemo and use our platform as a merchant, we collect and process data about you directly. For this data, Vantemo is the Data Controller — we determine why and how your data is processed, and we are directly responsible to you under GDPR. This is covered in Sections 3–13 of this policy.
Role B — Data Processor (for end-customer data). When your customers visit your store and make purchases, their personal data flows through Vantemo's systems on your behalf. For this data, you (the merchant) are the Data Controller. Vantemo is the Data Processor — we process this data only on your instructions and under your responsibility. This relationship is governed by our Data Processing Agreement (DPA), not by this Privacy Policy.
If you are a shopper who bought something from a store powered by Vantemo, your data is controlled by that store's owner, not by Vantemo. Please contact that merchant directly with any privacy requests.
3. Data We Collect About Merchants
We collect the minimum data necessary to provide the platform and comply with our legal obligations.
3.1 Account data (collected at signup)
| Data | Why we collect it |
|---|---|
| Full name | To identify your account |
| Email address | Account access, communications, billing |
| Password (stored as a bcrypt hash — your actual password is never stored) | Authentication |
| Shop name and URL slug | To create your store and subdomain |
| Country | To determine applicable VAT rules for your subscription |
| Social sign-in details (if you register or log in with Google or Meta): email, name, profile picture, and the provider's account ID | Authenticating your account without a password |
Signing in with Google or Meta is optional. If you use it, Google or Meta acts as an independent controller for that authentication event — see Section 6.1.
3.2 Billing data (collected when you upgrade to a paid plan)
| Data | Why we collect it |
|---|---|
| Billing name and billing email | Issuing invoices and billing communications |
| Business address and VAT number (optional) — collected by Stripe during paid-plan checkout for tax calculation; held by Stripe, not stored in Vantemo's own systems | Tax compliance and invoicing |
| Payment method (processed by Stripe — we never see your raw card details) | Subscription billing |
| Subscription history and invoices | Accounting, billing disputes, legal obligation |
We do not separately collect or store a business legal name; invoices use your billing name together with any business details Stripe collects at checkout.
3.3 Shop and platform usage data
| Data | Why we collect it |
|---|---|
| Shop configuration (theme, settings, integrations) | Operating your store |
| Products, pages, blog posts you create | Operating your store |
| Admin session tokens (short-lived, stored in Redis) | Keeping you logged in securely |
| Dashboard usage patterns (which features you use, how often) | Improving the platform |
| Email communications we send you (via AWS SES) and delivery logs | Support, compliance |
The account and service emails we send you are not tracked for opens or clicks: we do not embed tracking pixels or wrap links in the messages sent to your account.
3.4 Technical and security data
| Data | Why we collect it |
|---|---|
| IP address | Security, fraud prevention, rate limiting |
| Browser and device type (user agent) | Security, debugging |
| Login attempts and admin actions (audit log) | Security, fraud detection, compliance |
| Error reports and performance traces (collected by Sentry — includes IP address, request URL, browser info, and stack traces) | Detecting and fixing crashes, platform stability |
Referral and attribution data (URL parameters such as gclid, utm_source, utm_medium, utm_campaign) | Marketing attribution; measuring advertising effectiveness |
3.5 Support correspondence
| Data | Why we collect it |
|---|---|
| Email content and metadata for support enquiries sent to our team | Resolving your support request |
3.6 Ad platform connection data (if you use Analytics features)
If you connect your Google, Meta, or TikTok advertising accounts to the Vantemo analytics dashboard, we store:
| Data | Why we collect it |
|---|---|
| OAuth access tokens for connected ad accounts | Fetching your ad spend data to display in your dashboard |
| Ad account IDs and campaign metadata | Syncing spend data for ROI reporting |
These tokens are stored encrypted at rest (AES-256-GCM). We use them to retrieve your own advertising data for your dashboard. If you also enable server-side conversion tracking for Meta, the same Meta connection token is additionally used to send your store's conversion events — which may include hashed customer identifiers and IP address — to Meta on your behalf; see our DPA for that processor relationship. (TikTok and Google Ads conversion tracking use separate credentials you provide, not this connection token.) You can disconnect any ad account at any time from your dashboard settings.
3.7 Data from Stripe Connect
If you connect Stripe to receive payouts from your store, Stripe collects and holds your bank account details, identity verification documents, and payout records directly. Vantemo stores only your Stripe account ID as a reference. Stripe's privacy policy governs that data: stripe.com/privacy.
3.8 AI-generated content data
If you use Vantemo's AI content generation features, we process:
| Data | Why we collect it |
|---|---|
| Product data and text submitted for AI generation | Sent to your chosen AI provider to generate content |
| AI provider selection and model preference | Operating the AI feature |
| Token usage counts (prompt + completion tokens) | Metering against your plan allowance |
| BYOK API keys (stored AES-256-GCM encrypted) | Authenticating with the provider on your behalf |
In BYOK (Bring Your Own Key) mode, your API key is encrypted at rest and never logged in plain text. Generated content is stored as regular shop data (covered by Section 3.3).
3.9 Phone number (SMS features)
If you enable SMS features with a custom sender ID, we collect and store your phone number.
| Data | Why we collect it |
|---|---|
| Merchant phone number | Verifying your SMS sender ID with a one-time code and preventing impersonation |
We send the verification code to your phone via Twilio (see Section 6.2).
3.10 Domain registration contact details
If you purchase a domain through Vantemo, ICANN rules require us to collect registrant contact details.
| Data | Why we collect it |
|---|---|
| Registrant name, email, phone number, and postal address | Registering the domain in your name (ICANN requirement) |
We transmit these details to our registrar, NameSilo (see Section 6.2), which forwards them to the domain registry operator and to ICANN-mandated data escrow. WHOIS privacy is enabled by default, so your registrant details are not published in public WHOIS records.
3.11 Job applicants (careers)
If you apply for a job at Vantemo through our careers pages, Vantemo is the data controller for your application data (this subsection is not about merchants or shoppers).
| Data | Why we collect it |
|---|---|
| First name, last name, email, phone number (optional) | Contacting you about your application |
| Your CV / résumé (uploaded file) | Evaluating your application for the role |
Résumé files are stored with our object-storage provider (Cloudflare — see Section 6.2).
We keep applications for 180 days from the date you apply, after which they are automatically deleted, unless you are hired. If you are hired, your application becomes part of your employment record and is retained for the duration of your employment and for 3 years after it ends, in line with the limitation period for employment-law claims under the Lithuanian Labour Code, after which it is deleted.
Our lawful basis for the processing that is objectively necessary to evaluate the application you submitted is that it is done to take steps at your request before we may enter into an employment contract (GDPR Article 6(1)(b)). For anything beyond that strict necessity — keeping your application on file for a limited period after a hiring decision, comparing it against other candidates, and maintaining the integrity of our recruitment records to establish, exercise or defend legal claims — we rely on our legitimate interests (Article 6(1)(f)), for which we have carried out a balancing test (see Section 4); where we rely on this basis you have the right to object at any time (Article 21). We do not ask for, and ask you not to include, special categories of data. If such information appears in your CV, we do not use it in our decision and will delete or redact it where practicable. You can ask us to delete your application at any time by emailing [email protected].
4. Legal Basis for Processing Merchant Data
GDPR requires us to have a lawful reason — a "legal basis" — for each type of processing.
| Processing activity | Legal basis | Explanation |
|---|---|---|
| Creating and maintaining your account | Contract performance (Art. 6(1)(b)) | Necessary to provide the service you signed up for |
| Issuing invoices and billing records | Legal obligation (Art. 6(1)(c)) | Lithuanian accounting law requires financial record retention |
| Sending transactional emails (invoices, security alerts, system notifications) | Contract performance (Art. 6(1)(b)) | Part of delivering the service |
| Sending product updates, tips, and marketing communications | Legitimate interest (Art. 6(1)(f)) | We have a genuine interest in communicating with active customers about the product they use. You can unsubscribe at any time. |
| Dashboard usage analytics | Legitimate interest (Art. 6(1)(f)) | We have a genuine interest in understanding how the platform is used to improve it |
| IP address logging, rate limiting, security audit logs | Legitimate interest + Legal obligation (Art. 6(1)(f) + (c)) | Security is a recognised legitimate interest under GDPR Recital 49 |
| Error monitoring and crash reporting (Sentry) | Legitimate interest (Art. 6(1)(f)) | Platform stability and security; recognised under GDPR Recital 49 |
| Processing your payments via Stripe | Contract performance (Art. 6(1)(b)) | Necessary to operate your subscription |
| AI content generation via third-party providers | Contract performance (Art. 6(1)(b)) | Feature of the service; triggered only when you explicitly request a generation |
For all legitimate interest processing, we have conducted a balancing test confirming that our interests do not override your rights and freedoms.
5. Tracking Technologies and Cookies on Vantemo.com
5.1 Strictly necessary cookies
We set one strictly necessary cookie: session_id — a secure, httpOnly, SameSite=Lax cookie that keeps you logged in to the admin dashboard. This cookie contains no personal data and expires after 8 hours. No consent is required for this cookie as it is essential for the service to function.
We also use Sentryfor error monitoring and performance tracing. Sentry's SDK runs in your browser and captures technical telemetry — unhandled errors, failed network requests, a sample of performance traces, and your IP address — and sends it directly from your browser to Sentry to help us detect and fix crashes. This runs under legitimate interest and is essential for platform stability and security. Sentry's error monitoring does not set any cookies. Sentry Session Replay — an optional feature that records page interactions — is not loaded unless you accept analytics cookies (see Section 5.2).
Functional cookies (dashboard). The admin dashboard sets a few first-party cookies to remember your interface preferences: last_shop_handle (which store you last worked on), admin:sidebarWidth, admin:chatWidth, and admin:chatOpen. These contain no personal data — only a store handle, layout sizes, and an open/closed flag — and exist purely to keep the dashboard laid out the way you left it. See our Cookie Policy for their durations.
Dashboard usage analytics (Section 3.3) is collected under legitimate interest and does not require consent. The consent banner on vantemo.com applies only to optional analytics cookies (Section 5.2).
5.2 Analytics cookies (consent required)
When you visit vantemo.com, we use PostHog for product analytics and feature adoption analysis. Your analytics data is hosted on PostHog Cloud EU (Frankfurt, Germany); the vendor, PostHog Inc., is a US company. PostHog collects usage data to help us understand how the marketing site is used and improve it.
We only activate PostHog after you give your explicit consent via our cookie consent banner. You can withdraw consent at any time by clicking "Cookie Settings" in the website footer, which will reopen the consent banner.
If you decline analytics cookies, only the strictly necessary trackers described in Section 5.1 above will run.
For a full list of cookies, their names, durations, and providers, see our Cookie Policy.
5.3 Cookie consent on merchant storefronts
If you are visiting a store powered by Vantemo (not vantemo.com itself), cookie management is the responsibility of that store's owner. Please refer to that store's own cookie policy. Vantemo provides store owners with tools to implement GDPR-compliant consent banners on their storefronts.
In addition to any cookies a merchant configures, the Vantemo platform itself sets a small number of cookies on storefronts: a session cookie for logged-in shoppers (customer_session), and a _fbcclick-attribution cookie that is set whenever a visitor arrives via a link carrying Meta's click identifier (fbclid). The _fbccookie is set across storefronts on that basis and does not depend on the merchant's own pixel configuration. Merchants remain responsible for obtaining any consent required for tracking cookies on their storefront.
6. Third Parties We Share Your Data With
6.1 Independent Data Controllers
These companies receive certain data and process it for their own purposes under their own privacy policies. They are not acting on our instructions.
| Company | What we share | Their privacy policy |
|---|---|---|
| Stripe Inc. | Billing data, payment processing | stripe.com/privacy |
| Google LLC | Authentication event when you sign in with Google (email, name, profile) | policies.google.com/privacy |
| Meta Platforms, Inc. | Authentication event when you sign in with Meta (email, name, profile) | facebook.com/privacy/policy |
6.2 Data Processors (Sub-processors)
These companies process data only on our instructions, under contract, and only for the purposes we specify. See our full sub-processor list for details.
| Company | Country | What they process | Transfer mechanism |
|---|---|---|---|
| Amazon Web Services (SES) | EU (eu-north-1, Stockholm) | Email delivery — your email address and email content | EU-based processing, no international transfer (AWS's US parent is DPF-certified as a residual safeguard) |
| Cloudflare Inc. | USA | CDN, DDoS protection, and object storage (media, invoice PDFs, résumé uploads) — IP addresses, request metadata, and stored files | EU-US DPF + SCCs |
| PostHog Inc. (vantemo.com marketing analytics) | EU (PostHog Cloud EU, Frankfurt); vendor is a US company | Product analytics for the vantemo.com marketing site | EU-based hosting, no international transfer (DPF + SCCs cover any US vendor support access) |
| PostHog Inc. (dashboard product analytics) | USA | Product-usage analytics for the merchant dashboard | EU-US DPF + SCCs |
| Sentry (Functional Software Inc.) | USA | Error monitoring, performance tracing — IP address, request metadata, stack traces | EU-US DPF + SCCs |
| Twilio Inc. | USA | SMS delivery — merchant sender-ID verification (OTP) and, where enabled, customer cart-recovery messages | EU-US DPF + SCCs |
| DeepL SE | Germany / EU | Machine translation of shop content — product and category text | EU-based when DeepL is used; translation may fall back to OpenAI (USA) under the OpenAI SCCs (see the OpenAI row) |
| NameSilo LLC | USA | Domain registration — registrant contact details (name, email, phone, address) | SCCs |
| Anthropic PBC | USA | AI content generation and the AI store-management assistant's access to your store records, which may include order and customer names and emails (Platform mode) | SCCs |
| OpenAI Inc. | USA | AI content generation and text embeddings used by the AI assistant's search (Platform mode) | SCCs |
| Google LLC (Gemini API) | USA | AI content generation — text submitted for generation (Platform mode only) | EU-US DPF + SCCs |
| Hostinger | Lithuania / EU | VPS infrastructure — all platform data | EU-based, no transfer |
Some of these sub-processors engage their own downstream sub-processors (for example, their hosting or infrastructure providers). We keep an up-to-date record of the full processing chain, available on request, and require each sub-processor by contract to impose equivalent data-protection obligations on its own sub-processors (per EDPB Opinion 22/2024).
In BYOK mode, data is processed under your own agreement with the provider; Vantemo does not act as a processor for that data flow.
We will notify you by email at least 30 days before adding or replacing a sub-processor. See our DPA for full details.
We do not sell your personal data to any third party. Ever.
7. International Data Transfers
Vantemo is based in Lithuania (EU) and stores its primary data on servers located within the European Union. Several of our sub-processors also process data entirely within the EU/EEA — including AWS SES (Stockholm, eu-north-1), PostHog's vantemo.com marketing analytics (PostHog Cloud EU, Frankfurt), and Hostinger (Lithuania) — so no international transfer occurs for those flows. Machine translation is provided by DeepL in the EU but can fall back to OpenAI in the United States (see Sections 6 and 10).
Some of our sub-processors are based in the United States. Where personal data is transferred to the USA, we ensure adequate protection through:
- EU-US Data Privacy Framework (DPF) — where the recipient is DPF-certified (Cloudflare, Google, Stripe, Sentry, Twilio, and PostHog are DPF-certified)
- Standard Contractual Clauses (SCCs) — the EU Commission's standard data transfer contracts, in place with our US sub-processors as an additional safeguard
Anthropic, OpenAI, and NameSilo are not DPF-certified; transfers to them are protected by SCCs as the primary mechanism.
You can request a copy of the relevant SCCs by contacting [email protected].
8. Data Retention
We keep your data only as long as necessary.
| Data category | Retention period | Reason |
|---|---|---|
| Financial records (invoices, billing history, subscription records, order records) | 10 years from creation | Mandatory under Lithuanian accounting law (Finansinės apskaitos įstatymas / Law on Financial Accounting, No. IX-574) |
| Account and shop data (profile, shop content, configuration) | Until account deletion, then deleted within 30 days. Free-tier stores that stay inactive are suspended around day 90 and, after further warnings, deleted around day 210 from your last dashboard activity | No longer needed; free-tier inactivity lifecycle (see our Terms of Service) |
| Storefront analytics (your customers' page views and store events — processed on your behalf as your data processor under the DPA, not your own dashboard usage) | Page views and clicks are deleted after 365 days; purchase and refund events are kept for the life of the store | Store analytics and reporting |
| Admin session tokens | Your session token lives in Redis with an 8-hour sliding expiry. A backup copy of each session (token, IP address, device) is stored in our database; once a session has expired, its record — including the token — is cleared and deleted 90 days after expiry | Keeping you logged in securely; session recovery and security auditing |
| IP address and rate-limit logs | 90 days | Security, industry standard |
| Administrative-action audit logs (records of admin actions, including IP address and device) | Retained for a maximum of 12 months, except records placed under a legal hold for an active investigation, dispute or regulatory request, which are kept until the hold is lifted | Security, fraud detection, compliance |
| Email delivery and event logs | 90 days | Delivery troubleshooting |
| Email audit logs (records of emails we have sent) | 365 days | Compliance, delivery disputes |
| Error reports and performance traces (Sentry) | 90 days | Debugging, platform stability |
| AI assistant conversation history (your messages to the AI assistant, its replies, and any store records it retrieved to answer you — which may include end-customer personal data) | Deleted when you close your account, and otherwise deleted 12 months after the conversation's last activity. The recent-message window kept for each conversation is limited in size, and the rolling summary is a bounded-size digest (regenerated, not accumulated) | Conversation continuity; safety and abuse investigation |
| AI safety logs (records of AI events we blocked or flagged, including a short, truncated excerpt of the message that triggered them) | Deleted when you close your account. Otherwise, the raw user-message excerpt and any captured secret snippet are purged at 12 months, and the remaining record (event type and metadata) is deleted in full at 24 months | Platform safety, abuse detection, incident analysis |
| AI store/brand memory (facts the assistant extracts about your store to personalise its help) | Deleted within 30 days of account closure. It holds only a bounded set of operational facts (deduplicated against a fixed list of fields and refreshed as you use the assistant, not an accumulating log), so no separate age-based limit applies (GDPR Art. 5(1)(e)) | Personalising the AI assistant |
| AI-generated draft images (any Studio image generations you have not saved to your Media Library) | Unsaved drafts are deleted after 7 days; images you save are kept until you delete them | Lifecycle of any stored image data (AI image generation is not currently offered — see Section 10.4) |
| Marketing opt-out preferences | Kept for as long as needed to honour your opt-out | So we continue to respect your opt-out (GDPR Art. 21(3)) |
| Account-deletion audit records (a record that your account was deleted, including the terms you accepted) | The stored email address is destroyed (set to null) within 30 days of deletion; the non-personal record — that a deletion occurred, plus non-identifying counts — is kept as an accountability record | Demonstrating we handled your deletion lawfully (GDPR Art. 5(2)) |
| Cookie consent records | Persistent (stored locally in your browser) | Proof of consent |
| Backups containing personal data | Purged within 90 days of primary deletion or anonymisation | Backup rotation; ensures deleted data does not persist indefinitely in backups |
When you delete your account: Your personal data is deleted or anonymised within 30 days, except where we are required to keep it. Backups containing your deleted data are purged within 90 days of the primary deletion. Financial records required by law are retained for 10 years: we remove your email from these records, but the name, address, VAT ID and company code are retained where they are required for a valid invoice under accounting law; amounts, dates, and transaction IDs are preserved for accounting purposes. We also keep a minimal account-deletion audit record (see the retention table above).
9. Your Rights Under GDPR
As a data subject, you have the following rights. To exercise any of them, contact [email protected]. We will respond within one month (GDPR Art. 12).
| Right | What it means |
|---|---|
| Right of access (Art. 15) | Request a copy of all personal data we hold about you |
| Right to rectification (Art. 16) | Ask us to correct inaccurate data |
| Right to erasure (Art. 17) | Ask us to delete your data (subject to legal retention obligations) |
| Right to data portability (Art. 20) | Receive your data in a machine-readable format (JSON or CSV) |
| Right to object (Art. 21) | Object to processing based on legitimate interest, including direct marketing |
| Right to restrict processing (Art. 18) | Ask us to pause processing while a dispute is resolved |
| Right to withdraw consent | Where processing is based on consent, withdraw it at any time (e.g. via cookie settings or email unsubscribe) |
Automated decision-making: We do not make solely automated decisions that produce legal or similarly significant effects on you (GDPR Art. 22). We do use automated analysis to estimate account health and churn risk — for example, from how recently you have logged in or received orders — to decide when to send you account-health and re-engagement messages. This never produces legal or similarly significant effects: at most it triggers a reminder email or an in-app notification, never a change to your pricing, access, or account status. You can object to this profiling for direct-marketing purposes at any time (GDPR Art. 21(2)). AI content generation features (Section 10) are tools that assist you — they do not make decisions about you or your account.
Direct marketing: You have an absolute right to object to direct marketing at any time (GDPR Art. 21(2)). We will stop immediately upon receiving your objection — no balancing test applies.
Self-service options: You can delete your account at any time from Settings → Profile in your admin dashboard. To receive a copy of your data (data portability), email [email protected] and we will provide it in a machine-readable format.
If you are an end-customer of a Vantemo-powered store (not a Vantemo merchant): your rights must be exercised with the store owner, who is the Data Controller for your data. Vantemo cannot fulfil erasure or access requests for data we process only as a processor on the merchant's behalf. If the merchant is unresponsive, contact us at [email protected] and we will assist in forwarding your request.
10. Artificial Intelligence and Automated Processing
Vantemo offers AI features in two distinct forms, which process data differently. This section explains what each one does, which providers are involved, and how we handle the data.
10.1 How AI features work
(a) The AI store-management assistant. Your dashboard includes an AI assistant (a chat interface) that helps you run your store. When you ask it something, it can call internal tools that read your live store data to answer — and that data can include your end-customers' personal data (for example, customer names, email addresses, phone numbers, shipping and billing addresses, and order details). The records needed to answer your request are sent to our AI provider Anthropic (Claude). A single message you send can trigger an automatic, multi-step pipeline — an automated safety screen, intent routing, retrieval of relevant store and help-centre content, and a rolling conversation summary — so the assistant is not a single, isolated request per click. The assistant can also take actions in your store and draft or publish content when you instruct it to. Higher-impact changes — such as creating products, changing prices, updating order status or inventory, or cancelling a subscription — require you to confirm before they take effect. Other changes, including content it drafts and publishes (for example, blog posts, storefront copy, product descriptions, and SEO), are applied directly without a separate confirmation step, so you should review what it produces. To personalise its help, the assistant also extracts and stores a small set of persistent facts about your store and brand (a "store memory") that it reuses across your conversations.
(b) Content-generation tools. Separately, Vantemo offers merchant-initiated tools that generate content on request — product descriptions, marketing copy, and replies to customer reviews. (Vantemo does not currently offer AI image or ad-creative generation — see Section 10.4.) You trigger these, you submit the input, and the output is returned to your dashboard for your review before you use it. Most of them process only the text you submit. One exception: when you use the tool to draft a reply to a customer review, that customer's review text and author name (your end-customer's personal data) are sent to the selected AI provider to generate the reply.
Both forms operate in two modes:
- Platform mode — uses Vantemo's own provider API keys, subject to tier-based usage limits.
- BYOK ("bring your own key") mode — uses your own provider API key with no platform limits. In BYOK mode, your relationship with the AI provider is governed by your own agreement with that provider, not by Vantemo's platform terms.
10.2 AI providers and how each is used
For content generation, you choose your provider (Anthropic, OpenAI, or Google Gemini) in Settings → AI, and you can switch at any time. Some functions always use a fixed provider: the store-management assistant chat always uses Anthropic (Claude); the text embeddings behind the assistant's knowledge search always use OpenAI; and machine translation of your store content uses DeepL, falling back to OpenAI (in the United States) if DeepL is unavailable.
| Provider | What it receives | Training | Provider retention |
|---|---|---|---|
| Anthropic (Claude) | Assistant chat — including store records that may contain end-customer personal data — and any content-generation input you submit; and, for AI-drafted review replies, the customer's review text and author name | Not used to train Anthropic's models | Not retained by default under Anthropic's API terms; inputs/outputs flagged by Anthropic's automated trust-and-safety systems may be kept for up to 2 years |
| OpenAI | Text embeddings for knowledge search (your typed queries and platform help content); any content-generation input you submit; store content submitted for translation when DeepL is unavailable (fallback); and, for AI-drafted review replies, the customer's review text and author name | Not used to train OpenAI's models (API data) | Per OpenAI's API terms (currently up to ~30 days for abuse monitoring) |
| Google (Gemini) | Content-generation input you submit (text); and, for AI-drafted review replies, the customer's review text and author name | Not used to train Google's models (paid API) | Per Google's API data-use terms |
| DeepL | Your store content submitted for translation (product and category text) — no end-customer data | Not used to train DeepL's models (Pro API) | Per DeepL's Pro API terms |
Vantemo accesses each of these providers through their business/paid API tiers, under which submitted content is contractually excluded from model training. Because you select a single content-generation provider per store (and can switch at any time), the list above is a superset: any individual store's content-generation data reaches at most one of these providers at a time. (The fixed-provider functions noted above — assistant chat via Anthropic, and embeddings and translation-fallback via OpenAI — apply regardless of that selection.)
10.3 Data transfers
- Anthropic and OpenAI (USA): Standard Contractual Clauses (not DPF-certified).
- Google (USA): EU-US Data Privacy Framework and Standard Contractual Clauses.
- DeepL (Germany, EU): store-content translation is processed within the EEA when DeepL is used — no international transfer. If translation falls back to OpenAI (United States) because DeepL is unavailable, the OpenAI safeguards above (Standard Contractual Clauses) apply.
See Section 7 for full details on the safeguards for international data transfers.
10.4 Human oversight, transparency, and the EU AI Act
For the AI features we build into the platform — the assistant, content generation, AI-drafted review replies, and translation — Vantemo is a provider of those AI systems under Regulation (EU) 2024/1689 (the EU AI Act), because we put them into service under our own name using third-party foundation models that we do not train. We act as a deployer where we use AI systems under our own authority. The providers of the underlying foundation models remain responsible for their own obligations, including any machine-readable marking of generated outputs at the model level.
- Where you interact with an AI system (the assistant) or view AI-generated content, you are informed that AI is involved, and AI-generated content is identified as AI-generated where required (Art. 50 transparency obligations, which apply from 2 August 2026).
- Where an AI feature is used to generate or manipulate image, audio or video content that constitutes a "deep fake" of a real, identifiable person, we will disclose that the content has been artificially generated or manipulated (Art. 50(4)).
- Content-generation output is returned to you for review before use. The assistant can also act in your store: higher-impact changes require your confirmation before they take effect, while content it drafts and publishes (such as blog posts and storefront copy) is applied directly without a separate confirmation step (see Section 10.1) — so you should review what it produces.
- We keep records of AI interactions (conversation history and safety logs) as described in Section 8.
- You remain responsible for any downstream disclosure to your own customers that applicable law requires.
How we mark AI-generated text. For text our AI features generate — such as product descriptions, blog posts, storefront section copy, and AI translations of that content — we attach an invisible, machine-readable indicator that the text is AI-generated. It is carried in the page's structured data (the metadata that search engines and other software read), not shown as a visible label to shoppers. This marking is go-forward only (it applies to content generated after the feature launched, and is not yet uniform across every storefront template), and, because the indicator lives in the page's structured data rather than being embedded in the text itself, it does not travel with the text if it is copied and pasted elsewhere. This is a best-effort, machine-readable provenance record rather than an in-band text watermark; the reasons for that approach are explained in our AI Content guidance (docs/legal/ai-content-guidance.md). We do not currently offer AI image, audio or video generation, so there is no such AI-generated media output for us to mark.
The Art. 50 transparency and marking duties apply from 2 August 2026. Where an AI feature is first placed on the market or put into service on or after 2 August 2026, the machine-readable-marking duty under Art. 50(2) applies from its launch. A proposed grace period to 2 December 2026 for that marking duty is contained in the EU "Digital Omnibus" package amending Regulation (EU) 2024/1689 (adopted by the Council on 29 June 2026; Official Journal publication pending, so it is not yet in force) — until it is published, the original AI Act timeline governs.
10.5 What our AI features do NOT do
- No solely-automated decisions with legal or similar effect — we do not use AI to make automated decisions about your account, such as pricing, access levels, or suspension. Any store "health" or churn indicator you see in your dashboard is produced by fixed, rule-based logic, not AI.
- No AI scoring of you as a merchant — apart from the store/brand "memory" the assistant keeps to personalise its help (see Section 10.1), we do not use AI to profile or score you for pricing, credit, eligibility, or enforcement.
- No training on your data — the providers do not use your submitted content to train their models (see Section 10.2).
- No retention beyond what is necessary — the AI providers keep data only for their stated trust-and-safety or abuse-monitoring periods. We keep the AI interaction records described in Section 8 only for the retention periods stated there: conversation history is deleted 12 months after its last activity (and on account closure), and safety-log content is purged on a tiered 12- and 24-month schedule. We do not keep them longer than necessary, except where longer retention is required by law or court order, or is reasonably necessary to protect the service, our users, or third parties.
11. United States Regional Privacy Notice
11.1 Scope
This section provides additional disclosures required under US state privacy laws, including the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), Virginia Consumer Data Protection Act (VCDPA), Colorado Privacy Act (CPA), Connecticut Data Privacy Act (CTDPA), and similar state laws. This section applies if you are a US resident.
11.2 Categories of personal information
We collect the categories of personal information described in Section 3, which map to the following CCPA categories: identifiers (name, email, IP address), commercial information (billing and subscription data), internet or electronic network activity (usage data, error logs), and professional or employment-related information (business details provided at signup).
11.3 Sale and sharing
We do not sell your personal information. We do not share your personal information for cross-context behavioural advertising. We have not sold or shared personal information in the preceding 12 months.
11.4 Your rights under US state laws
| Right | Description |
|---|---|
| Right to know | Request disclosure of what personal information we collect, use, and disclose |
| Right to delete | Request deletion of your personal information |
| Right to correct | Request correction of inaccurate personal information |
| Right to opt out of sale/sharing | We do not sell or share your data, but you may still exercise this right |
| Non-discrimination | We will not discriminate against you for exercising your privacy rights |
To exercise these rights, contact [email protected]. We will respond within 45 days as required by applicable law.
11.5 Global Privacy Control
We do not sell your personal information and we do not share it for cross-context behavioural advertising, so there is no sale or sharing for you to opt out of. If your browser sends a Global Privacy Control (GPC) signal, we recognise it as a valid opt-out request — but because we already never sell or share personal information, every visitor is treated as opted out by default.
11.6 Service provider role
For end-customer data processed on behalf of merchants, Vantemo acts as a "service provider" (as defined by CCPA). See Section 2 for details on our controller/processor roles.
11.7 Authorized agents
You may designate an authorized agent to submit privacy requests on your behalf. We may require verification of the agent's authority before processing the request.
12. Children
Vantemo is a business platform. Merchant accounts are restricted to individuals aged 18 or over. We do not knowingly collect personal data from anyone under 18.
If you are aware that a person under 18 has created a Vantemo merchant account, please contact [email protected] and we will delete the account.
Regarding end-customers of merchant storefronts: merchants are prohibited under our Terms of Service from knowingly collecting personal data from individuals under 16 without implementing appropriate parental consent mechanisms. Vantemo is not responsible for a merchant's compliance with this obligation.
13. Security
We implement appropriate technical and organisational measures to protect your data, including:
- Encrypted connections (HTTPS/TLS) for all data in transit
- Passwords stored as bcrypt hashes — never in plain text
- httpOnly, Secure, SameSite session cookies — not accessible to JavaScript
- Optional two-factor authentication (TOTP) for merchant accounts, with AES-256-GCM-encrypted secrets and single-use backup codes
- Rate limiting and layered brute-force protection on authentication endpoints
- Audit logging of administrative actions
- Regular security reviews
- Access controls limiting data access to authorised personnel only
No system is perfectly secure. In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the Lithuanian State Data Protection Inspectorate (VDAI) within 72 hours and notify you without undue delay. If a data breach originates at one of our sub-processors, we will notify you as soon as we are informed and cooperate fully in mitigation.
14. Changes to This Policy
We may update this Privacy Policy from time to time. When we do:
- The "Last updated" date at the top of this page will change
- For significant changes, we will notify you by email at least 30 days before the change takes effect
- Previous versions are available on request — email [email protected]
If a change materially affects how we process your personal data, we will seek your explicit consent where required by law before that change takes effect.
15. Complaints
If you believe we have handled your personal data incorrectly, please contact us first at [email protected]. We will do our best to resolve your concern within one month.
If you are not satisfied with our response, you have the right to lodge a complaint with the supervisory authority:
Lithuanian State Data Protection Inspectorate (VDAI)
L. Sapiegos g. 17, LT-10312 Vilnius
[email protected]
www.vdai.lrv.lt
If you are located in another EU/EEA country, you may also contact your local DPA.
16. Contact
Inovacijų dialogas, MB (trading as Vantemo)
P. Vileišio g. 15-25, LT-10306 Vilnius, Lithuania
[email protected]