Legal
Privacy Policy
Last updated: 21 April 2026
This Privacy Policy explains how EcomBase (operated by HHS Holding, info@hhsholding.com, the Netherlands — hereafter "EcomBase", "we", "us") collects, uses, stores and shares personal data when you use the EcomBase platform at ecombase.ai(the "Service"). Effective 21 April 2026.
EcomBase is a software-as-a-service platform that connects to your e-commerce stores and ad platforms to generate creatives, analyse performance and automate reporting. This policy covers both the people who sign in to EcomBase ("Users") and the customers or contacts of our Users whose data passes through the Service ("End Customers").
1. Quick summary
- We only collect data needed to run the Service you asked for.
- We never sell your data. We never train generative models on it.
- We share data only with subprocessors listed in section 7, under data-processing agreements that enforce this policy.
- You can export or delete your account at any time from
/settings/me/dangeror by emailing info@hhsholding.com. - Meta user-data deletion instructions are on the data deletion page.
2. Who is the data controller
For data about EcomBase Users, HHS Holding is the controller. For End Customer data that Users import into the Service (for example Shopify customer records or Meta Ads audiences), HHS Holding acts as a processor on behalf of the User, who remains the controller under the GDPR and equivalent laws.
3. What data we collect
3.1 Account & profile data
- Name, email address, profile picture, language — obtained via Google Sign-In when you create an account.
- Team membership, roles, per-shop access grants, invitation tokens.
- Audit log of security-relevant actions (who invited whom, who connected which platform, who deleted which shop).
3.2 Integration tokens
- OAuth access tokens + refresh tokens for connected platforms — Shopify, Meta, Google, Pinterest, TikTok, Google Calendar.
- All tokens are encrypted at rest with AES-256-GCM. You can disconnect any integration at any time from the Shop integrations screen.
3.3 E-commerce data imported on your behalf
- Shop identity (domain, currency, plan), products, collections and product images (public catalog metadata).
- Orders and order lines when the Shopify Orders sync is enabled — including customer email, addresses on the order, financial and fulfilment status, line items and refunds.
- Ad campaigns, ad sets, creatives, budgets and daily performance metrics (spend, impressions, clicks, conversions, revenue) pulled from connected ad platforms.
3.4 Usage & device data
- Session metadata, IP address, user agent, referrer — used for authentication, abuse detection and basic product analytics.
- In-app events (page navigated, button clicked, sync triggered) to improve the product. We do not profile End Customers.
3.5 Content you create
- AI-generated ad creatives, business plans, notes, tasks, comments, calendar events, P&L entries and AI advisor chat transcripts.
3.6 What we do NOT collect
- Payment card numbers, CVV, full bank details — payments (if any) are handled by our payment processor.
- Special-category data (health, political, religious, biometric) — if you upload such data it is done against our terms.
4. Why we use your data (legal bases)
| Purpose | Legal basis (GDPR art. 6) |
|---|---|
| Providing the Service you signed up for | Contract (6 (1) b) |
| Fraud & abuse prevention, security monitoring | Legitimate interest (6 (1) f) |
| Product analytics & improvement | Legitimate interest (6 (1) f) |
| Legal & tax obligations | Legal obligation (6 (1) c) |
| Marketing email newsletters (opt-in) | Consent (6 (1) a) |
5. AI processing
When you ask EcomBase to generate ad creatives, copy or analyses, we send the relevant inputs to third-party AI providers (Anthropic, Google, Fal.ai) purely to fulfill your request. These providers are contractually obliged not to train their models on our API traffic and to retain the data only as long as necessary to return the output.
You can see exactly what context a given generation used, and delete the corresponding chat / asset at any time. EcomBase never passes End Customer personal data to AI providers unless you explicitly opt into a feature that requires it (for example, a personalised creative).
6. Who we share data with
We share data with three categories of parties:
- Subprocessors — infrastructure we rely on to run the Service (see section 7).
- Ad / commerce platforms you chose to connect — requests we make on your behalf (e.g. pulling your Meta campaign stats) share the minimum data necessary. EcomBase does not push End Customer PII to these platforms unless you explicitly enable a feature that requires it.
- Law enforcement or regulators, where compelled by valid legal process.
We do not sell personal data to anyone.
7. Subprocessors
| Subprocessor | Purpose | Region |
|---|---|---|
| Vercel Inc. | Application hosting & edge network | US / EU |
| Neon Inc. | Managed PostgreSQL database | EU |
| Vercel Blob | Object storage for uploads and generated assets | Global CDN |
| Resend Inc. | Transactional email delivery | US |
| Anthropic PBC | Claude AI model inference | US |
| Google LLC | Gemini AI inference, Google Sign-In, Google Calendar API, Google Ads API | US / EU |
| Fal.ai (Fal Inc.) | Image / video generation inference | US |
| Meta Platforms Inc. | Meta Ads API (only when connected) | US / EU |
| Pinterest Inc. | Pinterest Ads API (only when connected) | US |
| TikTok Pte. Ltd. | TikTok Business Ads API (only when connected) | Ireland / US |
| Shopify Inc. | Shopify Admin API (only when connected) | Canada / EU |
For subprocessors outside the EEA, transfers rely on the EU Standard Contractual Clauses (SCCs) and, where applicable, the EU-US Data Privacy Framework certification held by the subprocessor.
8. How long we keep data
- Account data: kept while your account is active and for 30 days after closure, then permanently deleted.
- Integration tokens: deleted immediately when you disconnect the integration or close the account.
- Imported shop / ad data: kept while your shop is connected; when you hard-delete a shop, associated rows are removed within 24 hours.
- Audit logs: kept for 12 months for security purposes, then purged.
- Invoices and tax-relevant records: retained for 7 years as required by Dutch law.
9. Your rights
Depending on your location (EEA, UK, Switzerland, California, Brazil, Canada and others), you have some or all of the following rights:
- Access — get a copy of the data we hold about you.
- Rectification — fix inaccurate data.
- Erasure — ask us to delete your data (see section 10).
- Restriction — pause our processing while we investigate a complaint.
- Portability — receive your data in a machine-readable format.
- Objection — object to processing based on legitimate interest.
- Withdrawal of consent — for anything we rely on consent for.
- Lodging a complaint — with your local supervisory authority (in the Netherlands: Autoriteit Persoonsgegevens).
To exercise any right, email info@hhsholding.com. We respond within 30 days (usually much faster). We may verify your identity before acting on the request.
10. Data deletion
You can delete data yourself:
- A connected shop: Shops → … → "Delete permanently" — typed confirmation required.
- An ad platform integration: Shops → the shop → Connected platforms → Disconnect on the platform card.
- Your entire account: Settings → Danger zone → "Delete account".
To request deletion via email (for example because you cannot sign in), write to info@hhsholding.com with subject "Delete my data". See also the dedicated Data deletion page.
Data portability (Art. 20): signed-in users can download every piece of data Ecombase holds about them from Settings → Danger zone→ "Download my data (JSON)". Rate-limited to one export per hour.
B2B customers: a GDPR Art. 28 Data Processing Agreement (DPA) template is available at /dpa. Counter-signed copies for enterprise contracts via legal@hhsholding.com.
11. Google API Services — Limited Use disclosure
EcomBase's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, data we obtain from Google APIs (your email, profile, and Google Calendar events for connected project calendars) is used only for the following purposes:
- Identifying your account and displaying your name and avatar in the EcomBase dashboard.
- Reading your existing Google Calendar events on-demand, in order to display them alongside project tasks in the EcomBase calendar view. Read events are never persisted.
- Writing task due dates to a dedicated EcomBase project calendar you explicitly connect. We never modify events outside this project calendar.
We do not transfer Google user data to third parties except as necessary to provide or improve user-facing features, comply with applicable law, or as part of a merger, acquisition, or sale of assets with notice to you. We do not use Google user data to serve advertisements. We do not allow humans to read Google user data except (a) with your explicit consent for a specific message, (b) for security purposes (e.g., investigating abuse), (c) to comply with applicable law, or (d) where the data is aggregated and used for internal operations in accordance with applicable privacy regulations.
You can revoke EcomBase's access to your Google account at any time via your Google Account permissions page or from Settings → Integrations in EcomBase.
12. Cookies & similar tech
EcomBase uses a small number of strictly necessary cookies:
next-auth.session-token— keeps you signed in.next-auth.csrf-token— prevents cross-site request forgery on auth routes.ecombase.shop— remembers which shop you're currently viewing.
We do not use third-party advertising or analytics trackers on the EcomBase marketing site. Basic privacy-preserving page-view counts are collected server-side without a cookie.
12. Security
- TLS everywhere, HSTS on production domains.
- At-rest encryption via Neon + AES-256-GCM for sensitive columns (OAuth tokens, API keys).
- Role-based access inside the product, per-shop permissions.
- Background jobs isolated per tenant.
- We notify affected users within 72 hours of discovering a breach involving personal data.
13. Children
EcomBase is not directed at children under 16. We do not knowingly collect data from them. If you believe a child has provided us with data, contact us and we will delete it.
14. Changes to this policy
We may update this policy — when we do, we'll change the "Last updated" date at the top of the page and, for material changes, notify signed-in Users by email at least 14 days before the new policy takes effect.
15. Contact
HHS Holding B.V.
Email: info@hhsholding.com
Subject line for privacy matters: "Privacy".