Woo Ops privacy policy
The shortest possible version. The app connects to your store directly. Your store password, your orders and your customers' data stay on your phone and never reach our servers. Our cloud handles the account, the subscription, notifications and Pro features, and it then sees only what we describe in sections 4 and 5: the account email address, your store address, product purchase costs and summary sales numbers. There are no names, addresses or email addresses of your customers there.
- Who is responsible for the data
- Two different roles: controller and processor
- What stays on the phone and what goes to the cloud
- Data we process as a controller
- Store data, meaning your customers' data
- AI features
- Push notifications
- App error diagnostics
- Payments and subscriptions
- Who we share data with
- Transfers outside the European Economic Area
- How long we keep data
- Your rights
- Deleting your account and data
- Security
- App permissions on your phone
- Cookies and the wooops.pl website
- Children
- Changes to this policy
- Contact
1. Who is responsible for the data
The controller of personal data in the scope described in section 4 is:
APTURN Spółka z ograniczoną odpowiedzialnością
ul. Pustola 24/49, 01-129 Warszawa, Poland
NIP 5273142724 (tax identification number) · REGON 540378447 (statistical number) · KRS 0001142653 (National Court Register number)
Share capital: PLN 5,000.00
E-mail: kontakt@wooops.pl
We have not appointed a data protection officer. For all matters concerning personal data, write to the address above.
2. Two different roles: controller and processor
This distinction matters, because it determines who is responsible for what.
- We are the controller of your data as a Woo Ops user: the account email address, billing data and device identifier. The purposes and legal bases are described in section 4.
- We are the processor of the personal data of your customers held in your WooCommerce store. You are the controller of that data. The rules of that processing on behalf are set out in a separate document: the data processing agreement, which forms part of our contract with you.
3. What stays on the phone and what goes to the cloud
Woo Ops is built of two layers and we do not hide where the line runs.
Core Private
The app on your phone connects to your WooCommerce store directly, with no middleman on our side. The special application password you create in your store admin is kept in the phone's system key store (Keychain on iOS, Keystore on Android) and is never sent to our servers. Orders, products, stock levels and customer data are downloaded straight from the store into the phone's memory.
Woo Ops Cloud
The cloud at api.apturn.pl handles the account, the subscription and
Pro plan features. The push.apturn.pl service handles instant notifications.
Only what we list in sections 4, 6, 7 and 9 goes to the cloud.
We say this plainly, because it is more honest than the slogan "nothing leaves your phone". Cloud features are cloud features. If you enable AI, store uptime monitoring or the plugin security scan, the data described below goes to our server, including your store's web address. You see the scope before enabling a feature, and simply not enabling it means the data is not sent.
4. Data we process as a controller
| Data | Purpose | Legal basis |
|---|---|---|
| The email address and password for your Woo Ops account (we store the password only as an Argon2id hash, we do not know it) | Creating and running the account, signing in, assigning the subscription | Article 6(1)(b) GDPR: performance of a contract |
| Device token (an identifier issued by Firebase Cloud Messaging) and operating system type | Delivering push notifications to your devices | Article 6(1)(b) GDPR: performance of a contract |
| Your store's web address: as an irreversible hash for product costs and notifications, and in plain form for uptime monitoring and the security scan | Assigning data to the right store, checking store availability, detecting plugin vulnerabilities | Article 6(1)(b) GDPR: performance of a contract |
| Product purchase costs that you enter yourself (product identifier, amount, currency) | Calculating margin on the Pro plan across several devices | Article 6(1)(b) GDPR: performance of a contract |
| The list of your store's plugins and themes together with their versions, and the store address | Warning about known vulnerabilities (a Pro feature) | Article 6(1)(b) GDPR: performance of a contract |
| Billing data: plan, period, currency, transaction identifier from the app store or the payment provider | Handling the subscription, granting entitlements, tax obligations | Article 6(1)(b) and (c) GDPR: contract and legal obligation |
| IP address and timestamp of a failed sign-in attempt | Protecting the account against password attacks | Article 6(1)(f) GDPR: our legitimate interest in the security of the service |
| The content of the correspondence you send us | Handling your request or complaint | Article 6(1)(b) and (f) GDPR |
Providing this data is voluntary, but without an email address you cannot create an account, and without an account the cloud features and the subscription do not work. We do not use automated decision-making that produces legal effects concerning you, nor profiling within the meaning of Article 22 GDPR.
5. Store data, meaning your customers' data
Orders, buyer details, delivery addresses, phone numbers, email addresses and order notes are downloaded from your store straight into your phone's memory and stored there so that the app also works without an internet connection. We do not keep a copy of your order or customer database on our servers. We have no access to that data.
The first download covers orders from the last 90 days, after which the app fetches only changes. The data disappears from the phone when you disconnect the store in the app or uninstall the app.
For that data we act as a processor on your instructions. The details, including the list of sub-processors and the security measures, are in the data processing agreement.
6. AI features
AI features work on the Pro plan and only when you use them yourself. The language model is provided by Anthropic PBC (United States). Requests are sent by our server; the app does not connect to Anthropic directly.
What reaches the model
- Automatically generated summaries and analyses (the morning briefing, the weekly summary, an explanation of a number, a product description) receive only summary numbers and product names: the period, the currency, sales amounts, order counts, margin and refund percentages, the list of low stock products and alert contents. The scope is limited by a closed list of fields on the server side and by hard length limits. There are no names, addresses, email addresses or phone numbers of your customers there.
- A question asked in your own words in the "Ask Woo Ops" feature is sent to the model as the text you type yourself, up to 240 characters.
This has a practical consequence and we prefer to name it. The automatic paths never pass on your customers' personal data. If, however, you type into your own question the name or address of a buyer, for example, that text will be sent to Anthropic along with the question. Please do not put personal data into the content of your questions.
We record AI feature usage (account identifier, token count, cost, request type) in order to account for plan limits. We do not store the content of requests and responses on our servers.
7. Push notifications
Notifications are delivered by Firebase Cloud Messaging (Google). Through it we send only a technical message containing the store identifier, the event type, the object identifier and a timestamp. The text you see on screen is assembled locally by your phone from data it already has. No names, amounts or email addresses of your customers pass through Google's infrastructure.
If you install the optional Woo Ops Connect plugin, your store sends an event
notice to the push.apturn.pl service. From it we use only the
object identifier, so that we know what to notify you about; we do not store
the contents of the notice.
8. App error diagnostics
The app uses Sentry (Functional Software, Inc., United States) to report crashes. Technical information goes there: the error type, the place in the code, the device model and the system version. The tool is configured so that it does not collect the user's personal data; we do not send the contents of your orders or your customer data to it.
9. Payments and subscriptions
How you pay depends on where you buy:
- In the Android app the subscription is sold by Google through Google Play. Card details and billing are handled by Google; we receive only a purchase confirmation, so that we can grant the plan entitlements.
- Outside Google Play the payment is handled by Stripe. We pass your account email address and account identifier to Stripe. We never see or store your payment card details.
Data needed for tax settlements is kept for the period required by law, as a rule 5 years counted from the end of the year in which the tax payment deadline fell.
10. Who we share data with
| Entity | Role | Scope |
|---|---|---|
| Anthropic PBC (USA) | Language model | Summary numbers and product names; the content of a question if you ask one yourself |
| Google Ireland Ltd. / Google LLC | Push notifications, distribution and sales in Google Play | Device token, technical message; transaction data on Google's side |
| Stripe Payments Europe, Ltd. | Payment handling outside Google Play | Account email address, account identifier, transaction data |
| Functional Software, Inc. (Sentry, USA) | App crash diagnostics | Technical error and device data |
| Apple Inc. | App distribution in the App Store | Data on Apple's side, in line with Apple's policy |
| The provider of the servers running Woo Ops Cloud | Hosting | Data from section 4 stored on the server |
We may also disclose data to authorities entitled to it under the law, if they submit a request in the form provided for by law.
11. Transfers outside the European Economic Area
Using Anthropic and Sentry involves transferring data to the United States. The transfer takes place on the basis of standard contractual clauses approved by the European Commission or another mechanism provided for in Chapter V of the GDPR, as set out in our agreements with those providers. We provide a copy of, or information about, the safeguard applied on request sent to the address in section 20.
12. How long we keep data
- Account data and the data from section 4 assigned to it: for as long as you have the account. Deleting the account erases them immediately, with no grace period, together with entitlements, device tokens, product costs, monitoring configuration and AI usage records.
- Billing data and accounting documents: 5 years counted from the end of the year in which the tax payment deadline fell.
- IP address from a failed sign-in: deleted after a successful sign-in, and in no case later than after 90 days.
- Store uptime check results: 48 hours.
- AI feature usage records: 24 months, for the purpose of accounting for limits and handling complaints.
- Correspondence: 12 months from the last contact, unless a longer period follows from defending against claims.
- Data in your phone's memory: until you disconnect the store in the app or uninstall the app. You control it yourself.
13. Your rights
You have the right to: access your data and obtain a copy of it, rectification, erasure, restriction of processing, data portability and objection to processing based on our legitimate interest.
Send your request to kontakt@wooops.pl. We reply without undue delay and within one month at the latest.
You also have the right to lodge a complaint with the supervisory authority: the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warsaw, Poland.
If your request concerns the personal data of store customers, address it to the store owner, who is their controller. We may act only on that owner's instructions.
14. Deleting your account and data
We will delete your Woo Ops account and the data linked to it at your request.
In the app, immediately. Account, then Delete account, confirmed with your password. Deletion runs at once, with no grace period, and cannot be undone. We ask for the password because a signed-in phone alone should not be enough to erase someone else's data.
Or by email. Write to kontakt@wooops.pl from the address assigned to the account. We will confirm receipt within 7 days and delete the account within 30 days at the latest.
The deletion covers the email address, the password hash, device tokens, the product costs you entered, the monitoring configuration and the AI usage records. We keep only the data that tax and accounting regulations require us to keep, in the scope and for the period stated in section 12. Data held in your phone's memory you delete yourself, by disconnecting the store or uninstalling the app.
Deleting the account means losing access to the cloud features. Cancel an active subscription separately, where you bought it.
15. Security
- Connections to our services and to your store are encrypted (HTTPS/TLS).
- We store the Woo Ops account password only as an Argon2id hash.
- The application password for your store is kept in the phone's system key store and does not leave the device.
- Only authorised people have access to production servers, and the number of failed sign-ins is limited.
No safeguard gives a hundred per cent certainty. If a personal data breach occurs that may result in a high risk to your rights, we will notify you without undue delay.
16. App permissions on your phone
- Camera: scanning barcodes in inventory and the QR code when connecting a store. The camera image is processed on the device and is not sent anywhere.
- Notifications: delivering alerts about events in your store.
- Network access and connection state information: connecting to your store and queuing changes when there is no internet.
- Vibration and wake lock: signalling notifications and finishing a sync.
You can withdraw any of these permissions in your system settings. Withdrawing camera access disables the scanner, withdrawing notifications disables alerts.
17. Cookies and the wooops.pl website
The wooops.pl website does not use cookies, does not use web analytics and does not embed third-party content. Typefaces are served from our own server, so browsing this site sends no data to third parties. For that reason we do not display a consent banner, because there is nothing to consent to.
The server hosting the site records standard access logs covering the IP address, the request date and the browser type. The basis is our legitimate interest in maintaining and securing the site (Article 6(1)(f) GDPR).
18. Children
Woo Ops is a tool for running a business and is not intended for people under 16. We do not knowingly collect children's data.
19. Changes to this policy
We will inform you of material changes at least 14 days in advance, by an email message to the address assigned to your account or by a notice in the app. At the end of the document we state the version number and the date it takes effect.
20. Contact
APTURN Sp. z o.o., ul. Pustola 24/49, 01-129 Warszawa, Poland
kontakt@wooops.pl
Woo Ops