Privacy

Privacy Policy

Last updated: August 17, 2026

1. Data controller

Controller: Lorenzo Coullet, sole proprietor (Entrepreneur individuel, EI) SIREN: 992 807 750 Address: 450 Chemin des Carriers, 83136 Forcalqueiret, France GDPR contact: support@shiiift.ai

2. Data we collect

Depending on how you use Shiiift, we may collect:

  • Account: email address, username, login information (including through Google OAuth), your company name, industry, target audience, desired tone, and custom instructions for the CMO agent.

  • Content produced: the URL of the analyzed site, public content scraped from that site, tracked prompts, followed topics, added competitors, conversations with the CMO agent, generated articles, and data from Google Search Console (clicks, impressions, positions, queries) when you connect your GSC account.

  • Payment: transaction-related information (processed by Stripe; we do not store card numbers).

  • Product usage: navigation events, pages viewed, interactions, and display preferences.

  • Technical: IP address, user agent, server logs, cookies, and technical identifiers.

3. Purposes and legal bases

  • Account creation and management (email or Google OAuth authentication): performance of the contract and pre-contractual measures.

  • Access to the service and rights management (Essential / Pro / Business / Enterprise plans): performance of the contract.

  • AI visibility analysis (sending prompts to third-party LLMs, aggregating results, scoring): performance of the contract.

  • Connection to Google Search Console and retrieval of the related data: performance of the contract, based on your explicit consent through the Google OAuth flow.

  • Content and recommendation generation by the CMO agent: performance of the contract.

  • Payment, fraud prevention, and proof of transaction: performance of the contract and legitimate interest.

  • Customer support: legitimate interest and performance of the contract.

  • Product improvement and security (performance measurement, analytics): legitimate interest.

  • Technical security logs: legitimate interest.

  • Product, onboarding, and service emails: legitimate interest or performance of the contract.

  • Marketing emails: consent (where required), with easy unsubscribe on every send.

  • Targeted advertising (for example Meta Ads, LinkedIn Ads): consent. You can withdraw your consent at any time through the cookie banner or by contacting us at support@shiiift.ai.

4. Retention periods

  • Active account data: for the entire duration of your subscription, plus 3 years from the last contact in case of inactivity.

  • Transactional data: the applicable legal accounting and tax retention period (10 years).

  • Technical security logs: 12 months maximum.

  • Google Search Console data: kept for as long as the GSC connection is active. Deleted within 30 days of disconnection.

  • Cookies: duration varies by type, detailed in Article 6 below.

5. Subprocessors and recipients

We use the following providers to operate the service:

  • Vercel Inc. (United States): hosting of the web application and assets.

  • Supabase Inc. (Singapore / United States): authentication (email and Google OAuth), database, storage, server functions, and technical logs.

  • Stripe Inc. (United States): payment processing, billing, anti-fraud, and chargeback management.

  • Google LLC (United States): Google OAuth login, access to Google Search Console (with your explicit consent), and Google Workspace for internal email.

  • OpenRouter Inc. (United States): routing of calls to the third-party language models (LLMs) used by Shiiift.

  • Anthropic, OpenAI, Google AI, xAI, DeepSeek, Perplexity: language model providers queried through OpenRouter as part of the AI visibility analysis. Your prompts are transmitted to these providers only for the duration of processing the request.

  • Framer B.V. (Netherlands): hosting of the landing page (shiiift.ai).

  • Resend Inc. (United States): sending of transactional emails (notifications, confirmations).

These providers process data only according to our instructions and in line with their confidentiality commitments.

6. Cookies and trackers

6.1 What is a cookie?

A cookie is a small text file placed on your device when you visit shiiift.ai or use the app.shiiift.ai application. It helps recognize your browser, remember certain information, and provide a tailored experience.

6.2 Cookies used

Strictly necessary cookies (no consent required, essential to the Service):

Purpose Issuer Duration Authentication and session persistence Shiiift / Supabase Session + 7 days Security (CSRF protection, fraud prevention) Shiiift / Supabase Session Technical preferences (language, theme, configuration) Shiiift 12 months Current subscription status Stripe Session

Audience measurement cookies (subject to consent where required):

Purpose Issuer Duration Statistical usage analysis Analytics tool used by Shiiift 13 months max

Advertising cookies (subject to consent, where applicable):

Purpose Issuer Duration Ad conversion tracking Meta Pixel 13 months max B2B conversion tracking LinkedIn Insight Tag 6 months max

6.3 Managing your preferences

On your first visit, a consent banner lets you accept or decline non-essential cookies. You can change your preferences at any time by:

  • Resetting the cookie banner from the footer (the "Manage my cookies" link)

  • Contacting us at support@shiiift.ai

  • Configuring your browser to block or delete cookies

In line with CNIL recommendations, your consent to non-essential cookies is valid for a maximum of 6 months. After that, the banner will be shown to you again.

Blocking all cookies may prevent the correct use of the Service, in particular authentication.

7. Security

We implement reasonable technical and organizational measures to protect your data: encryption in transit (TLS 1.2+), strict access control (Row Level Security on the database), logging of sensitive access, regular automatic backups, and environment isolation.

Since no method of transmission or storage is 100% secure, we cannot guarantee absolute security. In the event of a data breach affecting you, we will notify you within the timeframes and conditions set out by the GDPR.

8. Your rights

In accordance with the GDPR, you have the following rights over your personal data:

  • Right of access

  • Right to rectification

  • Right to erasure (the "right to be forgotten")

  • Right to object to processing

  • Right to restriction of processing

  • Right to data portability

  • Right to withdraw your consent at any time where processing is based on it

You can exercise your rights by contacting us at: support@shiiift.ai. We undertake to respond to your request within a maximum of one month.

You may also lodge a complaint with the CNIL (www.cnil.fr), or with the data protection authority of your country of residence, if you believe that the processing of your data does not comply with the applicable regulations.

8.1 Additional rights depending on your location

European Union and European Economic Area: in addition to the rights above, you may contact your local supervisory authority. For France, this is the CNIL.

United Kingdom: if you are in the United Kingdom, your data is processed in line with the UK GDPR. You have rights equivalent to those listed above and may lodge a complaint with the Information Commissioner's Office (ICO, www.ico.org.uk).

United States, including California: depending on your state of residence, you may have the right to know what personal information we collect, to access, correct or delete it, and to opt out of the "sale" or "sharing" of personal information for targeted advertising. We do not sell your personal information for money. We do use advertising cookies (Meta Pixel, LinkedIn Insight Tag) that may qualify as "sharing" for targeted advertising. You can opt out at any time by declining advertising cookies in the cookie banner, or by contacting us at support@shiiift.ai. We will not discriminate against you for exercising these rights.

9. Transfers outside the EU

Some of our providers (in particular Vercel, Supabase, Stripe, Google, OpenRouter, Anthropic, OpenAI, Resend) process data outside the European Union, mainly in the United States.

In such cases, we make sure that appropriate safeguards are in place: Standard Contractual Clauses adopted by the European Commission, certification under the Data Privacy Framework (DPF) where the provider is eligible, or any other applicable compliance mechanism, in order to ensure an adequate level of protection for your personal data.

10. Changes

This policy may change to reflect developments in the service, our infrastructure, or applicable regulations. The version published online is the version in force. We encourage you to review it regularly.

In the event of a substantial change, we will inform you by email or through a notification in the application.

© 2026 Shiiift. All rights reserved.

© 2026 Shiiift. All rights reserved.