Privacy policy
Last updated: July 24, 2026
ShopiCraft is a trading name of Daniel Perera, sole trader, based in Dublin, Ireland. We provide professional Shopify consulting and development services.
This Privacy Policy explains how we collect, use and share personal information when you visit this website, contact us, book a call, or engage us for a project. For the purposes of the General Data Protection Regulation (GDPR), we are the data controller of the personal information described in this policy.
If you have any questions, contact us at support@shopicraft.io.
1. WHAT THIS POLICY COVERS
This policy covers personal information we hold about website visitors, enquirers, businesses we contact, and clients.
It does not cover personal information we handle on behalf of a client during a project, for example customer records inside a client's Shopify store. In those circumstances we act as a data processor and the client remains the data controller. See section 10.
2. PERSONAL INFORMATION WE COLLECT
Depending on how you interact with us, we may collect:
- Contact details. Your name, email address, business name, and any phone number or billing address you provide.
- Enquiry information. The content of your message and any business context you share when contacting us or requesting a quotation.
- Booking information. Your name, email address, timezone and any details you enter when scheduling a call through our booking tool.
- Call recordings and transcripts. Where a call is recorded, an audio recording, an automated transcript, and an automated summary. See section 4.
- Engagement information. Project correspondence, requirements, scope documents, invoices and payment records relating to work we carry out for you.
- Access credentials. Where you invite us as a collaborator or staff user on a Shopify store or other system so that we can carry out work.
- Business contact information. Where we contact a business directly to introduce our services, publicly available business contact details and related company information. See section 5.
- Device and usage information. Your IP address, browser and device type, pages viewed and how you navigate this website, collected through cookies and similar technologies.
We do not knowingly collect special category data, such as health or biometric data, and we ask that you do not send it to us.
3. HOW WE USE PERSONAL INFORMATION, AND OUR LAWFUL BASIS
Responding to enquiries, scheduling and holding calls, and preparing quotations.
Lawful basis: steps taken at your request before entering into a contract, and our legitimate interest in responding to people who contact us.
Delivering agreed work, managing the engagement, and invoicing.
Lawful basis: performance of a contract with you.
Recording and transcribing calls where agreed.
Lawful basis: your consent, which you may withdraw at any time.
Contacting businesses to introduce our services.
Lawful basis: our legitimate interest in promoting our services to businesses likely to find them relevant. See section 5.
Operating and securing this website, and understanding how it is used.
Lawful basis: our legitimate interest in maintaining and improving our website. Where analytics cookies are used, your consent.
Keeping accounting and tax records.
Lawful basis: compliance with a legal obligation under Irish law.
Establishing, exercising or defending legal claims.
Lawful basis: our legitimate interest in protecting our business.
We do not sell personal information, and we do not share it for cross-context behavioural advertising.
4. CALL RECORDING AND TRANSCRIPTION
We use a third-party meeting assistant to record, transcribe and summarise some client calls, so that we have an accurate record of what was discussed and agreed.
Calls are only recorded where all participants have been asked for their consent at the start of the call and have agreed. You may decline, and we will continue the call without recording. You may also withdraw your consent during or after the call. Declining or withdrawing will not affect the service you receive.
Recordings, transcripts and summaries are stored in our meeting assistant provider's platform and are accessible only to us. You may ask us to delete a recording relating to a call you attended by emailing support@shopicraft.io.
5. MARKETING AND BUSINESS OUTREACH
We do not send marketing newsletters.
We may contact businesses directly to introduce our services where we believe those services are relevant to that business. Where we do this:
- We obtain business contact details from publicly available sources, business directories, professional networks and third-party business data providers.
- We process this information on the basis of our legitimate interest in promoting our services to businesses likely to find them relevant. Before contacting anyone we assess that interest against the rights and reasonable expectations of the individuals concerned.
- We contact people in their business capacity, using business contact details. We do not contact individuals in a personal capacity.
- Where we have obtained your details from a source other than you, we will tell you what that source was in our first message to you.
- Every message includes a clear and simple way to ask us not to contact you again.
- If you ask us to stop, we will stop, and we will retain the minimum information necessary on a suppression list so that we do not contact you again in error.
You may object to this processing at any time by replying to any message or emailing support@shopicraft.io. We will act on your request without needing a reason.
6. COOKIES AND ANALYTICS
This website uses cookies and similar technologies to operate the site, remember your preferences, and understand how visitors use it.
We use Google Analytics to measure website traffic and usage, and Google Search Console to understand how the site performs in search results. Search Console does not set cookies on this site.
Where required, non-essential cookies are set only after you consent through the cookie banner shown when you first visit. You can change your preferences at any time through the banner or through your browser settings.
7. WHO WE SHARE PERSONAL INFORMATION WITH
We share personal information with service providers who help us operate our business. Each processes it on our instructions and under a written agreement.
- Shopify. Website and store hosting, order and invoicing records.
- Calendly. Call scheduling and confirmations.
- Fathom. Meeting recording, transcription and summaries.
- Google. Email, documents and file storage through Google Workspace, and website analytics through Google Analytics.
- Notion. Project and client documentation.
- n8n. Workflow automation.
We may also disclose personal information to our accountant or professional advisers, and to a public authority or court where we are legally required to do so.
8. INTERNATIONAL TRANSFERS
Some of the providers listed above are based outside the European Economic Area, including in the United States. Where personal information is transferred outside the EEA, we rely on an appropriate safeguard recognised under the GDPR, such as the European Commission's Standard Contractual Clauses, an adequacy decision, or the provider's certification under an approved transfer framework.
You may request further information about the safeguards that apply by contacting us.
9. HOW LONG WE KEEP PERSONAL INFORMATION
- Enquiries that do not lead to an engagement: up to 12 months from our last contact.
- Business outreach records: up to 24 months from our last contact.
- Suppression list records: for as long as necessary to honour your request not to be contacted.
- Client records, contracts and correspondence: 6 years from the end of the engagement, in line with Irish record-keeping requirements.
- Invoices and accounting records: 6 years, as required by Irish tax law.
- Call recordings, transcripts and summaries: up to 12 months, or sooner on request.
- Website analytics: in line with the retention period configured in Google Analytics.
We delete or anonymise personal information once it is no longer needed for the purpose it was collected for.
10. WHEN WE ACT AS A DATA PROCESSOR
During a client project we often access systems containing personal information belonging to our client's own customers, for example customer records, orders or email subscriber lists inside a Shopify store.
In those circumstances the client is the data controller and we act as a data processor. We access that information only as necessary to carry out the agreed work, only on the client's documented instructions, and we do not use it for our own purposes.
Where required, we enter into a written data processing agreement with the client setting out the scope, duration and security measures applying to that processing. Clients may request one at any time by emailing support@shopicraft.io.
11. SECURITY
We take reasonable technical and organisational measures to protect personal information, including access controls, multi-factor authentication on business accounts, and limiting access to systems on a need-to-know basis.
No method of transmission or storage is completely secure, so we cannot guarantee absolute security. Please do not send sensitive information to us through unsecured channels.
12. YOUR RIGHTS
Under the GDPR you have the right to:
- Access the personal information we hold about you.
- Have inaccurate personal information corrected.
- Request deletion of your personal information.
- Restrict or object to how we process your personal information, including objecting to business outreach.
- Receive your personal information in a portable format.
- Withdraw consent at any time where we rely on consent. This does not affect processing carried out before you withdrew it.
To exercise any of these rights, email support@shopicraft.io. We may need to verify your identity first. We will respond within one month, and will tell you if we need longer.
13. COMPLAINTS
If you are unhappy with how we have handled your personal information, please contact us first so that we can try to resolve it.
You also have the right to lodge a complaint with the Irish Data Protection Commission, the supervisory authority for Ireland, at dataprotection.ie. If you live in another EEA country, you may complain to your local supervisory authority instead.
14. CHANGES TO THIS POLICY
We may update this policy to reflect changes to our practices or for legal or operational reasons. We will post the updated version here and change the "Last updated" date above.
15. CONTACT
ShopiCraft (Daniel Perera, sole trader)
Spencer Dock, Dublin, D01 CC60, Ireland
support@shopicraft.io
We are the data controller of the personal information described in this policy.