Draft. Entries marked “To be completed · Angaben werden ergänzt” are being completed; until they are, this page is not offered to search engines.
1. Controller
The controller within the meaning of Art. 4(7) GDPR for the processing described here is:
- Provider
- ARCHITECT Commerce, Inc.
- Street
- 1521 Concord Pike, Suite 201
- Postal code, city
- Wilmington, DE 19803
- Country
- United States of America
- Represented by
- To be completed · Angaben werden ergänzt
- info@architectcommerce.com
- Phone
- To be completed · Angaben werden ergänzt
2. What this policy covers
This policy covers the website architectcommerce.com (including the www and staging subdomains), the client portal under /portal, the read-only share pages under /portal/share, and the e-mails we send about analyses and requests. The ARCHITECT Music services on architectmusic.ai are a separate offer with their own privacy policy.
3. Hosting and technical logs
The site is served from a server we operate. When you open a page, the reverse proxy and the application may record the requested URL, date and time, HTTP status, the referring page, your browser's user-agent string and your IP address in technical logs. We use these logs to keep the service secure and to diagnose errors (Art. 6(1)(f) GDPR). They are not merged with other data about you.
The domain's DNS is hosted at Cloudflare. At the time of this version, visitor requests are not routed through Cloudflare's proxy network; they reach our server directly.
- Hosting provider
- Google Cloud EMEA Limited / Google LLC — Firebase App Hosting (europe-west4), Cloud Firestore, BigQuery; Hetzner Online GmbH, Gunzenhausen (Germany) — the server that serves architectcommerce.com, runs the crawlers and the Postgres database; Cloudflare, Inc. — DNS and Turnstile; Sinch Mailgun (EU region) — transactional e-mail
Retention period of the technical logs: to be confirmed and stated here.
4. Contact form
The form on /contact asks for your name, e-mail address, an optional company name and your message. We receive the submission as an e-mail and use it to answer you (Art. 6(1)(b) GDPR). To limit abuse, a per-IP counter (IP address and timestamps) is stored in our database for a short window around the submission (Art. 6(1)(f) GDPR).
The form is protected by Cloudflare Turnstile. The Turnstile script is loaded from challenges.cloudflare.com, and Cloudflare, Inc. (San Francisco, USA) processes your IP address and browser and device signals to tell people from bots. Legal basis is our legitimate interest in keeping the form free of automated abuse (Art. 6(1)(f) GDPR); see section 11 for transfers to the USA.
For funnel statistics we additionally record that a submission happened and the page it came from — never its content — together with the technical fingerprint described in section 5.
5. Analysis requests and the client account
Requesting a potential analysis requires a client account. Sign-in runs on Firebase Authentication (Google). Google stores your e-mail address, a hashed password, a user id and sign-in timestamps on our behalf. Firebase App Check with reCAPTCHA Enterprise (Google) protects the sign-in and portal APIs; it processes your IP address and browser signals to score whether a request comes from a real browser.
A request stores the brand name, category and market you enter, together with the e-mail address of your account as the requester, in our database (Cloud Firestore, Google). Our team is notified of the request. The finished analysis is stored under your account and, when you or your colleagues request the same brand and market again, an existing analysis may be reused and shared with you rather than crawled again. A per-address daily cap on requests is enforced with a counter.
Purpose and legal basis: preparing and delivering the analysis you asked for (Art. 6(1)(b) GDPR). The analyses themselves concern brands and companies, not people; where a brand is run by a natural person, their trade name may appear in the analysis on the basis of Art. 6(1)(f) GDPR. Retention: as long as your account exists or the analysis is kept for you; deletion on request.
Usage records: when you use the client portal we record which analysis was opened, which portal page was viewed, whether the methodology was opened, a PDF exported or the market selection changed, and whether an audit offer was requested. Each record carries a hashed, daily-rotating fingerprint of your IP address (not the address itself), your browser family and the host name of the referring site — no cookie and no identifier that survives the day. Purpose: understanding how analyses are used and improving the service (Art. 6(1)(f) GDPR). Retention: see section 12.
7. E-mail
Notifications about requests and released analyses are sent through Sinch Mailgun using its EU sending region, from the sub-domain mg.architectcommerce.com. Mailgun processes the recipient address, the message and delivery events (accepted, delivered, bounced) on our behalf. Open and click tracking are switched off for this sending domain (verified 2026-08-27): no tracking pixel is embedded and links are not rewritten.
Legal basis: Art. 6(1)(b) GDPR for the e-mails that belong to your request, Art. 6(1)(f) GDPR for delivery diagnostics.
8. Analytics and usage measurement
Firebase Analytics (Google Analytics 4) records page views and clicks on links and buttons on this site — the path, the link target and the trimmed link text. Google Ireland Limited and Google LLC (USA) process this together with identifiers stored in cookies or browser storage, your IP address and device information.
Contentsquare (Contentsquare SAS, Paris) is loaded from t.contentsquare.net only after you accept analytics in the cookie banner, and never on client-portal or share-link pages; it records how a page is used (scrolling, clicks, session-level interaction) for product improvement.
Legal basis: consent (Art. 6(1)(a) GDPR, § 25(1) TDDDG).
Consent control for Firebase Analytics on this site: to be completed (it currently starts without a consent choice; share-link pages are excluded and share tokens are never sent).
9. The public Shopify store directory
The pages under /shops, /brands, /catalog and /search publish observations from Shopify storefronts. Our sweeper reads the public catalogue that every Shopify storefront serves to any visitor — product titles, vendors, prices, stock status and the storefront's public metadata — at intervals, and stores the readings as a time series. From these readings we publish per-store aggregates (product count, price levels, discount activity, stock rate, the brands a store carries, the country a store states), lists of newest products and largest discounts, and brand pages that list the stores carrying a brand.
Where a store is run by a natural person, the store domain, the vendor name and the store's public metadata can be personal data. Source of that data is the store's own public storefront (Art. 14(2)(f) GDPR). We do not read customer, order, account or contact data, and opening a directory page does not contact the store — the page is rendered from our own database.
Legal basis is our legitimate interest in market transparency and in providing e-commerce intelligence to brands (Art. 6(1)(f) GDPR): the data published here is what the store itself publishes to every visitor, aggregated. Store operators may object to the publication on grounds relating to their particular situation (Art. 21 GDPR) by e-mail to the address in section 1. We assess the objection and, unless compelling legitimate grounds exist, stop publishing the store's pages.
10. Recipients and processors
The following providers process data on our behalf under data-processing agreements:
- Google Cloud EMEA Limited / Google Ireland Limited (Firebase Authentication, Cloud Firestore, App Check with reCAPTCHA Enterprise, Firebase Analytics, Google Cloud data services used to compile analyses).
- Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany (dedicated server hosting for the architectcommerce.com web application, the store crawlers and the Postgres database; data centre in Germany).
- Cloudflare, Inc. (Turnstile on the contact form; DNS for the domain).
- Sinch Mailgun (Mailgun Technologies, Inc.; EU sending region) for transactional e-mail.
- Contentsquare SAS for usage measurement.
- The hosting provider of the public site (see section 3).
11. Transfers outside the EU/EEA
Google, Cloudflare and Contentsquare may process data in the United States. Transfers rely on the EU-U.S. Data Privacy Framework where the provider is certified under it, and otherwise on the European Commission's standard contractual clauses (Art. 46(2)(c) GDPR).
12. Retention
- Technical logs: short-term, for security and troubleshooting (see section 3).
- Contact-form submissions: as long as needed to handle the enquiry, plus statutory retention where the exchange becomes part of a contract.
- Client account and analyses: until you delete the account or ask us to delete the analysis.
- Directory readings: as long as the directory is operated; aggregates are recomputed from the time series.
Retention period for portal usage records (sections 5 and 6): to be set — no automatic deletion is configured for them yet.
13. Your rights
You have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on legitimate interest (Art. 21 GDPR). Consent can be withdrawn at any time with effect for the future. To exercise a right, write to the e-mail address in section 1. You also have the right to lodge a complaint with a data-protection supervisory authority.
- Supervisory authority
- To be completed · Angaben werden ergänzt
14. Changes
We update this policy when the service or the law changes. The version date is shown at the top of the page; the current version applies.